<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:podcast="https://podcastindex.org/namespace/1.0" xmlns:media="http://search.yahoo.com/mrss/" version="2.0"><channel><title>SANS Stormcast: Daily Cyber Security News</title><link>https://isc.sans.edu</link><description><![CDATA[A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Storm Center. You may submit questions and comments via our contact form at <a href="https://isc.sans.edu/contact.html" rel="noopener">https://isc.sans.edu/contact.html</a> .]]></description><atom:link href="https://www.spreaker.com/show/2053650/episodes/feed" rel="self" type="application/rss+xml"/><language>en</language><category>Technology</category><copyright>Copyright Johannes Ullrich</copyright><image><url>https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg</url><title>SANS Stormcast: Daily Cyber Security News</title><link>https://isc.sans.edu</link></image><lastBuildDate>Tue, 11 Aug 2026 02:16:57 +0000</lastBuildDate><itunes:author>Johannes Ullrich</itunes:author><itunes:owner><itunes:name>Johannes Ullrich</itunes:name><itunes:email>handlers@isc.sans.edu</itunes:email></itunes:owner><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:subtitle>A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of current network security related events. The content...</itunes:subtitle><itunes:summary><![CDATA[A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Storm Center. You may submit questions and comments via our contact form at <a href="https://isc.sans.edu/contact.html" rel="noopener">https://isc.sans.edu/contact.html</a> .]]></itunes:summary><itunes:category text="Technology"/><itunes:explicit>false</itunes:explicit><itunes:type>episodic</itunes:type><item><title>SANS Stormcast Tuesday, August 11th, 2026: Solana Attacks; AI Generated Patches; Gunra Ransomware; Neo4J/GraphQL Patch</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-august-11th-2026-solana-attacks-ai-generated-patches-gunra-ransomware-neo4j-graphql-patch--73791569</link><description><![CDATA[<br /> Scans for Solana (Surfpool?) Endpoints<br /><a href="https://isc.sans.edu/diary/Scans%20for%20Solana%20%28Surfpool%3F%29%20Endpoints/33230" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20Solana%20%28Surfpool%3F%29%20Endpoints/33230</a><br /> Why AI-generated vulnerability patches still require expert human review<br /><a href="https://1password.com/blog/why-ai-generated-patches-still-require-human-review?_sp=15ec2845-9e6c-4d15-8ac5-fe9bc1fe4c08.1786396502013" target="_blank" rel="noreferrer noopener">https://1password.com/blog/why-ai-generated-patches-still-require-human-review?_sp=15ec2845-9e6c-4d15-8ac5-fe9bc1fe4c08.1786396502013</a><br /> Gunra Ransomware<br /><a href="https://www.cisa.gov/sites/default/files/2026-08/aa26-222a-stopransomware-gunra-ransomware_508c.pdf" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/sites/default/files/2026-08/aa26-222a-stopransomware-gunra-ransomware_508c.pdf</a><br /> Neo4J/GraphQL Vulnerability CVE-2026-5423<br /><a href="https://github.com/neo4j/graphql/security/advisories/GHSA-fcpg-3fw5-vc65" target="_blank" rel="noreferrer noopener">https://github.com/neo4j/graphql/security/advisories/GHSA-fcpg-3fw5-vc65</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/10046.mp3</guid><pubDate>Tue, 11 Aug 2026 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73791569/10046.mp3" length="5341152" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=10046" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Scans for Solana (Surfpool?) Endpoints
https://isc.sans.edu/diary/Scans%20for%20Solana%20%28Surfpool%3F%29%20Endpoints/33230
 Why AI-generated vulnerability patches still require expert human review...</itunes:subtitle><itunes:summary><![CDATA[<br /> Scans for Solana (Surfpool?) Endpoints<br /><a href="https://isc.sans.edu/diary/Scans%20for%20Solana%20%28Surfpool%3F%29%20Endpoints/33230" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20Solana%20%28Surfpool%3F%29%20Endpoints/33230</a><br /> Why AI-generated vulnerability patches still require expert human review<br /><a href="https://1password.com/blog/why-ai-generated-patches-still-require-human-review?_sp=15ec2845-9e6c-4d15-8ac5-fe9bc1fe4c08.1786396502013" target="_blank" rel="noreferrer noopener">https://1password.com/blog/why-ai-generated-patches-still-require-human-review?_sp=15ec2845-9e6c-4d15-8ac5-fe9bc1fe4c08.1786396502013</a><br /> Gunra Ransomware<br /><a href="https://www.cisa.gov/sites/default/files/2026-08/aa26-222a-stopransomware-gunra-ransomware_508c.pdf" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/sites/default/files/2026-08/aa26-222a-stopransomware-gunra-ransomware_508c.pdf</a><br /> Neo4J/GraphQL Vulnerability CVE-2026-5423<br /><a href="https://github.com/neo4j/graphql/security/advisories/GHSA-fcpg-3fw5-vc65" target="_blank" rel="noreferrer noopener">https://github.com/neo4j/graphql/security/advisories/GHSA-fcpg-3fw5-vc65</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>382</itunes:duration><itunes:keywords>ai,business,computer,cyber,cybersecurity,daily,graphql,gunra,hacking,infosec,internet,it,neo4j,network,news,patches,ransomware,security,sonana,vulnerabilities</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>10046</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, August 10th, 2026: Linux Shell Forensics; Criticial MacOS Patch; More N-Central Hotfixes; Exploited Metabase Vuln;</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-august-10th-2026-linux-shell-forensics-criticial-macos-patch-more-n-central-hotfixes-exploited-metabase-vuln--73733801</link><description><![CDATA[<br /> Linux Shell Forensic: Let s Dive Into Atuin!<br /><a href="https://isc.sans.edu/diary/Linux+Shell+Forensic+Lets+Dive+Into+Atuin/33226" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Linux+Shell+Forensic+Lets+Dive+Into+Atuin/33226</a><br /> Apple Patches macOS Screen Sharing Vulnerability<br /><a href="https://support.apple.com/en-us/148170" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/148170</a><br /> More N-Able N-Central Issues<br /><a href="https://www.n-able.com/blog/n-central-security-update-august-6-2026" target="_blank" rel="noreferrer noopener">https://www.n-able.com/blog/n-central-security-update-august-6-2026</a><br /> Metabase Unauthenticated SQL injection<br /><a href="https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf" target="_blank" rel="noreferrer noopener">https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/10044.mp3</guid><pubDate>Mon, 10 Aug 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73733801/10044.mp3" length="6764824" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=10044" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Linux Shell Forensic: Let s Dive Into Atuin!
https://isc.sans.edu/diary/Linux+Shell+Forensic+Lets+Dive+Into+Atuin/33226
 Apple Patches macOS Screen Sharing Vulnerability
https://support.apple.com/en-us/148170
 More N-Able N-Central Issues...</itunes:subtitle><itunes:summary><![CDATA[<br /> Linux Shell Forensic: Let s Dive Into Atuin!<br /><a href="https://isc.sans.edu/diary/Linux+Shell+Forensic+Lets+Dive+Into+Atuin/33226" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Linux+Shell+Forensic+Lets+Dive+Into+Atuin/33226</a><br /> Apple Patches macOS Screen Sharing Vulnerability<br /><a href="https://support.apple.com/en-us/148170" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/148170</a><br /> More N-Able N-Central Issues<br /><a href="https://www.n-able.com/blog/n-central-security-update-august-6-2026" target="_blank" rel="noreferrer noopener">https://www.n-able.com/blog/n-central-security-update-august-6-2026</a><br /> Metabase Unauthenticated SQL injection<br /><a href="https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf" target="_blank" rel="noreferrer noopener">https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>483</itunes:duration><itunes:keywords>apple,atuin,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,linux,macos,metabase,n-able,n-central,network,news,screen sharing,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>10044</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, August 7th, 2026: Fast SSH Attacks; Dell BIOS Passwd Weakness; Crypto Wallet Vuln; Benchmarking LLMs for Threat Intel</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-august-7th-2026-fast-ssh-attacks-dell-bios-passwd-weakness-crypto-wallet-vuln-benchmarking-llms-for-threat-intel--73589017</link><description><![CDATA[<br /> 22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary]<br /><a href="https://isc.sans.edu/diary/22+Seconds+to+Compromise+How+Automated+SSH+Actors+Move+From+Login+to+Persistence+Before+You+Can+Blink+Guest+Diary/33220" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/22+Seconds+to+Compromise+How+Automated+SSH+Actors+Move+From+Login+to+Persistence+Before+You+Can+Blink+Guest+Diary/33220</a><br /> Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)<br /><a href="https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/" target="_blank" rel="noreferrer noopener">https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/</a><br /> Ill Bloom: Crypto Wallet Vulnerability<br /><a href="https://illbloom.org" target="_blank" rel="noreferrer noopener">https://illbloom.org</a><br /> Benchmarking Free-Tier Large Language Models as Cognitive Aids for Operationalizing Unstructured Cyber Threat Intelligence<br /><a href="https://www.sans.edu/cyber-research/benchmarking-free-tier-large-language-models-cognitive-aids-operationalizing-unstructured-cyber-threat-intelligence" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/benchmarking-free-tier-large-language-models-cognitive-aids-operationalizing-unstructured-cyber-threat-intelligence</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/10042.mp3</guid><pubDate>Fri, 07 Aug 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73589017/10042.mp3" length="13850875" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=10042" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary]...</itunes:subtitle><itunes:summary><![CDATA[<br /> 22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary]<br /><a href="https://isc.sans.edu/diary/22+Seconds+to+Compromise+How+Automated+SSH+Actors+Move+From+Login+to+Persistence+Before+You+Can+Blink+Guest+Diary/33220" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/22+Seconds+to+Compromise+How+Automated+SSH+Actors+Move+From+Login+to+Persistence+Before+You+Can+Blink+Guest+Diary/33220</a><br /> Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)<br /><a href="https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/" target="_blank" rel="noreferrer noopener">https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/</a><br /> Ill Bloom: Crypto Wallet Vulnerability<br /><a href="https://illbloom.org" target="_blank" rel="noreferrer noopener">https://illbloom.org</a><br /> Benchmarking Free-Tier Large Language Models as Cognitive Aids for Operationalizing Unstructured Cyber Threat Intelligence<br /><a href="https://www.sans.edu/cyber-research/benchmarking-free-tier-large-language-models-cognitive-aids-operationalizing-unstructured-cyber-threat-intelligence" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/benchmarking-free-tier-large-language-models-cognitive-aids-operationalizing-unstructured-cyber-threat-intelligence</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>989</itunes:duration><itunes:keywords>bios,business,crypto,cryptojs,cyber,cybersecurity,daily,hacking,ill bloom,infosec,it,llm,network,news,research,@sans_edu,sans.edu,ssh,threatintel,wallet</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>10042</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, August 6th, 2026: keyv/cachable Worm IR; Apple Private Relay Leak; COLDCARD Phish</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-august-6th-2026-keyv-cachable-worm-ir-apple-private-relay-leak-coldcard-phish--73528876</link><description><![CDATA[<br /> Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm<br /><a href="https://isc.sans.edu/diary/Don%27t%20Revoke%20That%20Token%20Yet%3A%20Inside%20the%20keyv%20cacheable%20npm%20Worm/33218" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Don%27t%20Revoke%20That%20Token%20Yet%3A%20Inside%20the%20keyv%20cacheable%20npm%20Worm/33218</a><br /> IP and DNS Leaks in WebKit Affecting Proxy Browsers and Apple iCloud Private Relay<br /><a href="https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/?ref=404media.co" target="_blank" rel="noreferrer noopener">https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/?ref=404media.co</a><br /> COLDCARD Issues<br /><a href="https://x.com/threatinsight/status/2084328552481112429" target="_blank" rel="noreferrer noopener">https://x.com/threatinsight/status/2084328552481112429</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/10040.mp3</guid><pubDate>Thu, 06 Aug 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73528876/10040.mp3" length="7044439" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=10040" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm
https://isc.sans.edu/diary/Don%27t%20Revoke%20That%20Token%20Yet%3A%20Inside%20the%20keyv%20cacheable%20npm%20Worm/33218
 IP and DNS Leaks in WebKit Affecting Proxy Browsers and Apple...</itunes:subtitle><itunes:summary><![CDATA[<br /> Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm<br /><a href="https://isc.sans.edu/diary/Don%27t%20Revoke%20That%20Token%20Yet%3A%20Inside%20the%20keyv%20cacheable%20npm%20Worm/33218" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Don%27t%20Revoke%20That%20Token%20Yet%3A%20Inside%20the%20keyv%20cacheable%20npm%20Worm/33218</a><br /> IP and DNS Leaks in WebKit Affecting Proxy Browsers and Apple iCloud Private Relay<br /><a href="https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/?ref=404media.co" target="_blank" rel="noreferrer noopener">https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/?ref=404media.co</a><br /> COLDCARD Issues<br /><a href="https://x.com/threatinsight/status/2084328552481112429" target="_blank" rel="noreferrer noopener">https://x.com/threatinsight/status/2084328552481112429</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>503</itunes:duration><itunes:keywords>browser,business,cacheable,coldcard,cyber,cybersecurity,daily,hacking,icloud,infosec,it,keyv,network,news,npm,phishing,private relay,proxy,tor,worm</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>10040</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, August 5th, 2026: Diagnostic Tool Hunt; Device Code Phishing; XCSSET; NuGet API Keys</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-august-5th-2026-diagnostic-tool-hunt-device-code-phishing-xcsset-nuget-api-keys--73469738</link><description><![CDATA[<br /> Botnet Hunting for Vulnerabilities in Diagnostic Tools<br /><a href="https://isc.sans.edu/diary/Botnet%20Hunting%20for%20Vulnerabilities%20in%20Diagnostic%20Tools/33214" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Botnet%20Hunting%20for%20Vulnerabilities%20in%20Diagnostic%20Tools/33214</a><br /> Inside Greatness: Telegram-Distributed M365 AiTM PhaaS<br /><a href="https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing" target="_blank" rel="noreferrer noopener">https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing</a><br /> A Deep Dive Into the Latest XCSSET Version<br /><a href="https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/</a><br /> Strengthening NuGet Supply Chain Security: Reducing API Key Lifetime<br /><a href="https://devblogs.microsoft.com/dotnet/strengthening-nuget-supply-chain-security-reducing-api-key-lifetime/" target="_blank" rel="noreferrer noopener">https://devblogs.microsoft.com/dotnet/strengthening-nuget-supply-chain-security-reducing-api-key-lifetime/</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/10038.mp3</guid><pubDate>Wed, 05 Aug 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73469738/10038.mp3" length="5462533" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=10038" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Botnet Hunting for Vulnerabilities in Diagnostic Tools
https://isc.sans.edu/diary/Botnet%20Hunting%20for%20Vulnerabilities%20in%20Diagnostic%20Tools/33214
 Inside Greatness: Telegram-Distributed M365 AiTM PhaaS...</itunes:subtitle><itunes:summary><![CDATA[<br /> Botnet Hunting for Vulnerabilities in Diagnostic Tools<br /><a href="https://isc.sans.edu/diary/Botnet%20Hunting%20for%20Vulnerabilities%20in%20Diagnostic%20Tools/33214" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Botnet%20Hunting%20for%20Vulnerabilities%20in%20Diagnostic%20Tools/33214</a><br /> Inside Greatness: Telegram-Distributed M365 AiTM PhaaS<br /><a href="https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing" target="_blank" rel="noreferrer noopener">https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing</a><br /> A Deep Dive Into the Latest XCSSET Version<br /><a href="https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/</a><br /> Strengthening NuGet Supply Chain Security: Reducing API Key Lifetime<br /><a href="https://devblogs.microsoft.com/dotnet/strengthening-nuget-supply-chain-security-reducing-api-key-lifetime/" target="_blank" rel="noreferrer noopener">https://devblogs.microsoft.com/dotnet/strengthening-nuget-supply-chain-security-reducing-api-key-lifetime/</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>390</itunes:duration><itunes:keywords>botnet,business,computer,cyber,cybersecurity,daily,device code,diagnostic,hacking,infosec,it,m365,mitm,network,news,nuget,phishing,security,telegram,xcsset</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>10038</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, August 4th, 2026: More Arch Linux AUR trouble; iCloud Sharing; Pass the Passkey</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-august-4th-2026-more-arch-linux-aur-trouble-icloud-sharing-pass-the-passkey--73415653</link><description><![CDATA[<br /> AUR packages adoption disabled<br /><a href="https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/DRDEU3JUSC72CB265XHXPFA3DFSLXPBP/" target="_blank" rel="noreferrer noopener">https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/DRDEU3JUSC72CB265XHXPFA3DFSLXPBP/</a><br /> Apple's iCloud File Sharing Left Ex-Employees With Access to Secret Documents<br /><a href="https://www.macrumors.com/2026/08/03/apple-icloud-sharing-ex-employees/" target="_blank" rel="noreferrer noopener">https://www.macrumors.com/2026/08/03/apple-icloud-sharing-ex-employees/</a><br /> Pass the Passkey: A Novel Attack Surface in Passwordless Authentication<br /><a href="https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/10036.mp3</guid><pubDate>Tue, 04 Aug 2026 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73415653/10036.mp3" length="5745688" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=10036" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 AUR packages adoption disabled
https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/DRDEU3JUSC72CB265XHXPFA3DFSLXPBP/
 Apple's iCloud File Sharing Left Ex-Employees With Access to Secret Documents...</itunes:subtitle><itunes:summary><![CDATA[<br /> AUR packages adoption disabled<br /><a href="https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/DRDEU3JUSC72CB265XHXPFA3DFSLXPBP/" target="_blank" rel="noreferrer noopener">https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/DRDEU3JUSC72CB265XHXPFA3DFSLXPBP/</a><br /> Apple's iCloud File Sharing Left Ex-Employees With Access to Secret Documents<br /><a href="https://www.macrumors.com/2026/08/03/apple-icloud-sharing-ex-employees/" target="_blank" rel="noreferrer noopener">https://www.macrumors.com/2026/08/03/apple-icloud-sharing-ex-employees/</a><br /> Pass the Passkey: A Novel Attack Surface in Passwordless Authentication<br /><a href="https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>411</itunes:duration><itunes:keywords>apple,arch,aur,business,computer,cyber,cybersecurity,daily,employee,hacking,icloud,infosec,internet,it,linux,network,news,passkey,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>10036</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, August 3rd, 2026: zipdump.py update; Atomic MacOS Analysis; OpenAI Phishing; COLDCARD Vulnerability</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-august-3rd-2026-zipdump-py-update-atomic-macos-analysis-openai-phishing-coldcard-vulnerability--73361630</link><description><![CDATA[<br /> zipdump.py Metadata Encoding<br /><a href="https://isc.sans.edu/diary/zipdumppy+Metadata+Encoding/33202/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/zipdumppy+Metadata+Encoding/33202/</a><br /> Atomic MacOS (AMOS) stealer infection<br /><a href="https://isc.sans.edu/diary/Atomic%20MacOS%20%28AMOS%29%20stealer%20infection/33208" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Atomic%20MacOS%20%28AMOS%29%20stealer%20infection/33208</a><br /> Phishing Campaigns Targeting AI Solutions Providers<br /><a href="https://isc.sans.edu/diary/Phishing+Campaigns+Targeting+AI+Solutions+Providers/33206/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Phishing+Campaigns+Targeting+AI+Solutions+Providers/33206/</a><br /> Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware<br /><a href="https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware" target="_blank" rel="noreferrer noopener">https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/10034.mp3</guid><pubDate>Mon, 03 Aug 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73361630/10034.mp3" length="6370504" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=10034" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 zipdump.py Metadata Encoding
https://isc.sans.edu/diary/zipdumppy+Metadata+Encoding/33202/
 Atomic MacOS (AMOS) stealer infection
https://isc.sans.edu/diary/Atomic%20MacOS%20%28AMOS%29%20stealer%20infection/33208
 Phishing Campaigns Targeting AI...</itunes:subtitle><itunes:summary><![CDATA[<br /> zipdump.py Metadata Encoding<br /><a href="https://isc.sans.edu/diary/zipdumppy+Metadata+Encoding/33202/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/zipdumppy+Metadata+Encoding/33202/</a><br /> Atomic MacOS (AMOS) stealer infection<br /><a href="https://isc.sans.edu/diary/Atomic%20MacOS%20%28AMOS%29%20stealer%20infection/33208" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Atomic%20MacOS%20%28AMOS%29%20stealer%20infection/33208</a><br /> Phishing Campaigns Targeting AI Solutions Providers<br /><a href="https://isc.sans.edu/diary/Phishing+Campaigns+Targeting+AI+Solutions+Providers/33206/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Phishing+Campaigns+Targeting+AI+Solutions+Providers/33206/</a><br /> Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware<br /><a href="https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware" target="_blank" rel="noreferrer noopener">https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>452</itunes:duration><itunes:keywords>atomic,business,coldcard,cold wallet,cyber,cybersecurity,daily,hacking,infosec,it,macos,network,news,open ai,phishing,random,rng,security,stealer,zipdump</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>10034</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, July 31st, 2026: Pre Botnet Recon; Cisco Backdoor Exploited; Inconsistent Group Chats</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-july-31st-2026-pre-botnet-recon-cisco-backdoor-exploited-inconsistent-group-chats--73269056</link><description><![CDATA[<br /> Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner<br /><a href="https://isc.sans.edu/diary/Reconnaissance%20First%3A%20An%20SSH%20Bot%20That%20Sizes%20Up%20Your%20Hardware%20Before%20Deploying%20a%20Miner%20%5BGuest%20Diary%5D/33198" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Reconnaissance%20First%3A%20An%20SSH%20Bot%20That%20Sizes%20Up%20Your%20Hardware%20Before%20Deploying%20a%20Miner%20%5BGuest%20Diary%5D/33198</a><br /> Cisco Secure Firewall Management Center Software Static Credential Vulnerability Exploited CVE-2026-20316<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh</a><br /> Inconsistent Group Chats<br /><a href="https://www.usenix.org/conference/usenixsecurity26/presentation/gegenhuber" target="_blank" rel="noreferrer noopener">https://www.usenix.org/conference/usenixsecurity26/presentation/gegenhuber</a><br /><a href="https://www.heise.de/en/news/Encrypted-but-wrong-Group-chats-vulnerable-to-manipulated-content-11384112.html" target="_blank" rel="noreferrer noopener">https://www.heise.de/en/news/Encrypted-but-wrong-Group-chats-vulnerable-to-manipulated-content-11384112.html</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/10032.mp3</guid><pubDate>Fri, 31 Jul 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73269056/10032.mp3" length="4910978" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=10032" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner...</itunes:subtitle><itunes:summary><![CDATA[<br /> Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner<br /><a href="https://isc.sans.edu/diary/Reconnaissance%20First%3A%20An%20SSH%20Bot%20That%20Sizes%20Up%20Your%20Hardware%20Before%20Deploying%20a%20Miner%20%5BGuest%20Diary%5D/33198" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Reconnaissance%20First%3A%20An%20SSH%20Bot%20That%20Sizes%20Up%20Your%20Hardware%20Before%20Deploying%20a%20Miner%20%5BGuest%20Diary%5D/33198</a><br /> Cisco Secure Firewall Management Center Software Static Credential Vulnerability Exploited CVE-2026-20316<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh</a><br /> Inconsistent Group Chats<br /><a href="https://www.usenix.org/conference/usenixsecurity26/presentation/gegenhuber" target="_blank" rel="noreferrer noopener">https://www.usenix.org/conference/usenixsecurity26/presentation/gegenhuber</a><br /><a href="https://www.heise.de/en/news/Encrypted-but-wrong-Group-chats-vulnerable-to-manipulated-content-11384112.html" target="_blank" rel="noreferrer noopener">https://www.heise.de/en/news/Encrypted-but-wrong-Group-chats-vulnerable-to-manipulated-content-11384112.html</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>351</itunes:duration><itunes:keywords>business,cisco,computer,cyber,cybersecurity,daily,encryption,group chats,hacking,infosec,internet,it,minder,network,news,nvidia,security,ssh</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>10032</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, July 30th, 2026: Apple Patches; IPMI Admin PW Hash Leak; VMWare Patches; OpenWRT Patch</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-july-30th-2026-apple-patches-ipmi-admin-pw-hash-leak-vmware-patches-openwrt-patch--73249435</link><description><![CDATA[<br /> Apple Patch Summary / Postscript<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything%20%28July%202026%29/33196" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Everything%20%28July%202026%29/33196</a><br /> IPMI Admin Password Hash Leak<br /><a href="https://lavahq.io/research/bmc-exposure-alert" target="_blank" rel="noreferrer noopener">https://lavahq.io/research/bmc-exposure-alert</a><br /> Patches for VMWare<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017</a><br /> OpenWRT Patch, odhcpd vulnerability CVE-2026-53921<br /><a href="https://github.com/openwrt/odhcpd/security/advisories/GHSA-7fwx-hhrg-3496" target="_blank" rel="noreferrer noopener">https://github.com/openwrt/odhcpd/security/advisories/GHSA-7fwx-hhrg-3496</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/10030.mp3</guid><pubDate>Thu, 30 Jul 2026 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73249435/10030.mp3" length="5838921" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=10030" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Apple Patch Summary / Postscript
https://isc.sans.edu/diary/Apple%20Patches%20Everything%20%28July%202026%29/33196
 IPMI Admin Password Hash Leak
https://lavahq.io/research/bmc-exposure-alert
 Patches for VMWare...</itunes:subtitle><itunes:summary><![CDATA[<br /> Apple Patch Summary / Postscript<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything%20%28July%202026%29/33196" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Everything%20%28July%202026%29/33196</a><br /> IPMI Admin Password Hash Leak<br /><a href="https://lavahq.io/research/bmc-exposure-alert" target="_blank" rel="noreferrer noopener">https://lavahq.io/research/bmc-exposure-alert</a><br /> Patches for VMWare<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017</a><br /> OpenWRT Patch, odhcpd vulnerability CVE-2026-53921<br /><a href="https://github.com/openwrt/odhcpd/security/advisories/GHSA-7fwx-hhrg-3496" target="_blank" rel="noreferrer noopener">https://github.com/openwrt/odhcpd/security/advisories/GHSA-7fwx-hhrg-3496</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>417</itunes:duration><itunes:keywords>apple,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,ipmi,it,network,news,odhcpd,openwrt,security,vmware</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>10030</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, July 29th, 2026: AutoIT Payload Injector; Appele Patches; SourTrade Malware; NGINX Exploit</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-july-29th-2026-autoit-payload-injector-appele-patches-sourtrade-malware-nginx-exploit--73225847</link><description><![CDATA[<br /> AutoIT Payload Injector<br /><a href="https://isc.sans.edu/diary/AutoIT%20Payload%20Injector%20/33192" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/AutoIT%20Payload%20Injector%20/33192</a><br /> Apple Security Update<br /><a href="https://support.apple.com/en-us/100100" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/100100</a><br /> SourTrade: Browser-Assembled Malware Delivered Through Malvertising<br /><a href="https://blog.confiant.com/p/sourtrade-browser-assembled-malware" target="_blank" rel="noreferrer noopener">https://blog.confiant.com/p/sourtrade-browser-assembled-malware</a><br /> NGINX Exploit CVE-2026-42530, CVE-2026-42533<br /><a href="https://github.com/DepthFirstDisclosures/Nginx-Rift/tree/main" target="_blank" rel="noreferrer noopener">https://github.com/DepthFirstDisclosures/Nginx-Rift/tree/main</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/10028.mp3</guid><pubDate>Wed, 29 Jul 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73225847/10028.mp3" length="5873813" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=10028" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 AutoIT Payload Injector
https://isc.sans.edu/diary/AutoIT%20Payload%20Injector%20/33192
 Apple Security Update
https://support.apple.com/en-us/100100
 SourTrade: Browser-Assembled Malware Delivered Through Malvertising...</itunes:subtitle><itunes:summary><![CDATA[<br /> AutoIT Payload Injector<br /><a href="https://isc.sans.edu/diary/AutoIT%20Payload%20Injector%20/33192" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/AutoIT%20Payload%20Injector%20/33192</a><br /> Apple Security Update<br /><a href="https://support.apple.com/en-us/100100" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/100100</a><br /> SourTrade: Browser-Assembled Malware Delivered Through Malvertising<br /><a href="https://blog.confiant.com/p/sourtrade-browser-assembled-malware" target="_blank" rel="noreferrer noopener">https://blog.confiant.com/p/sourtrade-browser-assembled-malware</a><br /> NGINX Exploit CVE-2026-42530, CVE-2026-42533<br /><a href="https://github.com/DepthFirstDisclosures/Nginx-Rift/tree/main" target="_blank" rel="noreferrer noopener">https://github.com/DepthFirstDisclosures/Nginx-Rift/tree/main</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>420</itunes:duration><itunes:keywords>apple,autoit,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,nginx,security,sourtrade</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>10028</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, July 28th, 2026: Spring Boot Scans; VBulletin Vulnerability; MSFT Defender for Linux; MongoDB Update</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-july-28th-2026-spring-boot-scans-vbulletin-vulnerability-msft-defender-for-linux-mongodb-update--73204354</link><description><![CDATA[<br /> Java Spring Boot "heapdump" scans<br /><a href="https://isc.sans.edu/diary/Java%20Spring%20Boot%20%22heapdump%22%20scans/33188" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Java%20Spring%20Boot%20%22heapdump%22%20scans/33188</a><br /> VBULLETIN RUNTIME TEMPLATE RUNMATHS PREAUTH RCE<br /><a href="https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/" target="_blank" rel="noreferrer noopener">https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/</a><br /> Microsoft Defender for Linux Update may disable restart<br /><a href="https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint-releases#issues-have-been-found-with-versions-101260420000101260420009" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint-releases#issues-have-been-found-with-versions-101260420000101260420009</a><br /> MongoDB Updates CVE-2026-13072<br /><a href="https://github.com/advisories/GHSA-wvx7-gr2m-7rf5" target="_blank" rel="noreferrer noopener">https://github.com/advisories/GHSA-wvx7-gr2m-7rf5</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/10026.mp3</guid><pubDate>Tue, 28 Jul 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73204354/10026.mp3" length="4580354" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=10026" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Java Spring Boot "heapdump" scans
https://isc.sans.edu/diary/Java%20Spring%20Boot%20%22heapdump%22%20scans/33188
 VBULLETIN RUNTIME TEMPLATE RUNMATHS PREAUTH RCE
https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/
 Microsoft...</itunes:subtitle><itunes:summary><![CDATA[<br /> Java Spring Boot "heapdump" scans<br /><a href="https://isc.sans.edu/diary/Java%20Spring%20Boot%20%22heapdump%22%20scans/33188" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Java%20Spring%20Boot%20%22heapdump%22%20scans/33188</a><br /> VBULLETIN RUNTIME TEMPLATE RUNMATHS PREAUTH RCE<br /><a href="https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/" target="_blank" rel="noreferrer noopener">https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/</a><br /> Microsoft Defender for Linux Update may disable restart<br /><a href="https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint-releases#issues-have-been-found-with-versions-101260420000101260420009" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint-releases#issues-have-been-found-with-versions-101260420000101260420009</a><br /> MongoDB Updates CVE-2026-13072<br /><a href="https://github.com/advisories/GHSA-wvx7-gr2m-7rf5" target="_blank" rel="noreferrer noopener">https://github.com/advisories/GHSA-wvx7-gr2m-7rf5</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>327</itunes:duration><itunes:keywords>boot,business,computer,cyber,cybersecurity,daily,defender,hacking,infosec,it,java,linux,microsoft,mongodb,network,news,rce,security,spring,vbulletin</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>10026</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, July 27th, 2026: ESAFENET CDG Scans; DNS Poisoning; macOS Gatekeeper bypass; GitHub and PyPi updates</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-july-27th-2026-esafenet-cdg-scans-dns-poisoning-macos-gatekeeper-bypass-github-and-pypi-updates--73185880</link><description><![CDATA[<br /> Scans for ESAFENET CDG 3 Document Management System Weak Logins<br /><a href="https://isc.sans.edu/diary/Scans%20for%20ESAFENET%20CDG%203%20Document%20Management%20System%20Weak%20Logins/33184" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20ESAFENET%20CDG%203%20Document%20Management%20System%20Weak%20Logins/33184</a><br /> DNS Poisoning Tactics Expand to Hospitality Wi-Fi<br /><a href="https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/" target="_blank" rel="noreferrer noopener">https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/</a><br /> Silent Replacement of Trusted macOS App Executables<br /><a href="https://mysk.blog/2026/07/23/macos-overwrite-app-executables/" target="_blank" rel="noreferrer noopener">https://mysk.blog/2026/07/23/macos-overwrite-app-executables/</a><br /> GitHub and PyPi Defense updates<br /><a href="https://github.blog/security/supply-chain-security/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates/" target="_blank" rel="noreferrer noopener">https://github.blog/security/supply-chain-security/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates/</a><br /><a href="https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days/" target="_blank" rel="noreferrer noopener">https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days/</a><br /><a href="https://www.bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/10024.mp3</guid><pubDate>Mon, 27 Jul 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73185880/10024.mp3" length="6011675" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=10024" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Scans for ESAFENET CDG 3 Document Management System Weak Logins
https://isc.sans.edu/diary/Scans%20for%20ESAFENET%20CDG%203%20Document%20Management%20System%20Weak%20Logins/33184
 DNS Poisoning Tactics Expand to Hospitality Wi-Fi...</itunes:subtitle><itunes:summary><![CDATA[<br /> Scans for ESAFENET CDG 3 Document Management System Weak Logins<br /><a href="https://isc.sans.edu/diary/Scans%20for%20ESAFENET%20CDG%203%20Document%20Management%20System%20Weak%20Logins/33184" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20ESAFENET%20CDG%203%20Document%20Management%20System%20Weak%20Logins/33184</a><br /> DNS Poisoning Tactics Expand to Hospitality Wi-Fi<br /><a href="https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/" target="_blank" rel="noreferrer noopener">https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/</a><br /> Silent Replacement of Trusted macOS App Executables<br /><a href="https://mysk.blog/2026/07/23/macos-overwrite-app-executables/" target="_blank" rel="noreferrer noopener">https://mysk.blog/2026/07/23/macos-overwrite-app-executables/</a><br /> GitHub and PyPi Defense updates<br /><a href="https://github.blog/security/supply-chain-security/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates/" target="_blank" rel="noreferrer noopener">https://github.blog/security/supply-chain-security/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates/</a><br /><a href="https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days/" target="_blank" rel="noreferrer noopener">https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days/</a><br /><a href="https://www.bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>429</itunes:duration><itunes:keywords>applications,business,computer,cyber,cybersecurity,daily,dns,gatekeeper,github,hacking,hotel,infosec,internet,it,macos,network,news,pypi,security,wifi</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>10024</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, July 24th, 2026: OpenAI vs. Huggingface; Zimbra Exploited; Notepad++ Abuse; Browser as C2</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-july-24th-2026-openai-vs-huggingface-zimbra-exploited-notepad-abuse-browser-as-c2--73136909</link><description><![CDATA[<br /> When the "Autonomous Attacker" Is Your Own AI Model<br /><a href="https://isc.sans.edu/diary/When%20the%20%22Autonomous%20Attacker%22%20Is%20Your%20Own%20AI%20Model/33180" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/When%20the%20%22Autonomous%20Attacker%22%20Is%20Your%20Own%20AI%20Model/33180</a><br /> Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a</a><br /><a href="https://cert.gov.ua/article/6318634" target="_blank" rel="noreferrer noopener">https://cert.gov.ua/article/6318634</a><br /><a href="https://cybersecuritynews.com/hackers-abuse-notepad-plugins/" target="_blank" rel="noreferrer noopener">https://cybersecuritynews.com/hackers-abuse-notepad-plugins/</a><br /> Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel<br /><a href="https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/10022.mp3</guid><pubDate>Fri, 24 Jul 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73136909/10022.mp3" length="5813289" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=10022" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 When the "Autonomous Attacker" Is Your Own AI Model
https://isc.sans.edu/diary/When%20the%20%22Autonomous%20Attacker%22%20Is%20Your%20Own%20AI%20Model/33180
 Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra...</itunes:subtitle><itunes:summary><![CDATA[<br /> When the "Autonomous Attacker" Is Your Own AI Model<br /><a href="https://isc.sans.edu/diary/When%20the%20%22Autonomous%20Attacker%22%20Is%20Your%20Own%20AI%20Model/33180" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/When%20the%20%22Autonomous%20Attacker%22%20Is%20Your%20Own%20AI%20Model/33180</a><br /> Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a</a><br /><a href="https://cert.gov.ua/article/6318634" target="_blank" rel="noreferrer noopener">https://cert.gov.ua/article/6318634</a><br /><a href="https://cybersecuritynews.com/hackers-abuse-notepad-plugins/" target="_blank" rel="noreferrer noopener">https://cybersecuritynews.com/hackers-abuse-notepad-plugins/</a><br /> Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel<br /><a href="https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>415</itunes:duration><itunes:keywords>browser,business,c2,cert,computer,cyber,cybersecurity,daily,hacking,huggingface,infosec,internet,it,msarat,network,news,notepad++,openai,security,zimbra</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>10022</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, July 23rd, 2026: Rondo and Geoserver; Oracle Patches; Checkpoint  0-day; OpenAI vs Huggingface</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-july-23rd-2026-rondo-and-geoserver-oracle-patches-checkpoint-0-day-openai-vs-huggingface--73117392</link><description><![CDATA[<br /> Rondo Meets Geoserver<br /><a href="https://isc.sans.edu/diary/Rondo%20Meets%20Geoserver/33176" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Rondo%20Meets%20Geoserver/33176</a><br /> Oracle July Patch Update<br /><a href="https://www.oracle.com/security-alerts/cpujul2026.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpujul2026.html</a><br /> OpenAI and Hugging Face partner to address security incident during model evaluation<br /><a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/" target="_blank" rel="noreferrer noopener">https://openai.com/index/hugging-face-model-evaluation-security-incident/</a><br /> Checkpoint July 2026 Security Advisory (CVE-2026-16232)<br /><a href="https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232/" target="_blank" rel="noreferrer noopener">https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232/</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/10020.mp3</guid><pubDate>Thu, 23 Jul 2026 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73117392/10020.mp3" length="5414087" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=10020" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Rondo Meets Geoserver
https://isc.sans.edu/diary/Rondo%20Meets%20Geoserver/33176
 Oracle July Patch Update
https://www.oracle.com/security-alerts/cpujul2026.html
 OpenAI and Hugging Face partner to address security incident during model evaluation...</itunes:subtitle><itunes:summary><![CDATA[<br /> Rondo Meets Geoserver<br /><a href="https://isc.sans.edu/diary/Rondo%20Meets%20Geoserver/33176" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Rondo%20Meets%20Geoserver/33176</a><br /> Oracle July Patch Update<br /><a href="https://www.oracle.com/security-alerts/cpujul2026.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpujul2026.html</a><br /> OpenAI and Hugging Face partner to address security incident during model evaluation<br /><a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/" target="_blank" rel="noreferrer noopener">https://openai.com/index/hugging-face-model-evaluation-security-incident/</a><br /> Checkpoint July 2026 Security Advisory (CVE-2026-16232)<br /><a href="https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232/" target="_blank" rel="noreferrer noopener">https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232/</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>387</itunes:duration><itunes:keywords>business,checkpoint,computer,cyber,cybersecurity,daily,geoserver,hacking,huggingface,infosec,internet,it,network,news,openai,oracle,rondo,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>10020</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, July 22nd, 2026: Captive Portals; Critical Serv-U and Zimbra Update; Apple Hide-My-Email fix</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-july-22nd-2026-captive-portals-critical-serv-u-and-zimbra-update-apple-hide-my-email-fix--73097637</link><description><![CDATA[<br /> Captive Portal Detection<br /><a href="https://isc.sans.edu/diary/Captive%20Portal%20Detection/33172" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Captive%20Portal%20Detection/33172</a><br /> Critical SolarWinds Serv-U Update<br /><a href="https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm" target="_blank" rel="noreferrer noopener">https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm</a><br /> Zimbra Update with Critical Security Fixes<br /><a href="https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/" target="_blank" rel="noreferrer noopener">https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/</a><br /> Apple Fixed Hide My E-Mail Leak<br /><a href="https://www.404media.co/apple-fixes-hide-my-email-vulnerability-after-404-media-coverage/" target="_blank" rel="noreferrer noopener">https://www.404media.co/apple-fixes-hide-my-email-vulnerability-after-404-media-coverage/</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/10018.mp3</guid><pubDate>Wed, 22 Jul 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73097637/10018.mp3" length="4627613" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=10018" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Captive Portal Detection
https://isc.sans.edu/diary/Captive%20Portal%20Detection/33172
 Critical SolarWinds Serv-U Update
https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm
 Zimbra...</itunes:subtitle><itunes:summary><![CDATA[<br /> Captive Portal Detection<br /><a href="https://isc.sans.edu/diary/Captive%20Portal%20Detection/33172" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Captive%20Portal%20Detection/33172</a><br /> Critical SolarWinds Serv-U Update<br /><a href="https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm" target="_blank" rel="noreferrer noopener">https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm</a><br /> Zimbra Update with Critical Security Fixes<br /><a href="https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/" target="_blank" rel="noreferrer noopener">https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/</a><br /> Apple Fixed Hide My E-Mail Leak<br /><a href="https://www.404media.co/apple-fixes-hide-my-email-vulnerability-after-404-media-coverage/" target="_blank" rel="noreferrer noopener">https://www.404media.co/apple-fixes-hide-my-email-vulnerability-after-404-media-coverage/</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>331</itunes:duration><itunes:keywords>apple,business,captive,computer,cyber,cybersecurity,daily,e-mail,hacking,hide-my,infosec,it,network,news,portal,privacy,security,serv-u,solarwinds,zimbra</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>10018</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, July 21st, 2026: More Wordpress Details; HOLLOWGRAPH MSFT Calendar Abuse; Gitea Vulnerability</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-july-21st-2026-more-wordpress-details-hollowgraph-msft-calendar-abuse-gitea-vulnerability--73078676</link><description><![CDATA[<br /> WordPress Exploitation Underway (CVE-2026-63030)<br /><a href="https://isc.sans.edu/diary/WordPress%20Exploitation%20Underway%20%28CVE-2026-63030%29/33168" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/WordPress%20Exploitation%20Underway%20%28CVE-2026-63030%29/33168</a><br /> HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels<br /><a href="https://www.group-ib.com/blog/hollowgraph-microsoft-365/" target="_blank" rel="noreferrer noopener">https://www.group-ib.com/blog/hollowgraph-microsoft-365/</a><br /> Gitea Vulnerablity CVE-2026-58443<br /><a href="https://github.com/go-gitea/gitea/security/advisories/GHSA-xxjv-752h-3vp2" target="_blank" rel="noreferrer noopener">https://github.com/go-gitea/gitea/security/advisories/GHSA-xxjv-752h-3vp2</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/10016.mp3</guid><pubDate>Tue, 21 Jul 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73078676/10016.mp3" length="7223825" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=10016" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 WordPress Exploitation Underway (CVE-2026-63030)
https://isc.sans.edu/diary/WordPress%20Exploitation%20Underway%20%28CVE-2026-63030%29/33168
 HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels...</itunes:subtitle><itunes:summary><![CDATA[<br /> WordPress Exploitation Underway (CVE-2026-63030)<br /><a href="https://isc.sans.edu/diary/WordPress%20Exploitation%20Underway%20%28CVE-2026-63030%29/33168" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/WordPress%20Exploitation%20Underway%20%28CVE-2026-63030%29/33168</a><br /> HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels<br /><a href="https://www.group-ib.com/blog/hollowgraph-microsoft-365/" target="_blank" rel="noreferrer noopener">https://www.group-ib.com/blog/hollowgraph-microsoft-365/</a><br /> Gitea Vulnerablity CVE-2026-58443<br /><a href="https://github.com/go-gitea/gitea/security/advisories/GHSA-xxjv-752h-3vp2" target="_blank" rel="noreferrer noopener">https://github.com/go-gitea/gitea/security/advisories/GHSA-xxjv-752h-3vp2</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>516</itunes:duration><itunes:keywords>business,calendar,computer,cyber,cybersecurity,daily,exploitation,gitea,hacking,infosec,internet,it,microsoft,network,news,o365,security,wordpress</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>10016</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, July 17th, 2026: Hikvision Scans; LG Spyware; Huggingface Hack; Wordpress Core RCE</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-july-17th-2026-hikvision-scans-lg-spyware-huggingface-hack-wordpress-core-rce--73062676</link><description><![CDATA[<br /> Scans for Hikvision Intelligent Security API<br /><a href="https://isc.sans.edu/diary/Scans%20for%20Hikvision%20Intelligent%20Security%20API/33164" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20Hikvision%20Intelligent%20Security%20API/33164</a><br /> LG Monitor Spyware<br /><a href="https://www.techradar.com/televisions/lgs-gaming-monitors-and-tvs-are-facing-a-user-revolt" target="_blank" rel="noreferrer noopener">https://www.techradar.com/televisions/lgs-gaming-monitors-and-tvs-are-facing-a-user-revolt</a> <a href="https://www.youtube.com/watch?v=Q9uefFYe6bM" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=Q9uefFYe6bM</a><br /> Huggingface Hack<br /><a href="https://huggingface.co/blog/security-incident-july-2026" target="_blank" rel="noreferrer noopener">https://huggingface.co/blog/security-incident-july-2026</a><br /> Wordpress Core RCE<br /><a href="https://wp2shell.com" target="_blank" rel="noreferrer noopener">https://wp2shell.com</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/10014.mp3</guid><pubDate>Mon, 20 Jul 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73062676/10014.mp3" length="5881381" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=10014" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Scans for Hikvision Intelligent Security API
https://isc.sans.edu/diary/Scans%20for%20Hikvision%20Intelligent%20Security%20API/33164
 LG Monitor Spyware
https://www.techradar.com/televisions/lgs-gaming-monitors-and-tvs-are-facing-a-user-revolt...</itunes:subtitle><itunes:summary><![CDATA[<br /> Scans for Hikvision Intelligent Security API<br /><a href="https://isc.sans.edu/diary/Scans%20for%20Hikvision%20Intelligent%20Security%20API/33164" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20Hikvision%20Intelligent%20Security%20API/33164</a><br /> LG Monitor Spyware<br /><a href="https://www.techradar.com/televisions/lgs-gaming-monitors-and-tvs-are-facing-a-user-revolt" target="_blank" rel="noreferrer noopener">https://www.techradar.com/televisions/lgs-gaming-monitors-and-tvs-are-facing-a-user-revolt</a> <a href="https://www.youtube.com/watch?v=Q9uefFYe6bM" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=Q9uefFYe6bM</a><br /> Huggingface Hack<br /><a href="https://huggingface.co/blog/security-incident-july-2026" target="_blank" rel="noreferrer noopener">https://huggingface.co/blog/security-incident-july-2026</a><br /> Wordpress Core RCE<br /><a href="https://wp2shell.com" target="_blank" rel="noreferrer noopener">https://wp2shell.com</a><br />]]></itunes:summary><itunes:duration>420</itunes:duration><itunes:keywords>business,compromise,computer,cyber,cybersecurity,daily,hacking,hikvision,huggingface,infosec,it,lg,monitor,network,news,security,shell,spyware,wordpress,wp2shell</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>10014</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, July 17th, 2026: Windows Hello for Business; NGINX Vuln; 7-zip vuln</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-july-17th-2026-windows-hello-for-business-nginx-vuln-7-zip-vuln--73020863</link><description><![CDATA[<br /> German Federal Information Security Office Analyzes Windows Hello for Business<br /><a href="https://www.heise.de/en/news/BSI-dissects-Windows-Hello-Where-Microsoft-s-login-reaches-its-limits-11366125.html" target="_blank" rel="noreferrer noopener">https://www.heise.de/en/news/BSI-dissects-Windows-Hello-Where-Microsoft-s-login-reaches-its-limits-11366125.html</a><br /><a href="https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/Studies/Windows_dissected/AP1_Windows-Hello-for-Business.pdf?__blob=publicationFile&amp;v=7" target="_blank" rel="noreferrer noopener">https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/Studies/Windows_dissected/AP1_Windows-Hello-for-Business.pdf?__blob=publicationFile&amp;v=7</a><br /> NGINX Vulnerability<br /><a href="https://my.f5.com/manage/s/article/K000162097" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000162097</a><br /> 7-Zip XZ Decompression CVE-2026-14266<br /><a href="https://www.zerodayinitiative.com/advisories/ZDI-26-444/" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/advisories/ZDI-26-444/</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/10012.mp3</guid><pubDate>Fri, 17 Jul 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73020863/10012.mp3" length="4700898" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=10012" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 German Federal Information Security Office Analyzes Windows Hello for Business
https://www.heise.de/en/news/BSI-dissects-Windows-Hello-Where-Microsoft-s-login-reaches-its-limits-11366125.html...</itunes:subtitle><itunes:summary><![CDATA[<br /> German Federal Information Security Office Analyzes Windows Hello for Business<br /><a href="https://www.heise.de/en/news/BSI-dissects-Windows-Hello-Where-Microsoft-s-login-reaches-its-limits-11366125.html" target="_blank" rel="noreferrer noopener">https://www.heise.de/en/news/BSI-dissects-Windows-Hello-Where-Microsoft-s-login-reaches-its-limits-11366125.html</a><br /><a href="https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/Studies/Windows_dissected/AP1_Windows-Hello-for-Business.pdf?__blob=publicationFile&amp;v=7" target="_blank" rel="noreferrer noopener">https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/Studies/Windows_dissected/AP1_Windows-Hello-for-Business.pdf?__blob=publicationFile&amp;v=7</a><br /> NGINX Vulnerability<br /><a href="https://my.f5.com/manage/s/article/K000162097" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000162097</a><br /> 7-Zip XZ Decompression CVE-2026-14266<br /><a href="https://www.zerodayinitiative.com/advisories/ZDI-26-444/" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/advisories/ZDI-26-444/</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>336</itunes:duration><itunes:keywords>7zip,business,computer,cyber,cybersecurity,daily,hacking,hello,infosec,internet,it,network,news,nginx,security,windows</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>10012</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, July 16th, 2026: DShield SIEM Update; MSFT Patches vs. Intel IPF; Zoom Patch; Forgotten UEFI Shims</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-july-16th-2026-dshield-siem-update-msft-patches-vs-intel-ipf-zoom-patch-forgotten-uefi-shims--73006725</link><description><![CDATA[<br /> DShield SIEM Update<br /><a href="https://isc.sans.edu/diary/Recent%20DShield%20SIEM%20Update/33156" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Recent%20DShield%20SIEM%20Update/33156</a><br /> Microsoft Patch Tuesday vs. Dell Intel Innovation Platform Framework (IPF) drivers<br /><a href="https://support.microsoft.com/en-us/servicing/os/windows-11/2026/07/july-14-2026-kb5101650-os-builds-26200-8875-and-26100-8875" target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-us/servicing/os/windows-11/2026/07/july-14-2026-kb5101650-os-builds-26200-8875-and-26100-8875</a><br /> Zoom Account Takeover Patch<br /><a href="https://www.zoom.com/en/trust/security-bulletin/zsb-26014/" target="_blank" rel="noreferrer noopener">https://www.zoom.com/en/trust/security-bulletin/zsb-26014/</a><br /> Forgotten UEFI shims undermining Secure Boot<br /><a href="https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/10010.mp3</guid><pubDate>Thu, 16 Jul 2026 02:40:10 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73006725/10010.mp3" length="3436288" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=10010" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 DShield SIEM Update
https://isc.sans.edu/diary/Recent%20DShield%20SIEM%20Update/33156
 Microsoft Patch Tuesday vs. Dell Intel Innovation Platform Framework (IPF) drivers...</itunes:subtitle><itunes:summary><![CDATA[<br /> DShield SIEM Update<br /><a href="https://isc.sans.edu/diary/Recent%20DShield%20SIEM%20Update/33156" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Recent%20DShield%20SIEM%20Update/33156</a><br /> Microsoft Patch Tuesday vs. Dell Intel Innovation Platform Framework (IPF) drivers<br /><a href="https://support.microsoft.com/en-us/servicing/os/windows-11/2026/07/july-14-2026-kb5101650-os-builds-26200-8875-and-26100-8875" target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-us/servicing/os/windows-11/2026/07/july-14-2026-kb5101650-os-builds-26200-8875-and-26100-8875</a><br /> Zoom Account Takeover Patch<br /><a href="https://www.zoom.com/en/trust/security-bulletin/zsb-26014/" target="_blank" rel="noreferrer noopener">https://www.zoom.com/en/trust/security-bulletin/zsb-26014/</a><br /> Forgotten UEFI shims undermining Secure Boot<br /><a href="https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>246</itunes:duration><itunes:keywords>boot,business,computer,cyber,cybersecurity,daily,dell,dshield,hacking,infosec,intel,ipf,it,network,news,patch,security,siem,uefi,zoom</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>10010</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, July 15th, 2026: Microsoft Patches; New MSFT Priv Escalation; Progress ShareFile 0-Day; Grok Exfiltration</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-july-15th-2026-microsoft-patches-new-msft-priv-escalation-progress-sharefile-0-day-grok-exfiltration--72982038</link><description><![CDATA[<br /> Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20July%202026%20-%20The%20AI%20Acopolypse%20is%20Here%20/33154" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20July%202026%20-%20The%20AI%20Acopolypse%20is%20Here%20/33154</a><br /> LegacyHive : Windows user profile service arbitrary hive load elevation of privileges vulnerability<br /><a href="https://git.projectnightcrawler.dev/NightmareEclipse/LegacyHive" target="_blank" rel="noreferrer noopener">https://git.projectnightcrawler.dev/NightmareEclipse/LegacyHive</a><br /> Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown<br /><a href="https://www.bleepingcomputer.com/news/security/progress-confirms-sharefile-zero-day-flaw-behind-storage-zone-shutdown/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/progress-confirms-sharefile-zero-day-flaw-behind-storage-zone-shutdown/</a><br /> xAI/Grok Exfiltrating Data and Secrets<br /><a href="https://cereblab.com" target="_blank" rel="noreferrer noopener">https://cereblab.com</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/10008.mp3</guid><pubDate>Wed, 15 Jul 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72982038/10008.mp3" length="5669350" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=10008" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20July%202026%20-%20The%20AI%20Acopolypse%20is%20Here%20/33154
 LegacyHive : Windows user profile service arbitrary hive load...</itunes:subtitle><itunes:summary><![CDATA[<br /> Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20July%202026%20-%20The%20AI%20Acopolypse%20is%20Here%20/33154" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20July%202026%20-%20The%20AI%20Acopolypse%20is%20Here%20/33154</a><br /> LegacyHive : Windows user profile service arbitrary hive load elevation of privileges vulnerability<br /><a href="https://git.projectnightcrawler.dev/NightmareEclipse/LegacyHive" target="_blank" rel="noreferrer noopener">https://git.projectnightcrawler.dev/NightmareEclipse/LegacyHive</a><br /> Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown<br /><a href="https://www.bleepingcomputer.com/news/security/progress-confirms-sharefile-zero-day-flaw-behind-storage-zone-shutdown/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/progress-confirms-sharefile-zero-day-flaw-behind-storage-zone-shutdown/</a><br /> xAI/Grok Exfiltrating Data and Secrets<br /><a href="https://cereblab.com" target="_blank" rel="noreferrer noopener">https://cereblab.com</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>405</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,grok,hacking,infosec,internet,it,legacyhive,microsoft,network,news,progress,security,sharefile,storage,xai</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>10008</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, July 14th, 2026: MCP/AI Related Scans; Improve Router Hygiene; OAuth Client ID Spoofing; Veeam Vuln;</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-july-14th-2026-mcp-ai-related-scans-improve-router-hygiene-oauth-client-id-spoofing-veeam-vuln--72959164</link><description><![CDATA[<br /> Someone Is Scanning for Your MCP Servers and AI Assistant Credentials<br /><a href="https://isc.sans.edu/diary/Someone%20Is%20Scanning%20for%20Your%20MCP%20Servers%20and%20AI%20Assistant%20Credentials/33150" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Someone%20Is%20Scanning%20for%20Your%20MCP%20Servers%20and%20AI%20Assistant%20Credentials/33150</a><br /> Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a</a><br /> OAuth Client ID Spoofing<br /><a href="https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy" target="_blank" rel="noreferrer noopener">https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy</a><br /> Vulnerability Resolved in Veeam Backup &amp; Replication 12.3.2.4854<br /><a href="https://www.veeam.com/kb4869" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4869</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/10006.mp3</guid><pubDate>Tue, 14 Jul 2026 02:15:11 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72959164/10006.mp3" length="6102951" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=10006" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Someone Is Scanning for Your MCP Servers and AI Assistant Credentials
https://isc.sans.edu/diary/Someone%20Is%20Scanning%20for%20Your%20MCP%20Servers%20and%20AI%20Assistant%20Credentials/33150
 Improve Router Hygiene to Protect Against Russian...</itunes:subtitle><itunes:summary><![CDATA[<br /> Someone Is Scanning for Your MCP Servers and AI Assistant Credentials<br /><a href="https://isc.sans.edu/diary/Someone%20Is%20Scanning%20for%20Your%20MCP%20Servers%20and%20AI%20Assistant%20Credentials/33150" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Someone%20Is%20Scanning%20for%20Your%20MCP%20Servers%20and%20AI%20Assistant%20Credentials/33150</a><br /> Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a</a><br /> OAuth Client ID Spoofing<br /><a href="https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy" target="_blank" rel="noreferrer noopener">https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy</a><br /> Vulnerability Resolved in Veeam Backup &amp; Replication 12.3.2.4854<br /><a href="https://www.veeam.com/kb4869" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4869</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>436</itunes:duration><itunes:keywords>ai,business,cisco,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,mcp,network,news,oauth,router,russian,scanning,security,veeam</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>10006</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, July 13th, 2026: Progress Sharefile Shutdown; U-Boot Vuln; More Nightmare Eclipse; Cisco AI Response</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-july-13th-2026-progress-sharefile-shutdown-u-boot-vuln-more-nightmare-eclipse-cisco-ai-response--72943883</link><description><![CDATA[<br /> Progress Sharefile Emergency Shutdown Notice<br /><a href="https://status.sharefile.com" target="_blank" rel="noreferrer noopener">https://status.sharefile.com</a><br /><a href="https://www.reddit.com/r/sysadmin/comments/1usohco/psa_shutdown_your_sharefile_storage_zone/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/sysadmin/comments/1usohco/psa_shutdown_your_sharefile_storage_zone/</a><br /><a href="https://www.bleepingcomputer.com/news/security/progress-urges-sharefile-customers-to-shut-down-servers-over-credible-threat/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/progress-urges-sharefile-customers-to-shut-down-servers-over-credible-threat/</a><br /> U-Boot Vulnerabilities<br /><a href="https://www.binarly.io/blog/unfit-to-boot-breaking-u-boots-fit-signature-verification" target="_blank" rel="noreferrer noopener">https://www.binarly.io/blog/unfit-to-boot-breaking-u-boots-fit-signature-verification</a><br /> Nightmare Eclipse Releases Next Microsoft Defender Exploit<br /><a href="https://blog.projectnightcrawler.dev/posts/2026-07-09-some-interesting-findings-in-windows-defender/" target="_blank" rel="noreferrer noopener">https://blog.projectnightcrawler.dev/posts/2026-07-09-some-interesting-findings-in-windows-defender/</a><br /> Cisco Increases Patch Cadence<br /><a href="https://blogs.cisco.com/security/strengthening-the-foundation-a-predictable-customer-focused-response-to-ai-accelerated-vulnerability-discovery" target="_blank" rel="noreferrer noopener">https://blogs.cisco.com/security/strengthening-the-foundation-a-predictable-customer-focused-response-to-ai-accelerated-vulnerability-discovery</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/10004.mp3</guid><pubDate>Mon, 13 Jul 2026 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72943883/10004.mp3" length="4648860" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=10004" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Progress Sharefile Emergency Shutdown Notice
https://status.sharefile.com
https://www.reddit.com/r/sysadmin/comments/1usohco/psa_shutdown_your_sharefile_storage_zone/...</itunes:subtitle><itunes:summary><![CDATA[<br /> Progress Sharefile Emergency Shutdown Notice<br /><a href="https://status.sharefile.com" target="_blank" rel="noreferrer noopener">https://status.sharefile.com</a><br /><a href="https://www.reddit.com/r/sysadmin/comments/1usohco/psa_shutdown_your_sharefile_storage_zone/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/sysadmin/comments/1usohco/psa_shutdown_your_sharefile_storage_zone/</a><br /><a href="https://www.bleepingcomputer.com/news/security/progress-urges-sharefile-customers-to-shut-down-servers-over-credible-threat/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/progress-urges-sharefile-customers-to-shut-down-servers-over-credible-threat/</a><br /> U-Boot Vulnerabilities<br /><a href="https://www.binarly.io/blog/unfit-to-boot-breaking-u-boots-fit-signature-verification" target="_blank" rel="noreferrer noopener">https://www.binarly.io/blog/unfit-to-boot-breaking-u-boots-fit-signature-verification</a><br /> Nightmare Eclipse Releases Next Microsoft Defender Exploit<br /><a href="https://blog.projectnightcrawler.dev/posts/2026-07-09-some-interesting-findings-in-windows-defender/" target="_blank" rel="noreferrer noopener">https://blog.projectnightcrawler.dev/posts/2026-07-09-some-interesting-findings-in-windows-defender/</a><br /> Cisco Increases Patch Cadence<br /><a href="https://blogs.cisco.com/security/strengthening-the-foundation-a-predictable-customer-focused-response-to-ai-accelerated-vulnerability-discovery" target="_blank" rel="noreferrer noopener">https://blogs.cisco.com/security/strengthening-the-foundation-a-predictable-customer-focused-response-to-ai-accelerated-vulnerability-discovery</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>332</itunes:duration><itunes:keywords>business,cisco,computer,cyber,cybersecurity,daily,defender,hacking,infosec,internet,it,microsoft,network,news,nightmare eclipes,patches,progress,security,sharefile,u-boot</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>10004</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, July 10th, 2026: Belarus Graffiti Bot @sans_edu; Discontinuing Mac OS Ext. FS; Chrome Update; Rogue Planet Patch</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-july-10th-2026-belarus-graffiti-bot-sans-edu-discontinuing-mac-os-ext-fs-chrome-update-rogue-planet-patch--72904086</link><description><![CDATA[<br /> _HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary]<br /><a href="https://isc.sans.edu/diary/_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_%20%5BGuest%20Diary%5D/33130" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_%20%5BGuest%20Diary%5D/33130</a><br /> Apple Discontinuing Support for Encrypted Mac OS Extended disks in macOS 28<br /><a href="https://support.apple.com/en-us/125615" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/125615</a><br /> Google Chrome Update<br /><a href="https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html</a><br /> Microsoft Patches Rogue Planet Vulnerability CVE-2026-50656<br /><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50656/" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50656/</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/10002.mp3</guid><pubDate>Fri, 10 Jul 2026 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72904086/10002.mp3" length="5555377" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=10002" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 _HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary]
https://isc.sans.edu/diary/_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_%20%5BGuest%20Diary%5D/33130
 Apple Discontinuing Support for Encrypted Mac OS Extended disks in macOS 28...</itunes:subtitle><itunes:summary><![CDATA[<br /> _HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary]<br /><a href="https://isc.sans.edu/diary/_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_%20%5BGuest%20Diary%5D/33130" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_%20%5BGuest%20Diary%5D/33130</a><br /> Apple Discontinuing Support for Encrypted Mac OS Extended disks in macOS 28<br /><a href="https://support.apple.com/en-us/125615" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/125615</a><br /> Google Chrome Update<br /><a href="https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html</a><br /> Microsoft Patches Rogue Planet Vulnerability CVE-2026-50656<br /><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50656/" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50656/</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>397</itunes:duration><itunes:keywords>apfs,apple,belarus,business,chrome,computer,cyber,cybersecurity,daily,google,hacking,infosec,internet,it,microsoft,network,news,nightmare eclypse,rogue planet,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>10002</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, July 9th, 2026: Stack Simulator; RootAsRole; Hoymiles; Git Hash Malleability</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-july-9th-2026-stack-simulator-rootasrole-hoymiles-git-hash-malleability--72879730</link><description><![CDATA[<br /> My Stack Simulator <a href="https://isc.sans.edu/diary/My%20Stack%20Simulator/33138" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/My%20Stack%20Simulator/33138</a><br /> RootAsRole<br /><a href="https://github.com/LeChatP/RootAsRole" target="_blank" rel="noreferrer noopener">https://github.com/LeChatP/RootAsRole</a><br /> Hoymiles Inverter Vulnerability<br /><a href="https://www.ccc.de/system/uploads/382/original/hoymiles_dtu_vuln.pdf" target="_blank" rel="noreferrer noopener">https://www.ccc.de/system/uploads/382/original/hoymiles_dtu_vuln.pdf</a><br /> Git Hash Chain Malleability<br /><a href="https://arxiv.org/abs/2607.02820" target="_blank" rel="noreferrer noopener">https://arxiv.org/abs/2607.02820</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/10000.mp3</guid><pubDate>Thu, 09 Jul 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72879730/10000.mp3" length="4138842" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=10000" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 My Stack Simulator https://isc.sans.edu/diary/My%20Stack%20Simulator/33138
 RootAsRole
https://github.com/LeChatP/RootAsRole
 Hoymiles Inverter Vulnerability
https://www.ccc.de/system/uploads/382/original/hoymiles_dtu_vuln.pdf
 Git Hash Chain...</itunes:subtitle><itunes:summary><![CDATA[<br /> My Stack Simulator <a href="https://isc.sans.edu/diary/My%20Stack%20Simulator/33138" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/My%20Stack%20Simulator/33138</a><br /> RootAsRole<br /><a href="https://github.com/LeChatP/RootAsRole" target="_blank" rel="noreferrer noopener">https://github.com/LeChatP/RootAsRole</a><br /> Hoymiles Inverter Vulnerability<br /><a href="https://www.ccc.de/system/uploads/382/original/hoymiles_dtu_vuln.pdf" target="_blank" rel="noreferrer noopener">https://www.ccc.de/system/uploads/382/original/hoymiles_dtu_vuln.pdf</a><br /> Git Hash Chain Malleability<br /><a href="https://arxiv.org/abs/2607.02820" target="_blank" rel="noreferrer noopener">https://arxiv.org/abs/2607.02820</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>296</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,gith,github,hacking,hoymiles,infosec,internet,it,network,news,rootasrole,security,simulator,solar,stack,sudo</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>10000</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, July 8th, 2026: Odd DNS; AnyDesk Phishing; Tenda Backdoor; GitLost</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-july-8th-2026-odd-dns-anydesk-phishing-tenda-backdoor-gitlost--72861836</link><description><![CDATA[<br /> More Odd DNS Records: NIMLOC<br /><a href="https://isc.sans.edu/diary/More%20Odd%20DNS%20Records%3A%20NIMLOC/33128" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/More%20Odd%20DNS%20Records%3A%20NIMLOC/33128</a><br /> From Invoice to AnyDesk: Uncovering a Phishing Campaign Targeting  Russian Aerospace Organizations <br /><a href="https://www.seqrite.com/blog/from-invoice-to-anydesk-uncovering-a-phishing-campaign-targeting-russian-aerospace-organizations/" target="_blank" rel="noreferrer noopener">https://www.seqrite.com/blog/from-invoice-to-anydesk-uncovering-a-phishing-campaign-targeting-russian-aerospace-organizations/</a><br /> Tenda firmware (multiple versions) contains hidden authentication backdoor<br /><a href="https://kb.cert.org/vuls/id/213560" target="_blank" rel="noreferrer noopener">https://kb.cert.org/vuls/id/213560</a><br /> GitLost: GitHub AI Agent Leak<br /><a href="https://noma.security/wp-content/uploads/GitLostWorkflow_2.gif" target="_blank" rel="noreferrer noopener">https://noma.security/wp-content/uploads/GitLostWorkflow_2.gif</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9998.mp3</guid><pubDate>Wed, 08 Jul 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72861836/9998.mp3" length="6164996" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9998" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 More Odd DNS Records: NIMLOC
https://isc.sans.edu/diary/More%20Odd%20DNS%20Records%3A%20NIMLOC/33128
 From Invoice to AnyDesk: Uncovering a Phishing Campaign Targeting  Russian Aerospace Organizations...</itunes:subtitle><itunes:summary><![CDATA[<br /> More Odd DNS Records: NIMLOC<br /><a href="https://isc.sans.edu/diary/More%20Odd%20DNS%20Records%3A%20NIMLOC/33128" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/More%20Odd%20DNS%20Records%3A%20NIMLOC/33128</a><br /> From Invoice to AnyDesk: Uncovering a Phishing Campaign Targeting  Russian Aerospace Organizations <br /><a href="https://www.seqrite.com/blog/from-invoice-to-anydesk-uncovering-a-phishing-campaign-targeting-russian-aerospace-organizations/" target="_blank" rel="noreferrer noopener">https://www.seqrite.com/blog/from-invoice-to-anydesk-uncovering-a-phishing-campaign-targeting-russian-aerospace-organizations/</a><br /> Tenda firmware (multiple versions) contains hidden authentication backdoor<br /><a href="https://kb.cert.org/vuls/id/213560" target="_blank" rel="noreferrer noopener">https://kb.cert.org/vuls/id/213560</a><br /> GitLost: GitHub AI Agent Leak<br /><a href="https://noma.security/wp-content/uploads/GitLostWorkflow_2.gif" target="_blank" rel="noreferrer noopener">https://noma.security/wp-content/uploads/GitLostWorkflow_2.gif</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>441</itunes:duration><itunes:keywords>anydesk,business,computer,cyber,cybersecurity,daily,dns,github,gitlost,hacking,infosec,internet,it,network,news,nimloc,security,tenda</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9998</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, July 7th, 2026: RCS and DNS; OpenSSH Update; Beyond Trust Advisory; PolinRider Update</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-july-7th-2026-rcs-and-dns-openssh-update-beyond-trust-advisory-polinrider-update--72847583</link><description><![CDATA[<br /> RCS and DNS: The NAPTR Record<br /><a href="https://isc.sans.edu/diary/RCS%20and%20DNS%3A%20The%20NAPTR%20Record/33124" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/RCS%20and%20DNS%3A%20The%20NAPTR%20Record/33124</a><br /> OpenSSH 10.4 released<br /><a href="https://seclists.org/oss-sec/2026/q3/62" target="_blank" rel="noreferrer noopener">https://seclists.org/oss-sec/2026/q3/62</a><br /> Beyond Trust Advisory CVE-2026-40138 CVE-2026-40139<br /><a href="https://www.beyondtrust.com/trust-center/security-advisories/bt26-03" target="_blank" rel="noreferrer noopener">https://www.beyondtrust.com/trust-center/security-advisories/bt26-03</a><br /> PolinRider: North Korea-Linked Supply Chain Campaign<br /><a href="https://socket.dev/blog/polinrider-north-korea-linked-supply-chain-campaign-expands" target="_blank" rel="noreferrer noopener">https://socket.dev/blog/polinrider-north-korea-linked-supply-chain-campaign-expands</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9996.mp3</guid><pubDate>Tue, 07 Jul 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72847583/9996.mp3" length="5572045" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9996" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 RCS and DNS: The NAPTR Record
https://isc.sans.edu/diary/RCS%20and%20DNS%3A%20The%20NAPTR%20Record/33124
 OpenSSH 10.4 released
https://seclists.org/oss-sec/2026/q3/62
 Beyond Trust Advisory CVE-2026-40138 CVE-2026-40139...</itunes:subtitle><itunes:summary><![CDATA[<br /> RCS and DNS: The NAPTR Record<br /><a href="https://isc.sans.edu/diary/RCS%20and%20DNS%3A%20The%20NAPTR%20Record/33124" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/RCS%20and%20DNS%3A%20The%20NAPTR%20Record/33124</a><br /> OpenSSH 10.4 released<br /><a href="https://seclists.org/oss-sec/2026/q3/62" target="_blank" rel="noreferrer noopener">https://seclists.org/oss-sec/2026/q3/62</a><br /> Beyond Trust Advisory CVE-2026-40138 CVE-2026-40139<br /><a href="https://www.beyondtrust.com/trust-center/security-advisories/bt26-03" target="_blank" rel="noreferrer noopener">https://www.beyondtrust.com/trust-center/security-advisories/bt26-03</a><br /> PolinRider: North Korea-Linked Supply Chain Campaign<br /><a href="https://socket.dev/blog/polinrider-north-korea-linked-supply-chain-campaign-expands" target="_blank" rel="noreferrer noopener">https://socket.dev/blog/polinrider-north-korea-linked-supply-chain-campaign-expands</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>398</itunes:duration><itunes:keywords>beyond trust,business,computer,cyber,cybersecurity,daily,dns,hacking,infosec,internet,it,naptr,network,news,north korea,openssh,polinrider,rcs,security,supply chain</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9996</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, July 6th, 2026: Apple Patch Policy; FatFS Vulns; OpenWRT; Multi-Agent Offensive AI;</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-july-6th-2026-apple-patch-policy-fatfs-vulns-openwrt-multi-agent-offensive-ai--72838333</link><description><![CDATA[<br /> Apple Updated Patch Policy<br /><a href="https://www.reuters.com/business/apple-says-it-is-releasing-updates-early-response-ai-cybersecurity-concerns-2026-06-29/" target="_blank" rel="noreferrer noopener">https://www.reuters.com/business/apple-says-it-is-releasing-updates-early-response-ai-cybersecurity-concerns-2026-06-29/</a><br /> T3MP3ST multi-agent offensive-security framework<br /><a href="https://github.com/elder-plinius/T3MP3ST" target="_blank" rel="noreferrer noopener">https://github.com/elder-plinius/T3MP3ST</a><br /> Seven FatFs bugs, one very large blast radius<br /><a href="https://www.runzero.com/blog/fatfs-bugs/" target="_blank" rel="noreferrer noopener">https://www.runzero.com/blog/fatfs-bugs/</a><br /> OpenWRT Releases v25.12.5<br /><a href="https://github.com/openwrt/openwrt/releases" target="_blank" rel="noreferrer noopener">https://github.com/openwrt/openwrt/releases</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9994.mp3</guid><pubDate>Mon, 06 Jul 2026 11:36:06 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72838333/9994.mp3" length="4898791" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9994" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Apple Updated Patch Policy
https://www.reuters.com/business/apple-says-it-is-releasing-updates-early-response-ai-cybersecurity-concerns-2026-06-29/
 T3MP3ST multi-agent offensive-security framework
https://github.com/elder-plinius/T3MP3ST
 Seven...</itunes:subtitle><itunes:summary><![CDATA[<br /> Apple Updated Patch Policy<br /><a href="https://www.reuters.com/business/apple-says-it-is-releasing-updates-early-response-ai-cybersecurity-concerns-2026-06-29/" target="_blank" rel="noreferrer noopener">https://www.reuters.com/business/apple-says-it-is-releasing-updates-early-response-ai-cybersecurity-concerns-2026-06-29/</a><br /> T3MP3ST multi-agent offensive-security framework<br /><a href="https://github.com/elder-plinius/T3MP3ST" target="_blank" rel="noreferrer noopener">https://github.com/elder-plinius/T3MP3ST</a><br /> Seven FatFs bugs, one very large blast radius<br /><a href="https://www.runzero.com/blog/fatfs-bugs/" target="_blank" rel="noreferrer noopener">https://www.runzero.com/blog/fatfs-bugs/</a><br /> OpenWRT Releases v25.12.5<br /><a href="https://github.com/openwrt/openwrt/releases" target="_blank" rel="noreferrer noopener">https://github.com/openwrt/openwrt/releases</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>350</itunes:duration><itunes:keywords>ai,apple,business,computer,cyber,cybersecurity,daily,fatfs,hacking,infosec,internet,it,network,news,openwrt,security,t3mp3st</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9994</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, July 2nd, 2026: MetaMask Phishing; Adobe Patches; Google Chrome Patches; Apple Hide-My-Email Vuln</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-july-2nd-2026-metamask-phishing-adobe-patches-google-chrome-patches-apple-hide-my-email-vuln--72782784</link><description><![CDATA[<br /> Why Ask Credentials If There Are Secret Codes?<br /><a href="https://isc.sans.edu/diary/Why%20Ask%20Credentials%20If%20There%20Are%20Secret%20Codes%3F/33118" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Why%20Ask%20Credentials%20If%20There%20Are%20Secret%20Codes%3F/33118</a><br /> Adobe Patches and Updated Patch Release Policy<br /><a href="https://helpx.adobe.com/security/Home.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/Home.html</a><br /><a href="https://blog.adobe.com/security/protecting-customers-faster-how-adobe-is-responding-to-ai-accelerated-vulnerability-discovery" target="_blank" rel="noreferrer noopener">https://blog.adobe.com/security/protecting-customers-faster-how-adobe-is-responding-to-ai-accelerated-vulnerability-discovery</a><br /> Google Chrome Update (link had issues loading while recording)<br /><a href="https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html</a><br /> Apple Hide My Email Vulnerability<br /><a href="https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses/" target="_blank" rel="noreferrer noopener">https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses/</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9992.mp3</guid><pubDate>Thu, 02 Jul 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72782784/9992.mp3" length="5254134" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9992" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Why Ask Credentials If There Are Secret Codes?
https://isc.sans.edu/diary/Why%20Ask%20Credentials%20If%20There%20Are%20Secret%20Codes%3F/33118
 Adobe Patches and Updated Patch Release Policy
https://helpx.adobe.com/security/Home.html...</itunes:subtitle><itunes:summary><![CDATA[<br /> Why Ask Credentials If There Are Secret Codes?<br /><a href="https://isc.sans.edu/diary/Why%20Ask%20Credentials%20If%20There%20Are%20Secret%20Codes%3F/33118" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Why%20Ask%20Credentials%20If%20There%20Are%20Secret%20Codes%3F/33118</a><br /> Adobe Patches and Updated Patch Release Policy<br /><a href="https://helpx.adobe.com/security/Home.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/Home.html</a><br /><a href="https://blog.adobe.com/security/protecting-customers-faster-how-adobe-is-responding-to-ai-accelerated-vulnerability-discovery" target="_blank" rel="noreferrer noopener">https://blog.adobe.com/security/protecting-customers-faster-how-adobe-is-responding-to-ai-accelerated-vulnerability-discovery</a><br /> Google Chrome Update (link had issues loading while recording)<br /><a href="https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html</a><br /> Apple Hide My Email Vulnerability<br /><a href="https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses/" target="_blank" rel="noreferrer noopener">https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses/</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>375</itunes:duration><itunes:keywords>adobe,apple,business,chrome,crypto,cyber,cybersecurity,daily,google,hacking,hide-my-email,infosec,it,metamask,mfa,network,news,patches,phishing,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9992</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, July 1st, 2026: Apple Patches; SimpleHelp Exploit; Git DNS Tricks;</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-july-1st-2026-apple-patches-simplehelp-exploit-git-dns-tricks--72765089</link><description><![CDATA[<br /> June 2026 Apple Updates<br /><a href="https://isc.sans.edu/diary/June%202026%20Apple%20Updates/33114" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/June%202026%20Apple%20Updates/33114</a><br /> SimpleHelp Exploit used to reply TaskWeaver<br /><a href="https://blackpointcyber.com/blog/a-djinn-in-the-machine-taskweavers-node-js-intrusion-chain/" target="_blank" rel="noreferrer noopener">https://blackpointcyber.com/blog/a-djinn-in-the-machine-taskweavers-node-js-intrusion-chain/</a><br /> DNS Tricks to Load Malware into Cloned Repository<br /><a href="https://0din.ai/blog/clone-this-repo-and-i-own-your-machine" target="_blank" rel="noreferrer noopener">https://0din.ai/blog/clone-this-repo-and-i-own-your-machine</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9990.mp3</guid><pubDate>Wed, 01 Jul 2026 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72765089/9990.mp3" length="4102689" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9990" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 June 2026 Apple Updates
https://isc.sans.edu/diary/June%202026%20Apple%20Updates/33114
 SimpleHelp Exploit used to reply TaskWeaver
https://blackpointcyber.com/blog/a-djinn-in-the-machine-taskweavers-node-js-intrusion-chain/
 DNS Tricks to Load...</itunes:subtitle><itunes:summary><![CDATA[<br /> June 2026 Apple Updates<br /><a href="https://isc.sans.edu/diary/June%202026%20Apple%20Updates/33114" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/June%202026%20Apple%20Updates/33114</a><br /> SimpleHelp Exploit used to reply TaskWeaver<br /><a href="https://blackpointcyber.com/blog/a-djinn-in-the-machine-taskweavers-node-js-intrusion-chain/" target="_blank" rel="noreferrer noopener">https://blackpointcyber.com/blog/a-djinn-in-the-machine-taskweavers-node-js-intrusion-chain/</a><br /> DNS Tricks to Load Malware into Cloned Repository<br /><a href="https://0din.ai/blog/clone-this-repo-and-i-own-your-machine" target="_blank" rel="noreferrer noopener">https://0din.ai/blog/clone-this-repo-and-i-own-your-machine</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>293</itunes:duration><itunes:keywords>apple,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,ios,it,macos,network,news,safari,security,simplehelp,taskweaver</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9990</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, June 30th, 2026: Favicon Recon Automation; Targeting Messaging; Gemini CLI vuln; IPv6 Frag Escape</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-june-30th-2026-favicon-recon-automation-targeting-messaging-gemini-cli-vuln-ipv6-frag-escape--72751063</link><description><![CDATA[<br /> Adding some Automation to the favicon.ico method of Host Recon<br /><a href="https://isc.sans.edu/diary/Adding%20some%20Automation%20to%20the%20favicon.ico%20method%20of%20Host%20Recon/33110" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Adding%20some%20Automation%20to%20the%20favicon.ico%20method%20of%20Host%20Recon/33110</a><br /> Russian Intelligence Services Continue to Target Commercial Messaging Applications<br /><a href="https://www.ic3.gov/PSA/2026/PSA260626" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/PSA/2026/PSA260626</a><br /> Google Gemini CLI Vulnerability CVE-2026-12537<br /><a href="https://github.com/advisories/GHSA-jj69-4grx-fqj5" target="_blank" rel="noreferrer noopener">https://github.com/advisories/GHSA-jj69-4grx-fqj5</a><br /> IPv6 Frag Escape<br /><a href="https://github.com/sgkdev/ipv6_frag_escape" target="_blank" rel="noreferrer noopener">https://github.com/sgkdev/ipv6_frag_escape</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9988.mp3</guid><pubDate>Tue, 30 Jun 2026 02:25:12 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72751063/9988.mp3" length="4543789" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9988" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Adding some Automation to the favicon.ico method of Host Recon
https://isc.sans.edu/diary/Adding%20some%20Automation%20to%20the%20favicon.ico%20method%20of%20Host%20Recon/33110
 Russian Intelligence Services Continue to Target Commercial Messaging...</itunes:subtitle><itunes:summary><![CDATA[<br /> Adding some Automation to the favicon.ico method of Host Recon<br /><a href="https://isc.sans.edu/diary/Adding%20some%20Automation%20to%20the%20favicon.ico%20method%20of%20Host%20Recon/33110" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Adding%20some%20Automation%20to%20the%20favicon.ico%20method%20of%20Host%20Recon/33110</a><br /> Russian Intelligence Services Continue to Target Commercial Messaging Applications<br /><a href="https://www.ic3.gov/PSA/2026/PSA260626" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/PSA/2026/PSA260626</a><br /> Google Gemini CLI Vulnerability CVE-2026-12537<br /><a href="https://github.com/advisories/GHSA-jj69-4grx-fqj5" target="_blank" rel="noreferrer noopener">https://github.com/advisories/GHSA-jj69-4grx-fqj5</a><br /> IPv6 Frag Escape<br /><a href="https://github.com/sgkdev/ipv6_frag_escape" target="_blank" rel="noreferrer noopener">https://github.com/sgkdev/ipv6_frag_escape</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>325</itunes:duration><itunes:keywords>business,cli,computer,container,cyber,cybersecurity,daily,escape,favicon,gemini,google,hacking,infosec,internet,ipv6,it,messenger,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9988</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, June 29th, 2026: Automated Cybercrime; Linux Process Names; Amazon Q VS Code</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-june-29th-2026-automated-cybercrime-linux-process-names-amazon-q-vs-code--72733973</link><description><![CDATA[<br /> What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime<br /><a href="https://isc.sans.edu/diary/What%20do%20Ports%20Hear%20When%20Nobody%27s%20Listening%3F%20An%20Assessment%20of%20Automated%20Cybercrime%20%5BGuest%20Diary%5D/33104" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20do%20Ports%20Hear%20When%20Nobody%27s%20Listening%3F%20An%20Assessment%20of%20Automated%20Cybercrime%20%5BGuest%20Diary%5D/33104</a><br /> Linux Process Name Masquerading<br /><a href="https://isc.sans.edu/diary/Linux+Process+Name+Masquerading/33102" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Linux+Process+Name+Masquerading/33102</a><br /> Amazon Q VS Code Extension Vulnerability<br /><a href="https://www.wiz.io/blog/amazon-q-vulnerability" target="_blank" rel="noreferrer noopener">https://www.wiz.io/blog/amazon-q-vulnerability</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9986.mp3</guid><pubDate>Mon, 29 Jun 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72733973/9986.mp3" length="4945015" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9986" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime
https://isc.sans.edu/diary/What%20do%20Ports%20Hear%20When%20Nobody%27s%20Listening%3F%20An%20Assessment%20of%20Automated%20Cybercrime%20%5BGuest%20Diary%5D/33104...</itunes:subtitle><itunes:summary><![CDATA[<br /> What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime<br /><a href="https://isc.sans.edu/diary/What%20do%20Ports%20Hear%20When%20Nobody%27s%20Listening%3F%20An%20Assessment%20of%20Automated%20Cybercrime%20%5BGuest%20Diary%5D/33104" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20do%20Ports%20Hear%20When%20Nobody%27s%20Listening%3F%20An%20Assessment%20of%20Automated%20Cybercrime%20%5BGuest%20Diary%5D/33104</a><br /> Linux Process Name Masquerading<br /><a href="https://isc.sans.edu/diary/Linux+Process+Name+Masquerading/33102" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Linux+Process+Name+Masquerading/33102</a><br /> Amazon Q VS Code Extension Vulnerability<br /><a href="https://www.wiz.io/blog/amazon-q-vulnerability" target="_blank" rel="noreferrer noopener">https://www.wiz.io/blog/amazon-q-vulnerability</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>353</itunes:duration><itunes:keywords>amazon,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,internship,it,linux,network,news,port,process,q,sans_edu,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9986</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, June 24th, 2026: Patching vs. Configurations Updates; libssh2 and ffmpeg vuln;</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-june-24th-2026-patching-vs-configurations-updates-libssh2-and-ffmpeg-vuln--72659900</link><description><![CDATA[<br /> CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration.<br /><a href="https://isc.sans.edu/diary/CVE-2024-40766%3A%20The%20Patch%20Fixed%20the%20Bug.%20Nobody%20Fixed%20the%20Configuration./33094" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CVE-2024-40766%3A%20The%20Patch%20Fixed%20the%20Bug.%20Nobody%20Fixed%20the%20Configuration./33094</a><br /> libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c<br /><a href="https://www.vulncheck.com/advisories/libssh2-out-of-bounds-write-via-unchecked-packet-length-in-transport-c" target="_blank" rel="noreferrer noopener">https://www.vulncheck.com/advisories/libssh2-out-of-bounds-write-via-unchecked-packet-length-in-transport-c</a><br /> PixelSmash   Critical FFmpeg Vulnerability Turns Media Files into Weapons<br /><a href="https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons/" target="_blank" rel="noreferrer noopener">https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons/</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9984.mp3</guid><pubDate>Wed, 24 Jun 2026 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72659900/9984.mp3" length="5716537" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9984" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration.
https://isc.sans.edu/diary/CVE-2024-40766%3A%20The%20Patch%20Fixed%20the%20Bug.%20Nobody%20Fixed%20the%20Configuration./33094
 libssh2 - Out-of-Bounds Write via Unchecked...</itunes:subtitle><itunes:summary><![CDATA[<br /> CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration.<br /><a href="https://isc.sans.edu/diary/CVE-2024-40766%3A%20The%20Patch%20Fixed%20the%20Bug.%20Nobody%20Fixed%20the%20Configuration./33094" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CVE-2024-40766%3A%20The%20Patch%20Fixed%20the%20Bug.%20Nobody%20Fixed%20the%20Configuration./33094</a><br /> libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c<br /><a href="https://www.vulncheck.com/advisories/libssh2-out-of-bounds-write-via-unchecked-packet-length-in-transport-c" target="_blank" rel="noreferrer noopener">https://www.vulncheck.com/advisories/libssh2-out-of-bounds-write-via-unchecked-packet-length-in-transport-c</a><br /> PixelSmash   Critical FFmpeg Vulnerability Turns Media Files into Weapons<br /><a href="https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons/" target="_blank" rel="noreferrer noopener">https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons/</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>408</itunes:duration><itunes:keywords>business,computer,configurations,cyber,cybersecurity,daily,ffmpeg,hacking,infosec,internet,it,libssh2,network,news,patching,pixelsmash,security,sonicwall,ssh</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9984</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, June 23rd, 2026:  Webshells; GitHub Actions Update; Fortibleed Update; Private Access Control Tokens</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-june-23rd-2026-webshells-github-actions-update-fortibleed-update-private-access-control-tokens--72641530</link><description><![CDATA[<br /> Webshells Remain Popular<br /><a href="https://isc.sans.edu/diary/Webshells%20Remain%20Popular/33096" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Webshells%20Remain%20Popular/33096</a><br /> Safer pull_request_target defaults for GitHub Actions checkout<br /><a href="https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/" target="_blank" rel="noreferrer noopener">https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/</a><br /> Private Access Control Tokens<br /><a href="https://cloudflare.net/news/news-details/2026/Cloudflare-Collaborates-With-Leading-Browsers-to-Develop-a-Privacy-First-Protocol-For-the-Global-Internet/default.aspx" target="_blank" rel="noreferrer noopener">https://cloudflare.net/news/news-details/2026/Cloudflare-Collaborates-With-Leading-Browsers-to-Develop-a-Privacy-First-Protocol-For-the-Global-Internet/default.aspx</a><br /><a href="https://blog.cloudflare.com/eliminating-captchas-on-iphones-and-macs-using-new-standard/" target="_blank" rel="noreferrer noopener">https://blog.cloudflare.com/eliminating-captchas-on-iphones-and-macs-using-new-standard/</a><br /> Fortibleed Update<br /><a href="https://socradar.io/resources/whitepapers/dismantling-fortibleed-inside-a-russian-fortinet-compromise-operation/" target="_blank" rel="noreferrer noopener">https://socradar.io/resources/whitepapers/dismantling-fortibleed-inside-a-russian-fortinet-compromise-operation/</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9982.mp3</guid><pubDate>Tue, 23 Jun 2026 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72641530/9982.mp3" length="6739002" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9982" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Webshells Remain Popular
https://isc.sans.edu/diary/Webshells%20Remain%20Popular/33096
 Safer pull_request_target defaults for GitHub Actions checkout...</itunes:subtitle><itunes:summary><![CDATA[<br /> Webshells Remain Popular<br /><a href="https://isc.sans.edu/diary/Webshells%20Remain%20Popular/33096" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Webshells%20Remain%20Popular/33096</a><br /> Safer pull_request_target defaults for GitHub Actions checkout<br /><a href="https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/" target="_blank" rel="noreferrer noopener">https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/</a><br /> Private Access Control Tokens<br /><a href="https://cloudflare.net/news/news-details/2026/Cloudflare-Collaborates-With-Leading-Browsers-to-Develop-a-Privacy-First-Protocol-For-the-Global-Internet/default.aspx" target="_blank" rel="noreferrer noopener">https://cloudflare.net/news/news-details/2026/Cloudflare-Collaborates-With-Leading-Browsers-to-Develop-a-Privacy-First-Protocol-For-the-Global-Internet/default.aspx</a><br /><a href="https://blog.cloudflare.com/eliminating-captchas-on-iphones-and-macs-using-new-standard/" target="_blank" rel="noreferrer noopener">https://blog.cloudflare.com/eliminating-captchas-on-iphones-and-macs-using-new-standard/</a><br /> Fortibleed Update<br /><a href="https://socradar.io/resources/whitepapers/dismantling-fortibleed-inside-a-russian-fortinet-compromise-operation/" target="_blank" rel="noreferrer noopener">https://socradar.io/resources/whitepapers/dismantling-fortibleed-inside-a-russian-fortinet-compromise-operation/</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>481</itunes:duration><itunes:keywords>actions,business,cloudflare,computer,cyber,cybersecurity,daily,fortibleed,fortinet,gihtub,hacking,infosec,internet,it,network,news,pact,pull_request_target,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9982</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, June 22nd, 2026: IPv4 Mapped Phish; nginx bug; squid bleeds; AMD encryption fix</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-june-22nd-2026-ipv4-mapped-phish-nginx-bug-squid-bleeds-amd-encryption-fix--72624923</link><description><![CDATA[<br /> eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address<br /><a href="https://isc.sans.edu/diary/eBanking%20Phishing%20Delivered%20Through%20IPv4-Mapped%20IPv6%20Address/33090" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/eBanking%20Phishing%20Delivered%20Through%20IPv4-Mapped%20IPv6%20Address/33090</a><br /> NGINX ngx_http_v3_module vulnerability CVE-2026-42530<br /><a href="https://my.f5.com/manage/s/article/K000161616" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000161616</a><br /> Squidbleed (CVE-2026-47729)<br /><a href="https://blog.calif.io/p/squidbleed-cve-2026-47729" target="_blank" rel="noreferrer noopener">https://blog.calif.io/p/squidbleed-cve-2026-47729</a><br /> AMD will reinstate memory encryption on Ryzen 9000 CPUs through a BIOS update in July <br /><a href="https://www.tomshardware.com/pc-components/cpus/amd-will-reinstate-memory-encryption-on-ryzen-9000-cpus-through-a-bios-update-in-july-tsme-is-coming-back-after-valuable-community-feedback" target="_blank" rel="noreferrer noopener">https://www.tomshardware.com/pc-components/cpus/amd-will-reinstate-memory-encryption-on-ryzen-9000-cpus-through-a-bios-update-in-july-tsme-is-coming-back-after-valuable-community-feedback</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9980.mp3</guid><pubDate>Mon, 22 Jun 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72624923/9980.mp3" length="5132321" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9980" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address
https://isc.sans.edu/diary/eBanking%20Phishing%20Delivered%20Through%20IPv4-Mapped%20IPv6%20Address/33090
 NGINX ngx_http_v3_module vulnerability CVE-2026-42530...</itunes:subtitle><itunes:summary><![CDATA[<br /> eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address<br /><a href="https://isc.sans.edu/diary/eBanking%20Phishing%20Delivered%20Through%20IPv4-Mapped%20IPv6%20Address/33090" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/eBanking%20Phishing%20Delivered%20Through%20IPv4-Mapped%20IPv6%20Address/33090</a><br /> NGINX ngx_http_v3_module vulnerability CVE-2026-42530<br /><a href="https://my.f5.com/manage/s/article/K000161616" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000161616</a><br /> Squidbleed (CVE-2026-47729)<br /><a href="https://blog.calif.io/p/squidbleed-cve-2026-47729" target="_blank" rel="noreferrer noopener">https://blog.calif.io/p/squidbleed-cve-2026-47729</a><br /> AMD will reinstate memory encryption on Ryzen 9000 CPUs through a BIOS update in July <br /><a href="https://www.tomshardware.com/pc-components/cpus/amd-will-reinstate-memory-encryption-on-ryzen-9000-cpus-through-a-bios-update-in-july-tsme-is-coming-back-after-valuable-community-feedback" target="_blank" rel="noreferrer noopener">https://www.tomshardware.com/pc-components/cpus/amd-will-reinstate-memory-encryption-on-ryzen-9000-cpus-through-a-bios-update-in-july-tsme-is-coming-back-after-valuable-community-feedback</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>367</itunes:duration><itunes:keywords>amd,business,computer,cyber,cybersecurity,daily,ebanking,encryption,hacking,infosec,internet,ipv6,it,network,news,nginx,phishing,quid,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9980</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, June 18th, 2026: QUIC Challenge; Android 17; Oracle CSPU; JetBrains Plugins;</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-june-18th-2026-quic-challenge-android-17-oracle-cspu-jetbrains-plugins--72572472</link><description><![CDATA[<br /> The browser blind spot: Why your security tool may not be blocking what you think it is [Guest Diary]<br /><a href="https://isc.sans.edu/diary/The%20browser%20blind%20spot%3A%20Why%20your%20security%20tool%20may%20not%20be%20blocking%20what%20you%20think%20it%20is%20%5BGuest%20Diary%5D/33084" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20browser%20blind%20spot%3A%20Why%20your%20security%20tool%20may%20not%20be%20blocking%20what%20you%20think%20it%20is%20%5BGuest%20Diary%5D/33084</a><br /> Android 17 Security Patches<br /><a href="https://source.android.com/docs/security/bulletin/android-17" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/android-17</a><br /> Oracle Critical Security Patch Update Advisory - June 2026<br /><a href="https://www.oracle.com/security-alerts/cspujun2026.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cspujun2026.html</a><br /> Multiple JetBrains IDE plugins caught stealing AI keys<br /><a href="https://www.aikido.dev/blog/multiple-jetbrains-ide-plugins-caught-stealing-ai-keys" target="_blank" rel="noreferrer noopener">https://www.aikido.dev/blog/multiple-jetbrains-ide-plugins-caught-stealing-ai-keys</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9978.mp3</guid><pubDate>Thu, 18 Jun 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72572472/9978.mp3" length="5377744" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9978" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 The browser blind spot: Why your security tool may not be blocking what you think it is [Guest Diary]...</itunes:subtitle><itunes:summary><![CDATA[<br /> The browser blind spot: Why your security tool may not be blocking what you think it is [Guest Diary]<br /><a href="https://isc.sans.edu/diary/The%20browser%20blind%20spot%3A%20Why%20your%20security%20tool%20may%20not%20be%20blocking%20what%20you%20think%20it%20is%20%5BGuest%20Diary%5D/33084" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20browser%20blind%20spot%3A%20Why%20your%20security%20tool%20may%20not%20be%20blocking%20what%20you%20think%20it%20is%20%5BGuest%20Diary%5D/33084</a><br /> Android 17 Security Patches<br /><a href="https://source.android.com/docs/security/bulletin/android-17" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/android-17</a><br /> Oracle Critical Security Patch Update Advisory - June 2026<br /><a href="https://www.oracle.com/security-alerts/cspujun2026.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cspujun2026.html</a><br /> Multiple JetBrains IDE plugins caught stealing AI keys<br /><a href="https://www.aikido.dev/blog/multiple-jetbrains-ide-plugins-caught-stealing-ai-keys" target="_blank" rel="noreferrer noopener">https://www.aikido.dev/blog/multiple-jetbrains-ide-plugins-caught-stealing-ai-keys</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>384</itunes:duration><itunes:keywords>android,business,computer,cyber,cybersecurity,daily,hacking,http,http3,ide,infosec,internet,it,jetbrains,network,news,oracle,patches,quic,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9978</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, June 17th, 2026: VHDX to Remocs RAT; Fake Job Offer; OpenBSD Vuln; Copilot M365 Leakage</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-june-17th-2026-vhdx-to-remocs-rat-fake-job-offer-openbsd-vuln-copilot-m365-leakage--72557947</link><description><![CDATA[<br /> From a VHDX File to a Remcos RAT<br /><a href="https://isc.sans.edu/diary/From%20a%20VHDX%20File%20to%20a%20Remcos%20RAT/33080" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/From%20a%20VHDX%20File%20to%20a%20Remcos%20RAT/33080</a><br /> A backdoor in a LinkedIn job offer<br /><a href="https://roman.pt/posts/linkedin-backdoor/" target="_blank" rel="noreferrer noopener">https://roman.pt/posts/linkedin-backdoor/</a><br /> A 27-Year-Old Authentication Bypass in OpenBSD's PPP Stack<br /><a href="https://blog.argus-systems.ai/blog/openbsd-pap-27-year-auth-bypass.html" target="_blank" rel="noreferrer noopener">https://blog.argus-systems.ai/blog/openbsd-pap-27-year-auth-bypass.html</a><br /> Copilot M365 Data Leakage<br /><a href="https://www.varonis.com/blog/searchleak" target="_blank" rel="noreferrer noopener">https://www.varonis.com/blog/searchleak</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9976.mp3</guid><pubDate>Wed, 17 Jun 2026 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72557947/9976.mp3" length="6823368" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9976" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 From a VHDX File to a Remcos RAT
https://isc.sans.edu/diary/From%20a%20VHDX%20File%20to%20a%20Remcos%20RAT/33080
 A backdoor in a LinkedIn job offer
https://roman.pt/posts/linkedin-backdoor/
 A 27-Year-Old Authentication Bypass in OpenBSD's PPP...</itunes:subtitle><itunes:summary><![CDATA[<br /> From a VHDX File to a Remcos RAT<br /><a href="https://isc.sans.edu/diary/From%20a%20VHDX%20File%20to%20a%20Remcos%20RAT/33080" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/From%20a%20VHDX%20File%20to%20a%20Remcos%20RAT/33080</a><br /> A backdoor in a LinkedIn job offer<br /><a href="https://roman.pt/posts/linkedin-backdoor/" target="_blank" rel="noreferrer noopener">https://roman.pt/posts/linkedin-backdoor/</a><br /> A 27-Year-Old Authentication Bypass in OpenBSD's PPP Stack<br /><a href="https://blog.argus-systems.ai/blog/openbsd-pap-27-year-auth-bypass.html" target="_blank" rel="noreferrer noopener">https://blog.argus-systems.ai/blog/openbsd-pap-27-year-auth-bypass.html</a><br /> Copilot M365 Data Leakage<br /><a href="https://www.varonis.com/blog/searchleak" target="_blank" rel="noreferrer noopener">https://www.varonis.com/blog/searchleak</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>488</itunes:duration><itunes:keywords>backdoor,business,copilot,cyber,cybersecurity,daily,hacking,infosec,it,job offer,linkedin,m365,network,news,openbsd,ppp,rat,remcos,security,vhdx</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9976</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, June 16th, 2026: BASE64 Statistics; Cisco SD-WAN Exploited; AMD TSME Disabled; Poisoning Deep Research Agents</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-june-16th-2026-base64-statistics-cisco-sd-wan-exploited-amd-tsme-disabled-poisoning-deep-research-agents--72543328</link><description><![CDATA[<br /> Evil MSI Background: BASE64 Statistical Analysis<br /><a href="https://isc.sans.edu/diary/Evil%20MSI%20Background%3A%20BASE64%20Statistical%20Analysis/33072" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Evil%20MSI%20Background%3A%20BASE64%20Statistical%20Analysis/33072</a><br /> Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ</a><br /> TSME/SME not activating on Ryzen 7 9700X<br /><a href="https://github.com/AMDESE/AMDSEV/issues/292" target="_blank" rel="noreferrer noopener">https://github.com/AMDESE/AMDSEV/issues/292</a><br /> Deep-Research Agents Can Be Poisoned via User-Generated Content<br /><a href="https://arxiv.org/pdf/2605.24245" target="_blank" rel="noreferrer noopener">https://arxiv.org/pdf/2605.24245</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9974.mp3</guid><pubDate>Tue, 16 Jun 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72543328/9974.mp3" length="5237511" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9974" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Evil MSI Background: BASE64 Statistical Analysis
https://isc.sans.edu/diary/Evil%20MSI%20Background%3A%20BASE64%20Statistical%20Analysis/33072
 Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability...</itunes:subtitle><itunes:summary><![CDATA[<br /> Evil MSI Background: BASE64 Statistical Analysis<br /><a href="https://isc.sans.edu/diary/Evil%20MSI%20Background%3A%20BASE64%20Statistical%20Analysis/33072" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Evil%20MSI%20Background%3A%20BASE64%20Statistical%20Analysis/33072</a><br /> Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ</a><br /> TSME/SME not activating on Ryzen 7 9700X<br /><a href="https://github.com/AMDESE/AMDSEV/issues/292" target="_blank" rel="noreferrer noopener">https://github.com/AMDESE/AMDSEV/issues/292</a><br /> Deep-Research Agents Can Be Poisoned via User-Generated Content<br /><a href="https://arxiv.org/pdf/2605.24245" target="_blank" rel="noreferrer noopener">https://arxiv.org/pdf/2605.24245</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>374</itunes:duration><itunes:keywords>0-day,amd,base64,business,cisco,cyber,cybersecurity,daily,deep-research,hacking,infosec,it,llm,msi,network,news,ryzen,sd-wan,seo,wallpaper</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9974</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, June 15th, 2026:  Arch Linux Malicious User Packages; Splunk Vuln and Exploit; Exploiting AI Coding Agents</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-june-15th-2026-arch-linux-malicious-user-packages-splunk-vuln-and-exploit-exploiting-ai-coding-agents--72528206</link><description><![CDATA[<br /> Atomic Arch: Attackers Hijack Trusted AUR Packages to Deliver Rootkit-Like Malware<br /><a href="https://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency" target="_blank" rel="noreferrer noopener">https://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency</a><br /> Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE) <a href="https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/</a><br /> A Fake Bug Report Hijacks Your AI Coding Agent   and Nothing Catches It.<br /><a href="https://tenetsecurity.ai/blog/agentjacking-coding-agents-with-fake-sentry-errors/" target="_blank" rel="noreferrer noopener">https://tenetsecurity.ai/blog/agentjacking-coding-agents-with-fake-sentry-errors/</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9972.mp3</guid><pubDate>Mon, 15 Jun 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72528206/9972.mp3" length="5738620" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9972" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Atomic Arch: Attackers Hijack Trusted AUR Packages to Deliver Rootkit-Like Malware
https://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency
 Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise...</itunes:subtitle><itunes:summary><![CDATA[<br /> Atomic Arch: Attackers Hijack Trusted AUR Packages to Deliver Rootkit-Like Malware<br /><a href="https://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency" target="_blank" rel="noreferrer noopener">https://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency</a><br /> Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE) <a href="https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/</a><br /> A Fake Bug Report Hijacks Your AI Coding Agent   and Nothing Catches It.<br /><a href="https://tenetsecurity.ai/blog/agentjacking-coding-agents-with-fake-sentry-errors/" target="_blank" rel="noreferrer noopener">https://tenetsecurity.ai/blog/agentjacking-coding-agents-with-fake-sentry-errors/</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>410</itunes:duration><itunes:keywords>agent,ai,arch,arch linux,atomic arch,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,postgresql,security,splunk</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9972</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, June 12th, 2026: Bitlocker Trouble; Ivanti and Oracle Exploited; macOS Malicious Installers</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-june-12th-2026-bitlocker-trouble-ivanti-and-oracle-exploited-macos-malicious-installers--72498217</link><description><![CDATA[<br /> More Bitlocker Issues: GreatXML<br /><a href="https://git.churchofmalware.org/Nightmare_Eclipse/GreatXML" target="_blank" rel="noreferrer noopener">https://git.churchofmalware.org/Nightmare_Eclipse/GreatXML</a><br /> Security Advisory Ivanti Sentry (CVE-2026-10520, CVE-2026-10523)<br /><a href="https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US" target="_blank" rel="noreferrer noopener">https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US</a><br /> Oracle Security Alert Advisory - CVE-2026-35273<br /><a href="https://www.oracle.com/security-alerts/alert-cve-2026-35273.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/alert-cve-2026-35273.html</a><br /><a href="https://www.bleepingcomputer.com/news/security/oracle-mitigates-peoplesoft-zero-day-exploited-in-data-theft-attacks/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/oracle-mitigates-peoplesoft-zero-day-exploited-in-data-theft-attacks/</a><br /> How Deceptive Installers Are Targeting macOS Users<br /><a href="https://www.huntress.com/blog/deceptive-installers-macos-infostealers" target="_blank" rel="noreferrer noopener">https://www.huntress.com/blog/deceptive-installers-macos-infostealers</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9970.mp3</guid><pubDate>Fri, 12 Jun 2026 12:30:10 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72498217/9970.mp3" length="5587748" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9970" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 More Bitlocker Issues: GreatXML
https://git.churchofmalware.org/Nightmare_Eclipse/GreatXML
 Security Advisory Ivanti Sentry (CVE-2026-10520, CVE-2026-10523)...</itunes:subtitle><itunes:summary><![CDATA[<br /> More Bitlocker Issues: GreatXML<br /><a href="https://git.churchofmalware.org/Nightmare_Eclipse/GreatXML" target="_blank" rel="noreferrer noopener">https://git.churchofmalware.org/Nightmare_Eclipse/GreatXML</a><br /> Security Advisory Ivanti Sentry (CVE-2026-10520, CVE-2026-10523)<br /><a href="https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US" target="_blank" rel="noreferrer noopener">https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US</a><br /> Oracle Security Alert Advisory - CVE-2026-35273<br /><a href="https://www.oracle.com/security-alerts/alert-cve-2026-35273.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/alert-cve-2026-35273.html</a><br /><a href="https://www.bleepingcomputer.com/news/security/oracle-mitigates-peoplesoft-zero-day-exploited-in-data-theft-attacks/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/oracle-mitigates-peoplesoft-zero-day-exploited-in-data-theft-attacks/</a><br /> How Deceptive Installers Are Targeting macOS Users<br /><a href="https://www.huntress.com/blog/deceptive-installers-macos-infostealers" target="_blank" rel="noreferrer noopener">https://www.huntress.com/blog/deceptive-installers-macos-infostealers</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>399</itunes:duration><itunes:keywords>bitlocker,business,computer,cyber,cybersecurity,daily,greatxml,hacking,infosec,internet,it,ivanti,mac malware,network,news,oracle,peoplesoft,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9970</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, June 11th, 2026: Framing Protections; npm improvements; Adobe Patches; New Defender 0-day</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-june-11th-2026-framing-protections-npm-improvements-adobe-patches-new-defender-0-day--72471232</link><description><![CDATA[<br /> How has use of framing protection security headers changed in the past 3 years?<br /><a href="https://isc.sans.edu/diary/How%20has%20use%20of%20framing%20protection%20security%20headers%20changed%20in%20the%20past%203%20years%3F/33068" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20has%20use%20of%20framing%20protection%20security%20headers%20changed%20in%20the%20past%203%20years%3F/33068</a><br /> Preparing for npm v12: install scripts and non-registry sources become opt-in<br /><a href="https://github.com/orgs/community/discussions/198547" target="_blank" rel="noreferrer noopener">https://github.com/orgs/community/discussions/198547</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security.html</a><br /> Rogue Planet new Microsoft Defender Vulnerability<br /><a href="https://github.com/MSNightmare/RoguePlanet" target="_blank" rel="noreferrer noopener">https://github.com/MSNightmare/RoguePlanet</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9968.mp3</guid><pubDate>Thu, 11 Jun 2026 02:25:20 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72471232/9968.mp3" length="4952837" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9968" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 How has use of framing protection security headers changed in the past 3 years?
https://isc.sans.edu/diary/How%20has%20use%20of%20framing%20protection%20security%20headers%20changed%20in%20the%20past%203%20years%3F/33068
 Preparing for npm v12:...</itunes:subtitle><itunes:summary><![CDATA[<br /> How has use of framing protection security headers changed in the past 3 years?<br /><a href="https://isc.sans.edu/diary/How%20has%20use%20of%20framing%20protection%20security%20headers%20changed%20in%20the%20past%203%20years%3F/33068" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20has%20use%20of%20framing%20protection%20security%20headers%20changed%20in%20the%20past%203%20years%3F/33068</a><br /> Preparing for npm v12: install scripts and non-registry sources become opt-in<br /><a href="https://github.com/orgs/community/discussions/198547" target="_blank" rel="noreferrer noopener">https://github.com/orgs/community/discussions/198547</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security.html</a><br /> Rogue Planet new Microsoft Defender Vulnerability<br /><a href="https://github.com/MSNightmare/RoguePlanet" target="_blank" rel="noreferrer noopener">https://github.com/MSNightmare/RoguePlanet</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>354</itunes:duration><itunes:keywords>0-day,adobe,business,computer,cyber,cybersecurity,daily,defender,hacking,headers,iframe,infosec,internet,it,network,news,npm,rogue planet,security,vulnerability</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9968</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, June 10th, 2026: Microsoft Patch Tuesday; Miasma Source Published; Fortinet Patches</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-june-10th-2026-microsoft-patch-tuesday-miasma-source-published-fortinet-patches--72448459</link><description><![CDATA[<br /> Microsoft June 2026 Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20June%202026%20Patch%20Tuesday/33064" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20June%202026%20Patch%20Tuesday/33064</a><br /> Miasma Software Supply Chain Attack Toolkit Source Published<br /><a href="https://safedep.io/inside-the-miasma-supply-chain-attack-toolkit/" target="_blank" rel="noreferrer noopener">https://safedep.io/inside-the-miasma-supply-chain-attack-toolkit/</a><br /> Fortinet FortiSandbox Vulnerability<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-141" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-26-141</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9966.mp3</guid><pubDate>Wed, 10 Jun 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72448459/9966.mp3" length="6005680" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9966" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Microsoft June 2026 Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20June%202026%20Patch%20Tuesday/33064
 Miasma Software Supply Chain Attack Toolkit Source Published
https://safedep.io/inside-the-miasma-supply-chain-attack-toolkit/
 Fortinet...</itunes:subtitle><itunes:summary><![CDATA[<br /> Microsoft June 2026 Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20June%202026%20Patch%20Tuesday/33064" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20June%202026%20Patch%20Tuesday/33064</a><br /> Miasma Software Supply Chain Attack Toolkit Source Published<br /><a href="https://safedep.io/inside-the-miasma-supply-chain-attack-toolkit/" target="_blank" rel="noreferrer noopener">https://safedep.io/inside-the-miasma-supply-chain-attack-toolkit/</a><br /> Fortinet FortiSandbox Vulnerability<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-141" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-26-141</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>429</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,fortinet,fortisandbox,hacking,infosec,internet,it,miasma,microsoft,network,news,patches,security,supply chain</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9966</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, June 9th, 2026: Azure Repos Infected; Checkpoint VPN 0-Day; Verizon VoLTE missing IPSec integrity prot.</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-june-9th-2026-azure-repos-infected-checkpoint-vpn-0-day-verizon-volte-missing-ipsec-integrity-prot--72428977</link><description><![CDATA[<br /> Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack<br /><a href="https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents" target="_blank" rel="noreferrer noopener">https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents</a><br /> Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751)<br /><a href="https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/" target="_blank" rel="noreferrer noopener">https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/</a><br /> Missing IPsec Integrity Protection for IMS SIP Signaling in Verizon VoLTE Deployments<br /><a href="https://kb.cert.org/vuls/id/615987" target="_blank" rel="noreferrer noopener">https://kb.cert.org/vuls/id/615987</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9964.mp3</guid><pubDate>Tue, 09 Jun 2026 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72428977/9964.mp3" length="4578722" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9964" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack...</itunes:subtitle><itunes:summary><![CDATA[<br /> Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack<br /><a href="https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents" target="_blank" rel="noreferrer noopener">https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents</a><br /> Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751)<br /><a href="https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/" target="_blank" rel="noreferrer noopener">https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/</a><br /> Missing IPsec Integrity Protection for IMS SIP Signaling in Verizon VoLTE Deployments<br /><a href="https://kb.cert.org/vuls/id/615987" target="_blank" rel="noreferrer noopener">https://kb.cert.org/vuls/id/615987</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>327</itunes:duration><itunes:keywords>azure,business,checkpoint,check point,computer,cyber,cybersecurity,daily,hacking,infosec,internet,ipsec,it,network,news,security,verizon,volte,vpn</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9964</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, June 8th, 2026: Wetransfer Phish; Spying Smart TV; Dashlane Brute Force</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-june-8th-2026-wetransfer-phish-spying-smart-tv-dashlane-brute-force--72409961</link><description><![CDATA[<br /> The Evil MSI Background is Back!<br /><a href="https://isc.sans.edu/diary/The%20Evil%20MSI%20Background%20is%20Back!/33054" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20Evil%20MSI%20Background%20is%20Back!/33054</a><br /> The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy<br /><a href="https://blog.includesecurity.com/2026/06/the-smart-tv-in-your-livingroom-is-a-node-in-the-aiscraping-economy/" target="_blank" rel="noreferrer noopener">https://blog.includesecurity.com/2026/06/the-smart-tv-in-your-livingroom-is-a-node-in-the-aiscraping-economy/</a><br /> Brute force attack on Dashlane user accounts<br /><a href="https://support.dashlane.com/hc/en-us/articles/36038764990866-Security-advisory-Brute-force-attack-on-Dashlane-user-accounts#update-jun-4" target="_blank" rel="noreferrer noopener">https://support.dashlane.com/hc/en-us/articles/36038764990866-Security-advisory-Brute-force-attack-on-Dashlane-user-accounts#update-jun-4</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9962.mp3</guid><pubDate>Mon, 08 Jun 2026 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72409961/9962.mp3" length="6171467" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9962" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 The Evil MSI Background is Back!
https://isc.sans.edu/diary/The%20Evil%20MSI%20Background%20is%20Back!/33054
 The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy...</itunes:subtitle><itunes:summary><![CDATA[<br /> The Evil MSI Background is Back!<br /><a href="https://isc.sans.edu/diary/The%20Evil%20MSI%20Background%20is%20Back!/33054" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20Evil%20MSI%20Background%20is%20Back!/33054</a><br /> The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy<br /><a href="https://blog.includesecurity.com/2026/06/the-smart-tv-in-your-livingroom-is-a-node-in-the-aiscraping-economy/" target="_blank" rel="noreferrer noopener">https://blog.includesecurity.com/2026/06/the-smart-tv-in-your-livingroom-is-a-node-in-the-aiscraping-economy/</a><br /> Brute force attack on Dashlane user accounts<br /><a href="https://support.dashlane.com/hc/en-us/articles/36038764990866-Security-advisory-Brute-force-attack-on-Dashlane-user-accounts#update-jun-4" target="_blank" rel="noreferrer noopener">https://support.dashlane.com/hc/en-us/articles/36038764990866-Security-advisory-Brute-force-attack-on-Dashlane-user-accounts#update-jun-4</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>441</itunes:duration><itunes:keywords>ai,background,business,cloudlfare,computer,cyber,cybersecurity,daily,dashlane,evil,hacking,infosec,it,msi,network,news,proxy,security,smart tv,wetransfer</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9962</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, June 5th, 2026: Coreutils for Windows; Cisco Unified Comm Manager Fix and Exploit; OAuth Orphans</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-june-5th-2026-coreutils-for-windows-cisco-unified-comm-manager-fix-and-exploit-oauth-orphans--72358070</link><description><![CDATA[<br /> Microsoft's Coreutils for Windows<br /><a href="https://isc.sans.edu/diary/Microsoft%27s%20Coreutils%20for%20Windows/33048" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%27s%20Coreutils%20for%20Windows/33048</a><br /> Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability CVE-2026-20230<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW</a><br /> Firmware Update for Acer Connect W6x Router <br /><a href="https://community.acer.com/en/kb/articles/19672" target="_blank" rel="noreferrer noopener">https://community.acer.com/en/kb/articles/19672</a><br /> OAuth marketplace apps keep access after publishers vanish<br /><a href="https://www.helpnetsecurity.com/2026/06/04/oauth-marketplace-apps-audit/" target="_blank" rel="noreferrer noopener">https://www.helpnetsecurity.com/2026/06/04/oauth-marketplace-apps-audit/</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9960.mp3</guid><pubDate>Fri, 05 Jun 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72358070/9960.mp3" length="5205928" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9960" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Microsoft's Coreutils for Windows
https://isc.sans.edu/diary/Microsoft%27s%20Coreutils%20for%20Windows/33048
 Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability CVE-2026-20230...</itunes:subtitle><itunes:summary><![CDATA[<br /> Microsoft's Coreutils for Windows<br /><a href="https://isc.sans.edu/diary/Microsoft%27s%20Coreutils%20for%20Windows/33048" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%27s%20Coreutils%20for%20Windows/33048</a><br /> Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability CVE-2026-20230<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW</a><br /> Firmware Update for Acer Connect W6x Router <br /><a href="https://community.acer.com/en/kb/articles/19672" target="_blank" rel="noreferrer noopener">https://community.acer.com/en/kb/articles/19672</a><br /> OAuth marketplace apps keep access after publishers vanish<br /><a href="https://www.helpnetsecurity.com/2026/06/04/oauth-marketplace-apps-audit/" target="_blank" rel="noreferrer noopener">https://www.helpnetsecurity.com/2026/06/04/oauth-marketplace-apps-audit/</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>372</itunes:duration><itunes:keywords>acer,business,cisco,computer,coreutils,cyber,cybersecurity,daily,hacking,infosec,internet,it,microsoft,network,news,oauth,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9960</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, June 4th, 2026: swagger.json Scans; Android Fake Call Detection; Anthropic Dashboard</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-june-4th-2026-swagger-json-scans-android-fake-call-detection-anthropic-dashboard--72334522</link><description><![CDATA[<br /> Continuing Scans for swagger.json<br /><a href="https://isc.sans.edu/diary/Continuing+Scans+for+swaggerjson/33044/#comments" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Continuing+Scans+for+swaggerjson/33044/#comments</a><br /> Fake call detection on Android<br /><a href="https://blog.google/security/android-fake-call-detection/" target="_blank" rel="noreferrer noopener">https://blog.google/security/android-fake-call-detection/</a><br /> Anthropic's coordinated vulnerability disclosure dashboard<br /><a href="https://red.anthropic.com/2026/cvd/" target="_blank" rel="noreferrer noopener">https://red.anthropic.com/2026/cvd/</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9958.mp3</guid><pubDate>Thu, 04 Jun 2026 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72334522/9958.mp3" length="5798506" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9958" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Continuing Scans for swagger.json
https://isc.sans.edu/diary/Continuing+Scans+for+swaggerjson/33044/#comments
 Fake call detection on Android
https://blog.google/security/android-fake-call-detection/
 Anthropic's coordinated vulnerability disclosure...</itunes:subtitle><itunes:summary><![CDATA[<br /> Continuing Scans for swagger.json<br /><a href="https://isc.sans.edu/diary/Continuing+Scans+for+swaggerjson/33044/#comments" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Continuing+Scans+for+swaggerjson/33044/#comments</a><br /> Fake call detection on Android<br /><a href="https://blog.google/security/android-fake-call-detection/" target="_blank" rel="noreferrer noopener">https://blog.google/security/android-fake-call-detection/</a><br /> Anthropic's coordinated vulnerability disclosure dashboard<br /><a href="https://red.anthropic.com/2026/cvd/" target="_blank" rel="noreferrer noopener">https://red.anthropic.com/2026/cvd/</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>414</itunes:duration><itunes:keywords>adnroid,anthropic,business,caller-id,computer,cyber,cybersecurity,daily,dashboard,hacking,infosec,internet,it,json,network,news,security,swagger</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9958</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, June 3rd, 2026: SVG Phishing; Android Patches; Poly Voice Vuln; Ivanti Neurons Priv Escelation</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-june-3rd-2026-svg-phishing-android-patches-poly-voice-vuln-ivanti-neurons-priv-escelation--72310597</link><description><![CDATA[<br /> New Wave Of Phishing Emails with SVG Files<br /><a href="https://isc.sans.edu/diary/New%20Wave%20Of%20Phishing%20Emails%20with%20SVG%20Files/33040" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/New%20Wave%20Of%20Phishing%20Emails%20with%20SVG%20Files/33040</a><br /> Android 2026-06-01 security patch level vulnerability details<br /><a href="https://source.android.com/docs/security/bulletin/2026/2026-06-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2026/2026-06-01</a><br /> Poly Voice   Possible Remote Control of Certain Poly Devices CVE-2026-0826<br /><a href="https://support.hp.com/us-en/document/ish_15052661-15052687-16/hpsbpy04083" target="_blank" rel="noreferrer noopener">https://support.hp.com/us-en/document/ish_15052661-15052687-16/hpsbpy04083</a><br /><a href="https://www.rapid7.com/blog/post/ve-cve-2026-0826-critical-unauthenticated-stack-buffer-overflow-hp-poly-vvx-trio-voip-phones-fixed/" target="_blank" rel="noreferrer noopener">https://www.rapid7.com/blog/post/ve-cve-2026-0826-critical-unauthenticated-stack-buffer-overflow-hp-poly-vvx-trio-voip-phones-fixed/</a><br /> Security Advisory Ivanti Neurons for ITSM (CVE-2026-9614)<br /><a href="https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-9614?language=en_US" target="_blank" rel="noreferrer noopener">https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-9614?language=en_US</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9956.mp3</guid><pubDate>Wed, 03 Jun 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72310597/9956.mp3" length="3345957" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9956" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 New Wave Of Phishing Emails with SVG Files
https://isc.sans.edu/diary/New%20Wave%20Of%20Phishing%20Emails%20with%20SVG%20Files/33040
 Android 2026-06-01 security patch level vulnerability details...</itunes:subtitle><itunes:summary><![CDATA[<br /> New Wave Of Phishing Emails with SVG Files<br /><a href="https://isc.sans.edu/diary/New%20Wave%20Of%20Phishing%20Emails%20with%20SVG%20Files/33040" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/New%20Wave%20Of%20Phishing%20Emails%20with%20SVG%20Files/33040</a><br /> Android 2026-06-01 security patch level vulnerability details<br /><a href="https://source.android.com/docs/security/bulletin/2026/2026-06-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2026/2026-06-01</a><br /> Poly Voice   Possible Remote Control of Certain Poly Devices CVE-2026-0826<br /><a href="https://support.hp.com/us-en/document/ish_15052661-15052687-16/hpsbpy04083" target="_blank" rel="noreferrer noopener">https://support.hp.com/us-en/document/ish_15052661-15052687-16/hpsbpy04083</a><br /><a href="https://www.rapid7.com/blog/post/ve-cve-2026-0826-critical-unauthenticated-stack-buffer-overflow-hp-poly-vvx-trio-voip-phones-fixed/" target="_blank" rel="noreferrer noopener">https://www.rapid7.com/blog/post/ve-cve-2026-0826-critical-unauthenticated-stack-buffer-overflow-hp-poly-vvx-trio-voip-phones-fixed/</a><br /> Security Advisory Ivanti Neurons for ITSM (CVE-2026-9614)<br /><a href="https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-9614?language=en_US" target="_blank" rel="noreferrer noopener">https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-9614?language=en_US</a><br />     My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>239</itunes:duration><itunes:keywords>android,business,computer,cyber,cybersecurity,daily,hacking,hp,infosec,internet,it,itsm,ivanti,network,neurons,news,poly,poly voice,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9956</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, June 2nd, 2026: Netlogon Exploit; Unidentified RAT; Windows Netlogon Exploited; RedHat npm Affected; Dashlane Brutef</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-june-2nd-2026-netlogon-exploit-unidentified-rat-windows-netlogon-exploited-redhat-npm-affected-dashlane-brutef--72287967</link><description><![CDATA[<br /> Unidentified RAT pushes NetSupport RAT<br /><a href="https://isc.sans.edu/diary/Unidentified%20RAT%20pushes%20NetSupport%20RAT/33034" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Unidentified%20RAT%20pushes%20NetSupport%20RAT/33034</a><br /> CVE-2026-41089: Windows Netlogon Vulnerability Exploited<br /><a href="https://ccb.belgium.be/advisories/warning-microsoft-patch-tuesday-may-2026-patches-118-vulnerabilities-16-critical-102" target="_blank" rel="noreferrer noopener">https://ccb.belgium.be/advisories/warning-microsoft-patch-tuesday-may-2026-patches-118-vulnerabilities-16-critical-102</a><br /> RedHat npm Packages Affected<br /><a href="https://www.aikido.dev/blog/red-hat-npm-packages-compromised-credential-stealing-worm" target="_blank" rel="noreferrer noopener">https://www.aikido.dev/blog/red-hat-npm-packages-compromised-credential-stealing-worm</a><br /> Dashlane Locking Accounts after Brute Force<br /><a href="https://status.dashlane.com/pages/5aabcb89fccc4b04d3774443" target="_blank" rel="noreferrer noopener">https://status.dashlane.com/pages/5aabcb89fccc4b04d3774443</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9954.mp3</guid><pubDate>Tue, 02 Jun 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72287967/9954.mp3" length="4597667" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9954" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Unidentified RAT pushes NetSupport RAT
https://isc.sans.edu/diary/Unidentified%20RAT%20pushes%20NetSupport%20RAT/33034
 CVE-2026-41089: Windows Netlogon Vulnerability Exploited...</itunes:subtitle><itunes:summary><![CDATA[<br /> Unidentified RAT pushes NetSupport RAT<br /><a href="https://isc.sans.edu/diary/Unidentified%20RAT%20pushes%20NetSupport%20RAT/33034" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Unidentified%20RAT%20pushes%20NetSupport%20RAT/33034</a><br /> CVE-2026-41089: Windows Netlogon Vulnerability Exploited<br /><a href="https://ccb.belgium.be/advisories/warning-microsoft-patch-tuesday-may-2026-patches-118-vulnerabilities-16-critical-102" target="_blank" rel="noreferrer noopener">https://ccb.belgium.be/advisories/warning-microsoft-patch-tuesday-may-2026-patches-118-vulnerabilities-16-critical-102</a><br /> RedHat npm Packages Affected<br /><a href="https://www.aikido.dev/blog/red-hat-npm-packages-compromised-credential-stealing-worm" target="_blank" rel="noreferrer noopener">https://www.aikido.dev/blog/red-hat-npm-packages-compromised-credential-stealing-worm</a><br /> Dashlane Locking Accounts after Brute Force<br /><a href="https://status.dashlane.com/pages/5aabcb89fccc4b04d3774443" target="_blank" rel="noreferrer noopener">https://status.dashlane.com/pages/5aabcb89fccc4b04d3774443</a><br /> My Upcoming Classes<br /><a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">https://www.sans.org/profiles/dr-johannes-ullrich</a><br />]]></itunes:summary><itunes:duration>329</itunes:duration><itunes:keywords>business,clickfix,computer,cyber,cybersecurity,daily,dashlange,hacking,infosec,internet,it,netlogon,netsupport,network,news,npm,rat,redhat,security,windows</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9954</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, June 1st, 2026: Bitskrieg; Gogs Unpatched Vuln; Oracle Critical Updates; PAN-OS Exploited;</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-june-1st-2026-bitskrieg-gogs-unpatched-vuln-oracle-critical-updates-pan-os-exploited--72268881</link><description><![CDATA[<br /> Announcing Bitskrieg<br /><a href="https://deadeclipse666.blogspot.com/2026/05/announcing-bitskrieg.html" target="_blank" rel="noreferrer noopener">https://deadeclipse666.blogspot.com/2026/05/announcing-bitskrieg.html</a><br /> Vulnerability in Gogs<br /><a href="https://www.rapid7.com/blog/post/ve-authenticated-rce-via-argument-injection-gogs-unfixed/" target="_blank" rel="noreferrer noopener">https://www.rapid7.com/blog/post/ve-authenticated-rce-via-argument-injection-gogs-unfixed/</a><br /> Oracle Critical Security Patch Update Advisory - May 2026<br /><a href="https://www.oracle.com/security-alerts/cspumay2026.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cspumay2026.html</a><br /> GlobalProtect Authentication Bypass Vulnerabilities CVE-2026-0257<br /><a href="https://security.paloaltonetworks.com/CVE-2026-0257" target="_blank" rel="noreferrer noopener">https://security.paloaltonetworks.com/CVE-2026-0257</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9952.mp3</guid><pubDate>Mon, 01 Jun 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72268881/9952.mp3" length="4172073" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9952" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Announcing Bitskrieg
https://deadeclipse666.blogspot.com/2026/05/announcing-bitskrieg.html
 Vulnerability in Gogs
https://www.rapid7.com/blog/post/ve-authenticated-rce-via-argument-injection-gogs-unfixed/
 Oracle Critical Security Patch Update...</itunes:subtitle><itunes:summary><![CDATA[<br /> Announcing Bitskrieg<br /><a href="https://deadeclipse666.blogspot.com/2026/05/announcing-bitskrieg.html" target="_blank" rel="noreferrer noopener">https://deadeclipse666.blogspot.com/2026/05/announcing-bitskrieg.html</a><br /> Vulnerability in Gogs<br /><a href="https://www.rapid7.com/blog/post/ve-authenticated-rce-via-argument-injection-gogs-unfixed/" target="_blank" rel="noreferrer noopener">https://www.rapid7.com/blog/post/ve-authenticated-rce-via-argument-injection-gogs-unfixed/</a><br /> Oracle Critical Security Patch Update Advisory - May 2026<br /><a href="https://www.oracle.com/security-alerts/cspumay2026.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cspumay2026.html</a><br /> GlobalProtect Authentication Bypass Vulnerabilities CVE-2026-0257<br /><a href="https://security.paloaltonetworks.com/CVE-2026-0257" target="_blank" rel="noreferrer noopener">https://security.paloaltonetworks.com/CVE-2026-0257</a><br />]]></itunes:summary><itunes:duration>298</itunes:duration><itunes:keywords>bitskrieg,business,computer,cyber,cybersecurity,daily,global protect,gogs,hacking,infosec,internet,it,network,news,oracle,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9952</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, May 29th, 2026: @sans_edu research; Honeypot Log; VPN “Toad”; Silent Ransom Group</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-may-29th-2026-sans-edu-research-honeypot-log-vpn-toad-silent-ransom-group--72217965</link><description><![CDATA[<br /> Research Review Journal<br /><a href="https://assets.contentstack.io/v3/assets/blt83c410d686aa5f84/blt3cff46f63887f83e/research-review-journal" target="_blank" rel="noreferrer noopener">https://assets.contentstack.io/v3/assets/blt83c410d686aa5f84/blt3cff46f63887f83e/research-review-journal</a><br /><a href="https://www.sans.edu/cyber-research" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research</a><br /> Analysis of a Year of Files Uploaded to DShield Sensors<br /><a href="https://isc.sans.edu/diary/Analysis%20of%20a%20Year%20of%20Files%20Uploaded%20to%20DShield%20Sensors/33026" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analysis%20of%20a%20Year%20of%20Files%20Uploaded%20to%20DShield%20Sensors/33026</a><br /> The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular VPN<br /><a href="https://amibeingpwned.com/blog/urban-vpn-postmessage-command-injection" target="_blank" rel="noreferrer noopener">https://amibeingpwned.com/blog/urban-vpn-postmessage-command-injection</a><br /> Silent Ransom Group Impersonating IT Personnel through Social Engineering<br /><a href="https://www.ic3.gov/CSA/2026/260526.pdf" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/CSA/2026/260526.pdf</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9950.mp3</guid><pubDate>Fri, 29 May 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72217965/9950.mp3" length="5058882" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9950" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Research Review Journal
https://assets.contentstack.io/v3/assets/blt83c410d686aa5f84/blt3cff46f63887f83e/research-review-journal
https://www.sans.edu/cyber-research
 Analysis of a Year of Files Uploaded to DShield Sensors...</itunes:subtitle><itunes:summary><![CDATA[<br /> Research Review Journal<br /><a href="https://assets.contentstack.io/v3/assets/blt83c410d686aa5f84/blt3cff46f63887f83e/research-review-journal" target="_blank" rel="noreferrer noopener">https://assets.contentstack.io/v3/assets/blt83c410d686aa5f84/blt3cff46f63887f83e/research-review-journal</a><br /><a href="https://www.sans.edu/cyber-research" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research</a><br /> Analysis of a Year of Files Uploaded to DShield Sensors<br /><a href="https://isc.sans.edu/diary/Analysis%20of%20a%20Year%20of%20Files%20Uploaded%20to%20DShield%20Sensors/33026" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analysis%20of%20a%20Year%20of%20Files%20Uploaded%20to%20DShield%20Sensors/33026</a><br /> The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular VPN<br /><a href="https://amibeingpwned.com/blog/urban-vpn-postmessage-command-injection" target="_blank" rel="noreferrer noopener">https://amibeingpwned.com/blog/urban-vpn-postmessage-command-injection</a><br /> Silent Ransom Group Impersonating IT Personnel through Social Engineering<br /><a href="https://www.ic3.gov/CSA/2026/260526.pdf" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/CSA/2026/260526.pdf</a><br />]]></itunes:summary><itunes:duration>361</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dshield,hacking,infosec,it,network,news,on site,ransom ware,research,@sans_edu,sans.edu,security,sensor,toad,vpn</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9950</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, May 28th, 2026: Akira Ransomware; Vaultjacking; Poisoned Chatbot and Search Results;</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-may-28th-2026-akira-ransomware-vaultjacking-poisoned-chatbot-and-search-results--72198408</link><description><![CDATA[<br /> Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs<br /><a href="https://isc.sans.edu/diary/Reconstructing%20an%20Akira%20Ransomware%20Kill%20Chain%20from%20Perimeter%20and%20Endpoint%20Logs/33024" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Reconstructing%20an%20Akira%20Ransomware%20Kill%20Chain%20from%20Perimeter%20and%20Endpoint%20Logs/33024</a><br /> Vaultjacking: One Captured PIN, the Entire Google Password Manager Vault<br /><a href="https://phishu.net/blogs/blog-vaultjacking-phishing-the-google-password-manager-vault-in-the-phishu-framework.html" target="_blank" rel="noreferrer noopener">https://phishu.net/blogs/blog-vaultjacking-phishing-the-google-password-manager-vault-in-the-phishu-framework.html</a><br /> From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities<br /><a href="https://www.microsoft.com/en-us/security/blog/2026/05/26/poisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2026/05/26/poisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9948.mp3</guid><pubDate>Thu, 28 May 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72198408/9948.mp3" length="5101328" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9948" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs
https://isc.sans.edu/diary/Reconstructing%20an%20Akira%20Ransomware%20Kill%20Chain%20from%20Perimeter%20and%20Endpoint%20Logs/33024
 Vaultjacking: One Captured PIN, the...</itunes:subtitle><itunes:summary><![CDATA[<br /> Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs<br /><a href="https://isc.sans.edu/diary/Reconstructing%20an%20Akira%20Ransomware%20Kill%20Chain%20from%20Perimeter%20and%20Endpoint%20Logs/33024" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Reconstructing%20an%20Akira%20Ransomware%20Kill%20Chain%20from%20Perimeter%20and%20Endpoint%20Logs/33024</a><br /> Vaultjacking: One Captured PIN, the Entire Google Password Manager Vault<br /><a href="https://phishu.net/blogs/blog-vaultjacking-phishing-the-google-password-manager-vault-in-the-phishu-framework.html" target="_blank" rel="noreferrer noopener">https://phishu.net/blogs/blog-vaultjacking-phishing-the-google-password-manager-vault-in-the-phishu-framework.html</a><br /> From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities<br /><a href="https://www.microsoft.com/en-us/security/blog/2026/05/26/poisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2026/05/26/poisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities/</a><br />]]></itunes:summary><itunes:duration>364</itunes:duration><itunes:keywords>akira,business,computer,cyber,cybersecurity,daily,google,hacking,infosec,it,llm,malware,network,news,phishing,pin,ransomware,security,seo,vaultjacking</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9948</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, May 27th, 2026: Fake Claude Ads; SharePoint Vuln; Angular Vulnerabilities</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-may-27th-2026-fake-claude-ads-sharepoint-vuln-angular-vulnerabilities--72178313</link><description><![CDATA[<br /> Possible ACR Stealer From Page Impersonating Claude<br /><a href="https://isc.sans.edu/diary/Possible%20ACR%20Stealer%20From%20Page%20Impersonating%20Claude/33018" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Possible%20ACR%20Stealer%20From%20Page%20Impersonating%20Claude/33018</a><br /> Microsoft SharePoint Remote Code Execution Vulnerability CVE-2026-45659<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659</a><br /> Multiple Vulnerabilities in Angular Language Service VS Code Extension<br /><a href="https://github.com/angular/angular/security/advisories/GHSA-ccq4-xmxr-8hcq" target="_blank" rel="noreferrer noopener">https://github.com/angular/angular/security/advisories/GHSA-ccq4-xmxr-8hcq</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9946.mp3</guid><pubDate>Wed, 27 May 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72178313/9946.mp3" length="5233280" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9946" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Possible ACR Stealer From Page Impersonating Claude
https://isc.sans.edu/diary/Possible%20ACR%20Stealer%20From%20Page%20Impersonating%20Claude/33018
 Microsoft SharePoint Remote Code Execution Vulnerability CVE-2026-45659...</itunes:subtitle><itunes:summary><![CDATA[<br /> Possible ACR Stealer From Page Impersonating Claude<br /><a href="https://isc.sans.edu/diary/Possible%20ACR%20Stealer%20From%20Page%20Impersonating%20Claude/33018" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Possible%20ACR%20Stealer%20From%20Page%20Impersonating%20Claude/33018</a><br /> Microsoft SharePoint Remote Code Execution Vulnerability CVE-2026-45659<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659</a><br /> Multiple Vulnerabilities in Angular Language Service VS Code Extension<br /><a href="https://github.com/angular/angular/security/advisories/GHSA-ccq4-xmxr-8hcq" target="_blank" rel="noreferrer noopener">https://github.com/angular/angular/security/advisories/GHSA-ccq4-xmxr-8hcq</a><br />]]></itunes:summary><itunes:duration>374</itunes:duration><itunes:keywords>angular,business,claude,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microsoft,network,news,security,sharepoint,stealer</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9946</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, May 26th, 2026: VBA in MSFT Access; NPM Stealer; PHP Laravel Compromise; Google API Key Lag;</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-may-26th-2026-vba-in-msft-access-npm-stealer-php-laravel-compromise-google-api-key-lag--72161574</link><description><![CDATA[<br /> Microsoft Access VBA<br /><a href="https://isc.sans.edu/diary/Microsoft%20Access%20VBA/33012" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Access%20VBA/33012</a><br /> An Example of Stack String in High Level Language<br /><a href="https://isc.sans.edu/diary/An%20Example%20of%20Stack%20String%20in%20High%20Level%20Language/33008" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/An%20Example%20of%20Stack%20String%20in%20High%20Level%20Language/33008</a><br /> Cross-Platform NPM Stealer<br /><a href="https://isc.sans.edu/diary/Cross-Platform%20NPM%20Stealer/33006" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Cross-Platform%20NPM%20Stealer/33006</a><br /> Laravel Lang Compromised with RCE Backdoor Across<br /><a href="https://socket.dev/blog/laravel-lang-compromise" target="_blank" rel="noreferrer noopener">https://socket.dev/blog/laravel-lang-compromise</a><br /> Google API keys keep working after you delete them<br /><a href="https://www.aikido.dev/blog/google-api-keys-deletion" target="_blank" rel="noreferrer noopener">https://www.aikido.dev/blog/google-api-keys-deletion</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9944.mp3</guid><pubDate>Tue, 26 May 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72161574/9944.mp3" length="5749075" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9944" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Microsoft Access VBA
https://isc.sans.edu/diary/Microsoft%20Access%20VBA/33012
 An Example of Stack String in High Level Language
https://isc.sans.edu/diary/An%20Example%20of%20Stack%20String%20in%20High%20Level%20Language/33008
 Cross-Platform NPM...</itunes:subtitle><itunes:summary><![CDATA[<br /> Microsoft Access VBA<br /><a href="https://isc.sans.edu/diary/Microsoft%20Access%20VBA/33012" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Access%20VBA/33012</a><br /> An Example of Stack String in High Level Language<br /><a href="https://isc.sans.edu/diary/An%20Example%20of%20Stack%20String%20in%20High%20Level%20Language/33008" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/An%20Example%20of%20Stack%20String%20in%20High%20Level%20Language/33008</a><br /> Cross-Platform NPM Stealer<br /><a href="https://isc.sans.edu/diary/Cross-Platform%20NPM%20Stealer/33006" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Cross-Platform%20NPM%20Stealer/33006</a><br /> Laravel Lang Compromised with RCE Backdoor Across<br /><a href="https://socket.dev/blog/laravel-lang-compromise" target="_blank" rel="noreferrer noopener">https://socket.dev/blog/laravel-lang-compromise</a><br /> Google API keys keep working after you delete them<br /><a href="https://www.aikido.dev/blog/google-api-keys-deletion" target="_blank" rel="noreferrer noopener">https://www.aikido.dev/blog/google-api-keys-deletion</a><br />]]></itunes:summary><itunes:duration>411</itunes:duration><itunes:keywords>access,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microsoft,network,news,npm stealer,security,strack strings,vba</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9944</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, May 22nd, 2026: Selective HTTP Proxying; More GitHub Repo Trouble; MSFT Defender Patches;</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-may-22nd-2026-selective-http-proxying-more-github-repo-trouble-msft-defender-patches--72107098</link><description><![CDATA[<br /> Selective HTTP Proxying in Linux<br /><a href="https://isc.sans.edu/diary/Selective%20HTTP%20Proxying%20in%20Linux/33002" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Selective%20HTTP%20Proxying%20in%20Linux/33002</a><br /> Megalodon: Mass GitHub Repo Backdooring via CI Workflows<br /><a href="https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows/" target="_blank" rel="noreferrer noopener">https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows/</a><br /> MSFT Patches Recent Windows Defender Flaws CVE-2026-41091, CVE-2026-45498, CVE-2026-45584<br /><a href="https://x.com/fabian_bader/status/2057198207243804881" target="_blank" rel="noreferrer noopener">https://x.com/fabian_bader/status/2057198207243804881</a><br /> Cisco Secure Workload Unauthorized API Access Vulnerability CVE-2026-20223<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csw-pnbsa-g8WEnuy" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csw-pnbsa-g8WEnuy</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9942.mp3</guid><pubDate>Fri, 22 May 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72107098/9942.mp3" length="5532418" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9942" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Selective HTTP Proxying in Linux
https://isc.sans.edu/diary/Selective%20HTTP%20Proxying%20in%20Linux/33002
 Megalodon: Mass GitHub Repo Backdooring via CI Workflows
https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows/
 MSFT...</itunes:subtitle><itunes:summary><![CDATA[<br /> Selective HTTP Proxying in Linux<br /><a href="https://isc.sans.edu/diary/Selective%20HTTP%20Proxying%20in%20Linux/33002" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Selective%20HTTP%20Proxying%20in%20Linux/33002</a><br /> Megalodon: Mass GitHub Repo Backdooring via CI Workflows<br /><a href="https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows/" target="_blank" rel="noreferrer noopener">https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows/</a><br /> MSFT Patches Recent Windows Defender Flaws CVE-2026-41091, CVE-2026-45498, CVE-2026-45584<br /><a href="https://x.com/fabian_bader/status/2057198207243804881" target="_blank" rel="noreferrer noopener">https://x.com/fabian_bader/status/2057198207243804881</a><br /> Cisco Secure Workload Unauthorized API Access Vulnerability CVE-2026-20223<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csw-pnbsa-g8WEnuy" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csw-pnbsa-g8WEnuy</a><br />]]></itunes:summary><itunes:duration>395</itunes:duration><itunes:keywords>api,business,cisco,cyber,cybersecurity,daily,github,hacking,http,infosec,it,linux,megalodon,microsoft,network,news,patches,proxy,rest,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9942</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, May 21st, 2026: GitHub Breach; Agentic Threat Intel Feed; NGINX Vuln; YellowKey Fix; Incomplete SonicWall Patch</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-may-21st-2026-github-breach-agentic-threat-intel-feed-nginx-vuln-yellowkey-fix-incomplete-sonicwall-patch--72092300</link><description><![CDATA[<br /> GitHub Breach<br /><a href="https://x.com/github/status/2056949168208552080" target="_blank" rel="noreferrer noopener">https://x.com/github/status/2056949168208552080</a><br /> Agentic Threat Intelligence Feed - VS Code Extensions<br /><a href="https://agentmesh.knostic.ai/extensions" target="_blank" rel="noreferrer noopener">https://agentmesh.knostic.ai/extensions</a><br /> More NGINX Vulnerabilities<br /><a href="https://x.com/nebusecurity/status/2057071579876753643" target="_blank" rel="noreferrer noopener">https://x.com/nebusecurity/status/2057071579876753643</a><br /><a href="https://my.f5.com/manage/s/article/K000161307" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000161307</a><br /> Microsoft Publishes YellowKey Mitigation CVE-2026-45585<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585</a><br /> Incomplete Sonicwall Patch CVE-2024-12802<br /><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0001" target="_blank" rel="noreferrer noopener">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0001</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9940.mp3</guid><pubDate>Thu, 21 May 2026 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72092300/9940.mp3" length="4748717" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9940" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 GitHub Breach
https://x.com/github/status/2056949168208552080
 Agentic Threat Intelligence Feed - VS Code Extensions
https://agentmesh.knostic.ai/extensions
 More NGINX Vulnerabilities
https://x.com/nebusecurity/status/2057071579876753643...</itunes:subtitle><itunes:summary><![CDATA[<br /> GitHub Breach<br /><a href="https://x.com/github/status/2056949168208552080" target="_blank" rel="noreferrer noopener">https://x.com/github/status/2056949168208552080</a><br /> Agentic Threat Intelligence Feed - VS Code Extensions<br /><a href="https://agentmesh.knostic.ai/extensions" target="_blank" rel="noreferrer noopener">https://agentmesh.knostic.ai/extensions</a><br /> More NGINX Vulnerabilities<br /><a href="https://x.com/nebusecurity/status/2057071579876753643" target="_blank" rel="noreferrer noopener">https://x.com/nebusecurity/status/2057071579876753643</a><br /><a href="https://my.f5.com/manage/s/article/K000161307" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000161307</a><br /> Microsoft Publishes YellowKey Mitigation CVE-2026-45585<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585</a><br /> Incomplete Sonicwall Patch CVE-2024-12802<br /><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0001" target="_blank" rel="noreferrer noopener">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0001</a><br />]]></itunes:summary><itunes:duration>339</itunes:duration><itunes:keywords>agentic,bitlocker,business,computer,cyber,cybersecurity,daily,extensions,hacking,infosec,internet,it,microsoft,network,news,nginx,security,sonicwall,vscode,yellowkey</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9940</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, May 20th, 2026: Assume Supply Chain Compromise; GitHub Action Compromise;</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-may-20th-2026-assume-supply-chain-compromise-github-action-compromise--72077289</link><description><![CDATA[<br /> TeamPCP Supply Chain Campaign: Activity Through 2026-05-17<br /><a href="https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Activity%20Through%202026-05-17/32994" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Activity%20Through%202026-05-17/32994</a><br /><a href="https://slsa.dev/spec/v0.1/levels" target="_blank" rel="noreferrer noopener">https://slsa.dev/spec/v0.1/levels</a><br /> Github Action Compromise<br /><a href="https://www.stepsecurity.io/blog/actions-cool-issues-helper-github-action-compromised-all-tags-point-to-imposter-commit-that-exfiltrates-ci-cd-credentials" target="_blank" rel="noreferrer noopener">https://www.stepsecurity.io/blog/actions-cool-issues-helper-github-action-compromised-all-tags-point-to-imposter-commit-that-exfiltrates-ci-cd-credentials</a><br /> How Storm-2949 turned a compromised identity into a cloud-wide breach<br /><a href="https://www.microsoft.com/en-us/security/blog/2026/05/18/storm-2949-turned-compromised-identity-into-cloud-wide-breach/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2026/05/18/storm-2949-turned-compromised-identity-into-cloud-wide-breach/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9938.mp3</guid><pubDate>Wed, 20 May 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72077289/9938.mp3" length="5338792" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9938" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 TeamPCP Supply Chain Campaign: Activity Through 2026-05-17
https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Activity%20Through%202026-05-17/32994
https://slsa.dev/spec/v0.1/levels
 Github Action Compromise...</itunes:subtitle><itunes:summary><![CDATA[<br /> TeamPCP Supply Chain Campaign: Activity Through 2026-05-17<br /><a href="https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Activity%20Through%202026-05-17/32994" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Activity%20Through%202026-05-17/32994</a><br /><a href="https://slsa.dev/spec/v0.1/levels" target="_blank" rel="noreferrer noopener">https://slsa.dev/spec/v0.1/levels</a><br /> Github Action Compromise<br /><a href="https://www.stepsecurity.io/blog/actions-cool-issues-helper-github-action-compromised-all-tags-point-to-imposter-commit-that-exfiltrates-ci-cd-credentials" target="_blank" rel="noreferrer noopener">https://www.stepsecurity.io/blog/actions-cool-issues-helper-github-action-compromised-all-tags-point-to-imposter-commit-that-exfiltrates-ci-cd-credentials</a><br /> How Storm-2949 turned a compromised identity into a cloud-wide breach<br /><a href="https://www.microsoft.com/en-us/security/blog/2026/05/18/storm-2949-turned-compromised-identity-into-cloud-wide-breach/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2026/05/18/storm-2949-turned-compromised-identity-into-cloud-wide-breach/</a><br />]]></itunes:summary><itunes:duration>381</itunes:duration><itunes:keywords>azure,business,computer,cyber,cybersecurity,daily,github,github action,hacking,infosec,internet,it,network,news,security,supply chain,teampcp</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9938</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, May 19th, 2026: New libssh in Malware; Exchange 0-Day; MSFT Authenticator Update</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-may-19th-2026-new-libssh-in-malware-exchange-0-day-msft-authenticator-update--72062788</link><description><![CDATA[<br /> New Malware Libraries means New Signatures<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20%20New%20Malware%20Libraries%20means%20New%20Signatures/32986" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20%20New%20Malware%20Libraries%20means%20New%20Signatures/32986</a><br /> Addressing Exchange Server May 2026 vulnerability CVE-2026-42897<br /><a href="https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498</a><br /> Microsoft Authenticator Update CVE-2026-41615<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41615" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41615</a><br /> ssh-keysign-pwn (CVE-2026-46333) Patches Released<br /><a href="https://almalinux.org/blog/2026-05-15-ssh-keysign-pwn-cve-2026-46333/" target="_blank" rel="noreferrer noopener">https://almalinux.org/blog/2026-05-15-ssh-keysign-pwn-cve-2026-46333/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9936.mp3</guid><pubDate>Tue, 19 May 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72062788/9936.mp3" length="5162971" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9936" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 New Malware Libraries means New Signatures
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20%20New%20Malware%20Libraries%20means%20New%20Signatures/32986
 Addressing Exchange Server May 2026 vulnerability CVE-2026-42897...</itunes:subtitle><itunes:summary><![CDATA[<br /> New Malware Libraries means New Signatures<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20%20New%20Malware%20Libraries%20means%20New%20Signatures/32986" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20%20New%20Malware%20Libraries%20means%20New%20Signatures/32986</a><br /> Addressing Exchange Server May 2026 vulnerability CVE-2026-42897<br /><a href="https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498</a><br /> Microsoft Authenticator Update CVE-2026-41615<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41615" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41615</a><br /> ssh-keysign-pwn (CVE-2026-46333) Patches Released<br /><a href="https://almalinux.org/blog/2026-05-15-ssh-keysign-pwn-cve-2026-46333/" target="_blank" rel="noreferrer noopener">https://almalinux.org/blog/2026-05-15-ssh-keysign-pwn-cve-2026-46333/</a><br />]]></itunes:summary><itunes:duration>369</itunes:duration><itunes:keywords>authenticator,business,computer,cyber,cybersecurity,daily,exchange,hacking,infosec,internet,it,malware,network,news,security,ssh,ssh-keysign-pwn</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9936</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, May 15th, 2026: Website Fraud; Outlook Link Preview Bug; NGINX Vuln; Cisco 0-Day</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-may-15th-2026-website-fraud-outlook-link-preview-bug-nginx-vuln-cisco-0-day--72015124</link><description><![CDATA[<br /> Tearing apart website fraud to see how it works. (@sans_edu)<br /><a href="https://isc.sans.edu/diary/%5BGUEST%20DIARY%5D%20Tearing%20apart%20website%20fraud%20to%20see%20how%20it%20works./32958" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGUEST%20DIARY%5D%20Tearing%20apart%20website%20fraud%20to%20see%20how%20it%20works./32958</a><br /> Simple bypass of the link preview function in Outlook Junk folder<br /><a href="https://isc.sans.edu/diary/Simple%20bypass%20of%20the%20link%20preview%20function%20in%20Outlook%20Junk%20folder/32990" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Simple%20bypass%20of%20the%20link%20preview%20function%20in%20Outlook%20Junk%20folder/32990</a><br /> NGINX Vulnerability<br /><a href="https://depthfirst.com/nginx-rift" target="_blank" rel="noreferrer noopener">https://depthfirst.com/nginx-rift</a><br /> Cisco SDWan 0-Day<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9934.mp3</guid><pubDate>Fri, 15 May 2026 04:10:13 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72015124/9934.mp3" length="5805681" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9934" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Tearing apart website fraud to see how it works. (@sans_edu)
https://isc.sans.edu/diary/%5BGUEST%20DIARY%5D%20Tearing%20apart%20website%20fraud%20to%20see%20how%20it%20works./32958
 Simple bypass of the link preview function in Outlook Junk folder...</itunes:subtitle><itunes:summary><![CDATA[<br /> Tearing apart website fraud to see how it works. (@sans_edu)<br /><a href="https://isc.sans.edu/diary/%5BGUEST%20DIARY%5D%20Tearing%20apart%20website%20fraud%20to%20see%20how%20it%20works./32958" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGUEST%20DIARY%5D%20Tearing%20apart%20website%20fraud%20to%20see%20how%20it%20works./32958</a><br /> Simple bypass of the link preview function in Outlook Junk folder<br /><a href="https://isc.sans.edu/diary/Simple%20bypass%20of%20the%20link%20preview%20function%20in%20Outlook%20Junk%20folder/32990" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Simple%20bypass%20of%20the%20link%20preview%20function%20in%20Outlook%20Junk%20folder/32990</a><br /> NGINX Vulnerability<br /><a href="https://depthfirst.com/nginx-rift" target="_blank" rel="noreferrer noopener">https://depthfirst.com/nginx-rift</a><br /> Cisco SDWan 0-Day<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW</a><br />]]></itunes:summary><itunes:duration>415</itunes:duration><itunes:keywords>business,cisco,computer,cyber,cybersecurity,daily,fraud,hacking,infosec,internet,it,network,news,nginx,outlook,sdwan,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9934</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, May 14th, 2026: Flexbile Windows Proxy; News from Nightmare Eclipse; Adobe Patches</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-may-14th-2026-flexbile-windows-proxy-news-from-nightmare-eclipse-adobe-patches--72000686</link><description><![CDATA[<br /> Proxying the Unproxyable? Sending EXE traffic to a Proxy<br /><a href="https://isc.sans.edu/diary/Proxying%20the%20Unproxyable%3F%20Sending%20EXE%20traffic%20to%20a%20Proxy/32982" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Proxying%20the%20Unproxyable%3F%20Sending%20EXE%20traffic%20to%20a%20Proxy/32982</a><br /> New Nightmare Eclipse Vulnerabilities Disclosed<br /><a href="https://github.com/Nightmare-Eclipse/YellowKey" target="_blank" rel="noreferrer noopener">https://github.com/Nightmare-Eclipse/YellowKey</a><br /><a href="https://github.com/Nightmare-Eclipse/GreenPlasma" target="_blank" rel="noreferrer noopener">https://github.com/Nightmare-Eclipse/GreenPlasma</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9932.mp3</guid><pubDate>Thu, 14 May 2026 04:20:11 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72000686/9932.mp3" length="4564268" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9932" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Proxying the Unproxyable? Sending EXE traffic to a Proxy
https://isc.sans.edu/diary/Proxying%20the%20Unproxyable%3F%20Sending%20EXE%20traffic%20to%20a%20Proxy/32982
 New Nightmare Eclipse Vulnerabilities Disclosed...</itunes:subtitle><itunes:summary><![CDATA[<br /> Proxying the Unproxyable? Sending EXE traffic to a Proxy<br /><a href="https://isc.sans.edu/diary/Proxying%20the%20Unproxyable%3F%20Sending%20EXE%20traffic%20to%20a%20Proxy/32982" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Proxying%20the%20Unproxyable%3F%20Sending%20EXE%20traffic%20to%20a%20Proxy/32982</a><br /> New Nightmare Eclipse Vulnerabilities Disclosed<br /><a href="https://github.com/Nightmare-Eclipse/YellowKey" target="_blank" rel="noreferrer noopener">https://github.com/Nightmare-Eclipse/YellowKey</a><br /><a href="https://github.com/Nightmare-Eclipse/GreenPlasma" target="_blank" rel="noreferrer noopener">https://github.com/Nightmare-Eclipse/GreenPlasma</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security.html</a><br />]]></itunes:summary><itunes:duration>326</itunes:duration><itunes:keywords>adobe,bitlocker,business,computer,cyber,cybersecurity,daily,eclipse,greenplasma,hacking,infosec,internet,it,network,news,nightmare,patches,proxy,security,yellowkey</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9932</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, May 13th, 2026: Microsoft Patch Tuesday; Large npm/pypi Compromise; Rubygems Attack</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-may-13th-2026-microsoft-patch-tuesday-large-npm-pypi-compromise-rubygems-attack--71985077</link><description><![CDATA[<br /> Microsoft Patch Tuesday<br /><a href="https://isc.sans.edu/diary/32980" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/32980</a><br /> Tanstack npm and others compromised<br /><a href="https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack" target="_blank" rel="noreferrer noopener">https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack</a><br /> Ruby Gems Attack<br /><a href="https://x.com/maciejmensfeld/status/2054164602577940619" target="_blank" rel="noreferrer noopener">https://x.com/maciejmensfeld/status/2054164602577940619</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9930.mp3</guid><pubDate>Wed, 13 May 2026 03:05:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71985077/9930.mp3" length="6628603" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9930" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Microsoft Patch Tuesday
https://isc.sans.edu/diary/32980
 Tanstack npm and others compromised
https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack
 Ruby Gems Attack...</itunes:subtitle><itunes:summary><![CDATA[<br /> Microsoft Patch Tuesday<br /><a href="https://isc.sans.edu/diary/32980" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/32980</a><br /> Tanstack npm and others compromised<br /><a href="https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack" target="_blank" rel="noreferrer noopener">https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack</a><br /> Ruby Gems Attack<br /><a href="https://x.com/maciejmensfeld/status/2054164602577940619" target="_blank" rel="noreferrer noopener">https://x.com/maciejmensfeld/status/2054164602577940619</a><br />]]></itunes:summary><itunes:duration>474</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,gems,hacking,infosec,internet,it,microsoft,network,news,npm,patch,pypi,ruby,security,tanstack</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9930</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, May 12th, 2026: Apple Patches; Encrypted RCS; CAPTCHAs; Checkmarx vs TeamPCP;</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-may-12th-2026-apple-patches-encrypted-rcs-captchas-checkmarx-vs-teampcp--71968022</link><description><![CDATA[<br /> Apple Patches Everything<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything/32976" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Everything/32976</a><br /> End-to-End Encrypted RCS Messages<br /><a href="https://www.apple.com/newsroom/2026/05/end-to-end-encrypted-rcs-messaging-begins-rolling-out-today-in-beta/" target="_blank" rel="noreferrer noopener">https://www.apple.com/newsroom/2026/05/end-to-end-encrypted-rcs-messaging-begins-rolling-out-today-in-beta/</a><br /> Why we use CAPTCHAs<br /><a href="https://isc.sans.edu/diary/Why%20we%20use%20CAPTCHAs/32974" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Why%20we%20use%20CAPTCHAs/32974</a><br /> Checkmarx Jenkins AST plugin compromise<br /><a href="https://checkmarx.com/blog/ongoing-security-updates/" target="_blank" rel="noreferrer noopener">https://checkmarx.com/blog/ongoing-security-updates/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9928.mp3</guid><pubDate>Tue, 12 May 2026 03:15:10 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71968022/9928.mp3" length="4983369" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9928" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Apple Patches Everything
https://isc.sans.edu/diary/Apple%20Patches%20Everything/32976
 End-to-End Encrypted RCS Messages
https://www.apple.com/newsroom/2026/05/end-to-end-encrypted-rcs-messaging-begins-rolling-out-today-in-beta/
 Why we use...</itunes:subtitle><itunes:summary><![CDATA[<br /> Apple Patches Everything<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything/32976" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Everything/32976</a><br /> End-to-End Encrypted RCS Messages<br /><a href="https://www.apple.com/newsroom/2026/05/end-to-end-encrypted-rcs-messaging-begins-rolling-out-today-in-beta/" target="_blank" rel="noreferrer noopener">https://www.apple.com/newsroom/2026/05/end-to-end-encrypted-rcs-messaging-begins-rolling-out-today-in-beta/</a><br /> Why we use CAPTCHAs<br /><a href="https://isc.sans.edu/diary/Why%20we%20use%20CAPTCHAs/32974" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Why%20we%20use%20CAPTCHAs/32974</a><br /> Checkmarx Jenkins AST plugin compromise<br /><a href="https://checkmarx.com/blog/ongoing-security-updates/" target="_blank" rel="noreferrer noopener">https://checkmarx.com/blog/ongoing-security-updates/</a><br />]]></itunes:summary><itunes:duration>356</itunes:duration><itunes:keywords>apple,business,captcha,checkmarx,computer,cyber,cybersecurity,daily,hacking,infosec,internet,ios,it,jenkins,network,news,rcs,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9928</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, May 11th, 2026: New Linux Priv Escalation; PAM Backdoors; CPanel Updates; Let’s Encrypt</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-may-11th-2026-new-linux-priv-escalation-pam-backdoors-cpanel-updates-let-s-encrypt--71951604</link><description><![CDATA[<br /> Another Universal Linux Local Privilege Escalation (LPE) Vulnerability: Dirty Frag<br /><a href="https://isc.sans.edu/diary/Another%20Universal%20Linux%20Local%20Privilege%20Escalation%20%28LPE%29%20Vulnerability%3A%20Dirty%20Frag/32968" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Another%20Universal%20Linux%20Local%20Privilege%20Escalation%20%28LPE%29%20Vulnerability%3A%20Dirty%20Frag/32968</a><br /> PAM Backdoors Steel Passwords<br /><a href="https://flare.io/learn/resources/blog/pamdoora-new-linux-pam-based-backdoor-sale-dark-web" target="_blank" rel="noreferrer noopener">https://flare.io/learn/resources/blog/pamdoora-new-linux-pam-based-backdoor-sale-dark-web</a><br /> CPanel Updates<br /><a href="https://support.cpanel.net/hc/en-us/sections/360007088193-Security" target="_blank" rel="noreferrer noopener">https://support.cpanel.net/hc/en-us/sections/360007088193-Security</a><br /> Let s Encrypt Briefly Halts Certificate Issuance <br /><a href="https://letsencrypt.status.io" target="_blank" rel="noreferrer noopener">https://letsencrypt.status.io</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9926.mp3</guid><pubDate>Mon, 11 May 2026 02:15:11 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71951604/9926.mp3" length="5852660" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9926" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Another Universal Linux Local Privilege Escalation (LPE) Vulnerability: Dirty Frag
https://isc.sans.edu/diary/Another%20Universal%20Linux%20Local%20Privilege%20Escalation%20%28LPE%29%20Vulnerability%3A%20Dirty%20Frag/32968
 PAM Backdoors Steel...</itunes:subtitle><itunes:summary><![CDATA[<br /> Another Universal Linux Local Privilege Escalation (LPE) Vulnerability: Dirty Frag<br /><a href="https://isc.sans.edu/diary/Another%20Universal%20Linux%20Local%20Privilege%20Escalation%20%28LPE%29%20Vulnerability%3A%20Dirty%20Frag/32968" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Another%20Universal%20Linux%20Local%20Privilege%20Escalation%20%28LPE%29%20Vulnerability%3A%20Dirty%20Frag/32968</a><br /> PAM Backdoors Steel Passwords<br /><a href="https://flare.io/learn/resources/blog/pamdoora-new-linux-pam-based-backdoor-sale-dark-web" target="_blank" rel="noreferrer noopener">https://flare.io/learn/resources/blog/pamdoora-new-linux-pam-based-backdoor-sale-dark-web</a><br /> CPanel Updates<br /><a href="https://support.cpanel.net/hc/en-us/sections/360007088193-Security" target="_blank" rel="noreferrer noopener">https://support.cpanel.net/hc/en-us/sections/360007088193-Security</a><br /> Let s Encrypt Briefly Halts Certificate Issuance <br /><a href="https://letsencrypt.status.io" target="_blank" rel="noreferrer noopener">https://letsencrypt.status.io</a><br />]]></itunes:summary><itunes:duration>418</itunes:duration><itunes:keywords>backdoor,business,certificates,computer,copy fail,cpanel,cyber,cybersecurity,daily,dirty frag,hacking,infosec,it,lets encrypt,linux,network,news,pam,privilege escalation,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9926</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, May 8th, 2026: AI Generated Dashboard; Ivanti Patches; Redis Vuln; @sans_edu Marcio Enriquez</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-may-8th-2026-ai-generated-dashboard-ivanti-patches-redis-vuln-sans-edu-marcio-enriquez--71916425</link><description><![CDATA[<br /> An Adaptive Cyber Analytics UI for Web Honeypot Logs<br /><a href="https://isc.sans.edu/diary/An%20Adaptive%20Cyber%20Analytics%20UI%20for%20Web%20Honeypot%20Logs%20%5BGuest%20Diary%5D/32962" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/An%20Adaptive%20Cyber%20Analytics%20UI%20for%20Web%20Honeypot%20Logs%20%5BGuest%20Diary%5D/32962</a><br /> Ivanti May Patchday<br /><a href="https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs" target="_blank" rel="noreferrer noopener">https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs</a><br /> Redis Security advisory: [CVE 2026 23479] [CVE 2026 25243] [CVE-2026-25588] [CVE 2026 25589] [CVE-2026-23631]<br /><a href="https://redis.io/blog/security-advisory-cve202623479-cve202625243-cve-2026-25588-cve202625589-cve-2026-23631/" target="_blank" rel="noreferrer noopener">https://redis.io/blog/security-advisory-cve202623479-cve202625243-cve-2026-25588-cve202625589-cve-2026-23631/</a><br /> @sans_edu research paper: Marcio Enriquez<br /> [link will be added once the paper has been published]<br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9924.mp3</guid><pubDate>Fri, 08 May 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71916425/9924.mp3" length="12516572" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9924" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 An Adaptive Cyber Analytics UI for Web Honeypot Logs
https://isc.sans.edu/diary/An%20Adaptive%20Cyber%20Analytics%20UI%20for%20Web%20Honeypot%20Logs%20%5BGuest%20Diary%5D/32962
 Ivanti May Patchday...</itunes:subtitle><itunes:summary><![CDATA[<br /> An Adaptive Cyber Analytics UI for Web Honeypot Logs<br /><a href="https://isc.sans.edu/diary/An%20Adaptive%20Cyber%20Analytics%20UI%20for%20Web%20Honeypot%20Logs%20%5BGuest%20Diary%5D/32962" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/An%20Adaptive%20Cyber%20Analytics%20UI%20for%20Web%20Honeypot%20Logs%20%5BGuest%20Diary%5D/32962</a><br /> Ivanti May Patchday<br /><a href="https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs" target="_blank" rel="noreferrer noopener">https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs</a><br /> Redis Security advisory: [CVE 2026 23479] [CVE 2026 25243] [CVE-2026-25588] [CVE 2026 25589] [CVE-2026-23631]<br /><a href="https://redis.io/blog/security-advisory-cve202623479-cve202625243-cve-2026-25588-cve202625589-cve-2026-23631/" target="_blank" rel="noreferrer noopener">https://redis.io/blog/security-advisory-cve202623479-cve202625243-cve-2026-25588-cve202625589-cve-2026-23631/</a><br /> @sans_edu research paper: Marcio Enriquez<br /> [link will be added once the paper has been published]<br />]]></itunes:summary><itunes:duration>894</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,honepot,infosec,internet,it,ivanti,llm,network,news,redis,security,ui</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9924</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, May 7th, 2026: .DE DNSEC Fail; PAN OS 0-Day Patched;</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-may-7th-2026-de-dnsec-fail-pan-os-0-day-patched--71900685</link><description><![CDATA[<br /> Technical issue with .de domains<br /><a href="https://blog.denic.de/en/technical-issue-with-de-domains-resolved/" target="_blank" rel="noreferrer noopener">https://blog.denic.de/en/technical-issue-with-de-domains-resolved/</a><br /> CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID  Authentication Portal<br /><a href="https://security.paloaltonetworks.com/CVE-2026-0300" target="_blank" rel="noreferrer noopener">https://security.paloaltonetworks.com/CVE-2026-0300</a><br /> Android Security Bulletin May 2026 CVE-2026-0073<br /><a href="https://source.android.com/docs/security/bulletin/2026/2026-05-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2026/2026-05-01</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9922.mp3</guid><pubDate>Thu, 07 May 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71900685/9922.mp3" length="5103357" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9922" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Technical issue with .de domains
https://blog.denic.de/en/technical-issue-with-de-domains-resolved/
 CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID  Authentication Portal...</itunes:subtitle><itunes:summary><![CDATA[<br /> Technical issue with .de domains<br /><a href="https://blog.denic.de/en/technical-issue-with-de-domains-resolved/" target="_blank" rel="noreferrer noopener">https://blog.denic.de/en/technical-issue-with-de-domains-resolved/</a><br /> CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID  Authentication Portal<br /><a href="https://security.paloaltonetworks.com/CVE-2026-0300" target="_blank" rel="noreferrer noopener">https://security.paloaltonetworks.com/CVE-2026-0300</a><br /> Android Security Bulletin May 2026 CVE-2026-0073<br /><a href="https://source.android.com/docs/security/bulletin/2026/2026-05-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2026/2026-05-01</a><br />]]></itunes:summary><itunes:duration>365</itunes:duration><itunes:keywords>android,business,computer,cyber,cybersecurity,daily,.de,dnssec,hacking,infosec,internet,it,network,news,pan-os,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9922</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, May 6th, 2026: Cleartext Passwords in Edge; SSL.com Root Rotation; DAEMONTOOLS Backdoor;</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-may-6th-2026-cleartext-passwords-in-edge-ssl-com-root-rotation-daemontools-backdoor--71883466</link><description><![CDATA[<br /> Cleartext Passwords in MS Edge? In 2026?<br /><a href="https://isc.sans.edu/diary/Cleartext%20Passwords%20in%20MS%20Edge%3F%20In%202026%3F/32954" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Cleartext%20Passwords%20in%20MS%20Edge%3F%20In%202026%3F/32954</a><br /> SSL.com rotates its root certificate today<br /><a href="https://isc.sans.edu/diary/SSL.com%20rotates%20their%20root%20certificate%20today/32956" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SSL.com%20rotates%20their%20root%20certificate%20today/32956</a><br /> DEAMONTOOLS Compromise<br /><a href="https://securelist.com/tr/daemon-tools-backdoor/119654/" target="_blank" rel="noreferrer noopener">https://securelist.com/tr/daemon-tools-backdoor/119654/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9920.mp3</guid><pubDate>Wed, 06 May 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71883466/9920.mp3" length="6907336" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9920" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Cleartext Passwords in MS Edge? In 2026?
https://isc.sans.edu/diary/Cleartext%20Passwords%20in%20MS%20Edge%3F%20In%202026%3F/32954
 SSL.com rotates its root certificate today...</itunes:subtitle><itunes:summary><![CDATA[<br /> Cleartext Passwords in MS Edge? In 2026?<br /><a href="https://isc.sans.edu/diary/Cleartext%20Passwords%20in%20MS%20Edge%3F%20In%202026%3F/32954" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Cleartext%20Passwords%20in%20MS%20Edge%3F%20In%202026%3F/32954</a><br /> SSL.com rotates its root certificate today<br /><a href="https://isc.sans.edu/diary/SSL.com%20rotates%20their%20root%20certificate%20today/32956" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SSL.com%20rotates%20their%20root%20certificate%20today/32956</a><br /> DEAMONTOOLS Compromise<br /><a href="https://securelist.com/tr/daemon-tools-backdoor/119654/" target="_blank" rel="noreferrer noopener">https://securelist.com/tr/daemon-tools-backdoor/119654/</a><br />]]></itunes:summary><itunes:duration>494</itunes:duration><itunes:keywords>business,ca,cleartext,computer,cyber,cybersecurity,daemontools,daily,edge,hacking,infosec,internet,it,network,news,password,security,ssl.com,supply chain</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9920</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, May 5th, 2026: Honeypot Update; MOVEit Patches;  Apache http2 Vuln;</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-may-5th-2026-honeypot-update-moveit-patches-apache-http2-vuln--71869119</link><description><![CDATA[<br /> DShield Honeypot Update<br /><a href="https://isc.sans.edu/diary/DShield%20Honeypot%20Update/32948" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/DShield%20Honeypot%20Update/32948</a><br /> MOVEit Automation Critical Security Alert Bulletin   April 2026   (CVE-2026-4670, CVE-2026-5174)<br /><a href="https://community.progress.com/s/article/MOVEit-Automation-Critical-Security-Alert-Bulletin-April-2026-CVE-2026-4670-CVE-2026-5174" target="_blank" rel="noreferrer noopener">https://community.progress.com/s/article/MOVEit-Automation-Critical-Security-Alert-Bulletin-April-2026-CVE-2026-4670-CVE-2026-5174</a><br /> Apache httpd http2 vulnerability<br /><a href="https://seclists.org/oss-sec/2026/q2/387" target="_blank" rel="noreferrer noopener">https://seclists.org/oss-sec/2026/q2/387</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9918.mp3</guid><pubDate>Tue, 05 May 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71869119/9918.mp3" length="4279213" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9918" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 DShield Honeypot Update
https://isc.sans.edu/diary/DShield%20Honeypot%20Update/32948
 MOVEit Automation Critical Security Alert Bulletin   April 2026   (CVE-2026-4670, CVE-2026-5174)...</itunes:subtitle><itunes:summary><![CDATA[<br /> DShield Honeypot Update<br /><a href="https://isc.sans.edu/diary/DShield%20Honeypot%20Update/32948" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/DShield%20Honeypot%20Update/32948</a><br /> MOVEit Automation Critical Security Alert Bulletin   April 2026   (CVE-2026-4670, CVE-2026-5174)<br /><a href="https://community.progress.com/s/article/MOVEit-Automation-Critical-Security-Alert-Bulletin-April-2026-CVE-2026-4670-CVE-2026-5174" target="_blank" rel="noreferrer noopener">https://community.progress.com/s/article/MOVEit-Automation-Critical-Security-Alert-Bulletin-April-2026-CVE-2026-4670-CVE-2026-5174</a><br /> Apache httpd http2 vulnerability<br /><a href="https://seclists.org/oss-sec/2026/q2/387" target="_blank" rel="noreferrer noopener">https://seclists.org/oss-sec/2026/q2/387</a><br />]]></itunes:summary><itunes:duration>306</itunes:duration><itunes:keywords>apache,business,computer,cyber,cybersecurity,daily,hacking,honeypot,http2,infosec,internet,it,network,news,progress moveit,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9918</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, May 4th, 2026: Malicious Homebrew Ads; Wireshark Update; Digicert False Positive; cPanel Exploited</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-may-4th-2026-malicious-homebrew-ads-wireshark-update-digicert-false-positive-cpanel-exploited--71846165</link><description><![CDATA[<br /> Malicious Ad for Homebrew Leads to MacSync Stealer<br /><a href="https://isc.sans.edu/diary/Malicious%20Ad%20for%20Homebrew%20Leads%20to%20MacSync%20Stealer/32942" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Malicious%20Ad%20for%20Homebrew%20Leads%20to%20MacSync%20Stealer/32942</a><br /> Wireshark Update<br /><a href="https://www.wireshark.org/docs/relnotes/wireshark-4.6.5.html" target="_blank" rel="noreferrer noopener">https://www.wireshark.org/docs/relnotes/wireshark-4.6.5.html</a><br /> Digicert Microsoft Defender False Positive<br /><a href="https://www.reddit.com/r/cybersecurity/comments/1t2hfsh/mde_flagging_digi_cert_certificate_as_malicious/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/cybersecurity/comments/1t2hfsh/mde_flagging_digi_cert_certificate_as_malicious/</a><br /><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2033170" target="_blank" rel="noreferrer noopener">https://bugzilla.mozilla.org/show_bug.cgi?id=2033170</a><br /> cPanel Exploited<br /><a href="https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026" target="_blank" rel="noreferrer noopener">https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9916.mp3</guid><pubDate>Mon, 04 May 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71846165/9916.mp3" length="6529837" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9916" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Malicious Ad for Homebrew Leads to MacSync Stealer
https://isc.sans.edu/diary/Malicious%20Ad%20for%20Homebrew%20Leads%20to%20MacSync%20Stealer/32942
 Wireshark Update
https://www.wireshark.org/docs/relnotes/wireshark-4.6.5.html
 Digicert Microsoft...</itunes:subtitle><itunes:summary><![CDATA[<br /> Malicious Ad for Homebrew Leads to MacSync Stealer<br /><a href="https://isc.sans.edu/diary/Malicious%20Ad%20for%20Homebrew%20Leads%20to%20MacSync%20Stealer/32942" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Malicious%20Ad%20for%20Homebrew%20Leads%20to%20MacSync%20Stealer/32942</a><br /> Wireshark Update<br /><a href="https://www.wireshark.org/docs/relnotes/wireshark-4.6.5.html" target="_blank" rel="noreferrer noopener">https://www.wireshark.org/docs/relnotes/wireshark-4.6.5.html</a><br /> Digicert Microsoft Defender False Positive<br /><a href="https://www.reddit.com/r/cybersecurity/comments/1t2hfsh/mde_flagging_digi_cert_certificate_as_malicious/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/cybersecurity/comments/1t2hfsh/mde_flagging_digi_cert_certificate_as_malicious/</a><br /><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2033170" target="_blank" rel="noreferrer noopener">https://bugzilla.mozilla.org/show_bug.cgi?id=2033170</a><br /> cPanel Exploited<br /><a href="https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026" target="_blank" rel="noreferrer noopener">https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026</a><br />]]></itunes:summary><itunes:duration>467</itunes:duration><itunes:keywords>business,computer,cpanel,cyber,cybersecurity,daily,defender,digicert,false positive,hacking,homebrew,infosec,internet,it,microsoft,network,news,security,wireshark</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9916</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, May 1st, 2026: Libredtail; FreeBSD dhclient vuln; Linux Copy-Fail; @sans_edu Detecting AI Pickling</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-may-1st-2026-libredtail-freebsd-dhclient-vuln-linux-copy-fail-sans-edu-detecting-ai-pickling--71802386</link><description><![CDATA[<br /> Danger of Libredtail<br /><a href="https://isc.sans.edu/diary/Danger%20of%20Libredtail%20%5BGuest%20Diary%5D/32936" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Danger%20of%20Libredtail%20%5BGuest%20Diary%5D/32936</a><br /> FreeBSD dhclient vulnerability<br /><a href="https://www.freebsd.org/security/advisories/FreeBSD-SA-26:12.dhclient.asc" target="_blank" rel="noreferrer noopener">https://www.freebsd.org/security/advisories/FreeBSD-SA-26:12.dhclient.asc</a><br /> Linux Copy-Fail Vulnerability CVE-2026-31431<br /><a href="https://copy.fail" target="_blank" rel="noreferrer noopener">https://copy.fail</a><br /> Bryan Nice Research Paper<br /><a href="https://www.linkedin.com/in/bryannice/" target="_blank" rel="noreferrer noopener">https://www.linkedin.com/in/bryannice/</a><br /><a href="https://www.sans.edu/cyber-research/detecting-ai-pickling" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/detecting-ai-pickling</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9914.mp3</guid><pubDate>Fri, 01 May 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71802386/9914.mp3" length="12351578" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9914" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Danger of Libredtail
https://isc.sans.edu/diary/Danger%20of%20Libredtail%20%5BGuest%20Diary%5D/32936
 FreeBSD dhclient vulnerability
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:12.dhclient.asc
 Linux Copy-Fail Vulnerability...</itunes:subtitle><itunes:summary><![CDATA[<br /> Danger of Libredtail<br /><a href="https://isc.sans.edu/diary/Danger%20of%20Libredtail%20%5BGuest%20Diary%5D/32936" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Danger%20of%20Libredtail%20%5BGuest%20Diary%5D/32936</a><br /> FreeBSD dhclient vulnerability<br /><a href="https://www.freebsd.org/security/advisories/FreeBSD-SA-26:12.dhclient.asc" target="_blank" rel="noreferrer noopener">https://www.freebsd.org/security/advisories/FreeBSD-SA-26:12.dhclient.asc</a><br /> Linux Copy-Fail Vulnerability CVE-2026-31431<br /><a href="https://copy.fail" target="_blank" rel="noreferrer noopener">https://copy.fail</a><br /> Bryan Nice Research Paper<br /><a href="https://www.linkedin.com/in/bryannice/" target="_blank" rel="noreferrer noopener">https://www.linkedin.com/in/bryannice/</a><br /><a href="https://www.sans.edu/cyber-research/detecting-ai-pickling" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/detecting-ai-pickling</a><br />]]></itunes:summary><itunes:duration>882</itunes:duration><itunes:keywords>business,computer,copy-fail,cyber,cybersecurity,daily,danger,freebsd,hacking,infosec,internet,it,libredtail,linux,network,news,sans.edu,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9914</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, April 30th, 2026: Odd Requests; MSFT LNK Bug Exploited; Secure Boot Fix; TLS Updates; SAP npm malware</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-april-30th-2026-odd-requests-msft-lnk-bug-exploited-secure-boot-fix-tls-updates-sap-npm-malware--71765113</link><description><![CDATA[<br /> Today's Odd Web Requests<br /><a href="https://isc.sans.edu/diary/Today%27s%20Odd%20Web%20Requests/32934" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Today%27s%20Odd%20Web%20Requests/32934</a><br /> Incomplete Patch of APT28's Zero-Day Leads to CVE-2026-32202<br /><a href="https://www.akamai.com/blog/security-research/2026/apr/incomplete-patch-apt28s-zero-day-cve-2026-32202" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/2026/apr/incomplete-patch-apt28s-zero-day-cve-2026-32202</a><br /> Assess Secure Boot status with Microsoft Defender<br /><a href="https://techcommunity.microsoft.com/blog/MicrosoftDefenderATPBlog/assess-secure-boot-status-with-microsoft-defender/4510356" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/blog/MicrosoftDefenderATPBlog/assess-secure-boot-status-with-microsoft-defender/4510356</a><br /> Deprecating Legacy TLS and Endpoints for POP and IMAP in Exchange Online<br /><a href="https://techcommunity.microsoft.com/blog/exchange/deprecating-legacy-tls-and-endpoints-for-pop-and-imap-in-exchange-online/4515201" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/blog/exchange/deprecating-legacy-tls-and-endpoints-for-pop-and-imap-in-exchange-online/4515201</a><br /> SAP Related npm Packages Compromised<br /><a href="https://www.stepsecurity.io/blog/a-mini-shai-hulud-has-appeared" target="_blank" rel="noreferrer noopener">https://www.stepsecurity.io/blog/a-mini-shai-hulud-has-appeared</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9912.mp3</guid><pubDate>Thu, 30 Apr 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71765113/9912.mp3" length="5094301" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9912" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Today's Odd Web Requests
https://isc.sans.edu/diary/Today%27s%20Odd%20Web%20Requests/32934
 Incomplete Patch of APT28's Zero-Day Leads to CVE-2026-32202...</itunes:subtitle><itunes:summary><![CDATA[<br /> Today's Odd Web Requests<br /><a href="https://isc.sans.edu/diary/Today%27s%20Odd%20Web%20Requests/32934" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Today%27s%20Odd%20Web%20Requests/32934</a><br /> Incomplete Patch of APT28's Zero-Day Leads to CVE-2026-32202<br /><a href="https://www.akamai.com/blog/security-research/2026/apr/incomplete-patch-apt28s-zero-day-cve-2026-32202" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/2026/apr/incomplete-patch-apt28s-zero-day-cve-2026-32202</a><br /> Assess Secure Boot status with Microsoft Defender<br /><a href="https://techcommunity.microsoft.com/blog/MicrosoftDefenderATPBlog/assess-secure-boot-status-with-microsoft-defender/4510356" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/blog/MicrosoftDefenderATPBlog/assess-secure-boot-status-with-microsoft-defender/4510356</a><br /> Deprecating Legacy TLS and Endpoints for POP and IMAP in Exchange Online<br /><a href="https://techcommunity.microsoft.com/blog/exchange/deprecating-legacy-tls-and-endpoints-for-pop-and-imap-in-exchange-online/4515201" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/blog/exchange/deprecating-legacy-tls-and-endpoints-for-pop-and-imap-in-exchange-online/4515201</a><br /> SAP Related npm Packages Compromised<br /><a href="https://www.stepsecurity.io/blog/a-mini-shai-hulud-has-appeared" target="_blank" rel="noreferrer noopener">https://www.stepsecurity.io/blog/a-mini-shai-hulud-has-appeared</a><br />]]></itunes:summary><itunes:duration>364</itunes:duration><itunes:keywords>apt28,business,computer,cyber,cybersecurity,daily,defender,hacking,imap,infosec,it,microsoft,network,news,npm,pop,sap,security,tsl,web</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9912</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, April 29th, 2026: Odd Vercel Header Usage; GitHub Vuln Patches; MSFT RDP Notification Bug</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-april-29th-2026-odd-vercel-header-usage-github-vuln-patches-msft-rdp-notification-bug--71721513</link><description><![CDATA[<br /> HTTP Requests with X-Vercel-Set-Bypass-Cookie Header<br /><a href="https://isc.sans.edu/diary/HTTP%20Requests%20with%20X-Vercel-Set-Bypass-Cookie%20Header/32930" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/HTTP%20Requests%20with%20X-Vercel-Set-Bypass-Cookie%20Header/32930</a><br /> GitHub Vulnerability CVE-2026-3854<br /><a href="https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854" target="_blank" rel="noreferrer noopener">https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854</a><br /> Microsoft RDP Notification Bug<br /><a href="https://support.microsoft.com/en-us/topic/april-14-2026-kb5083768-os-build-28000-1836-839e4a25-d979-4158-b70c-182333045883" target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-us/topic/april-14-2026-kb5083768-os-build-28000-1836-839e4a25-d979-4158-b70c-182333045883</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9910.mp3</guid><pubDate>Wed, 29 Apr 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71721513/9910.mp3" length="4568721" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9910" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 HTTP Requests with X-Vercel-Set-Bypass-Cookie Header
https://isc.sans.edu/diary/HTTP%20Requests%20with%20X-Vercel-Set-Bypass-Cookie%20Header/32930
 GitHub Vulnerability CVE-2026-3854
https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854...</itunes:subtitle><itunes:summary><![CDATA[<br /> HTTP Requests with X-Vercel-Set-Bypass-Cookie Header<br /><a href="https://isc.sans.edu/diary/HTTP%20Requests%20with%20X-Vercel-Set-Bypass-Cookie%20Header/32930" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/HTTP%20Requests%20with%20X-Vercel-Set-Bypass-Cookie%20Header/32930</a><br /> GitHub Vulnerability CVE-2026-3854<br /><a href="https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854" target="_blank" rel="noreferrer noopener">https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854</a><br /> Microsoft RDP Notification Bug<br /><a href="https://support.microsoft.com/en-us/topic/april-14-2026-kb5083768-os-build-28000-1836-839e4a25-d979-4158-b70c-182333045883" target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-us/topic/april-14-2026-kb5083768-os-build-28000-1836-839e4a25-d979-4158-b70c-182333045883</a><br />]]></itunes:summary><itunes:duration>327</itunes:duration><itunes:keywords>business,bypass,computer,cyber,cybersecurity,daily,github,hacking,infosec,internet,it,microsoft,network,news,rdp,security,vercel</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9910</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, April 28th, 2026: More TeamPCP; Citrix XenServer Unpatched Vulns; Phantom RPC;</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-april-28th-2026-more-teampcp-citrix-xenserver-unpatched-vulns-phantom-rpc--71693453</link><description><![CDATA[<br /> TeamPCP Update<br /><a href="https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Update%20008%20-%2026-Day%20Pause%20Ends%20with%20Three%20Concurrent%20Compromises%20%28Checkmarx%20KICS%2C%20Bitwarden%20CLI%20Cascade%2C%20xinference%20PyPI%29%2C%20CanisterSprawl%20npm%20Worm%20Identified%2C%20and%20Tier%201%20Coverage%20Returns/32926" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Update%20008%20-%2026-Day%20Pause%20Ends%20with%20Three%20Concurrent%20Compromises%20%28Checkmarx%20KICS%2C%20Bitwarden%20CLI%20Cascade%2C%20xinference%20PyPI%29%2C%20CanisterSprawl%20npm%20Worm%20Identified%2C%20and%20Tier%201%20Coverage%20Returns/32926</a><br /><a href="https://socket.dev/blog/73-open-vsx-sleeper-extensions-glassworm" target="_blank" rel="noreferrer noopener">https://socket.dev/blog/73-open-vsx-sleeper-extensions-glassworm</a><br /><a href="https://checkmarx.com/blog/checkmarx-security-update-april-26/" target="_blank" rel="noreferrer noopener">https://checkmarx.com/blog/checkmarx-security-update-april-26/</a><br /> 89 vulnerabilities in XAPI / Citrix XenServer<br /><a href="https://shittrix.moksha.dk/#rationale" target="_blank" rel="noreferrer noopener">https://shittrix.moksha.dk/#rationale</a><br /> Phantom RPC<br /><a href="https://securelist.com/phantomrpc-rpc-vulnerability/119428/" target="_blank" rel="noreferrer noopener">https://securelist.com/phantomrpc-rpc-vulnerability/119428/</a><br /> Pi-Hole Vulnerability CVE-2026-41489<br /><a href="https://github.com/pi-hole/pi-hole/security/advisories/GHSA-6w8x-p785-6pm4" target="_blank" rel="noreferrer noopener">https://github.com/pi-hole/pi-hole/security/advisories/GHSA-6w8x-p785-6pm4</a><br /> Linux Kernel Problem CVE-2026-41651<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41651" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2026-41651</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9908.mp3</guid><pubDate>Tue, 28 Apr 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71693453/9908.mp3" length="5344240" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9908" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 TeamPCP Update...</itunes:subtitle><itunes:summary><![CDATA[<br /> TeamPCP Update<br /><a href="https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Update%20008%20-%2026-Day%20Pause%20Ends%20with%20Three%20Concurrent%20Compromises%20%28Checkmarx%20KICS%2C%20Bitwarden%20CLI%20Cascade%2C%20xinference%20PyPI%29%2C%20CanisterSprawl%20npm%20Worm%20Identified%2C%20and%20Tier%201%20Coverage%20Returns/32926" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Update%20008%20-%2026-Day%20Pause%20Ends%20with%20Three%20Concurrent%20Compromises%20%28Checkmarx%20KICS%2C%20Bitwarden%20CLI%20Cascade%2C%20xinference%20PyPI%29%2C%20CanisterSprawl%20npm%20Worm%20Identified%2C%20and%20Tier%201%20Coverage%20Returns/32926</a><br /><a href="https://socket.dev/blog/73-open-vsx-sleeper-extensions-glassworm" target="_blank" rel="noreferrer noopener">https://socket.dev/blog/73-open-vsx-sleeper-extensions-glassworm</a><br /><a href="https://checkmarx.com/blog/checkmarx-security-update-april-26/" target="_blank" rel="noreferrer noopener">https://checkmarx.com/blog/checkmarx-security-update-april-26/</a><br /> 89 vulnerabilities in XAPI / Citrix XenServer<br /><a href="https://shittrix.moksha.dk/#rationale" target="_blank" rel="noreferrer noopener">https://shittrix.moksha.dk/#rationale</a><br /> Phantom RPC<br /><a href="https://securelist.com/phantomrpc-rpc-vulnerability/119428/" target="_blank" rel="noreferrer noopener">https://securelist.com/phantomrpc-rpc-vulnerability/119428/</a><br /> Pi-Hole Vulnerability CVE-2026-41489<br /><a href="https://github.com/pi-hole/pi-hole/security/advisories/GHSA-6w8x-p785-6pm4" target="_blank" rel="noreferrer noopener">https://github.com/pi-hole/pi-hole/security/advisories/GHSA-6w8x-p785-6pm4</a><br /> Linux Kernel Problem CVE-2026-41651<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41651" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2026-41651</a><br />]]></itunes:summary><itunes:duration>382</itunes:duration><itunes:keywords>business,citrix,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,linux,network,news,phantom rpc,pi-hole,rpc,security,shitrix,windows</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9908</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday April 24rd, 2026: Apple Update; Bitwarden Compromise; ASP.NET Core Patch</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-april-24rd-2026-apple-update-bitwarden-compromise-asp-net-core-patch--71602123</link><description><![CDATA[<br /> Apple Patches Exploited Notification Flaw<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Notification%20Flaw/32922" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Notification%20Flaw/32922</a><br /> Bitwarden CLI Compromised<br /><a href="https://socket.dev/blog/bitwarden-cli-compromised" target="_blank" rel="noreferrer noopener">https://socket.dev/blog/bitwarden-cli-compromised</a><br /><a href="https://community.bitwarden.com/t/bitwarden-statement-on-checkmarx-supply-chain-incident/96127" target="_blank" rel="noreferrer noopener">https://community.bitwarden.com/t/bitwarden-statement-on-checkmarx-supply-chain-incident/96127</a><br /> Microsoft Security Advisory CVE-2026-40372   ASP.NET Core Elevation of Privilege<br /><a href="https://github.com/dotnet/announcements/issues/395" target="_blank" rel="noreferrer noopener">https://github.com/dotnet/announcements/issues/395</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9906.mp3</guid><pubDate>Fri, 24 Apr 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71602123/9906.mp3" length="5560142" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9906" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Apple Patches Exploited Notification Flaw
https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Notification%20Flaw/32922
 Bitwarden CLI Compromised
https://socket.dev/blog/bitwarden-cli-compromised...</itunes:subtitle><itunes:summary><![CDATA[<br /> Apple Patches Exploited Notification Flaw<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Notification%20Flaw/32922" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Notification%20Flaw/32922</a><br /> Bitwarden CLI Compromised<br /><a href="https://socket.dev/blog/bitwarden-cli-compromised" target="_blank" rel="noreferrer noopener">https://socket.dev/blog/bitwarden-cli-compromised</a><br /><a href="https://community.bitwarden.com/t/bitwarden-statement-on-checkmarx-supply-chain-incident/96127" target="_blank" rel="noreferrer noopener">https://community.bitwarden.com/t/bitwarden-statement-on-checkmarx-supply-chain-incident/96127</a><br /> Microsoft Security Advisory CVE-2026-40372   ASP.NET Core Elevation of Privilege<br /><a href="https://github.com/dotnet/announcements/issues/395" target="_blank" rel="noreferrer noopener">https://github.com/dotnet/announcements/issues/395</a><br />]]></itunes:summary><itunes:duration>397</itunes:duration><itunes:keywords>apple,asp.net,bitwarden,business,computer,core,cyber,cybersecurity,daily,fbi,hacking,infosec,internet,it,microsoft,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9906</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, April 23rd, 2026: Stealing Telegram Sessions; Oracle CPU; Firefox Patches</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-april-23rd-2026-stealing-telegram-sessions-oracle-cpu-firefox-patches--71579402</link><description><![CDATA[<br /> Beyond Cryptojacking: Telegram tdata as a Credential Harvesting Vector, Lessons from a Honeypot Incident<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Beyond%20Cryptojacking%3A%20Telegram%20tdata%20as%20a%20Credential%20Harvesting%20Vector%2C%20Lessons%20from%20a%20Honeypot%20Incident/32888" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Beyond%20Cryptojacking%3A%20Telegram%20tdata%20as%20a%20Credential%20Harvesting%20Vector%2C%20Lessons%20from%20a%20Honeypot%20Incident/32888</a><br /> Checkmarx Compromise<br /><a href="https://socket.dev/blog/checkmarx-supply-chain-compromise" target="_blank" rel="noreferrer noopener">https://socket.dev/blog/checkmarx-supply-chain-compromise</a><br /> Oracle Quarterly Critical Patch Update<br /><a href="https://www.oracle.com/security-alerts/cpuapr2026.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpuapr2026.html</a><br /> Firefox 150 - Mythos AI <br /><a href="https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9904.mp3</guid><pubDate>Thu, 23 Apr 2026 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71579402/9904.mp3" length="6722369" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9904" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Beyond Cryptojacking: Telegram tdata as a Credential Harvesting Vector, Lessons from a Honeypot Incident...</itunes:subtitle><itunes:summary><![CDATA[<br /> Beyond Cryptojacking: Telegram tdata as a Credential Harvesting Vector, Lessons from a Honeypot Incident<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Beyond%20Cryptojacking%3A%20Telegram%20tdata%20as%20a%20Credential%20Harvesting%20Vector%2C%20Lessons%20from%20a%20Honeypot%20Incident/32888" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Beyond%20Cryptojacking%3A%20Telegram%20tdata%20as%20a%20Credential%20Harvesting%20Vector%2C%20Lessons%20from%20a%20Honeypot%20Incident/32888</a><br /> Checkmarx Compromise<br /><a href="https://socket.dev/blog/checkmarx-supply-chain-compromise" target="_blank" rel="noreferrer noopener">https://socket.dev/blog/checkmarx-supply-chain-compromise</a><br /> Oracle Quarterly Critical Patch Update<br /><a href="https://www.oracle.com/security-alerts/cpuapr2026.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpuapr2026.html</a><br /> Firefox 150 - Mythos AI <br /><a href="https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/</a><br />]]></itunes:summary><itunes:duration>480</itunes:duration><itunes:keywords>ai,business,checkmarx,computer,crypto,cyber,cybersecurity,daily,firefox,hacking,infosec,internet,it,mythos,network,news,oracle,sans_edu,security,telegram</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9904</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, April 22nd, 2026: WAV Malware; GitHub OAUTH Phishing; Perforce Settings</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-april-22nd-2026-wav-malware-github-oauth-phishing-perforce-settings--71540163</link><description><![CDATA[<br /> A .WAV With A Payload<br /><a href="https://isc.sans.edu/diary/A%20.WAV%20With%20A%20Payload/32910" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20.WAV%20With%20A%20Payload/32910</a><br /> The Phishy GitHub Issue Case<br /><a href="https://blog.atsika.ninja/posts/the-phishy-github-issue-case/" target="_blank" rel="noreferrer noopener">https://blog.atsika.ninja/posts/the-phishy-github-issue-case/</a><br /> P4WNED: How Insecure Defaults in Perforce Expose Source Code Across the Internet<br /><a href="https://morganrobertson.net/p4wned/" target="_blank" rel="noreferrer noopener">https://morganrobertson.net/p4wned/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9902.mp3</guid><pubDate>Wed, 22 Apr 2026 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71540163/9902.mp3" length="6059945" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9902" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 A .WAV With A Payload
https://isc.sans.edu/diary/A%20.WAV%20With%20A%20Payload/32910
 The Phishy GitHub Issue Case
https://blog.atsika.ninja/posts/the-phishy-github-issue-case/
 P4WNED: How Insecure Defaults in Perforce Expose Source Code Across the...</itunes:subtitle><itunes:summary><![CDATA[<br /> A .WAV With A Payload<br /><a href="https://isc.sans.edu/diary/A%20.WAV%20With%20A%20Payload/32910" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20.WAV%20With%20A%20Payload/32910</a><br /> The Phishy GitHub Issue Case<br /><a href="https://blog.atsika.ninja/posts/the-phishy-github-issue-case/" target="_blank" rel="noreferrer noopener">https://blog.atsika.ninja/posts/the-phishy-github-issue-case/</a><br /> P4WNED: How Insecure Defaults in Perforce Expose Source Code Across the Internet<br /><a href="https://morganrobertson.net/p4wned/" target="_blank" rel="noreferrer noopener">https://morganrobertson.net/p4wned/</a><br />]]></itunes:summary><itunes:duration>433</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,github,hacking,infosec,internet,it,malware,network,news,payload,perforce,phishing,security,wav</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9902</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, April 21st, 2026: CVE and EPSS; Windows Server 2025 OOB;  QEMU Abuse;</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-april-21st-2026-cve-and-epss-windows-server-2025-oob-qemu-abuse--71508555</link><description><![CDATA[<br /> Handling the CVE Flood With EPSS<br /><a href="https://isc.sans.edu/diary/Handling%20the%20CVE%20Flood%20With%20EPSS/32914" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Handling%20the%20CVE%20Flood%20With%20EPSS/32914</a><br /> Windows Server 2025 Out of Band Patch<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#4835" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#4835</a><br /> QEMU abused to evade detection and enable ransomware delivery<br /><a href="https://www.sophos.com/en-us/blog/qemu-abused-to-evade-detection-and-enable-ransomware-delivery" target="_blank" rel="noreferrer noopener">https://www.sophos.com/en-us/blog/qemu-abused-to-evade-detection-and-enable-ransomware-delivery</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9900.mp3</guid><pubDate>Tue, 21 Apr 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71508555/9900.mp3" length="4666202" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9900" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Handling the CVE Flood With EPSS
https://isc.sans.edu/diary/Handling%20the%20CVE%20Flood%20With%20EPSS/32914
 Windows Server 2025 Out of Band Patch
https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#4835
 QEMU abused to...</itunes:subtitle><itunes:summary><![CDATA[<br /> Handling the CVE Flood With EPSS<br /><a href="https://isc.sans.edu/diary/Handling%20the%20CVE%20Flood%20With%20EPSS/32914" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Handling%20the%20CVE%20Flood%20With%20EPSS/32914</a><br /> Windows Server 2025 Out of Band Patch<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#4835" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#4835</a><br /> QEMU abused to evade detection and enable ransomware delivery<br /><a href="https://www.sophos.com/en-us/blog/qemu-abused-to-evade-detection-and-enable-ransomware-delivery" target="_blank" rel="noreferrer noopener">https://www.sophos.com/en-us/blog/qemu-abused-to-evade-detection-and-enable-ransomware-delivery</a><br />]]></itunes:summary><itunes:duration>334</itunes:duration><itunes:keywords>2025,business,computer,cve,cyber,cybersecurity,daily,epss,hacking,infosec,internet,it,network,news,oob,patch,qemu,security,server,windows</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9900</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, April 20th, 2026: Lumma Stealer and Sectop RAT; Windows 0-Day Exploited; NIST NVD Update; FortiSandbox PoC</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-april-20th-2026-lumma-stealer-and-sectop-rat-windows-0-day-exploited-nist-nvd-update-fortisandbox-poc--71477210</link><description><![CDATA[<br /> Lumma Stealer infection with Sectop RAT (ArechClient2)<br /><a href="https://isc.sans.edu/diary/Lumma%20Stealer%20infection%20with%20Sectop%20RAT%20%28ArechClient2%29/32904" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Lumma%20Stealer%20infection%20with%20Sectop%20RAT%20%28ArechClient2%29/32904</a><br /> Three Recent Windows Defender Vulnerabilities Exploited (one 0-day)<br /><a href="https://x.com/HuntressLabs/status/2044882115574091960" target="_blank" rel="noreferrer noopener">https://x.com/HuntressLabs/status/2044882115574091960</a><br /> FortiSandbox PoC Exploit CVE-2026-39808<br /><a href="https://github.com/samu-delucas/CVE-2026-39808?tab=readme-ov-file" target="_blank" rel="noreferrer noopener">https://github.com/samu-delucas/CVE-2026-39808?tab=readme-ov-file</a><br /> NIST Updates NVD Operations to Address Record CVE Growth<br /><a href="https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth" target="_blank" rel="noreferrer noopener">https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9898.mp3</guid><pubDate>Mon, 20 Apr 2026 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71477210/9898.mp3" length="5470745" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9898" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Lumma Stealer infection with Sectop RAT (ArechClient2)
https://isc.sans.edu/diary/Lumma%20Stealer%20infection%20with%20Sectop%20RAT%20%28ArechClient2%29/32904
 Three Recent Windows Defender Vulnerabilities Exploited (one 0-day)...</itunes:subtitle><itunes:summary><![CDATA[<br /> Lumma Stealer infection with Sectop RAT (ArechClient2)<br /><a href="https://isc.sans.edu/diary/Lumma%20Stealer%20infection%20with%20Sectop%20RAT%20%28ArechClient2%29/32904" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Lumma%20Stealer%20infection%20with%20Sectop%20RAT%20%28ArechClient2%29/32904</a><br /> Three Recent Windows Defender Vulnerabilities Exploited (one 0-day)<br /><a href="https://x.com/HuntressLabs/status/2044882115574091960" target="_blank" rel="noreferrer noopener">https://x.com/HuntressLabs/status/2044882115574091960</a><br /> FortiSandbox PoC Exploit CVE-2026-39808<br /><a href="https://github.com/samu-delucas/CVE-2026-39808?tab=readme-ov-file" target="_blank" rel="noreferrer noopener">https://github.com/samu-delucas/CVE-2026-39808?tab=readme-ov-file</a><br /> NIST Updates NVD Operations to Address Record CVE Growth<br /><a href="https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth" target="_blank" rel="noreferrer noopener">https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth</a><br />]]></itunes:summary><itunes:duration>391</itunes:duration><itunes:keywords>business,cve,cyber,cybersecurity,daily,defender,fortinet,fortisandbox,hacking,infosec,it,lumma stealer,network,news,nist,nvd,poc,rat,sectop,windows</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9898</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, April 17th, 2026: DVRs Again; Cisco Again; Windows Defender Again; Sonatype</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-april-17th-2026-dvrs-again-cisco-again-windows-defender-again-sonatype--71391793</link><description><![CDATA[<br /> Compromised DVRs and Finding Them in the Wild<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Compromised%20DVRs%20and%20Finding%20Them%20in%20the%20Wild/32886" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Compromised%20DVRs%20and%20Finding%20Them%20in%20the%20Wild/32886</a><br /> Cisco ISE RCE Vulnerability and WebEx Auth Bypass CVE-2026-20184 CVE-2026-20180 CVE-2026-20186<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-4fverepv" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-4fverepv</a><br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-cui-cert-8jSZYhWL" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-cui-cert-8jSZYhWL</a><br /> Windows Defender 0-Day (RedSun)<br /><a href="https://github.com/Nightmare-Eclipse/RedSun" target="_blank" rel="noreferrer noopener">https://github.com/Nightmare-Eclipse/RedSun</a><br /> Sonatype Vulnerability CVE-2026-5189<br /><a href="https://support.sonatype.com/hc/en-us/articles/50817138825491-CVE-2026-5189-Nexus-Repository-3-Hardcoded-Credential-in-Internal-Database-Component-2026-04-15" target="_blank" rel="noreferrer noopener">https://support.sonatype.com/hc/en-us/articles/50817138825491-CVE-2026-5189-Nexus-Repository-3-Hardcoded-Credential-in-Internal-Database-Component-2026-04-15</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9896.mp3</guid><pubDate>Fri, 17 Apr 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71391793/9896.mp3" length="4985138" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9896" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Compromised DVRs and Finding Them in the Wild
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Compromised%20DVRs%20and%20Finding%20Them%20in%20the%20Wild/32886
 Cisco ISE RCE Vulnerability and WebEx Auth Bypass CVE-2026-20184 CVE-2026-20180...</itunes:subtitle><itunes:summary><![CDATA[<br /> Compromised DVRs and Finding Them in the Wild<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Compromised%20DVRs%20and%20Finding%20Them%20in%20the%20Wild/32886" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Compromised%20DVRs%20and%20Finding%20Them%20in%20the%20Wild/32886</a><br /> Cisco ISE RCE Vulnerability and WebEx Auth Bypass CVE-2026-20184 CVE-2026-20180 CVE-2026-20186<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-4fverepv" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-4fverepv</a><br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-cui-cert-8jSZYhWL" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-cui-cert-8jSZYhWL</a><br /> Windows Defender 0-Day (RedSun)<br /><a href="https://github.com/Nightmare-Eclipse/RedSun" target="_blank" rel="noreferrer noopener">https://github.com/Nightmare-Eclipse/RedSun</a><br /> Sonatype Vulnerability CVE-2026-5189<br /><a href="https://support.sonatype.com/hc/en-us/articles/50817138825491-CVE-2026-5189-Nexus-Repository-3-Hardcoded-Credential-in-Internal-Database-Component-2026-04-15" target="_blank" rel="noreferrer noopener">https://support.sonatype.com/hc/en-us/articles/50817138825491-CVE-2026-5189-Nexus-Repository-3-Hardcoded-Credential-in-Internal-Database-Component-2026-04-15</a><br />]]></itunes:summary><itunes:duration>356</itunes:duration><itunes:keywords>business,cisco,computer,cyber,cybersecurity,daily,defender,dvr,hacking,hardcoded,infosec,internet,it,network,news,password,security,sonatype,windows</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9896</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, April 16th, 2026: AI Credential Scans; Microsoft Update Issues; RDP Warnings; GitHub Action Vulns;</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-april-16th-2026-ai-credential-scans-microsoft-update-issues-rdp-warnings-github-action-vulns--71356136</link><description><![CDATA[<br /> Scanning for AI Models<br /><a href="https://isc.sans.edu/diary/Scanning%20for%20AI%20Models/32896" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scanning%20for%20AI%20Models/32896</a><br /> Microsoft Update Problems<br /><a href="https://support.microsoft.com/en-us/topic/april-14-2026-kb5082063-os-build-26100-32690-c57e289d-27c9-47cd-a183-72fabc62c5d7#:~:text=Known%20issues%20in%20this%20update" target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-us/topic/april-14-2026-kb5082063-os-build-26100-32690-c57e289d-27c9-47cd-a183-72fabc62c5d7#:~:text=Known%20issues%20in%20this%20update</a><br /> Microsoft RDP File Warnings<br /><a href="https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remotepc/understanding-security-warnings" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remotepc/understanding-security-warnings</a><br /> AI GitHub Action Vulnerabilities<br /><a href="https://oddguan.com/blog/comment-and-control-prompt-injection-credential-theft-claude-code-gemini-cli-github-copilot/" target="_blank" rel="noreferrer noopener">https://oddguan.com/blog/comment-and-control-prompt-injection-credential-theft-claude-code-gemini-cli-github-copilot/</a><br /><a href="https://www.theregister.com/2026/04/15/claude_gemini_copilot_agents_hijacked/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2026/04/15/claude_gemini_copilot_agents_hijacked/</a><br /> Wireguard Update<br /><a href="https://lists.zx2c4.com/pipermail/wireguard/2026-April/009561.html" target="_blank" rel="noreferrer noopener">https://lists.zx2c4.com/pipermail/wireguard/2026-April/009561.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9894.mp3</guid><pubDate>Thu, 16 Apr 2026 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71356136/9894.mp3" length="5784384" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9894" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Scanning for AI Models
https://isc.sans.edu/diary/Scanning%20for%20AI%20Models/32896
 Microsoft Update Problems...</itunes:subtitle><itunes:summary><![CDATA[<br /> Scanning for AI Models<br /><a href="https://isc.sans.edu/diary/Scanning%20for%20AI%20Models/32896" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scanning%20for%20AI%20Models/32896</a><br /> Microsoft Update Problems<br /><a href="https://support.microsoft.com/en-us/topic/april-14-2026-kb5082063-os-build-26100-32690-c57e289d-27c9-47cd-a183-72fabc62c5d7#:~:text=Known%20issues%20in%20this%20update" target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-us/topic/april-14-2026-kb5082063-os-build-26100-32690-c57e289d-27c9-47cd-a183-72fabc62c5d7#:~:text=Known%20issues%20in%20this%20update</a><br /> Microsoft RDP File Warnings<br /><a href="https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remotepc/understanding-security-warnings" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remotepc/understanding-security-warnings</a><br /> AI GitHub Action Vulnerabilities<br /><a href="https://oddguan.com/blog/comment-and-control-prompt-injection-credential-theft-claude-code-gemini-cli-github-copilot/" target="_blank" rel="noreferrer noopener">https://oddguan.com/blog/comment-and-control-prompt-injection-credential-theft-claude-code-gemini-cli-github-copilot/</a><br /><a href="https://www.theregister.com/2026/04/15/claude_gemini_copilot_agents_hijacked/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2026/04/15/claude_gemini_copilot_agents_hijacked/</a><br /> Wireguard Update<br /><a href="https://lists.zx2c4.com/pipermail/wireguard/2026-April/009561.html" target="_blank" rel="noreferrer noopener">https://lists.zx2c4.com/pipermail/wireguard/2026-April/009561.html</a><br />]]></itunes:summary><itunes:duration>413</itunes:duration><itunes:keywords>action,business,computer,cyber,cybersecurity,daily,github,hacking,infosec,internet,it,microsoft,network,news,rdp,security,updates,wireguard</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9894</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, April 15th, 2026: Microsoft, Adobe, Fortinet and others Patches</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-april-15th-2026-microsoft-adobe-fortinet-and-others-patches--71332956</link><description><![CDATA[<br /> Microsoft Patch Tuesday April 2026<br /><a href="https://isc.sans.edu/forums/diary/Microsoft%20Patch%20Tuesday%20April%202026./32898/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Microsoft%20Patch%20Tuesday%20April%202026./32898/</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security/Home.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/Home.html</a><br /> Fortinet Patches<br /><a href="https://fortiguard.fortinet.com/psirt" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9892.mp3</guid><pubDate>Wed, 15 Apr 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71332956/9892.mp3" length="7172816" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9892" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Microsoft Patch Tuesday April 2026
https://isc.sans.edu/forums/diary/Microsoft%20Patch%20Tuesday%20April%202026./32898/
 Adobe Patches
https://helpx.adobe.com/security/Home.html
 Fortinet Patches
https://fortiguard.fortinet.com/psirt
</itunes:subtitle><itunes:summary><![CDATA[<br /> Microsoft Patch Tuesday April 2026<br /><a href="https://isc.sans.edu/forums/diary/Microsoft%20Patch%20Tuesday%20April%202026./32898/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Microsoft%20Patch%20Tuesday%20April%202026./32898/</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security/Home.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/Home.html</a><br /> Fortinet Patches<br /><a href="https://fortiguard.fortinet.com/psirt" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt</a><br />]]></itunes:summary><itunes:duration>513</itunes:duration><itunes:keywords>adobe,business,computer,cyber,cybersecurity,daily,fortinet,hacking,infosec,internet,it,microsoft,network,news,patches,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9892</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, April 14th, 2026: EncystPHP Webshell; CPUID Compromise; OpenAI Mac Cert Issue; Axios Vulnerability</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-april-14th-2026-encystphp-webshell-cpuid-compromise-openai-mac-cert-issue-axios-vulnerability--71304708</link><description><![CDATA[<br /> Scans for EncystPHP Webshell<br /><a href="https://isc.sans.edu/diary/Scans%20for%20EncystPHP%20Webshell/32892" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20EncystPHP%20Webshell/32892</a><br /> CPUID Compromise<br /><a href="https://securelist.com/tr/cpu-z/119365/" target="_blank" rel="noreferrer noopener">https://securelist.com/tr/cpu-z/119365/</a><br /><a href="https://x.com/d0cTB/status/2042520961824559150" target="_blank" rel="noreferrer noopener">https://x.com/d0cTB/status/2042520961824559150</a><br /> OpenAI Mac Application Update due to Axios Compromise<br /><a href="https://openai.com/index/axios-developer-tool-compromise/" target="_blank" rel="noreferrer noopener">https://openai.com/index/axios-developer-tool-compromise/</a><br /> Axios Vulnerability CVE-2026-40175<br /><a href="https://github.com/axios/axios/security/advisories/GHSA-fvcv-3m26-pcqx" target="_blank" rel="noreferrer noopener">https://github.com/axios/axios/security/advisories/GHSA-fvcv-3m26-pcqx</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9890.mp3</guid><pubDate>Tue, 14 Apr 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71304708/9890.mp3" length="5785990" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9890" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Scans for EncystPHP Webshell
https://isc.sans.edu/diary/Scans%20for%20EncystPHP%20Webshell/32892
 CPUID Compromise
https://securelist.com/tr/cpu-z/119365/
https://x.com/d0cTB/status/2042520961824559150
 OpenAI Mac Application Update due to Axios...</itunes:subtitle><itunes:summary><![CDATA[<br /> Scans for EncystPHP Webshell<br /><a href="https://isc.sans.edu/diary/Scans%20for%20EncystPHP%20Webshell/32892" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20EncystPHP%20Webshell/32892</a><br /> CPUID Compromise<br /><a href="https://securelist.com/tr/cpu-z/119365/" target="_blank" rel="noreferrer noopener">https://securelist.com/tr/cpu-z/119365/</a><br /><a href="https://x.com/d0cTB/status/2042520961824559150" target="_blank" rel="noreferrer noopener">https://x.com/d0cTB/status/2042520961824559150</a><br /> OpenAI Mac Application Update due to Axios Compromise<br /><a href="https://openai.com/index/axios-developer-tool-compromise/" target="_blank" rel="noreferrer noopener">https://openai.com/index/axios-developer-tool-compromise/</a><br /> Axios Vulnerability CVE-2026-40175<br /><a href="https://github.com/axios/axios/security/advisories/GHSA-fvcv-3m26-pcqx" target="_blank" rel="noreferrer noopener">https://github.com/axios/axios/security/advisories/GHSA-fvcv-3m26-pcqx</a><br />]]></itunes:summary><itunes:duration>413</itunes:duration><itunes:keywords>axios,business,computer,cpuid,cyber,cybersecurity,daily,encystphp,hacking,infosec,internet,it,mac,network,news,openai,security,webshell</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9890</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, April 13th, 2026: Obfuscated JavaScript; Numbers in Passwords; Adobe Patches 0-Day; ClickFix Fix Bypass</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-april-13th-2026-obfuscated-javascript-numbers-in-passwords-adobe-patches-0-day-clickfix-fix-bypass--71281340</link><description><![CDATA[<br /> Obfuscated JavaScript or Nothing<br /><a href="https://isc.sans.edu/diary/Obfuscated%20JavaScript%20or%20Nothing/32884" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Obfuscated%20JavaScript%20or%20Nothing/32884</a><br /> Numbers in Passwords<br /><a href="https://isc.sans.edu/diary/Number%20Usage%20in%20Passwords%3A%20Take%20Two/32866" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Number%20Usage%20in%20Passwords%3A%20Take%20Two/32866</a><br /> Adobe 0-Day Patch CVE-2026-34621<br /><a href="https://helpx.adobe.com/security/products/acrobat/apsb26-43.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/products/acrobat/apsb26-43.html</a><br /> ClickFix Bypass via ScriptEditor<br /><a href="https://www.jamf.com/blog/clickfix-macos-script-editor-atomic-stealer/" target="_blank" rel="noreferrer noopener">https://www.jamf.com/blog/clickfix-macos-script-editor-atomic-stealer/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9888.mp3</guid><pubDate>Mon, 13 Apr 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71281340/9888.mp3" length="5456324" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9888" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Obfuscated JavaScript or Nothing
https://isc.sans.edu/diary/Obfuscated%20JavaScript%20or%20Nothing/32884
 Numbers in Passwords
https://isc.sans.edu/diary/Number%20Usage%20in%20Passwords%3A%20Take%20Two/32866
 Adobe 0-Day Patch CVE-2026-34621...</itunes:subtitle><itunes:summary><![CDATA[<br /> Obfuscated JavaScript or Nothing<br /><a href="https://isc.sans.edu/diary/Obfuscated%20JavaScript%20or%20Nothing/32884" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Obfuscated%20JavaScript%20or%20Nothing/32884</a><br /> Numbers in Passwords<br /><a href="https://isc.sans.edu/diary/Number%20Usage%20in%20Passwords%3A%20Take%20Two/32866" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Number%20Usage%20in%20Passwords%3A%20Take%20Two/32866</a><br /> Adobe 0-Day Patch CVE-2026-34621<br /><a href="https://helpx.adobe.com/security/products/acrobat/apsb26-43.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/products/acrobat/apsb26-43.html</a><br /> ClickFix Bypass via ScriptEditor<br /><a href="https://www.jamf.com/blog/clickfix-macos-script-editor-atomic-stealer/" target="_blank" rel="noreferrer noopener">https://www.jamf.com/blog/clickfix-macos-script-editor-atomic-stealer/</a><br />]]></itunes:summary><itunes:duration>390</itunes:duration><itunes:keywords>acrobat,adobe,business,clickfix,cyber,cybersecurity,daily,hacking,infosec,it,javascript,macos,network,news,numbers,obfuscation,passwords,reader,scripteditor,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9888</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, April 9th, 2026: Honeypot Fingerprinting; Microsoft Locks Developer Accounts; ActiveMQ Vuln;</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-april-9th-2026-honeypot-fingerprinting-microsoft-locks-developer-accounts-activemq-vuln--71200858</link><description><![CDATA[<br /> Honeypot Fingerprinting<br /><a href="https://isc.sans.edu/diary/More%20Honeypot%20Fingerprinting%20Scans/32878" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/More%20Honeypot%20Fingerprinting%20Scans/32878</a><br /> Microsoft Locks Accounts for Privacy/Encryption Related Developers<br /><a href="https://sourceforge.net/p/veracrypt/discussion/general/thread/9620d7a4b3/" target="_blank" rel="noreferrer noopener">https://sourceforge.net/p/veracrypt/discussion/general/thread/9620d7a4b3/</a> <a href="https://news.ycombinator.com/item?id=47687884" target="_blank" rel="noreferrer noopener">https://news.ycombinator.com/item?id=47687884</a> <a href="https://x.com/windscribecom/status/2041929519628443943" target="_blank" rel="noreferrer noopener">https://x.com/windscribecom/status/2041929519628443943</a><br /><a href="https://windowsforum.com/threads/april-2026-windows-update-ends-cross-signed-kernel-driver-trust.410487/" target="_blank" rel="noreferrer noopener">https://windowsforum.com/threads/april-2026-windows-update-ends-cross-signed-kernel-driver-trust.410487/</a><br /> Remote Code Execution in Apache ActiveMQ (CVE-2026-34197)<br /><a href="https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/" target="_blank" rel="noreferrer noopener">https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9886.mp3</guid><pubDate>Thu, 09 Apr 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71200858/9886.mp3" length="6447318" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9886" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Honeypot Fingerprinting
https://isc.sans.edu/diary/More%20Honeypot%20Fingerprinting%20Scans/32878
 Microsoft Locks Accounts for Privacy/Encryption Related Developers
https://sourceforge.net/p/veracrypt/discussion/general/thread/9620d7a4b3/...</itunes:subtitle><itunes:summary><![CDATA[<br /> Honeypot Fingerprinting<br /><a href="https://isc.sans.edu/diary/More%20Honeypot%20Fingerprinting%20Scans/32878" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/More%20Honeypot%20Fingerprinting%20Scans/32878</a><br /> Microsoft Locks Accounts for Privacy/Encryption Related Developers<br /><a href="https://sourceforge.net/p/veracrypt/discussion/general/thread/9620d7a4b3/" target="_blank" rel="noreferrer noopener">https://sourceforge.net/p/veracrypt/discussion/general/thread/9620d7a4b3/</a> <a href="https://news.ycombinator.com/item?id=47687884" target="_blank" rel="noreferrer noopener">https://news.ycombinator.com/item?id=47687884</a> <a href="https://x.com/windscribecom/status/2041929519628443943" target="_blank" rel="noreferrer noopener">https://x.com/windscribecom/status/2041929519628443943</a><br /><a href="https://windowsforum.com/threads/april-2026-windows-update-ends-cross-signed-kernel-driver-trust.410487/" target="_blank" rel="noreferrer noopener">https://windowsforum.com/threads/april-2026-windows-update-ends-cross-signed-kernel-driver-trust.410487/</a><br /> Remote Code Execution in Apache ActiveMQ (CVE-2026-34197)<br /><a href="https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/" target="_blank" rel="noreferrer noopener">https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/</a><br />]]></itunes:summary><itunes:duration>461</itunes:duration><itunes:keywords>activemq,apache,business,computer,cyber,cybersecurity,daily,developers,fingerprinting,hacking,honeypot,infosec,it,microsoft,network,news,security,veracrypt,windscribe,wireguard</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9886</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, April 8th, 2026: Pivoting for Webshells; WatchGuard Firebox Patch; Project Glasswing; Kubernetes Misconfigurations</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-april-8th-2026-pivoting-for-webshells-watchguard-firebox-patch-project-glasswing-kubernetes-misconfigurations--71171058</link><description><![CDATA[<br /> A Little Bit Pivoting: What Web Shells are Attackers Looking for Today?<br /><a href="https://isc.sans.edu/diary/A%20Little%20Bit%20Pivoting%3A%20What%20Web%20Shells%20are%20Attackers%20Looking%20for%3F/32874" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20Little%20Bit%20Pivoting%3A%20What%20Web%20Shells%20are%20Attackers%20Looking%20for%3F/32874</a><br /> WatchGuard Firebox Arbitrary File Write via Path Traversal in Fireware Web UI<br /><a href="https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00009" target="_blank" rel="noreferrer noopener">https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00009</a><br /> Project Glasswing<br /><a href="https://www.anthropic.com/glasswing" target="_blank" rel="noreferrer noopener">https://www.anthropic.com/glasswing</a><br /> Current Threats Against Kubernetes<br /><a href="https://unit42.paloaltonetworks.com/modern-kubernetes-threats/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/modern-kubernetes-threats/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9884.mp3</guid><pubDate>Wed, 08 Apr 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71171058/9884.mp3" length="5224001" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9884" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 A Little Bit Pivoting: What Web Shells are Attackers Looking for Today?
https://isc.sans.edu/diary/A%20Little%20Bit%20Pivoting%3A%20What%20Web%20Shells%20are%20Attackers%20Looking%20for%3F/32874
 WatchGuard Firebox Arbitrary File Write via Path...</itunes:subtitle><itunes:summary><![CDATA[<br /> A Little Bit Pivoting: What Web Shells are Attackers Looking for Today?<br /><a href="https://isc.sans.edu/diary/A%20Little%20Bit%20Pivoting%3A%20What%20Web%20Shells%20are%20Attackers%20Looking%20for%3F/32874" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20Little%20Bit%20Pivoting%3A%20What%20Web%20Shells%20are%20Attackers%20Looking%20for%3F/32874</a><br /> WatchGuard Firebox Arbitrary File Write via Path Traversal in Fireware Web UI<br /><a href="https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00009" target="_blank" rel="noreferrer noopener">https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00009</a><br /> Project Glasswing<br /><a href="https://www.anthropic.com/glasswing" target="_blank" rel="noreferrer noopener">https://www.anthropic.com/glasswing</a><br /> Current Threats Against Kubernetes<br /><a href="https://unit42.paloaltonetworks.com/modern-kubernetes-threats/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/modern-kubernetes-threats/</a><br />]]></itunes:summary><itunes:duration>373</itunes:duration><itunes:keywords>anthropic,business,computer,cyber,cybersecurity,daily,firebox,glasswing,hacking,infosec,internet,it,network,news,pivoting,security,watchguard,webshell</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9884</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, April 7th, 2026: Redirects in Phishing; Internet Bug Bounty Suspended; Bluehammer; Keycloak MFA Bypass</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-april-7th-2026-redirects-in-phishing-internet-bug-bounty-suspended-bluehammer-keycloak-mfa-bypass--71145497</link><description><![CDATA[<br /> How often are redirects used in phishing in 2026?<br /><a href="https://isc.sans.edu/diary/How%20often%20are%20redirects%20used%20in%20phishing%20in%202026%3F/32870" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20often%20are%20redirects%20used%20in%20phishing%20in%202026%3F/32870</a><br /> Hackerone Suspends Internet Bug Bounty<br /><a href="https://hackerone.com/ibb?type=team" target="_blank" rel="noreferrer noopener">https://hackerone.com/ibb?type=team</a><br /><a href="https://www.linkedin.com/posts/danielstenberg_hackerone-share-7446667043380076545-RX9b/" target="_blank" rel="noreferrer noopener">https://www.linkedin.com/posts/danielstenberg_hackerone-share-7446667043380076545-RX9b/</a><br /> Bluehammer Windows 0-day Privilege Escalation<br /><a href="https://github.com/Nightmare-Eclipse/BlueHammer" target="_blank" rel="noreferrer noopener">https://github.com/Nightmare-Eclipse/BlueHammer</a><br /><a href="https://deadeclipse666.blogspot.com/2026/04/public-disclosure.html" target="_blank" rel="noreferrer noopener">https://deadeclipse666.blogspot.com/2026/04/public-disclosure.html</a><br /><a href="https://deepwiki.com/Nightmare-Eclipse/BlueHammer" target="_blank" rel="noreferrer noopener">https://deepwiki.com/Nightmare-Eclipse/BlueHammer</a><br /> Keycloak MFA Bypass CVE-2026-3429<br /><a href="https://access.redhat.com/security/cve/cve-2026-3429" target="_blank" rel="noreferrer noopener">https://access.redhat.com/security/cve/cve-2026-3429</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9882.mp3</guid><pubDate>Tue, 07 Apr 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71145497/9882.mp3" length="5817988" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9882" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 How often are redirects used in phishing in 2026?
https://isc.sans.edu/diary/How%20often%20are%20redirects%20used%20in%20phishing%20in%202026%3F/32870
 Hackerone Suspends Internet Bug Bounty
https://hackerone.com/ibb?type=team...</itunes:subtitle><itunes:summary><![CDATA[<br /> How often are redirects used in phishing in 2026?<br /><a href="https://isc.sans.edu/diary/How%20often%20are%20redirects%20used%20in%20phishing%20in%202026%3F/32870" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20often%20are%20redirects%20used%20in%20phishing%20in%202026%3F/32870</a><br /> Hackerone Suspends Internet Bug Bounty<br /><a href="https://hackerone.com/ibb?type=team" target="_blank" rel="noreferrer noopener">https://hackerone.com/ibb?type=team</a><br /><a href="https://www.linkedin.com/posts/danielstenberg_hackerone-share-7446667043380076545-RX9b/" target="_blank" rel="noreferrer noopener">https://www.linkedin.com/posts/danielstenberg_hackerone-share-7446667043380076545-RX9b/</a><br /> Bluehammer Windows 0-day Privilege Escalation<br /><a href="https://github.com/Nightmare-Eclipse/BlueHammer" target="_blank" rel="noreferrer noopener">https://github.com/Nightmare-Eclipse/BlueHammer</a><br /><a href="https://deadeclipse666.blogspot.com/2026/04/public-disclosure.html" target="_blank" rel="noreferrer noopener">https://deadeclipse666.blogspot.com/2026/04/public-disclosure.html</a><br /><a href="https://deepwiki.com/Nightmare-Eclipse/BlueHammer" target="_blank" rel="noreferrer noopener">https://deepwiki.com/Nightmare-Eclipse/BlueHammer</a><br /> Keycloak MFA Bypass CVE-2026-3429<br /><a href="https://access.redhat.com/security/cve/cve-2026-3429" target="_blank" rel="noreferrer noopener">https://access.redhat.com/security/cve/cve-2026-3429</a><br />]]></itunes:summary><itunes:duration>416</itunes:duration><itunes:keywords>0-day,bluehammer,business,computer,cyber,cybersecurity,daily,hackerone,hacking,infosec,internet,it,keycloak,mfa,network,news,phishing,redirects,security,windows</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9882</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, April 6th, 2026: TeamPCP Update and Axio Post Mortem; Fortinet 0-Day</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-april-6th-2026-teampcp-update-and-axio-post-mortem-fortinet-0-day--71124451</link><description><![CDATA[<br /> Team PCP Update and Axios Post Mortem<br /><a href="https://isc.sans.edu/diary/32864" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/32864</a><br /><a href="https://github.com/axios/axios/issues/10636" target="_blank" rel="noreferrer noopener">https://github.com/axios/axios/issues/10636</a><br /> Strapi NPM Packages Compromised<br /><a href="https://safedep.io/malicious-npm-strapi-plugin-events-c2-agent/" target="_blank" rel="noreferrer noopener">https://safedep.io/malicious-npm-strapi-plugin-events-c2-agent/</a><br /> Fortinet CVE-2026-35616 exctively exploited<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-099" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-26-099</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9880.mp3</guid><pubDate>Mon, 06 Apr 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71124451/9880.mp3" length="5165062" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9880" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Team PCP Update and Axios Post Mortem
https://isc.sans.edu/diary/32864
https://github.com/axios/axios/issues/10636
 Strapi NPM Packages Compromised
https://safedep.io/malicious-npm-strapi-plugin-events-c2-agent/
 Fortinet CVE-2026-35616 exctively...</itunes:subtitle><itunes:summary><![CDATA[<br /> Team PCP Update and Axios Post Mortem<br /><a href="https://isc.sans.edu/diary/32864" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/32864</a><br /><a href="https://github.com/axios/axios/issues/10636" target="_blank" rel="noreferrer noopener">https://github.com/axios/axios/issues/10636</a><br /> Strapi NPM Packages Compromised<br /><a href="https://safedep.io/malicious-npm-strapi-plugin-events-c2-agent/" target="_blank" rel="noreferrer noopener">https://safedep.io/malicious-npm-strapi-plugin-events-c2-agent/</a><br /> Fortinet CVE-2026-35616 exctively exploited<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-099" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-26-099</a><br />]]></itunes:summary><itunes:duration>369</itunes:duration><itunes:keywords>0-day,axios,business,computer,cyber,cybersecurity,daily,exploit,fortinet,hacking,infosec,internet,it,network,news,npm,security,strapi,teampcp</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9880</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, April 3rd, 2026: Vite Exploits; OpenSSH 10.3; Claude Code Vuln</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-april-3rd-2026-vite-exploits-openssh-10-3-claude-code-vuln--71075101</link><description><![CDATA[<br /> Attempts to Exploit Exposed "Vite" Installs (CVE-2025-30208)<br /><a href="https://isc.sans.edu/diary/Attempts%20to%20Exploit%20Exposed%20%22Vite%22%20Installs%20%28CVE-2025-30208%29/32860" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Attempts%20to%20Exploit%20Exposed%20%22Vite%22%20Installs%20%28CVE-2025-30208%29/32860</a><br /> OpenSSH 10.3 Release<br /><a href="https://seclists.org/oss-sec/2026/q2/7" target="_blank" rel="noreferrer noopener">https://seclists.org/oss-sec/2026/q2/7</a><br /> Claude Code Vulnerability<br /><a href="https://adversa.ai/claude-code-security-bypass-deny-rules-disabled/" target="_blank" rel="noreferrer noopener">https://adversa.ai/claude-code-security-bypass-deny-rules-disabled/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9878.mp3</guid><pubDate>Fri, 03 Apr 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71075101/9878.mp3" length="4413460" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9878" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Attempts to Exploit Exposed "Vite" Installs (CVE-2025-30208)
https://isc.sans.edu/diary/Attempts%20to%20Exploit%20Exposed%20%22Vite%22%20Installs%20%28CVE-2025-30208%29/32860
 OpenSSH 10.3 Release
https://seclists.org/oss-sec/2026/q2/7
 Claude Code...</itunes:subtitle><itunes:summary><![CDATA[<br /> Attempts to Exploit Exposed "Vite" Installs (CVE-2025-30208)<br /><a href="https://isc.sans.edu/diary/Attempts%20to%20Exploit%20Exposed%20%22Vite%22%20Installs%20%28CVE-2025-30208%29/32860" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Attempts%20to%20Exploit%20Exposed%20%22Vite%22%20Installs%20%28CVE-2025-30208%29/32860</a><br /> OpenSSH 10.3 Release<br /><a href="https://seclists.org/oss-sec/2026/q2/7" target="_blank" rel="noreferrer noopener">https://seclists.org/oss-sec/2026/q2/7</a><br /> Claude Code Vulnerability<br /><a href="https://adversa.ai/claude-code-security-bypass-deny-rules-disabled/" target="_blank" rel="noreferrer noopener">https://adversa.ai/claude-code-security-bypass-deny-rules-disabled/</a><br />]]></itunes:summary><itunes:duration>315</itunes:duration><itunes:keywords>business,claude,code,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,openssh,security,vite</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9878</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, April 2nd, 2026: Script Removing ADS/MotW; Google Chrome 0-Day; iOS/iPadOS 18 Update;</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-april-2nd-2026-script-removing-ads-motw-google-chrome-0-day-ios-ipados-18-update--71054213</link><description><![CDATA[<br /> Malicious Script That Gets Rid of ADS<br /><a href="https://isc.sans.edu/diary/Malicious%20Script%20That%20Gets%20Rid%20of%20ADS/32854" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Malicious%20Script%20That%20Gets%20Rid%20of%20ADS/32854</a><br /> Google Chrome Update fixes 21 Vulnerabilities and 0-Day<br /><a href="https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_31.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_31.html</a><br /> Apple Addresses Darksword Vulnerabilities for older devices<br /><a href="https://support.apple.com/en-us/126793" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/126793</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9876.mp3</guid><pubDate>Thu, 02 Apr 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71054213/9876.mp3" length="3382577" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9876" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Malicious Script That Gets Rid of ADS
https://isc.sans.edu/diary/Malicious%20Script%20That%20Gets%20Rid%20of%20ADS/32854
 Google Chrome Update fixes 21 Vulnerabilities and 0-Day...</itunes:subtitle><itunes:summary><![CDATA[<br /> Malicious Script That Gets Rid of ADS<br /><a href="https://isc.sans.edu/diary/Malicious%20Script%20That%20Gets%20Rid%20of%20ADS/32854" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Malicious%20Script%20That%20Gets%20Rid%20of%20ADS/32854</a><br /> Google Chrome Update fixes 21 Vulnerabilities and 0-Day<br /><a href="https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_31.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_31.html</a><br /> Apple Addresses Darksword Vulnerabilities for older devices<br /><a href="https://support.apple.com/en-us/126793" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/126793</a><br />]]></itunes:summary><itunes:duration>242</itunes:duration><itunes:keywords>ads,apple,business,chrome,computer,cyber,cybersecurity,daily,darksword,google,hacking,infosec,internet,ios,it,motw,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9876</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, April 1st, 2026:  Application Control Bypass; Axios NPM Module Compromise; TeamPCP vs Cloud</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-april-1st-2026-application-control-bypass-axios-npm-module-compromise-teampcp-vs-cloud--71034356</link><description><![CDATA[<br /> Application Control Bypass for Data Exfiltration<br /><a href="https://isc.sans.edu/diary/Application%20Control%20Bypass%20for%20Data%20Exfiltration/32850" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Application%20Control%20Bypass%20for%20Data%20Exfiltration/32850</a><br /> Axios NPM Module Supply Chain Compromise<br /><a href="https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan" target="_blank" rel="noreferrer noopener">https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan</a><br /><a href="https://www.linkedin.com/events/7444763050819092480/" target="_blank" rel="noreferrer noopener">https://www.linkedin.com/events/7444763050819092480/</a><br /> TeamPCP vs. Cloud Resources<br /><a href="https://www.wiz.io/blog/tracking-teampcp-investigating-post-compromise-attacks-seen-in-the-wild" target="_blank" rel="noreferrer noopener">https://www.wiz.io/blog/tracking-teampcp-investigating-post-compromise-attacks-seen-in-the-wild</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9874.mp3</guid><pubDate>Wed, 01 Apr 2026 02:05:11 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71034356/9874.mp3" length="5710101" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9874" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Application Control Bypass for Data Exfiltration
https://isc.sans.edu/diary/Application%20Control%20Bypass%20for%20Data%20Exfiltration/32850
 Axios NPM Module Supply Chain Compromise...</itunes:subtitle><itunes:summary><![CDATA[<br /> Application Control Bypass for Data Exfiltration<br /><a href="https://isc.sans.edu/diary/Application%20Control%20Bypass%20for%20Data%20Exfiltration/32850" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Application%20Control%20Bypass%20for%20Data%20Exfiltration/32850</a><br /> Axios NPM Module Supply Chain Compromise<br /><a href="https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan" target="_blank" rel="noreferrer noopener">https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan</a><br /><a href="https://www.linkedin.com/events/7444763050819092480/" target="_blank" rel="noreferrer noopener">https://www.linkedin.com/events/7444763050819092480/</a><br /> TeamPCP vs. Cloud Resources<br /><a href="https://www.wiz.io/blog/tracking-teampcp-investigating-post-compromise-attacks-seen-in-the-wild" target="_blank" rel="noreferrer noopener">https://www.wiz.io/blog/tracking-teampcp-investigating-post-compromise-attacks-seen-in-the-wild</a><br />]]></itunes:summary><itunes:duration>408</itunes:duration><itunes:keywords>application conftrol,axios,business,cloud,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,npm,palo alto,security,teampcp</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9874</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, March 31st, 2026: Honeypot Session Lifetime; Let’s Encrypt Tests Mass Revocation; F5 RCE Exploited</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-march-31st-2026-honeypot-session-lifetime-let-s-encrypt-tests-mass-revocation-f5-rce-exploited--71010531</link><description><![CDATA[<br /> Honeypot Session Lifetime<br /><a href="https://isc.sans.edu/diary/DShield%20%28Cowrie%29%20Honeypot%20Stats%20and%20When%20Sessions%20Disconnect/32840" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/DShield%20%28Cowrie%29%20Honeypot%20Stats%20and%20When%20Sessions%20Disconnect/32840</a><br /> Let s Encrypt Tests Mass Revocation<br /><a href="https://community.letsencrypt.org/t/lets-encrypt-2026-mass-revocation-simulation/245960" target="_blank" rel="noreferrer noopener">https://community.letsencrypt.org/t/lets-encrypt-2026-mass-revocation-simulation/245960</a><br /><a href="https://www.certkit.io/blog/ari-solves-mass-certificate-revocation" target="_blank" rel="noreferrer noopener">https://www.certkit.io/blog/ari-solves-mass-certificate-revocation</a><br /><a href="https://www.certkit.io/blog/lets-encrypt-mass-revocation-simulation" target="_blank" rel="noreferrer noopener">https://www.certkit.io/blog/lets-encrypt-mass-revocation-simulation</a><br /> F5 Vulnerability Re-Classified (and already exploited) as RCE<br /><a href="https://my.f5.com/manage/s/article/K000156741" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000156741</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9872.mp3</guid><pubDate>Tue, 31 Mar 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71010531/9872.mp3" length="4392299" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9872" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Honeypot Session Lifetime
https://isc.sans.edu/diary/DShield%20%28Cowrie%29%20Honeypot%20Stats%20and%20When%20Sessions%20Disconnect/32840
 Let s Encrypt Tests Mass Revocation...</itunes:subtitle><itunes:summary><![CDATA[<br /> Honeypot Session Lifetime<br /><a href="https://isc.sans.edu/diary/DShield%20%28Cowrie%29%20Honeypot%20Stats%20and%20When%20Sessions%20Disconnect/32840" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/DShield%20%28Cowrie%29%20Honeypot%20Stats%20and%20When%20Sessions%20Disconnect/32840</a><br /> Let s Encrypt Tests Mass Revocation<br /><a href="https://community.letsencrypt.org/t/lets-encrypt-2026-mass-revocation-simulation/245960" target="_blank" rel="noreferrer noopener">https://community.letsencrypt.org/t/lets-encrypt-2026-mass-revocation-simulation/245960</a><br /><a href="https://www.certkit.io/blog/ari-solves-mass-certificate-revocation" target="_blank" rel="noreferrer noopener">https://www.certkit.io/blog/ari-solves-mass-certificate-revocation</a><br /><a href="https://www.certkit.io/blog/lets-encrypt-mass-revocation-simulation" target="_blank" rel="noreferrer noopener">https://www.certkit.io/blog/lets-encrypt-mass-revocation-simulation</a><br /> F5 Vulnerability Re-Classified (and already exploited) as RCE<br /><a href="https://my.f5.com/manage/s/article/K000156741" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000156741</a><br />]]></itunes:summary><itunes:duration>314</itunes:duration><itunes:keywords>ari,business,computer,cyber,cybersecurity,daily,f5,hacking,honeypot,infosec,internet,it,lets’ encrypt,lifetime,network,news,revocation,security,session</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9872</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, March 30th, 2026: More TeamPCP: telnyx; Netscaler Exploit; macOS ClickFix Fix; Windows Smart Install</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-march-30th-2026-more-teampcp-telnyx-netscaler-exploit-macos-clickfix-fix-windows-smart-install--70994521</link><description><![CDATA[<br /> TeamPCP Update #2: Telnyx PyPi Compromise<br /><a href="https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Update%20002%20-%20Telnyx%20PyPI%20Compromise%2C%20Vect%20Ransomware%20Mass%20Affiliate%20Program%2C%20and%20First%20Named%20Victim%20Claim/32838" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Update%20002%20-%20Telnyx%20PyPI%20Compromise%2C%20Vect%20Ransomware%20Mass%20Affiliate%20Program%2C%20and%20First%20Named%20Victim%20Claim/32838</a><br /> Citrix Netscaler Vulnerability Details<br /><a href="https://labs.watchtowr.com/the-sequels-are-never-as-good-but-were-still-in-pain-citrix-netscaler-cve-2026-3055-memory-overread/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/the-sequels-are-never-as-good-but-were-still-in-pain-citrix-netscaler-cve-2026-3055-memory-overread/</a><br /> macOS Clickfix Warning<br /><a href="https://x.com/ClassicII_MrMac/status/2036797948911141129" target="_blank" rel="noreferrer noopener">https://x.com/ClassicII_MrMac/status/2036797948911141129</a><br /> Windows Smart Install<br /><a href="https://textslashplain.com/2026/03/24/windows-choose-where-to-get-apps/" target="_blank" rel="noreferrer noopener">https://textslashplain.com/2026/03/24/windows-choose-where-to-get-apps/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9870.mp3</guid><pubDate>Mon, 30 Mar 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70994521/9870.mp3" length="7089444" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9870" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 TeamPCP Update #2: Telnyx PyPi Compromise...</itunes:subtitle><itunes:summary><![CDATA[<br /> TeamPCP Update #2: Telnyx PyPi Compromise<br /><a href="https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Update%20002%20-%20Telnyx%20PyPI%20Compromise%2C%20Vect%20Ransomware%20Mass%20Affiliate%20Program%2C%20and%20First%20Named%20Victim%20Claim/32838" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Update%20002%20-%20Telnyx%20PyPI%20Compromise%2C%20Vect%20Ransomware%20Mass%20Affiliate%20Program%2C%20and%20First%20Named%20Victim%20Claim/32838</a><br /> Citrix Netscaler Vulnerability Details<br /><a href="https://labs.watchtowr.com/the-sequels-are-never-as-good-but-were-still-in-pain-citrix-netscaler-cve-2026-3055-memory-overread/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/the-sequels-are-never-as-good-but-were-still-in-pain-citrix-netscaler-cve-2026-3055-memory-overread/</a><br /> macOS Clickfix Warning<br /><a href="https://x.com/ClassicII_MrMac/status/2036797948911141129" target="_blank" rel="noreferrer noopener">https://x.com/ClassicII_MrMac/status/2036797948911141129</a><br /> Windows Smart Install<br /><a href="https://textslashplain.com/2026/03/24/windows-choose-where-to-get-apps/" target="_blank" rel="noreferrer noopener">https://textslashplain.com/2026/03/24/windows-choose-where-to-get-apps/</a><br />]]></itunes:summary><itunes:duration>507</itunes:duration><itunes:keywords>business,citrix,computer,cyber,cybersecurity,daily,hacking,infosec,install,internet,it,netscaler,network,news,security,smart,teampcp,telnyx,windows</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9870</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, March 27th, 2026: TeamPCP Update; DarkSword vs Patches; LangFlow Exploited</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-march-27th-2026-teampcp-update-darksword-vs-patches-langflow-exploited--70911184</link><description><![CDATA[<br /> TeamPCP Supply Chain Campaign: Update 001 - Checkmarx Scope Wider Than Reported, CISA KEV Entry, and Detection Tools Available<br /><a href="https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Update%20001%20-%20Checkmarx%20Scope%20Wider%20Than%20Reported%2C%20CISA%20KEV%20Entry%2C%20and%20Detection%20Tools%20Available/32834" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Update%20001%20-%20Checkmarx%20Scope%20Wider%20Than%20Reported%2C%20CISA%20KEV%20Entry%2C%20and%20Detection%20Tools%20Available/32834</a><br /> DarkSword and This Weeks iOS Updates<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain</a><br /> LangFlow Exploited<br /><a href="https://www.cisa.gov/news-events/alerts/2026/03/25/cisa-adds-one-known-exploited-vulnerability-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2026/03/25/cisa-adds-one-known-exploited-vulnerability-catalog</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9868.mp3</guid><pubDate>Fri, 27 Mar 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70911184/9868.mp3" length="5222864" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9868" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 TeamPCP Supply Chain Campaign: Update 001 - Checkmarx Scope Wider Than Reported, CISA KEV Entry, and Detection Tools Available...</itunes:subtitle><itunes:summary><![CDATA[<br /> TeamPCP Supply Chain Campaign: Update 001 - Checkmarx Scope Wider Than Reported, CISA KEV Entry, and Detection Tools Available<br /><a href="https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Update%20001%20-%20Checkmarx%20Scope%20Wider%20Than%20Reported%2C%20CISA%20KEV%20Entry%2C%20and%20Detection%20Tools%20Available/32834" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Update%20001%20-%20Checkmarx%20Scope%20Wider%20Than%20Reported%2C%20CISA%20KEV%20Entry%2C%20and%20Detection%20Tools%20Available/32834</a><br /> DarkSword and This Weeks iOS Updates<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain</a><br /> LangFlow Exploited<br /><a href="https://www.cisa.gov/news-events/alerts/2026/03/25/cisa-adds-one-known-exploited-vulnerability-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2026/03/25/cisa-adds-one-known-exploited-vulnerability-catalog</a><br />]]></itunes:summary><itunes:duration>373</itunes:duration><itunes:keywords>business,checkmarx,computer,cyber,cybersecurity,daily,darksword,hacking,infosec,internet,ios,it,langflow,network,news,patches,security,teampcp</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9868</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, March 26th, 2026: Apple Patches; SmatApeSG Update; Trivy/LiteLLM/TeamPCP Update; Google Accelerates Quantum Save Cr</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-march-26th-2026-apple-patches-smatapesg-update-trivy-litellm-teampcp-update-google-accelerates-quantum-save-cr--70883145</link><description><![CDATA[<br /> Apple Patches (almost) everything again. March 2026 edition.<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20%28almost%29%20everything%20again.%20March%202026%20edition./32830" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20%28almost%29%20everything%20again.%20March%202026%20edition./32830</a><br /> SmartApeSG campaign pushes Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2)<br /><a href="https://isc.sans.edu/diary/SmartApeSG%20campaign%20pushes%20Remcos%20RAT%2C%20NetSupport%20RAT%2C%20StealC%2C%20and%20Sectop%20RAT%20%28ArechClient2%29/32826" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SmartApeSG%20campaign%20pushes%20Remcos%20RAT%2C%20NetSupport%20RAT%2C%20StealC%2C%20and%20Sectop%20RAT%20%28ArechClient2%29/32826</a><br /> Trivy/LiteLLM/TeamPCP Updates<br /><a href="https://www.sans.org/webcasts/when-security-scanner-became-weapon" target="_blank" rel="noreferrer noopener">https://www.sans.org/webcasts/when-security-scanner-became-weapon</a><br /><a href="https://rosesecurity.dev/2026/03/24/sha-pinning-is-not-enough.html" target="_blank" rel="noreferrer noopener">https://rosesecurity.dev/2026/03/24/sha-pinning-is-not-enough.html</a><br /> Google Moves Up Quantum Crypto Deadline<br /><a href="https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/" target="_blank" rel="noreferrer noopener">https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9866.mp3</guid><pubDate>Thu, 26 Mar 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70883145/9866.mp3" length="5829229" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9866" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Apple Patches (almost) everything again. March 2026 edition.
https://isc.sans.edu/diary/Apple%20Patches%20%28almost%29%20everything%20again.%20March%202026%20edition./32830
 SmartApeSG campaign pushes Remcos RAT, NetSupport RAT, StealC, and Sectop...</itunes:subtitle><itunes:summary><![CDATA[<br /> Apple Patches (almost) everything again. March 2026 edition.<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20%28almost%29%20everything%20again.%20March%202026%20edition./32830" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20%28almost%29%20everything%20again.%20March%202026%20edition./32830</a><br /> SmartApeSG campaign pushes Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2)<br /><a href="https://isc.sans.edu/diary/SmartApeSG%20campaign%20pushes%20Remcos%20RAT%2C%20NetSupport%20RAT%2C%20StealC%2C%20and%20Sectop%20RAT%20%28ArechClient2%29/32826" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SmartApeSG%20campaign%20pushes%20Remcos%20RAT%2C%20NetSupport%20RAT%2C%20StealC%2C%20and%20Sectop%20RAT%20%28ArechClient2%29/32826</a><br /> Trivy/LiteLLM/TeamPCP Updates<br /><a href="https://www.sans.org/webcasts/when-security-scanner-became-weapon" target="_blank" rel="noreferrer noopener">https://www.sans.org/webcasts/when-security-scanner-became-weapon</a><br /><a href="https://rosesecurity.dev/2026/03/24/sha-pinning-is-not-enough.html" target="_blank" rel="noreferrer noopener">https://rosesecurity.dev/2026/03/24/sha-pinning-is-not-enough.html</a><br /> Google Moves Up Quantum Crypto Deadline<br /><a href="https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/" target="_blank" rel="noreferrer noopener">https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/</a><br />]]></itunes:summary><itunes:duration>416</itunes:duration><itunes:keywords>apple,business,computer,crypto,cyber,cybersecurity,daily,google,hacking,infosec,internet,it,litellm,network,news,quantum,security,smartapesg,teampcp,trivy</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9866</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, March 25th, 2026: IP KVM Usage; TeampPCP, Trivy, liteLLM and More</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-march-25th-2026-ip-kvm-usage-teamppcp-trivy-litellm-and-more--70862678</link><description><![CDATA[<br /> ---<br /> Special Webcast about Trivy Supply Chain Attacks<br /><a href="https://www.sans.org/webcasts/when-security-scanner-became-weapon" target="_blank" rel="noreferrer noopener">https://www.sans.org/webcasts/when-security-scanner-became-weapon</a><br /> ---<br /> Detecting IP KVM Usage<br /><a href="https://isc.sans.edu/diary/Detecting%20IP%20KVMs/32824" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Detecting%20IP%20KVMs/32824</a><br /> TeamPCP, Trivy, liteLLM, Iran and more<br /><a href="https://www.aikido.dev/blog/teampcp-stage-payload-canisterworm-iran" target="_blank" rel="noreferrer noopener">https://www.aikido.dev/blog/teampcp-stage-payload-canisterworm-iran</a><br /><a href="https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know/" target="_blank" rel="noreferrer noopener">https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know/</a><br /><a href="https://blog.gitguardian.com/trivys-march-supply-chain-attack-shows-where-secret-exposure-hurts-most/" target="_blank" rel="noreferrer noopener">https://blog.gitguardian.com/trivys-march-supply-chain-attack-shows-where-secret-exposure-hurts-most/</a><br /><a href="https://www.sysdig.com/blog/teampcp-expands-supply-chain-compromise-spreads-from-trivy-to-checkmarx-github-actions" target="_blank" rel="noreferrer noopener">https://www.sysdig.com/blog/teampcp-expands-supply-chain-compromise-spreads-from-trivy-to-checkmarx-github-actions</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9864.mp3</guid><pubDate>Wed, 25 Mar 2026 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70862678/9864.mp3" length="10005625" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9864" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 ---
 Special Webcast about Trivy Supply Chain Attacks
https://www.sans.org/webcasts/when-security-scanner-became-weapon
 ---
 Detecting IP KVM Usage
https://isc.sans.edu/diary/Detecting%20IP%20KVMs/32824
 TeamPCP, Trivy, liteLLM, Iran and more...</itunes:subtitle><itunes:summary><![CDATA[<br /> ---<br /> Special Webcast about Trivy Supply Chain Attacks<br /><a href="https://www.sans.org/webcasts/when-security-scanner-became-weapon" target="_blank" rel="noreferrer noopener">https://www.sans.org/webcasts/when-security-scanner-became-weapon</a><br /> ---<br /> Detecting IP KVM Usage<br /><a href="https://isc.sans.edu/diary/Detecting%20IP%20KVMs/32824" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Detecting%20IP%20KVMs/32824</a><br /> TeamPCP, Trivy, liteLLM, Iran and more<br /><a href="https://www.aikido.dev/blog/teampcp-stage-payload-canisterworm-iran" target="_blank" rel="noreferrer noopener">https://www.aikido.dev/blog/teampcp-stage-payload-canisterworm-iran</a><br /><a href="https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know/" target="_blank" rel="noreferrer noopener">https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know/</a><br /><a href="https://blog.gitguardian.com/trivys-march-supply-chain-attack-shows-where-secret-exposure-hurts-most/" target="_blank" rel="noreferrer noopener">https://blog.gitguardian.com/trivys-march-supply-chain-attack-shows-where-secret-exposure-hurts-most/</a><br /><a href="https://www.sysdig.com/blog/teampcp-expands-supply-chain-compromise-spreads-from-trivy-to-checkmarx-github-actions" target="_blank" rel="noreferrer noopener">https://www.sysdig.com/blog/teampcp-expands-supply-chain-compromise-spreads-from-trivy-to-checkmarx-github-actions</a><br />]]></itunes:summary><itunes:duration>715</itunes:duration><itunes:keywords>business,checkmarx,computer,cyber,cybersecurity,daily,hacking,infosec,internet,ipkvm,it,litellm,network,news,security,supply chain,teampcp,trivy</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9864</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, March 24th, 2026: Tax Scam to EDR Kill; Netscaler Patches; gRPC-Go Authz Bypass;</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-march-24th-2026-tax-scam-to-edr-kill-netscaler-patches-grpc-go-authz-bypass--70842057</link><description><![CDATA[<br /> From W-2 to BYOVD: How a Tax Search Leads to Kernel-Mode AV/EDR Kill<br /><a href="https://www.huntress.com/blog/w2-malvertising-to-kernel-mode-edr-kill" target="_blank" rel="noreferrer noopener">https://www.huntress.com/blog/w2-malvertising-to-kernel-mode-edr-kill</a><br /> NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-3055 and CVE-2026-4368<br /><a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300" target="_blank" rel="noreferrer noopener">https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300</a><br /> gRPC-Go Authorization bypass via missing leading slash in :path CVE-2026-33186<br /><a href="https://github.com/grpc/grpc-go/security/advisories/GHSA-p77j-4mvh-x3m3" target="_blank" rel="noreferrer noopener">https://github.com/grpc/grpc-go/security/advisories/GHSA-p77j-4mvh-x3m3</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9862.mp3</guid><pubDate>Tue, 24 Mar 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70842057/9862.mp3" length="4777832" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9862" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 From W-2 to BYOVD: How a Tax Search Leads to Kernel-Mode AV/EDR Kill
https://www.huntress.com/blog/w2-malvertising-to-kernel-mode-edr-kill
 NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-3055 and CVE-2026-4368...</itunes:subtitle><itunes:summary><![CDATA[<br /> From W-2 to BYOVD: How a Tax Search Leads to Kernel-Mode AV/EDR Kill<br /><a href="https://www.huntress.com/blog/w2-malvertising-to-kernel-mode-edr-kill" target="_blank" rel="noreferrer noopener">https://www.huntress.com/blog/w2-malvertising-to-kernel-mode-edr-kill</a><br /> NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-3055 and CVE-2026-4368<br /><a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300" target="_blank" rel="noreferrer noopener">https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300</a><br /> gRPC-Go Authorization bypass via missing leading slash in :path CVE-2026-33186<br /><a href="https://github.com/grpc/grpc-go/security/advisories/GHSA-p77j-4mvh-x3m3" target="_blank" rel="noreferrer noopener">https://github.com/grpc/grpc-go/security/advisories/GHSA-p77j-4mvh-x3m3</a><br />]]></itunes:summary><itunes:duration>341</itunes:duration><itunes:keywords>authz,business,byovd,citrix,cyber,cybersecurity,daily,go,google,grpc,hacking,infosec,it,netscaler,network,news,scam,seo,tax,w-2</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9862</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, March 23rd, 2026:  GSocket Backdoor in Bash; Oracle Security Alert; Rockwell Attacks</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-march-23rd-2026-gsocket-backdoor-in-bash-oracle-security-alert-rockwell-attacks--70820220</link><description><![CDATA[<br /> GSocket Backdoor Delivered Through Bash Script<br /><a href="https://isc.sans.edu/diary/GSocket+Backdoor+Delivered+Through+Bash+Script/32816/#comments" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/GSocket+Backdoor+Delivered+Through+Bash+Script/32816/#comments</a><br /> Oracle Security Alert CVE-2026-21992 Released<br /><a href="https://blogs.oracle.com/security/alert-cve-2026-21992" target="_blank" rel="noreferrer noopener">https://blogs.oracle.com/security/alert-cve-2026-21992</a><br /> Rockwell Automation Reiterates Customer Guidance to Disconnect Devices from the Internet and Harden PLCs to Protect from Cyber Threats<br /><a href="https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1771.html" target="_blank" rel="noreferrer noopener">https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1771.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9860.mp3</guid><pubDate>Mon, 23 Mar 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70820220/9860.mp3" length="4686665" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9860" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 GSocket Backdoor Delivered Through Bash Script
https://isc.sans.edu/diary/GSocket+Backdoor+Delivered+Through+Bash+Script/32816/#comments
 Oracle Security Alert CVE-2026-21992 Released
https://blogs.oracle.com/security/alert-cve-2026-21992
 Rockwell...</itunes:subtitle><itunes:summary><![CDATA[<br /> GSocket Backdoor Delivered Through Bash Script<br /><a href="https://isc.sans.edu/diary/GSocket+Backdoor+Delivered+Through+Bash+Script/32816/#comments" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/GSocket+Backdoor+Delivered+Through+Bash+Script/32816/#comments</a><br /> Oracle Security Alert CVE-2026-21992 Released<br /><a href="https://blogs.oracle.com/security/alert-cve-2026-21992" target="_blank" rel="noreferrer noopener">https://blogs.oracle.com/security/alert-cve-2026-21992</a><br /> Rockwell Automation Reiterates Customer Guidance to Disconnect Devices from the Internet and Harden PLCs to Protect from Cyber Threats<br /><a href="https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1771.html" target="_blank" rel="noreferrer noopener">https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1771.html</a><br />]]></itunes:summary><itunes:duration>335</itunes:duration><itunes:keywords>bash,business,computer,cyber,cybersecurity,daily,gsocket,hacking,infosec,internet,it,network,news,oracle,rockwell,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9860</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, March 20th, 2026: Cowrie Strings; MSFT Intune Hardening; Unifi Network Update;</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-march-20th-2026-cowrie-strings-msft-intune-hardening-unifi-network-update--70770258</link><description><![CDATA[<br /> Interesting Cowrie Strings<br /><a href="https://isc.sans.edu/diary/Interesting+Message+Stored+in+Cowrie+Logs/32810" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Interesting+Message+Stored+in+Cowrie+Logs/32810</a><br /> Microsoft Intune Hardening Advice<br /><a href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/best-practices-for-securing-microsoft-intune/4502117" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/blog/intunecustomersuccess/best-practices-for-securing-microsoft-intune/4502117</a><br /><a href="https://www.cisa.gov/news-events/alerts/2026/03/18/cisa-urges-endpoint-management-system-hardening-after-cyberattack-against-us-organization" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2026/03/18/cisa-urges-endpoint-management-system-hardening-after-cyberattack-against-us-organization</a><br /> Unifi Network Update<br /><a href="https://community.ui.com/releases/Security-Advisory-Bulletin-062-062/c29719c0-405e-4d4a-8f26-e343e99f931b" target="_blank" rel="noreferrer noopener">https://community.ui.com/releases/Security-Advisory-Bulletin-062-062/c29719c0-405e-4d4a-8f26-e343e99f931b</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9858.mp3</guid><pubDate>Fri, 20 Mar 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70770258/9858.mp3" length="4828058" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9858" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Interesting Cowrie Strings
https://isc.sans.edu/diary/Interesting+Message+Stored+in+Cowrie+Logs/32810
 Microsoft Intune Hardening Advice...</itunes:subtitle><itunes:summary><![CDATA[<br /> Interesting Cowrie Strings<br /><a href="https://isc.sans.edu/diary/Interesting+Message+Stored+in+Cowrie+Logs/32810" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Interesting+Message+Stored+in+Cowrie+Logs/32810</a><br /> Microsoft Intune Hardening Advice<br /><a href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/best-practices-for-securing-microsoft-intune/4502117" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/blog/intunecustomersuccess/best-practices-for-securing-microsoft-intune/4502117</a><br /><a href="https://www.cisa.gov/news-events/alerts/2026/03/18/cisa-urges-endpoint-management-system-hardening-after-cyberattack-against-us-organization" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2026/03/18/cisa-urges-endpoint-management-system-hardening-after-cyberattack-against-us-organization</a><br /> Unifi Network Update<br /><a href="https://community.ui.com/releases/Security-Advisory-Bulletin-062-062/c29719c0-405e-4d4a-8f26-e343e99f931b" target="_blank" rel="noreferrer noopener">https://community.ui.com/releases/Security-Advisory-Bulletin-062-062/c29719c0-405e-4d4a-8f26-e343e99f931b</a><br />]]></itunes:summary><itunes:duration>345</itunes:duration><itunes:keywords>business,computer,cowrie,cyber,cybersecurity,daily,hacking,infosec,internet,intune,iran,it,microsoft,network,news,security,ubiquity,unifi</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9858</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, March 19th, 2026: Adminer Scans; Apple WebKit Patch; another telnetd vuln; screenconnect vuln</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-march-19th-2026-adminer-scans-apple-webkit-patch-another-telnetd-vuln-screenconnect-vuln--70729594</link><description><![CDATA[<br /> Scans for "adminer"<br /><a href="https://isc.sans.edu/diary/Scans%20for%20%22adminer%22/32808" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20%22adminer%22/32808</a><br /> Background Security Improvement for WebKit<br /><a href="https://support.apple.com/en-us/126604" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/126604</a><br /> Remote Pre-Auth Buffer Overflow in GNU Inetutils telnetd (LINEMODE SLC)<br /><a href="https://lists.gnu.org/archive/html/bug-inetutils/2026-03/msg00031.html" target="_blank" rel="noreferrer noopener">https://lists.gnu.org/archive/html/bug-inetutils/2026-03/msg00031.html</a><br /> ScreenConnect  26.1 Security Hardening<br /><a href="https://www.connectwise.com/company/trust/security-bulletins/2026-03-17-screenconnect-bulletin" target="_blank" rel="noreferrer noopener">https://www.connectwise.com/company/trust/security-bulletins/2026-03-17-screenconnect-bulletin</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9856.mp3</guid><pubDate>Thu, 19 Mar 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70729594/9856.mp3" length="4978898" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9856" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Scans for "adminer"
https://isc.sans.edu/diary/Scans%20for%20%22adminer%22/32808
 Background Security Improvement for WebKit
https://support.apple.com/en-us/126604
 Remote Pre-Auth Buffer Overflow in GNU Inetutils telnetd (LINEMODE SLC)...</itunes:subtitle><itunes:summary><![CDATA[<br /> Scans for "adminer"<br /><a href="https://isc.sans.edu/diary/Scans%20for%20%22adminer%22/32808" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20%22adminer%22/32808</a><br /> Background Security Improvement for WebKit<br /><a href="https://support.apple.com/en-us/126604" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/126604</a><br /> Remote Pre-Auth Buffer Overflow in GNU Inetutils telnetd (LINEMODE SLC)<br /><a href="https://lists.gnu.org/archive/html/bug-inetutils/2026-03/msg00031.html" target="_blank" rel="noreferrer noopener">https://lists.gnu.org/archive/html/bug-inetutils/2026-03/msg00031.html</a><br /> ScreenConnect  26.1 Security Hardening<br /><a href="https://www.connectwise.com/company/trust/security-bulletins/2026-03-17-screenconnect-bulletin" target="_blank" rel="noreferrer noopener">https://www.connectwise.com/company/trust/security-bulletins/2026-03-17-screenconnect-bulletin</a><br />]]></itunes:summary><itunes:duration>356</itunes:duration><itunes:keywords>adminer,business,computer,connectwise,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,screenconnect,security,webkit</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9856</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, March 18th, 2026:  IPv4 mapped IPv6; KVM Vulnerabilities; AWS Bedrock DNS Covert Channel</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-march-18th-2026-ipv4-mapped-ipv6-kvm-vulnerabilities-aws-bedrock-dns-covert-channel--70714740</link><description><![CDATA[<br /> IPv4 Mapped IPv6 Addresses<br /><a href="https://isc.sans.edu/diary/IPv4%20Mapped%20IPv6%20Addresses/32804" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/IPv4%20Mapped%20IPv6%20Addresses/32804</a><br /> More IP KVM Vulnerabilities<br /><a href="https://eclypsium.com/blog/your-kvm-is-the-weak-link-how-30-dollar-devices-can-own-your-entire-network/" target="_blank" rel="noreferrer noopener">https://eclypsium.com/blog/your-kvm-is-the-weak-link-how-30-dollar-devices-can-own-your-entire-network/</a><br /> AWS Bedrock AgentCore Code Interpreter DNS Leak<br /><a href="https://www.beyondtrust.com/blog/entry/pwning-aws-agentcore-code-interpreter" target="_blank" rel="noreferrer noopener">https://www.beyondtrust.com/blog/entry/pwning-aws-agentcore-code-interpreter</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9854.mp3</guid><pubDate>Wed, 18 Mar 2026 11:05:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70714740/9854.mp3" length="5039906" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9854" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 IPv4 Mapped IPv6 Addresses
https://isc.sans.edu/diary/IPv4%20Mapped%20IPv6%20Addresses/32804
 More IP KVM Vulnerabilities
https://eclypsium.com/blog/your-kvm-is-the-weak-link-how-30-dollar-devices-can-own-your-entire-network/
 AWS Bedrock AgentCore...</itunes:subtitle><itunes:summary><![CDATA[<br /> IPv4 Mapped IPv6 Addresses<br /><a href="https://isc.sans.edu/diary/IPv4%20Mapped%20IPv6%20Addresses/32804" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/IPv4%20Mapped%20IPv6%20Addresses/32804</a><br /> More IP KVM Vulnerabilities<br /><a href="https://eclypsium.com/blog/your-kvm-is-the-weak-link-how-30-dollar-devices-can-own-your-entire-network/" target="_blank" rel="noreferrer noopener">https://eclypsium.com/blog/your-kvm-is-the-weak-link-how-30-dollar-devices-can-own-your-entire-network/</a><br /> AWS Bedrock AgentCore Code Interpreter DNS Leak<br /><a href="https://www.beyondtrust.com/blog/entry/pwning-aws-agentcore-code-interpreter" target="_blank" rel="noreferrer noopener">https://www.beyondtrust.com/blog/entry/pwning-aws-agentcore-code-interpreter</a><br />]]></itunes:summary><itunes:duration>360</itunes:duration><itunes:keywords>agentcore,aws,bedrock,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,ipv6,it,kvm,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9854</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, March 17th, 2026: Proxy URLs; Local Network Address Restrictions; Advanced Phishing</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-march-17th-2026-proxy-urls-local-network-address-restrictions-advanced-phishing--70673417</link><description><![CDATA[<br /> /proxy/ URL scans with IP addresses<br /><a href="https://isc.sans.edu/forums/diary/proxy+URL+scans+with+IP+addresses/32800/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/proxy+URL+scans+with+IP+addresses/32800/</a><br /> Local Network Address Restrictions <br /><a href="https://learn.microsoft.com/en-us/deployedge/ms-edge-local-network-access#how-to-mitigate-impact-for-cross-origin-iframes" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/deployedge/ms-edge-local-network-access#how-to-mitigate-impact-for-cross-origin-iframes</a> <a href="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnote-stable-channel" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnote-stable-channel</a><br /> European Security Vendor Targeted by Hackers Fronting as Cisco Domain<br /><a href="https://specopssoft.com/blog/phishing-campaign-cisco/" target="_blank" rel="noreferrer noopener">https://specopssoft.com/blog/phishing-campaign-cisco/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9852.mp3</guid><pubDate>Tue, 17 Mar 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70673417/9852.mp3" length="6590641" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9852" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 /proxy/ URL scans with IP addresses
https://isc.sans.edu/forums/diary/proxy+URL+scans+with+IP+addresses/32800/
 Local Network Address Restrictions...</itunes:subtitle><itunes:summary><![CDATA[<br /> /proxy/ URL scans with IP addresses<br /><a href="https://isc.sans.edu/forums/diary/proxy+URL+scans+with+IP+addresses/32800/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/proxy+URL+scans+with+IP+addresses/32800/</a><br /> Local Network Address Restrictions <br /><a href="https://learn.microsoft.com/en-us/deployedge/ms-edge-local-network-access#how-to-mitigate-impact-for-cross-origin-iframes" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/deployedge/ms-edge-local-network-access#how-to-mitigate-impact-for-cross-origin-iframes</a> <a href="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnote-stable-channel" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnote-stable-channel</a><br /> European Security Vendor Targeted by Hackers Fronting as Cisco Domain<br /><a href="https://specopssoft.com/blog/phishing-campaign-cisco/" target="_blank" rel="noreferrer noopener">https://specopssoft.com/blog/phishing-campaign-cisco/</a><br />]]></itunes:summary><itunes:duration>471</itunes:duration><itunes:keywords>business,chrome,computer,cyber,cybersecurity,daily,dkim,edge,hacking,infosec,internet,it,network,news,phishing,proxy,security,url</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9852</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, March 16th, 2026: SmartApeSG and Remcos RAT; React Based Phishing; Google Chrome Patches; AdGaurd Vuln</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-march-16th-2026-smartapesg-and-remcos-rat-react-based-phishing-google-chrome-patches-adgaurd-vuln--70653043</link><description><![CDATA[<br /> SmartApeSG campaign uses ClickFix page to push Remcos RAT<br /><a href="https://isc.sans.edu/diary/SmartApeSG%20campaign%20uses%20ClickFix%20page%20to%20push%20Remcos%20RAT/32796" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SmartApeSG%20campaign%20uses%20ClickFix%20page%20to%20push%20Remcos%20RAT/32796</a><br /> A React-based phishing page with credential exfiltration via EmailJS<br /><a href="https://isc.sans.edu/diary/32794" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/32794</a><br /> Google Chrome announced two zero-day fixes, then removed one.<br /><a href="https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html</a><br /> AdGuard Vulnerability<br /><a href="https://github.com/AdguardTeam/AdGuardHome/releases/tag/v0.107.73" target="_blank" rel="noreferrer noopener">https://github.com/AdguardTeam/AdGuardHome/releases/tag/v0.107.73</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9850.mp3</guid><pubDate>Mon, 16 Mar 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70653043/9850.mp3" length="5220702" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9850" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 SmartApeSG campaign uses ClickFix page to push Remcos RAT
https://isc.sans.edu/diary/SmartApeSG%20campaign%20uses%20ClickFix%20page%20to%20push%20Remcos%20RAT/32796
 A React-based phishing page with credential exfiltration via EmailJS...</itunes:subtitle><itunes:summary><![CDATA[<br /> SmartApeSG campaign uses ClickFix page to push Remcos RAT<br /><a href="https://isc.sans.edu/diary/SmartApeSG%20campaign%20uses%20ClickFix%20page%20to%20push%20Remcos%20RAT/32796" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SmartApeSG%20campaign%20uses%20ClickFix%20page%20to%20push%20Remcos%20RAT/32796</a><br /> A React-based phishing page with credential exfiltration via EmailJS<br /><a href="https://isc.sans.edu/diary/32794" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/32794</a><br /> Google Chrome announced two zero-day fixes, then removed one.<br /><a href="https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html</a><br /> AdGuard Vulnerability<br /><a href="https://github.com/AdguardTeam/AdGuardHome/releases/tag/v0.107.73" target="_blank" rel="noreferrer noopener">https://github.com/AdguardTeam/AdGuardHome/releases/tag/v0.107.73</a><br />]]></itunes:summary><itunes:duration>373</itunes:duration><itunes:keywords>adguard,business,chorme,computer,cyber,cybersecurity,daily,emailjs clickfix. smartagesg,google,hacking,infosec,internet,it,network,news,rat,react,remco,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9850</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, March 13th, 2026: IOT Device Discovery; Apple Patches; Veeam Patches</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-march-13th-2026-iot-device-discovery-apple-patches-veeam-patches--70616462</link><description><![CDATA[<br /> When your IoT Device Logs in as Admin, It s too Late!<br /><a href="https://isc.sans.edu/diary/When%20your%20IoT%20Device%20Logs%20in%20as%20Admin%2C%20It%3Fs%20too%20Late!%20%5BGuest%20Diary%5D/32788" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/When%20your%20IoT%20Device%20Logs%20in%20as%20Admin%2C%20It%3Fs%20too%20Late!%20%5BGuest%20Diary%5D/32788</a><br /> Apple Patches <br /><a href="https://support.apple.com/en-us/100100" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/100100</a><br /> Veeam Patches<br /><a href="https://www.veeam.com/kb4830" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4830</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9848.mp3</guid><pubDate>Fri, 13 Mar 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70616462/9848.mp3" length="4465267" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9848" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 When your IoT Device Logs in as Admin, It s too Late!
https://isc.sans.edu/diary/When%20your%20IoT%20Device%20Logs%20in%20as%20Admin%2C%20It%3Fs%20too%20Late!%20%5BGuest%20Diary%5D/32788
 Apple Patches 
https://support.apple.com/en-us/100100
 Veeam...</itunes:subtitle><itunes:summary><![CDATA[<br /> When your IoT Device Logs in as Admin, It s too Late!<br /><a href="https://isc.sans.edu/diary/When%20your%20IoT%20Device%20Logs%20in%20as%20Admin%2C%20It%3Fs%20too%20Late!%20%5BGuest%20Diary%5D/32788" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/When%20your%20IoT%20Device%20Logs%20in%20as%20Admin%2C%20It%3Fs%20too%20Late!%20%5BGuest%20Diary%5D/32788</a><br /> Apple Patches <br /><a href="https://support.apple.com/en-us/100100" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/100100</a><br /> Veeam Patches<br /><a href="https://www.veeam.com/kb4830" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4830</a><br />]]></itunes:summary><itunes:duration>319</itunes:duration><itunes:keywords>apple,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,iot,it,network,news,patches,security,veeam</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9848</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, March 12th, 2026: Zombie Zip;</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-march-12th-2026-zombie-zip--70602050</link><description><![CDATA[<br /> Analyzing "Zombie Zip" Files (CVE-2026-0866)<br /><a href="https://isc.sans.edu/diary/Analyzing%20%22Zombie%20Zip%22%20Files%20%28CVE-2026-0866%29/32786" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analyzing%20%22Zombie%20Zip%22%20Files%20%28CVE-2026-0866%29/32786</a><br /> How "Strengthening Crypto" Broke Authentication: FreshRSS and bcrypt's 72-Byte Limit<br /><a href="https://pentesterlab.com/blog/freshrss-bcrypt-truncation-auth-bypass" target="_blank" rel="noreferrer noopener">https://pentesterlab.com/blog/freshrss-bcrypt-truncation-auth-bypass</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9846.mp3</guid><pubDate>Thu, 12 Mar 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70602050/9846.mp3" length="6255548" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9846" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Analyzing "Zombie Zip" Files (CVE-2026-0866)
https://isc.sans.edu/diary/Analyzing%20%22Zombie%20Zip%22%20Files%20%28CVE-2026-0866%29/32786
 How "Strengthening Crypto" Broke Authentication: FreshRSS and bcrypt's 72-Byte Limit...</itunes:subtitle><itunes:summary><![CDATA[<br /> Analyzing "Zombie Zip" Files (CVE-2026-0866)<br /><a href="https://isc.sans.edu/diary/Analyzing%20%22Zombie%20Zip%22%20Files%20%28CVE-2026-0866%29/32786" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analyzing%20%22Zombie%20Zip%22%20Files%20%28CVE-2026-0866%29/32786</a><br /> How "Strengthening Crypto" Broke Authentication: FreshRSS and bcrypt's 72-Byte Limit<br /><a href="https://pentesterlab.com/blog/freshrss-bcrypt-truncation-auth-bypass" target="_blank" rel="noreferrer noopener">https://pentesterlab.com/blog/freshrss-bcrypt-truncation-auth-bypass</a><br />]]></itunes:summary><itunes:duration>447</itunes:duration><itunes:keywords>bcrypt,business,computer,cyber,cybersecurity,daily,fressrss,hacking,infosec,internet,it,network,news,security,zip,zombie</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9846</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, March 11th, 2026: Windows, Fortinet, Adobe, and Zoom Patches</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-march-11th-2026-windows-fortinet-adobe-and-zoom-patches--70583764</link><description><![CDATA[<br /> Microsoft Patch Tuesday, March 2026<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20March%202026/32782" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20March%202026/32782</a><br /> Fortinet Updates<br /><a href="https://fortiguard.fortinet.com/psirt" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt</a><br /> Adobe Updates<br /><a href="https://helpx.adobe.com/security.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security.html</a><br /> Zoom Update<br /><a href="https://www.instagram.com/direct/t/17848218473607233/" target="_blank" rel="noreferrer noopener">https://www.instagram.com/direct/t/17848218473607233/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9844.mp3</guid><pubDate>Wed, 11 Mar 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70583764/9844.mp3" length="5186436" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9844" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Microsoft Patch Tuesday, March 2026
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20March%202026/32782
 Fortinet Updates
https://fortiguard.fortinet.com/psirt
 Adobe Updates
https://helpx.adobe.com/security.html
 Zoom Update...</itunes:subtitle><itunes:summary><![CDATA[<br /> Microsoft Patch Tuesday, March 2026<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20March%202026/32782" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20March%202026/32782</a><br /> Fortinet Updates<br /><a href="https://fortiguard.fortinet.com/psirt" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt</a><br /> Adobe Updates<br /><a href="https://helpx.adobe.com/security.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security.html</a><br /> Zoom Update<br /><a href="https://www.instagram.com/direct/t/17848218473607233/" target="_blank" rel="noreferrer noopener">https://www.instagram.com/direct/t/17848218473607233/</a><br />]]></itunes:summary><itunes:duration>371</itunes:duration><itunes:keywords>adobe,business,computer,cyber,cybersecurity,daily,fortinet,hacking,infosec,internet,it,microsoft,network,news,security,zoom</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9844</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, March 10th, 2026: Encrypted Client Hello; ExitTool Vulnerability;</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-march-10th-2026-encrypted-client-hello-exittool-vulnerability--70559942</link><description><![CDATA[<br /> Encrypted Client Hello: Ready for Prime Time?<br /><a href="https://isc.sans.edu/diary/Encrypted%20Client%20Hello%3A%20Ready%20for%20Prime%20Time%3F/32778" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Encrypted%20Client%20Hello%3A%20Ready%20for%20Prime%20Time%3F/32778</a><br /> The ExifTool vulnerability: how an image can infect macOS systems<br /><a href="https://www.kaspersky.com/blog/exiftool-macos-picture-vulnerability-mitigation-cve-2026-3102/55362/" target="_blank" rel="noreferrer noopener">https://www.kaspersky.com/blog/exiftool-macos-picture-vulnerability-mitigation-cve-2026-3102/55362/</a><br /> Remote code execution in Nextcloud Flow via vulnerable Windmill version<br /><a href="https://github.com/nextcloud/security-advisories/security/advisories/GHSA-g7vj-98x3-qvjf" target="_blank" rel="noreferrer noopener">https://github.com/nextcloud/security-advisories/security/advisories/GHSA-g7vj-98x3-qvjf</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9842.mp3</guid><pubDate>Tue, 10 Mar 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70559942/9842.mp3" length="6257050" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9842" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Encrypted Client Hello: Ready for Prime Time?
https://isc.sans.edu/diary/Encrypted%20Client%20Hello%3A%20Ready%20for%20Prime%20Time%3F/32778
 The ExifTool vulnerability: how an image can infect macOS systems...</itunes:subtitle><itunes:summary><![CDATA[<br /> Encrypted Client Hello: Ready for Prime Time?<br /><a href="https://isc.sans.edu/diary/Encrypted%20Client%20Hello%3A%20Ready%20for%20Prime%20Time%3F/32778" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Encrypted%20Client%20Hello%3A%20Ready%20for%20Prime%20Time%3F/32778</a><br /> The ExifTool vulnerability: how an image can infect macOS systems<br /><a href="https://www.kaspersky.com/blog/exiftool-macos-picture-vulnerability-mitigation-cve-2026-3102/55362/" target="_blank" rel="noreferrer noopener">https://www.kaspersky.com/blog/exiftool-macos-picture-vulnerability-mitigation-cve-2026-3102/55362/</a><br /> Remote code execution in Nextcloud Flow via vulnerable Windmill version<br /><a href="https://github.com/nextcloud/security-advisories/security/advisories/GHSA-g7vj-98x3-qvjf" target="_blank" rel="noreferrer noopener">https://github.com/nextcloud/security-advisories/security/advisories/GHSA-g7vj-98x3-qvjf</a><br />]]></itunes:summary><itunes:duration>447</itunes:duration><itunes:keywords>business,client hello,computer,cyber,cybersecurity,daily,ech,encrypted,exiftool,hacking,https,infosec,internet,it,macos,network,news,security,tls,windmill</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9842</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, March 9th, 2026: YARA-X Update; IP Camera Targeting; Node.js Upgrades; nginx UI Vuln</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-march-9th-2026-yara-x-update-ip-camera-targeting-node-js-upgrades-nginx-ui-vuln--70542788</link><description><![CDATA[<br /> YARA-X 1.14.0 Release <a href="https://isc.sans.edu/diary/YARA-X%201.14.0%20Release/32774" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/YARA-X%201.14.0%20Release/32774</a><br /> INTERPLAY BETWEEN IRANIAN TARGETING OF IP CAMERAS AND PHYSICAL WARFARE IN THE MIDDLE EAST<br /><a href="https://research.checkpoint.com/2026/interplay-between-iranian-targeting-of-ip-cameras-and-physical-warfare-in-the-middle-east/" target="_blank" rel="noreferrer noopener">https://research.checkpoint.com/2026/interplay-between-iranian-targeting-of-ip-cameras-and-physical-warfare-in-the-middle-east/</a><br /> Announcing the Node.js LTS Upgrade and Modernization Program<br /><a href="https://openjsf.org/blog/nodejs-lts-upgrade-program" target="_blank" rel="noreferrer noopener">https://openjsf.org/blog/nodejs-lts-upgrade-program</a><br /> nginx UI Vulnerability<br /><a href="https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-g9w5-qffc-6762" target="_blank" rel="noreferrer noopener">https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-g9w5-qffc-6762</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9840.mp3</guid><pubDate>Mon, 09 Mar 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70542788/9840.mp3" length="4313113" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9840" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 YARA-X 1.14.0 Release https://isc.sans.edu/diary/YARA-X%201.14.0%20Release/32774
 INTERPLAY BETWEEN IRANIAN TARGETING OF IP CAMERAS AND PHYSICAL WARFARE IN THE MIDDLE EAST...</itunes:subtitle><itunes:summary><![CDATA[<br /> YARA-X 1.14.0 Release <a href="https://isc.sans.edu/diary/YARA-X%201.14.0%20Release/32774" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/YARA-X%201.14.0%20Release/32774</a><br /> INTERPLAY BETWEEN IRANIAN TARGETING OF IP CAMERAS AND PHYSICAL WARFARE IN THE MIDDLE EAST<br /><a href="https://research.checkpoint.com/2026/interplay-between-iranian-targeting-of-ip-cameras-and-physical-warfare-in-the-middle-east/" target="_blank" rel="noreferrer noopener">https://research.checkpoint.com/2026/interplay-between-iranian-targeting-of-ip-cameras-and-physical-warfare-in-the-middle-east/</a><br /> Announcing the Node.js LTS Upgrade and Modernization Program<br /><a href="https://openjsf.org/blog/nodejs-lts-upgrade-program" target="_blank" rel="noreferrer noopener">https://openjsf.org/blog/nodejs-lts-upgrade-program</a><br /> nginx UI Vulnerability<br /><a href="https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-g9w5-qffc-6762" target="_blank" rel="noreferrer noopener">https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-g9w5-qffc-6762</a><br />]]></itunes:summary><itunes:duration>308</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,ip cameras,iran,it,network,news,nginx,node.js,security,yara</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9840</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, March 6th, 2026: Targeted or Not? pac4j-jwt auth bypass; freescout dangerous uploads; MSFT Authenticator vs Graphene</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-march-6th-2026-targeted-or-not-pac4j-jwt-auth-bypass-freescout-dangerous-uploads-msft-authenticator-vs-graphene--70496512</link><description><![CDATA[<br /> Differentiating Between a Targeted Intrusion and an Automated Opportunistic Scanning [Guest Diary]<br /><a href="https://isc.sans.edu/diary/Differentiating%20Between%20a%20Targeted%20Intrusion%20and%20an%20Automated%20Opportunistic%20Scanning%20%5BGuest%20Diary%5D/32768" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Differentiating%20Between%20a%20Targeted%20Intrusion%20and%20an%20Automated%20Opportunistic%20Scanning%20%5BGuest%20Diary%5D/32768</a><br /> CVE-2026-29000: Critical Authentication Bypass in pac4j-jwt - Using Only a Public Key (CVSS 10)<br /><a href="https://www.codeant.ai/security-research/pac4j-jwt-authentication-bypass-public-key" target="_blank" rel="noreferrer noopener">https://www.codeant.ai/security-research/pac4j-jwt-authentication-bypass-public-key</a><br /> FreeScout Help Desk Vulnerability<br /><a href="https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-mw88-x7j3-74vc" target="_blank" rel="noreferrer noopener">https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-mw88-x7j3-74vc</a><br /> Microsoft Authenticator Not Supported on Graphene OS<br /><a href="https://www.heise.de/en/news/GrapheneOS-Microsoft-Authenticator-does-not-support-secure-Android-OS-11200495.html" target="_blank" rel="noreferrer noopener">https://www.heise.de/en/news/GrapheneOS-Microsoft-Authenticator-does-not-support-secure-Android-OS-11200495.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9838.mp3</guid><pubDate>Fri, 06 Mar 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70496512/9838.mp3" length="5816703" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9838" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Differentiating Between a Targeted Intrusion and an Automated Opportunistic Scanning [Guest Diary]...</itunes:subtitle><itunes:summary><![CDATA[<br /> Differentiating Between a Targeted Intrusion and an Automated Opportunistic Scanning [Guest Diary]<br /><a href="https://isc.sans.edu/diary/Differentiating%20Between%20a%20Targeted%20Intrusion%20and%20an%20Automated%20Opportunistic%20Scanning%20%5BGuest%20Diary%5D/32768" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Differentiating%20Between%20a%20Targeted%20Intrusion%20and%20an%20Automated%20Opportunistic%20Scanning%20%5BGuest%20Diary%5D/32768</a><br /> CVE-2026-29000: Critical Authentication Bypass in pac4j-jwt - Using Only a Public Key (CVSS 10)<br /><a href="https://www.codeant.ai/security-research/pac4j-jwt-authentication-bypass-public-key" target="_blank" rel="noreferrer noopener">https://www.codeant.ai/security-research/pac4j-jwt-authentication-bypass-public-key</a><br /> FreeScout Help Desk Vulnerability<br /><a href="https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-mw88-x7j3-74vc" target="_blank" rel="noreferrer noopener">https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-mw88-x7j3-74vc</a><br /> Microsoft Authenticator Not Supported on Graphene OS<br /><a href="https://www.heise.de/en/news/GrapheneOS-Microsoft-Authenticator-does-not-support-secure-Android-OS-11200495.html" target="_blank" rel="noreferrer noopener">https://www.heise.de/en/news/GrapheneOS-Microsoft-Authenticator-does-not-support-secure-Android-OS-11200495.html</a><br />]]></itunes:summary><itunes:duration>416</itunes:duration><itunes:keywords>algorithm confusion,business,computer,cyber,cybersecurity,daily,freesccout,hacking,honeypot,infosec,internet,it,network,news,pac4j-jwt,security,targeted</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9838</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, March 5th, 2026: XWorm Analysis; Cisco “Secure” Firewall Managmeent Center; LastPass Phishing</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-march-5th-2026-xworm-analysis-cisco-secure-firewall-managmeent-center-lastpass-phishing--70479100</link><description><![CDATA[<br /> Want More XWorm?<br /><a href="https://isc.sans.edu/diary/Want%20More%20XWorm%3F/32766" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Want%20More%20XWorm%3F/32766</a><br /> Cisco  Secure  Firewall Management Center Vulnerabilities<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh</a><br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2</a><br /> LastPass Phishing<br /><a href="https://www.securityweek.com/lastpass-users-targeted-with-backup-themed-phishing-emails/" target="_blank" rel="noreferrer noopener">https://www.securityweek.com/lastpass-users-targeted-with-backup-themed-phishing-emails/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9836.mp3</guid><pubDate>Thu, 05 Mar 2026 11:50:11 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70479100/9836.mp3" length="6420986" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9836" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Want More XWorm?
https://isc.sans.edu/diary/Want%20More%20XWorm%3F/32766
 Cisco  Secure  Firewall Management Center Vulnerabilities
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh...</itunes:subtitle><itunes:summary><![CDATA[<br /> Want More XWorm?<br /><a href="https://isc.sans.edu/diary/Want%20More%20XWorm%3F/32766" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Want%20More%20XWorm%3F/32766</a><br /> Cisco  Secure  Firewall Management Center Vulnerabilities<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh</a><br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2</a><br /> LastPass Phishing<br /><a href="https://www.securityweek.com/lastpass-users-targeted-with-backup-themed-phishing-emails/" target="_blank" rel="noreferrer noopener">https://www.securityweek.com/lastpass-users-targeted-with-backup-themed-phishing-emails/</a><br />]]></itunes:summary><itunes:duration>459</itunes:duration><itunes:keywords>business,cisco,computer,cyber,cybersecurity,daily,firewall management,hacking,infosec,internet,it,lastpass,network,news,security,xworm</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9836</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, March 4th, 2026: CrushFTP Brute Force; Android Patches 0-Day; 0Auth Phishing Abuse</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-march-4th-2026-crushftp-brute-force-android-patches-0-day-0auth-phishing-abuse--70432063</link><description><![CDATA[<br /> Bruteforce Scans for CrushFTP<br /><a href="https://isc.sans.edu/diary/Bruteforce%20Scans%20for%20CrushFTP%20/32762" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Bruteforce%20Scans%20for%20CrushFTP%20/32762</a><br /> Android March 2026 Patches, including 0-Day (CVE-2026-21385)<br /><a href="https://source.android.com/docs/security/bulletin/2026/2026-03-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2026/2026-03-01</a><br /> OAuth redirection abuse enables phishing and malware delivery<br /><a href="https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9834.mp3</guid><pubDate>Wed, 04 Mar 2026 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70432063/9834.mp3" length="4249464" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9834" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Bruteforce Scans for CrushFTP
https://isc.sans.edu/diary/Bruteforce%20Scans%20for%20CrushFTP%20/32762
 Android March 2026 Patches, including 0-Day (CVE-2026-21385)
https://source.android.com/docs/security/bulletin/2026/2026-03-01
 OAuth redirection...</itunes:subtitle><itunes:summary><![CDATA[<br /> Bruteforce Scans for CrushFTP<br /><a href="https://isc.sans.edu/diary/Bruteforce%20Scans%20for%20CrushFTP%20/32762" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Bruteforce%20Scans%20for%20CrushFTP%20/32762</a><br /> Android March 2026 Patches, including 0-Day (CVE-2026-21385)<br /><a href="https://source.android.com/docs/security/bulletin/2026/2026-03-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2026/2026-03-01</a><br /> OAuth redirection abuse enables phishing and malware delivery<br /><a href="https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/</a><br />]]></itunes:summary><itunes:duration>304</itunes:duration><itunes:keywords>android,brute force,business,computer,crushftp,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,oauth,phishing,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9834</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, March 3rd, 2026: Finding URLs in ZIPs in RTFs; Merkle Tree Certificates; Taming Agentic Browsers</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-march-3rd-2026-finding-urls-in-zips-in-rtfs-merkle-tree-certificates-taming-agentic-browsers--70401068</link><description><![CDATA[<br /> Quick Howto: ZIP Files Inside RTF<br /><a href="https://isc.sans.edu/diary/Quick+Howto+ZIP+Files+Inside+RTF/32696/#comments" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Quick+Howto+ZIP+Files+Inside+RTF/32696/#comments</a><br /> Keeping the Internet fast and secure: introducing Merkle Tree Certificates<br /><a href="https://blog.cloudflare.com/bootstrap-mtc/" target="_blank" rel="noreferrer noopener">https://blog.cloudflare.com/bootstrap-mtc/</a><br /> Taming Agentic Browsers: Vulnerability in Chrome Allowed Extensions to Hijack New Gemini Panel<br /><a href="https://unit42.paloaltonetworks.com/gemini-live-in-chrome-hijacking/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/gemini-live-in-chrome-hijacking/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9832.mp3</guid><pubDate>Tue, 03 Mar 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70401068/9832.mp3" length="6866258" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9832" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Quick Howto: ZIP Files Inside RTF
https://isc.sans.edu/diary/Quick+Howto+ZIP+Files+Inside+RTF/32696/#comments
 Keeping the Internet fast and secure: introducing Merkle Tree Certificates
https://blog.cloudflare.com/bootstrap-mtc/
 Taming Agentic...</itunes:subtitle><itunes:summary><![CDATA[<br /> Quick Howto: ZIP Files Inside RTF<br /><a href="https://isc.sans.edu/diary/Quick+Howto+ZIP+Files+Inside+RTF/32696/#comments" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Quick+Howto+ZIP+Files+Inside+RTF/32696/#comments</a><br /> Keeping the Internet fast and secure: introducing Merkle Tree Certificates<br /><a href="https://blog.cloudflare.com/bootstrap-mtc/" target="_blank" rel="noreferrer noopener">https://blog.cloudflare.com/bootstrap-mtc/</a><br /> Taming Agentic Browsers: Vulnerability in Chrome Allowed Extensions to Hijack New Gemini Panel<br /><a href="https://unit42.paloaltonetworks.com/gemini-live-in-chrome-hijacking/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/gemini-live-in-chrome-hijacking/</a><br />]]></itunes:summary><itunes:duration>491</itunes:duration><itunes:keywords>agentic,browsers,business,certificate,chrome,computer,cyber,cybersecurity,daily,gemini,hacking,infosec,internet,it,network,news,rtf,security,webpki,zip</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9832</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, March 2nd, 2026: Reversing Fake Fedex; Abusing .ARPA; MSFT Authenticator Update; Apex One Vuln; Special AirSnitch Web</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-march-2nd-2026-reversing-fake-fedex-abusing-arpa-msft-authenticator-update-apex-one-vuln-special-airsnitch-web--70381358</link><description><![CDATA[<br /> Fake Fedex Email Delivers Donuts!<br /><a href="https://isc.sans.edu/diary/Fake%20Fedex%20Email%20Delivers%20Donuts!/32754" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Fake%20Fedex%20Email%20Delivers%20Donuts!/32754</a><br /> Abusing .ARPA: The TLD that isn t supposed to host anything<br /><a href="https://www.infoblox.com/blog/threat-intelligence/abusing-arpa-the-tld-that-isnt-supposed-to-host-anything/" target="_blank" rel="noreferrer noopener">https://www.infoblox.com/blog/threat-intelligence/abusing-arpa-the-tld-that-isnt-supposed-to-host-anything/</a><br /> MC1179154 - Microsoft Authenticator app: Upcoming changes to jailbreak and root detection<br /><a href="https://mc.merill.net/message/MC1179154" target="_blank" rel="noreferrer noopener">https://mc.merill.net/message/MC1179154</a><br /> SECURITY BULLETIN: Apex One and Apex One (Mac) - February 2026<br /><a href="https://success.trendmicro.com/en-US/solution/KA-0022458" target="_blank" rel="noreferrer noopener">https://success.trendmicro.com/en-US/solution/KA-0022458</a><br /> Special Webcast: AirSnitch   How Worried Should You Be?<br /><a href="https://www.sans.org/webcasts/airsnitch-how-worried-should-you-be" target="_blank" rel="noreferrer noopener">https://www.sans.org/webcasts/airsnitch-how-worried-should-you-be</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9830.mp3</guid><pubDate>Mon, 02 Mar 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70381358/9830.mp3" length="6377866" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9830" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Fake Fedex Email Delivers Donuts!
https://isc.sans.edu/diary/Fake%20Fedex%20Email%20Delivers%20Donuts!/32754
 Abusing .ARPA: The TLD that isn t supposed to host anything...</itunes:subtitle><itunes:summary><![CDATA[<br /> Fake Fedex Email Delivers Donuts!<br /><a href="https://isc.sans.edu/diary/Fake%20Fedex%20Email%20Delivers%20Donuts!/32754" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Fake%20Fedex%20Email%20Delivers%20Donuts!/32754</a><br /> Abusing .ARPA: The TLD that isn t supposed to host anything<br /><a href="https://www.infoblox.com/blog/threat-intelligence/abusing-arpa-the-tld-that-isnt-supposed-to-host-anything/" target="_blank" rel="noreferrer noopener">https://www.infoblox.com/blog/threat-intelligence/abusing-arpa-the-tld-that-isnt-supposed-to-host-anything/</a><br /> MC1179154 - Microsoft Authenticator app: Upcoming changes to jailbreak and root detection<br /><a href="https://mc.merill.net/message/MC1179154" target="_blank" rel="noreferrer noopener">https://mc.merill.net/message/MC1179154</a><br /> SECURITY BULLETIN: Apex One and Apex One (Mac) - February 2026<br /><a href="https://success.trendmicro.com/en-US/solution/KA-0022458" target="_blank" rel="noreferrer noopener">https://success.trendmicro.com/en-US/solution/KA-0022458</a><br /> Special Webcast: AirSnitch   How Worried Should You Be?<br /><a href="https://www.sans.org/webcasts/airsnitch-how-worried-should-you-be" target="_blank" rel="noreferrer noopener">https://www.sans.org/webcasts/airsnitch-how-worried-should-you-be</a><br />]]></itunes:summary><itunes:duration>456</itunes:duration><itunes:keywords>airsnitch,apex,arpa,authenticator,business,cyber,cybersecurity,daily,fedex,hacking,infosec,it,microsoft,network,news,one,phishing,security,tld,webcast</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9830</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, February 27th, 2026: Finding Singal (@sans_edu intern); Google API Keys and Gemini; AirSnitch Breaking Client Isolati</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-february-27th-2026-finding-singal-sans-edu-intern-google-api-keys-and-gemini-airsnitch-breaking-client-isolati--70313151</link><description><![CDATA[<br /> Finding Signal in the Noise: Lessons Learned Running a Honeypot with AI Assistance [Guest Diary]<br /><a href="https://isc.sans.edu/diary/Finding%20Signal%20in%20the%20Noise%3A%20Lessons%20Learned%20Running%20a%20Honeypot%20with%20AI%20Assistance%20%5BGuest%20Diary%5D/32744" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Finding%20Signal%20in%20the%20Noise%3A%20Lessons%20Learned%20Running%20a%20Honeypot%20with%20AI%20Assistance%20%5BGuest%20Diary%5D/32744</a><br /> Google API Keys Weren't Secrets. But then Gemini Changed the Rules.<br /><a href="https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules" target="_blank" rel="noreferrer noopener">https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules</a><br /> AirSnitch: Demystifying and Breaking Client Isolation in Wi-Fi Networks<br /><a href="https://www.ndss-symposium.org/ndss-paper/airsnitch-demystifying-and-breaking-client-isolation-in-wi-fi-networks/" target="_blank" rel="noreferrer noopener">https://www.ndss-symposium.org/ndss-paper/airsnitch-demystifying-and-breaking-client-isolation-in-wi-fi-networks/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9828.mp3</guid><pubDate>Fri, 27 Feb 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70313151/9828.mp3" length="7869025" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9828" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Finding Signal in the Noise: Lessons Learned Running a Honeypot with AI Assistance [Guest Diary]...</itunes:subtitle><itunes:summary><![CDATA[<br /> Finding Signal in the Noise: Lessons Learned Running a Honeypot with AI Assistance [Guest Diary]<br /><a href="https://isc.sans.edu/diary/Finding%20Signal%20in%20the%20Noise%3A%20Lessons%20Learned%20Running%20a%20Honeypot%20with%20AI%20Assistance%20%5BGuest%20Diary%5D/32744" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Finding%20Signal%20in%20the%20Noise%3A%20Lessons%20Learned%20Running%20a%20Honeypot%20with%20AI%20Assistance%20%5BGuest%20Diary%5D/32744</a><br /> Google API Keys Weren't Secrets. But then Gemini Changed the Rules.<br /><a href="https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules" target="_blank" rel="noreferrer noopener">https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules</a><br /> AirSnitch: Demystifying and Breaking Client Isolation in Wi-Fi Networks<br /><a href="https://www.ndss-symposium.org/ndss-paper/airsnitch-demystifying-and-breaking-client-isolation-in-wi-fi-networks/" target="_blank" rel="noreferrer noopener">https://www.ndss-symposium.org/ndss-paper/airsnitch-demystifying-and-breaking-client-isolation-in-wi-fi-networks/</a><br />]]></itunes:summary><itunes:duration>562</itunes:duration><itunes:keywords>airsnitch,api,business,computer,cyber,cybersecurity,daily,gemini,google,hacking,honeypot,infosec,it,maps,network,news,noise,sans.edu,security,wifi</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9828</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, February 26th, 2026: CLAIR Model; Cisco SD-WAN 0-Day; Cortex XDR Abuse; OpenSSL Vuln;</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-february-26th-2026-clair-model-cisco-sd-wan-0-day-cortex-xdr-abuse-openssl-vuln--70289317</link><description><![CDATA[<br /> The CLAIR Model: A Synthesized Conceptual Framework for Mapping Critical Infrastructure Interdependencies [Guest Diary]<br /><a href="https://isc.sans.edu/diary/The+CLAIR+Model+A+Synthesized+Conceptual+Framework+for+Mapping+Critical+Infrastructure+Interdependencies+Guest+Diary/32748" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The+CLAIR+Model+A+Synthesized+Conceptual+Framework+for+Mapping+Critical+Infrastructure+Interdependencies+Guest+Diary/32748</a><br /> Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability CVE-2026-20127<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk</a> <a href="https://blog.talosintelligence.com/uat-8616-sd-wan/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/uat-8616-sd-wan/</a><br /> Abusing Cortex XDR Live<br /><a href="https://labs.infoguard.ch/posts/abusing_cortex_xdr_live_response_as_c2/" target="_blank" rel="noreferrer noopener">https://labs.infoguard.ch/posts/abusing_cortex_xdr_live_response_as_c2/</a><br /> OpenSSL Vulnerability CVE-2025-15467<br /><a href="https://seclists.org/oss-sec/2026/q1/220" target="_blank" rel="noreferrer noopener">https://seclists.org/oss-sec/2026/q1/220</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9826.mp3</guid><pubDate>Thu, 26 Feb 2026 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70289317/9826.mp3" length="5712396" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9826" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 The CLAIR Model: A Synthesized Conceptual Framework for Mapping Critical Infrastructure Interdependencies [Guest Diary]...</itunes:subtitle><itunes:summary><![CDATA[<br /> The CLAIR Model: A Synthesized Conceptual Framework for Mapping Critical Infrastructure Interdependencies [Guest Diary]<br /><a href="https://isc.sans.edu/diary/The+CLAIR+Model+A+Synthesized+Conceptual+Framework+for+Mapping+Critical+Infrastructure+Interdependencies+Guest+Diary/32748" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The+CLAIR+Model+A+Synthesized+Conceptual+Framework+for+Mapping+Critical+Infrastructure+Interdependencies+Guest+Diary/32748</a><br /> Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability CVE-2026-20127<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk</a> <a href="https://blog.talosintelligence.com/uat-8616-sd-wan/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/uat-8616-sd-wan/</a><br /> Abusing Cortex XDR Live<br /><a href="https://labs.infoguard.ch/posts/abusing_cortex_xdr_live_response_as_c2/" target="_blank" rel="noreferrer noopener">https://labs.infoguard.ch/posts/abusing_cortex_xdr_live_response_as_c2/</a><br /> OpenSSL Vulnerability CVE-2025-15467<br /><a href="https://seclists.org/oss-sec/2026/q1/220" target="_blank" rel="noreferrer noopener">https://seclists.org/oss-sec/2026/q1/220</a><br />]]></itunes:summary><itunes:duration>408</itunes:duration><itunes:keywords>business,catalyst,cisco,clair,computer,cortex,cyber,cybersecurity,daily,hacking,ics,infosec,internet,it,network,news,openssl,sd-wan,security,xdr</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9826</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, February 25th, 2026: Open Redirects; setHTML in Firefox; telnetd issues</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-february-25th-2026-open-redirects-sethtml-in-firefox-telnetd-issues--70260245</link><description><![CDATA[<br /> Open Redirects: A Forgotten Vulnerability?<br /><a href="https://isc.sans.edu/diary/Open%20Redirects%3A%20A%20Forgotten%20Vulnerability%3F/32742" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Open%20Redirects%3A%20A%20Forgotten%20Vulnerability%3F/32742</a><br /> Goodbye innerHTML, Hello setHTML: Stronger XSS Protection in Firefox 148<br /><a href="https://hacks.mozilla.org/2026/02/goodbye-innerhtml-hello-sethtml-stronger-xss-protection-in-firefox-148/" target="_blank" rel="noreferrer noopener">https://hacks.mozilla.org/2026/02/goodbye-innerhtml-hello-sethtml-stronger-xss-protection-in-firefox-148/</a><br /> More telnetd issues<br /><a href="https://seclists.org/oss-sec/2026/q1/199" target="_blank" rel="noreferrer noopener">https://seclists.org/oss-sec/2026/q1/199</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9824.mp3</guid><pubDate>Wed, 25 Feb 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70260245/9824.mp3" length="6289170" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9824" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Open Redirects: A Forgotten Vulnerability?
https://isc.sans.edu/diary/Open%20Redirects%3A%20A%20Forgotten%20Vulnerability%3F/32742
 Goodbye innerHTML, Hello setHTML: Stronger XSS Protection in Firefox 148...</itunes:subtitle><itunes:summary><![CDATA[<br /> Open Redirects: A Forgotten Vulnerability?<br /><a href="https://isc.sans.edu/diary/Open%20Redirects%3A%20A%20Forgotten%20Vulnerability%3F/32742" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Open%20Redirects%3A%20A%20Forgotten%20Vulnerability%3F/32742</a><br /> Goodbye innerHTML, Hello setHTML: Stronger XSS Protection in Firefox 148<br /><a href="https://hacks.mozilla.org/2026/02/goodbye-innerhtml-hello-sethtml-stronger-xss-protection-in-firefox-148/" target="_blank" rel="noreferrer noopener">https://hacks.mozilla.org/2026/02/goodbye-innerhtml-hello-sethtml-stronger-xss-protection-in-firefox-148/</a><br /> More telnetd issues<br /><a href="https://seclists.org/oss-sec/2026/q1/199" target="_blank" rel="noreferrer noopener">https://seclists.org/oss-sec/2026/q1/199</a><br />]]></itunes:summary><itunes:duration>449</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,innerhtml,internet,it,network,news,redirects,security,sethtml,telnet,xss</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9824</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, February 24th, 2026: Malicious JPEG Analysis; Calibre Vuln; jsPDF object injection; Roundcube Exploited</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-february-24th-2026-malicious-jpeg-analysis-calibre-vuln-jspdf-object-injection-roundcube-exploited--70243591</link><description><![CDATA[<br /> Another day, another malicious JPEG<br /><a href="https://isc.sans.edu/diary/Another%20day%2C%20another%20malicious%20JPEG/32738" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Another%20day%2C%20another%20malicious%20JPEG/32738</a><br /> Calibre Path Traversal Leading to Arbitrary File Write and Potentially Code Execution CVE-2026-26064 CVE-2026-26065 <br /><a href="https://github.com/kovidgoyal/calibre/security/advisories/GHSA-72ch-3hqc-pgmp" target="_blank" rel="noreferrer noopener">https://github.com/kovidgoyal/calibre/security/advisories/GHSA-72ch-3hqc-pgmp</a><br /><a href="https://github.com/kovidgoyal/calibre/security/advisories/GHSA-vmfh-7mr7-pp2w" target="_blank" rel="noreferrer noopener">https://github.com/kovidgoyal/calibre/security/advisories/GHSA-vmfh-7mr7-pp2w</a><br /> CVE-2026-25755: PDF Object Injection in jsPDF (addJS Method)<br /><a href="https://github.com/ZeroXJacks/CVEs/blob/main/2026/CVE-2026-25755.md" target="_blank" rel="noreferrer noopener">https://github.com/ZeroXJacks/CVEs/blob/main/2026/CVE-2026-25755.md</a><br /> Roundcube Webmail Exploited  CVE-2025-49113 <a href="https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10" target="_blank" rel="noreferrer noopener">https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10</a><br /><a href="https://www.openwall.com/lists/oss-security/2025/06/02/3" target="_blank" rel="noreferrer noopener">https://www.openwall.com/lists/oss-security/2025/06/02/3</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9822.mp3</guid><pubDate>Tue, 24 Feb 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70243591/9822.mp3" length="5945082" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9822" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Another day, another malicious JPEG
https://isc.sans.edu/diary/Another%20day%2C%20another%20malicious%20JPEG/32738
 Calibre Path Traversal Leading to Arbitrary File Write and Potentially Code Execution CVE-2026-26064 CVE-2026-26065...</itunes:subtitle><itunes:summary><![CDATA[<br /> Another day, another malicious JPEG<br /><a href="https://isc.sans.edu/diary/Another%20day%2C%20another%20malicious%20JPEG/32738" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Another%20day%2C%20another%20malicious%20JPEG/32738</a><br /> Calibre Path Traversal Leading to Arbitrary File Write and Potentially Code Execution CVE-2026-26064 CVE-2026-26065 <br /><a href="https://github.com/kovidgoyal/calibre/security/advisories/GHSA-72ch-3hqc-pgmp" target="_blank" rel="noreferrer noopener">https://github.com/kovidgoyal/calibre/security/advisories/GHSA-72ch-3hqc-pgmp</a><br /><a href="https://github.com/kovidgoyal/calibre/security/advisories/GHSA-vmfh-7mr7-pp2w" target="_blank" rel="noreferrer noopener">https://github.com/kovidgoyal/calibre/security/advisories/GHSA-vmfh-7mr7-pp2w</a><br /> CVE-2026-25755: PDF Object Injection in jsPDF (addJS Method)<br /><a href="https://github.com/ZeroXJacks/CVEs/blob/main/2026/CVE-2026-25755.md" target="_blank" rel="noreferrer noopener">https://github.com/ZeroXJacks/CVEs/blob/main/2026/CVE-2026-25755.md</a><br /> Roundcube Webmail Exploited  CVE-2025-49113 <a href="https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10" target="_blank" rel="noreferrer noopener">https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10</a><br /><a href="https://www.openwall.com/lists/oss-security/2025/06/02/3" target="_blank" rel="noreferrer noopener">https://www.openwall.com/lists/oss-security/2025/06/02/3</a><br />]]></itunes:summary><itunes:duration>425</itunes:duration><itunes:keywords>business,calibre,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,jpeg,jspdf,network,news,roundcube,security,webmail</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9822</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, February 23rd, 2026: Japanese Phishing; AI Agents Ignoring Instructions; Starkiller MFA Phishing</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-february-23rd-2026-japanese-phishing-ai-agents-ignoring-instructions-starkiller-mfa-phishing--70219574</link><description><![CDATA[<br /> Japanese-Language Phishing Emails<br /><a href="https://isc.sans.edu/diary/Japanese-Language%20Phishing%20Emails/32734" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Japanese-Language%20Phishing%20Emails/32734</a><br /> 'God-Like' Attack Machines: AI Agents Ignore Security Policies<br /><a href="https://www.darkreading.com/application-security/ai-agents-ignore-security-policies" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/application-security/ai-agents-ignore-security-policies</a><br /> Starkiller: New Phishing Framework Proxies Real Login Pages to Bypass MFA<br /><a href="https://abnormal.ai/blog/starkiller-phishing-kit" target="_blank" rel="noreferrer noopener">https://abnormal.ai/blog/starkiller-phishing-kit</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9820.mp3</guid><pubDate>Mon, 23 Feb 2026 02:45:11 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70219574/9820.mp3" length="5509740" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9820" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Japanese-Language Phishing Emails
https://isc.sans.edu/diary/Japanese-Language%20Phishing%20Emails/32734
 'God-Like' Attack Machines: AI Agents Ignore Security Policies...</itunes:subtitle><itunes:summary><![CDATA[<br /> Japanese-Language Phishing Emails<br /><a href="https://isc.sans.edu/diary/Japanese-Language%20Phishing%20Emails/32734" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Japanese-Language%20Phishing%20Emails/32734</a><br /> 'God-Like' Attack Machines: AI Agents Ignore Security Policies<br /><a href="https://www.darkreading.com/application-security/ai-agents-ignore-security-policies" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/application-security/ai-agents-ignore-security-policies</a><br /> Starkiller: New Phishing Framework Proxies Real Login Pages to Bypass MFA<br /><a href="https://abnormal.ai/blog/starkiller-phishing-kit" target="_blank" rel="noreferrer noopener">https://abnormal.ai/blog/starkiller-phishing-kit</a><br />]]></itunes:summary><itunes:duration>394</itunes:duration><itunes:keywords>agents,ai,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,japanese,mfa,mitm,network,news,phishing,security,starkiller</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9820</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, February 20th, 2026: DynoWiper Analysis; Vibe Passwords; IDE Extension Vulns; Gransstream GXP 1600 Vuln and PoC</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-february-20th-2026-dynowiper-analysis-vibe-passwords-ide-extension-vulns-gransstream-gxp-1600-vuln-and-poc--70168965</link><description><![CDATA[<br /> Under the Hood of DynoWiper<br /><a href="https://isc.sans.edu/diary/Under%20the%20Hood%20of%20DynoWiper/32730" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Under%20the%20Hood%20of%20DynoWiper/32730</a><br /> Vibe Password Generation: Predictable by Design<br /><a href="https://www.irregular.com/publications/vibe-password-generation" target="_blank" rel="noreferrer noopener">https://www.irregular.com/publications/vibe-password-generation</a><br /> Vulnerabilities (CVE-2025-65715, CVE-2025-65716, CVE-2025-65717) in four popular IDE Extensions<br /><a href="https://www.ox.security/blog/four-vulnerabilities-expose-a-massive-security-blind-spot-in-ide-extensions/" target="_blank" rel="noreferrer noopener">https://www.ox.security/blog/four-vulnerabilities-expose-a-massive-security-blind-spot-in-ide-extensions/</a><br /> Grandstream GXP1600 VoIP Phones<br /><a href="https://www.rapid7.com/blog/post/ve-cve-2026-2329-critical-unauthenticated-stack-buffer-overflow-in-grandstream-gxp1600-voip-phones-fixed/" target="_blank" rel="noreferrer noopener">https://www.rapid7.com/blog/post/ve-cve-2026-2329-critical-unauthenticated-stack-buffer-overflow-in-grandstream-gxp1600-voip-phones-fixed/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9818.mp3</guid><pubDate>Fri, 20 Feb 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70168965/9818.mp3" length="5317253" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9818" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Under the Hood of DynoWiper
https://isc.sans.edu/diary/Under%20the%20Hood%20of%20DynoWiper/32730
 Vibe Password Generation: Predictable by Design
https://www.irregular.com/publications/vibe-password-generation
 Vulnerabilities (CVE-2025-65715,...</itunes:subtitle><itunes:summary><![CDATA[<br /> Under the Hood of DynoWiper<br /><a href="https://isc.sans.edu/diary/Under%20the%20Hood%20of%20DynoWiper/32730" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Under%20the%20Hood%20of%20DynoWiper/32730</a><br /> Vibe Password Generation: Predictable by Design<br /><a href="https://www.irregular.com/publications/vibe-password-generation" target="_blank" rel="noreferrer noopener">https://www.irregular.com/publications/vibe-password-generation</a><br /> Vulnerabilities (CVE-2025-65715, CVE-2025-65716, CVE-2025-65717) in four popular IDE Extensions<br /><a href="https://www.ox.security/blog/four-vulnerabilities-expose-a-massive-security-blind-spot-in-ide-extensions/" target="_blank" rel="noreferrer noopener">https://www.ox.security/blog/four-vulnerabilities-expose-a-massive-security-blind-spot-in-ide-extensions/</a><br /> Grandstream GXP1600 VoIP Phones<br /><a href="https://www.rapid7.com/blog/post/ve-cve-2026-2329-critical-unauthenticated-stack-buffer-overflow-in-grandstream-gxp1600-voip-phones-fixed/" target="_blank" rel="noreferrer noopener">https://www.rapid7.com/blog/post/ve-cve-2026-2329-critical-unauthenticated-stack-buffer-overflow-in-grandstream-gxp1600-voip-phones-fixed/</a><br />]]></itunes:summary><itunes:duration>380</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dynowiper,extensions,grandstream,gxp1600,hacking,infosec,internet,it,network,news,password,security,vibe,vs code</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9818</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, February 19th, 2026: Malware Image Resuse; Dell RecoveryPoint; Admin Center Vuln; DNS-PERSIST-01</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-february-19th-2026-malware-image-resuse-dell-recoverypoint-admin-center-vuln-dns-persist-01--70140916</link><description><![CDATA[<br /> Tracking Malware Campaigns With Reused Material<br /><a href="https://isc.sans.edu/diary/Tracking%20Malware%20Campaigns%20With%20Reused%20Material/32726" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Tracking%20Malware%20Campaigns%20With%20Reused%20Material/32726</a><br /> From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day</a><br /> Windows Admin Center Elevation of Privilege Vulnerability CVE-2026-26119<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26119" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26119</a><br />  DNS-PERSIST-01: A New Model for DNS-based Challenge Validation<br /><a href="https://letsencrypt.org/2026/02/18/dns-persist-01.html" target="_blank" rel="noreferrer noopener">https://letsencrypt.org/2026/02/18/dns-persist-01.html</a><br /> Defending Web Apps<br /><a href="https://www.sans.org/cyber-security-courses/application-security-securing-web-apps-api-microservices" target="_blank" rel="noreferrer noopener">https://www.sans.org/cyber-security-courses/application-security-securing-web-apps-api-microservices</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9816.mp3</guid><pubDate>Thu, 19 Feb 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70140916/9816.mp3" length="5944993" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9816" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Tracking Malware Campaigns With Reused Material
https://isc.sans.edu/diary/Tracking%20Malware%20Campaigns%20With%20Reused%20Material/32726
 From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day...</itunes:subtitle><itunes:summary><![CDATA[<br /> Tracking Malware Campaigns With Reused Material<br /><a href="https://isc.sans.edu/diary/Tracking%20Malware%20Campaigns%20With%20Reused%20Material/32726" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Tracking%20Malware%20Campaigns%20With%20Reused%20Material/32726</a><br /> From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day</a><br /> Windows Admin Center Elevation of Privilege Vulnerability CVE-2026-26119<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26119" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26119</a><br />  DNS-PERSIST-01: A New Model for DNS-based Challenge Validation<br /><a href="https://letsencrypt.org/2026/02/18/dns-persist-01.html" target="_blank" rel="noreferrer noopener">https://letsencrypt.org/2026/02/18/dns-persist-01.html</a><br /> Defending Web Apps<br /><a href="https://www.sans.org/cyber-security-courses/application-security-securing-web-apps-api-microservices" target="_blank" rel="noreferrer noopener">https://www.sans.org/cyber-security-courses/application-security-securing-web-apps-api-microservices</a><br />]]></itunes:summary><itunes:duration>425</itunes:duration><itunes:keywords>admin center,brickstorm,business,computer,cyber,cybersecurity,daily,dell,dns-persist-01,grimpbolt,hacking,infosec,internet,it,malware,network,news,recoverypoint,security,windows</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9816</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, February 18th, 2026: IR Phishing; Neenadu Android Backdoor; NiFi Bugs; LLMs Phishing; Encrypted RCS</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-february-18th-2026-ir-phishing-neenadu-android-backdoor-nifi-bugs-llms-phishing-encrypted-rcs--70125093</link><description><![CDATA[<br /> Fake Incident Report Used in Phishing Campaign<br /><a href="https://isc.sans.edu/diary/Fake%20Incident%20Report%20Used%20in%20Phishing%20Campaign/32722" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Fake%20Incident%20Report%20Used%20in%20Phishing%20Campaign/32722</a><br /> Divide and conquer: how the new Keenadu backdoor exposed links between major Android botnets <a href="https://securelist.com/keenadu-android-backdoor/118913/" target="_blank" rel="noreferrer noopener">https://securelist.com/keenadu-android-backdoor/118913/</a><br /> CVE-2026-25903: Apache NiFi: Missing Authorization of Restricted Permissions for Component Updates <a href="https://seclists.org/oss-sec/2026/q1/166" target="_blank" rel="noreferrer noopener">https://seclists.org/oss-sec/2026/q1/166</a><br /> The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time<br /><a href="https://unit42.paloaltonetworks.com/real-time-malicious-javascript-through-llms/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/real-time-malicious-javascript-through-llms/</a> <br /> Encrypted RCS in iOS/iPadOS<br /><a href="https://developer.apple.com/documentation/ios-ipados-release-notes/ios-ipados-26_4-release-notes" target="_blank" rel="noreferrer noopener">https://developer.apple.com/documentation/ios-ipados-release-notes/ios-ipados-26_4-release-notes</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9814.mp3</guid><pubDate>Wed, 18 Feb 2026 02:15:12 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70125093/9814.mp3" length="6304792" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9814" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Fake Incident Report Used in Phishing Campaign
https://isc.sans.edu/diary/Fake%20Incident%20Report%20Used%20in%20Phishing%20Campaign/32722
 Divide and conquer: how the new Keenadu backdoor exposed links between major Android botnets...</itunes:subtitle><itunes:summary><![CDATA[<br /> Fake Incident Report Used in Phishing Campaign<br /><a href="https://isc.sans.edu/diary/Fake%20Incident%20Report%20Used%20in%20Phishing%20Campaign/32722" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Fake%20Incident%20Report%20Used%20in%20Phishing%20Campaign/32722</a><br /> Divide and conquer: how the new Keenadu backdoor exposed links between major Android botnets <a href="https://securelist.com/keenadu-android-backdoor/118913/" target="_blank" rel="noreferrer noopener">https://securelist.com/keenadu-android-backdoor/118913/</a><br /> CVE-2026-25903: Apache NiFi: Missing Authorization of Restricted Permissions for Component Updates <a href="https://seclists.org/oss-sec/2026/q1/166" target="_blank" rel="noreferrer noopener">https://seclists.org/oss-sec/2026/q1/166</a><br /> The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time<br /><a href="https://unit42.paloaltonetworks.com/real-time-malicious-javascript-through-llms/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/real-time-malicious-javascript-through-llms/</a> <br /> Encrypted RCS in iOS/iPadOS<br /><a href="https://developer.apple.com/documentation/ios-ipados-release-notes/ios-ipados-26_4-release-notes" target="_blank" rel="noreferrer noopener">https://developer.apple.com/documentation/ios-ipados-release-notes/ios-ipados-26_4-release-notes</a><br />]]></itunes:summary><itunes:duration>450</itunes:duration><itunes:keywords>android,apple,backdoor,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,nifi,phishing,rcs,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9814</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, February 17th, 2026: 64Bit Malware; Password Manager Weaknesses; OpenClaw Config Theft;</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-february-17th-2026-64bit-malware-password-manager-weaknesses-openclaw-config-theft--70090550</link><description><![CDATA[<br /> 2026 64-Bits Malware Trend<br /><a href="https://isc.sans.edu/diary/2026%2064-Bits%20Malware%20Trend/32718" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/2026%2064-Bits%20Malware%20Trend/32718</a><br /> A Comparative Security Analysis of Three Cloud-based Password Managers<br /><a href="https://zkae.io" target="_blank" rel="noreferrer noopener">https://zkae.io</a><br /> Infostealer Infection Targeting OpenClaw Configurations<br /><a href="https://www.infostealers.com/article/hudson-rock-identifies-real-world-infostealer-infection-targeting-openclaw-configurations/" target="_blank" rel="noreferrer noopener">https://www.infostealers.com/article/hudson-rock-identifies-real-world-infostealer-infection-targeting-openclaw-configurations/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9812.mp3</guid><pubDate>Tue, 17 Feb 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70090550/9812.mp3" length="4371878" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9812" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 2026 64-Bits Malware Trend
https://isc.sans.edu/diary/2026%2064-Bits%20Malware%20Trend/32718
 A Comparative Security Analysis of Three Cloud-based Password Managers
https://zkae.io
 Infostealer Infection Targeting OpenClaw Configurations...</itunes:subtitle><itunes:summary><![CDATA[<br /> 2026 64-Bits Malware Trend<br /><a href="https://isc.sans.edu/diary/2026%2064-Bits%20Malware%20Trend/32718" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/2026%2064-Bits%20Malware%20Trend/32718</a><br /> A Comparative Security Analysis of Three Cloud-based Password Managers<br /><a href="https://zkae.io" target="_blank" rel="noreferrer noopener">https://zkae.io</a><br /> Infostealer Infection Targeting OpenClaw Configurations<br /><a href="https://www.infostealers.com/article/hudson-rock-identifies-real-world-infostealer-infection-targeting-openclaw-configurations/" target="_blank" rel="noreferrer noopener">https://www.infostealers.com/article/hudson-rock-identifies-real-world-infostealer-infection-targeting-openclaw-configurations/</a><br />]]></itunes:summary><itunes:duration>312</itunes:duration><itunes:keywords>64 bit,business,computer,cyber,cybersecurity,daily,hacking,infosec,infostealer,internet,it,malware,managers,network,news,openclaw,password,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9812</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, February 16th, 2026: Graph Generator; nslookup and clickfix; Chrome 0-Day; TURN Threats</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-february-16th-2026-graph-generator-nslookup-and-clickfix-chrome-0-day-turn-threats--70074924</link><description><![CDATA[<br /> AI-Powered Knowledge Graph Generator &amp; APTs<br /><a href="https://isc.sans.edu/diary/AI-Powered%20Knowledge%20Graph%20Generator%20%26%20APTs/32712" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/AI-Powered%20Knowledge%20Graph%20Generator%20%26%20APTs/32712</a><br /> nslookup and ClickFix<br /><a href="https://x.com/MsftSecIntel/status/2022456612120629742" target="_blank" rel="noreferrer noopener">https://x.com/MsftSecIntel/status/2022456612120629742</a><br /> Google Chrome 0-Day Patch<br /><a href="https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_13.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_13.html</a><br /> TURN Security Threats<br /><a href="https://www.enablesecurity.com/blog/turn-server-security-threats/" target="_blank" rel="noreferrer noopener">https://www.enablesecurity.com/blog/turn-server-security-threats/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9810.mp3</guid><pubDate>Mon, 16 Feb 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70074924/9810.mp3" length="5041625" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9810" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 AI-Powered Knowledge Graph Generator &amp;amp; APTs
https://isc.sans.edu/diary/AI-Powered%20Knowledge%20Graph%20Generator%20%26%20APTs/32712
 nslookup and ClickFix
https://x.com/MsftSecIntel/status/2022456612120629742
 Google Chrome 0-Day Patch...</itunes:subtitle><itunes:summary><![CDATA[<br /> AI-Powered Knowledge Graph Generator &amp; APTs<br /><a href="https://isc.sans.edu/diary/AI-Powered%20Knowledge%20Graph%20Generator%20%26%20APTs/32712" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/AI-Powered%20Knowledge%20Graph%20Generator%20%26%20APTs/32712</a><br /> nslookup and ClickFix<br /><a href="https://x.com/MsftSecIntel/status/2022456612120629742" target="_blank" rel="noreferrer noopener">https://x.com/MsftSecIntel/status/2022456612120629742</a><br /> Google Chrome 0-Day Patch<br /><a href="https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_13.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_13.html</a><br /> TURN Security Threats<br /><a href="https://www.enablesecurity.com/blog/turn-server-security-threats/" target="_blank" rel="noreferrer noopener">https://www.enablesecurity.com/blog/turn-server-security-threats/</a><br />]]></itunes:summary><itunes:duration>360</itunes:duration><itunes:keywords>ai,business,chrome,clickfix,computer,cyber,cybersecurity,daily,graph,hacking,infosec,internet,it,network,news,nslookup,security,turn</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9810</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, February 13th, 2026: SSH Bot; OpenSSH MacOS Change; Abused Employee Monitoring</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-february-13th-2026-ssh-bot-openssh-macos-change-abused-employee-monitoring--70030563</link><description><![CDATA[<br /> Four Seconds to Botnet - Analyzing a Self-Propagating SSH Worm with Cryptographically Signed C2 [Guest Diary]<br /><a href="https://isc.sans.edu/diary/Four%20Seconds%20to%20Botnet%20-%20Analyzing%20a%20Self%20Propagating%20SSH%20Worm%20with%20Cryptographically%20Signed%20C2%20%5BGuest%20Diary%5D/32708" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Four%20Seconds%20to%20Botnet%20-%20Analyzing%20a%20Self%20Propagating%20SSH%20Worm%20with%20Cryptographically%20Signed%20C2%20%5BGuest%20Diary%5D/32708</a><br /> OpenSSH Update on MacOS<br /><a href="https://www.openssh.org/releasenotes.html" target="_blank" rel="noreferrer noopener">https://www.openssh.org/releasenotes.html</a><br /> Employee Monitoring and SimpleHelp Software Abused in Ransomware Operations<br /><a href="https://www.huntress.com/blog/employee-monitoring-simplehelp-abused-in-ransomware-operations" target="_blank" rel="noreferrer noopener">https://www.huntress.com/blog/employee-monitoring-simplehelp-abused-in-ransomware-operations</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9808.mp3</guid><pubDate>Fri, 13 Feb 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70030563/9808.mp3" length="4802804" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9808" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Four Seconds to Botnet - Analyzing a Self-Propagating SSH Worm with Cryptographically Signed C2 [Guest Diary]...</itunes:subtitle><itunes:summary><![CDATA[<br /> Four Seconds to Botnet - Analyzing a Self-Propagating SSH Worm with Cryptographically Signed C2 [Guest Diary]<br /><a href="https://isc.sans.edu/diary/Four%20Seconds%20to%20Botnet%20-%20Analyzing%20a%20Self%20Propagating%20SSH%20Worm%20with%20Cryptographically%20Signed%20C2%20%5BGuest%20Diary%5D/32708" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Four%20Seconds%20to%20Botnet%20-%20Analyzing%20a%20Self%20Propagating%20SSH%20Worm%20with%20Cryptographically%20Signed%20C2%20%5BGuest%20Diary%5D/32708</a><br /> OpenSSH Update on MacOS<br /><a href="https://www.openssh.org/releasenotes.html" target="_blank" rel="noreferrer noopener">https://www.openssh.org/releasenotes.html</a><br /> Employee Monitoring and SimpleHelp Software Abused in Ransomware Operations<br /><a href="https://www.huntress.com/blog/employee-monitoring-simplehelp-abused-in-ransomware-operations" target="_blank" rel="noreferrer noopener">https://www.huntress.com/blog/employee-monitoring-simplehelp-abused-in-ransomware-operations</a><br />]]></itunes:summary><itunes:duration>343</itunes:duration><itunes:keywords>botnet,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,macos,monitoring,network,news,openssh,security,ssh</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9808</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, February 12th, 2026: WSL in Malware; Apple and Adobe Patches</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-february-12th-2026-wsl-in-malware-apple-and-adobe-patches--70000954</link><description><![CDATA[<br /> WSL in the Malware Ecosystem <a href="https://isc.sans.edu/diary/32704" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/32704</a><br /> Apple Patches Everything: February 2026<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20February%202026/32706" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20February%202026/32706</a> <br /> Adobe Updates<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9806.mp3</guid><pubDate>Thu, 12 Feb 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70000954/9806.mp3" length="5162142" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9806" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 WSL in the Malware Ecosystem https://isc.sans.edu/diary/32704
 Apple Patches Everything: February 2026
https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20February%202026/32706 
 Adobe Updates...</itunes:subtitle><itunes:summary><![CDATA[<br /> WSL in the Malware Ecosystem <a href="https://isc.sans.edu/diary/32704" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/32704</a><br /> Apple Patches Everything: February 2026<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20February%202026/32706" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20February%202026/32706</a> <br /> Adobe Updates<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br />]]></itunes:summary><itunes:duration>369</itunes:duration><itunes:keywords>adobe,apple,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,malware,network,news,security,wsl</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9806</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, February 11th, 2026: Microsoft Patch Tuesday; Secure Boot Updates; Fake 7-Zip; FortiSlob</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-february-11th-2026-microsoft-patch-tuesday-secure-boot-updates-fake-7-zip-fortislob--69966322</link><description><![CDATA[<br /> Microsoft Patch Tuesday - February 2026<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20February%202026/32700" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20February%202026/32700</a><br /> Refreshing the root of trust<br /><a href="https://blogs.windows.com/windowsexperience/2026/02/10/refreshing-the-root-of-trust-industry-collaboration-on-secure-boot-certificate-updates/" target="_blank" rel="noreferrer noopener">https://blogs.windows.com/windowsexperience/2026/02/10/refreshing-the-root-of-trust-industry-collaboration-on-secure-boot-certificate-updates/</a><br /> Fake 7-Zip downloads are turning home PCs into proxy nodes<br /><a href="https://www.malwarebytes.com/blog/threat-intel/2026/02/fake-7-zip-downloads-are-turning-home-pcs-into-proxy-nodes" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/threat-intel/2026/02/fake-7-zip-downloads-are-turning-home-pcs-into-proxy-nodes</a><br /> FortiNet Vulnerabilities<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-093" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-25-093</a> <a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-1052" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-25-1052</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9804.mp3</guid><pubDate>Wed, 11 Feb 2026 02:05:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69966322/9804.mp3" length="6644712" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9804" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Microsoft Patch Tuesday - February 2026
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20February%202026/32700
 Refreshing the root of trust...</itunes:subtitle><itunes:summary><![CDATA[<br /> Microsoft Patch Tuesday - February 2026<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20February%202026/32700" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20February%202026/32700</a><br /> Refreshing the root of trust<br /><a href="https://blogs.windows.com/windowsexperience/2026/02/10/refreshing-the-root-of-trust-industry-collaboration-on-secure-boot-certificate-updates/" target="_blank" rel="noreferrer noopener">https://blogs.windows.com/windowsexperience/2026/02/10/refreshing-the-root-of-trust-industry-collaboration-on-secure-boot-certificate-updates/</a><br /> Fake 7-Zip downloads are turning home PCs into proxy nodes<br /><a href="https://www.malwarebytes.com/blog/threat-intel/2026/02/fake-7-zip-downloads-are-turning-home-pcs-into-proxy-nodes" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/threat-intel/2026/02/fake-7-zip-downloads-are-turning-home-pcs-into-proxy-nodes</a><br /> FortiNet Vulnerabilities<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-093" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-25-093</a> <a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-1052" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-25-1052</a><br />]]></itunes:summary><itunes:duration>475</itunes:duration><itunes:keywords>7zip,boot,business,cyber,cybersecurity,daily,fake,fortinet,hacking,infosec,it,microsoft,network,news,patch,root,security,trojan,trust,tuesday</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9804</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, February 10th, 2026: Extracting URLs; Singal Phishing; Ivanti PoC; BeyondTrust RCE; Forticlient SQL Inection</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-february-10th-2026-extracting-urls-singal-phishing-ivanti-poc-beyondtrust-rce-forticlient-sql-inection--69922443</link><description><![CDATA[<br /> Quick Howto: Extract URLs from RTF files<br /><a href="https://isc.sans.edu/diary/Quick%20Howto%3A%20Extract%20URLs%20from%20RTF%20files/32692" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Quick%20Howto%3A%20Extract%20URLs%20from%20RTF%20files/32692</a><br /> German Agencies Warn of Signal Phishing Targeting Politicians, Military, Journalists<br /> German: <a href="https://thehackernews.com/2026/02/german-agencies-warn-of-signal-phishing.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2026/02/german-agencies-warn-of-signal-phishing.html</a> English: <a href="https://www.verfassungsschutz.de/SharedDocs/publikationen/DE/praevention_wirtschafts-und_wissenschaftsschutz/2026-02-06-gemeinsame-warnmitteilung-phishing.pdf?__blob=publicationFile&amp;v=3" target="_blank" rel="noreferrer noopener">https://www.verfassungsschutz.de/SharedDocs/publikationen/DE/praevention_wirtschafts-und_wissenschaftsschutz/2026-02-06-gemeinsame-warnmitteilung-phishing.pdf?__blob=publicationFile&amp;v=3</a><br /> Someone Knows Bash Far Too Well, And We Love It - Pre-Auth RCEs<br /><a href="https://labs.watchtowr.com/someone-knows-bash-far-too-well-and-we-love-it-ivanti-epmm-pre-auth-rces-cve-2026-1281-cve-2026-1340/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/someone-knows-bash-far-too-well-and-we-love-it-ivanti-epmm-pre-auth-rces-cve-2026-1281-cve-2026-1340/</a><br /> Pre-Auth RCE in BeyondTrust Remote Support &amp; PRA CVE-2026-1731<br /><a href="https://www.hacktron.ai/blog/cve-2026-1731-beyondtrust-remote-support-rce" target="_blank" rel="noreferrer noopener">https://www.hacktron.ai/blog/cve-2026-1731-beyondtrust-remote-support-rce</a><br /><a href="https://www.beyondtrust.com/trust-center/security-advisories/bt26-02" target="_blank" rel="noreferrer noopener">https://www.beyondtrust.com/trust-center/security-advisories/bt26-02</a><br /> Fortinet FortiClientEMS SQLi in the administrative interface<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-1142" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-25-1142</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9802.mp3</guid><pubDate>Tue, 10 Feb 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69922443/9802.mp3" length="3786928" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9802" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Quick Howto: Extract URLs from RTF files
https://isc.sans.edu/diary/Quick%20Howto%3A%20Extract%20URLs%20from%20RTF%20files/32692
 German Agencies Warn of Signal Phishing Targeting Politicians, Military, Journalists
 German:...</itunes:subtitle><itunes:summary><![CDATA[<br /> Quick Howto: Extract URLs from RTF files<br /><a href="https://isc.sans.edu/diary/Quick%20Howto%3A%20Extract%20URLs%20from%20RTF%20files/32692" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Quick%20Howto%3A%20Extract%20URLs%20from%20RTF%20files/32692</a><br /> German Agencies Warn of Signal Phishing Targeting Politicians, Military, Journalists<br /> German: <a href="https://thehackernews.com/2026/02/german-agencies-warn-of-signal-phishing.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2026/02/german-agencies-warn-of-signal-phishing.html</a> English: <a href="https://www.verfassungsschutz.de/SharedDocs/publikationen/DE/praevention_wirtschafts-und_wissenschaftsschutz/2026-02-06-gemeinsame-warnmitteilung-phishing.pdf?__blob=publicationFile&amp;v=3" target="_blank" rel="noreferrer noopener">https://www.verfassungsschutz.de/SharedDocs/publikationen/DE/praevention_wirtschafts-und_wissenschaftsschutz/2026-02-06-gemeinsame-warnmitteilung-phishing.pdf?__blob=publicationFile&amp;v=3</a><br /> Someone Knows Bash Far Too Well, And We Love It - Pre-Auth RCEs<br /><a href="https://labs.watchtowr.com/someone-knows-bash-far-too-well-and-we-love-it-ivanti-epmm-pre-auth-rces-cve-2026-1281-cve-2026-1340/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/someone-knows-bash-far-too-well-and-we-love-it-ivanti-epmm-pre-auth-rces-cve-2026-1281-cve-2026-1340/</a><br /> Pre-Auth RCE in BeyondTrust Remote Support &amp; PRA CVE-2026-1731<br /><a href="https://www.hacktron.ai/blog/cve-2026-1731-beyondtrust-remote-support-rce" target="_blank" rel="noreferrer noopener">https://www.hacktron.ai/blog/cve-2026-1731-beyondtrust-remote-support-rce</a><br /><a href="https://www.beyondtrust.com/trust-center/security-advisories/bt26-02" target="_blank" rel="noreferrer noopener">https://www.beyondtrust.com/trust-center/security-advisories/bt26-02</a><br /> Fortinet FortiClientEMS SQLi in the administrative interface<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-1142" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-25-1142</a><br />]]></itunes:summary><itunes:duration>270</itunes:duration><itunes:keywords>beyondtrust,business,computer,cyber,cybersecurity,daily,fortinet,hacking,infosec,internet,it,ivanti,network,news,phishing,rtf,security,signal,urls</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9802</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, February 9th, 2026: Azure Vulnerabilties; AI Vulnerability Discovery; GitLab AI Gateway Vuln</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-february-9th-2026-azure-vulnerabilties-ai-vulnerability-discovery-gitlab-ai-gateway-vuln--69885724</link><description><![CDATA[<br /> Microsoft Patches Four Azure Vulnerabilities (three critical)<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability</a><br /> Evaluating and mitigating the growing risk of LLM-discovered 0-days<br /><a href="https://red.anthropic.com/2026/zero-days/" target="_blank" rel="noreferrer noopener">https://red.anthropic.com/2026/zero-days/</a><br /> Gitlab AI Gateway Vulnerability CVE-2026-1868<br /><a href="https://about.gitlab.com/releases/2026/02/06/patch-release-gitlab-ai-gateway-18-8-1-released/" target="_blank" rel="noreferrer noopener">https://about.gitlab.com/releases/2026/02/06/patch-release-gitlab-ai-gateway-18-8-1-released/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9800.mp3</guid><pubDate>Mon, 09 Feb 2026 11:47:32 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69885724/9800.mp3" length="4527773" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9800" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Microsoft Patches Four Azure Vulnerabilities (three critical)
https://msrc.microsoft.com/update-guide/vulnerability
 Evaluating and mitigating the growing risk of LLM-discovered 0-days
https://red.anthropic.com/2026/zero-days/
 Gitlab AI Gateway...</itunes:subtitle><itunes:summary><![CDATA[<br /> Microsoft Patches Four Azure Vulnerabilities (three critical)<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability</a><br /> Evaluating and mitigating the growing risk of LLM-discovered 0-days<br /><a href="https://red.anthropic.com/2026/zero-days/" target="_blank" rel="noreferrer noopener">https://red.anthropic.com/2026/zero-days/</a><br /> Gitlab AI Gateway Vulnerability CVE-2026-1868<br /><a href="https://about.gitlab.com/releases/2026/02/06/patch-release-gitlab-ai-gateway-18-8-1-released/" target="_blank" rel="noreferrer noopener">https://about.gitlab.com/releases/2026/02/06/patch-release-gitlab-ai-gateway-18-8-1-released/</a><br />]]></itunes:summary><itunes:duration>324</itunes:duration><itunes:keywords>0-days,ai gateway,anthropic,azure,business,claude,computer,cyber,cybersecurity,daily,gitlab,hacking,infosec,it,llm,microsoft,network,news,opus,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9800</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, February 6th, 2026: Broken Phishing; n8n vulnerability; Android Update; Watchguard Firebox LDAP Injection</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-february-6th-2026-broken-phishing-n8n-vulnerability-android-update-watchguard-firebox-ldap-injection--69831420</link><description><![CDATA[<br /> Broken Phishing URLs<br /><a href="https://isc.sans.edu/diary/Broken+Phishing+URLs/32686/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Broken+Phishing+URLs/32686/</a><br /> n8n command injection vulnerability<br /><a href="https://github.com/n8n-io/n8n/security/advisories/GHSA-6cqr-8cfr-67f8" target="_blank" rel="noreferrer noopener">https://github.com/n8n-io/n8n/security/advisories/GHSA-6cqr-8cfr-67f8</a><br /> Android February Update<br /><a href="https://source.android.com/docs/security/bulletin/pixel/2026/2026-02-01?hl=en" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/pixel/2026/2026-02-01?hl=en</a><br /> Watchguard Firebox LDAP Injection<br /><a href="https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00001" target="_blank" rel="noreferrer noopener">https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00001</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9798.mp3</guid><pubDate>Fri, 06 Feb 2026 02:05:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69831420/9798.mp3" length="3955864" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9798" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Broken Phishing URLs
https://isc.sans.edu/diary/Broken+Phishing+URLs/32686/
 n8n command injection vulnerability
https://github.com/n8n-io/n8n/security/advisories/GHSA-6cqr-8cfr-67f8
 Android February Update...</itunes:subtitle><itunes:summary><![CDATA[<br /> Broken Phishing URLs<br /><a href="https://isc.sans.edu/diary/Broken+Phishing+URLs/32686/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Broken+Phishing+URLs/32686/</a><br /> n8n command injection vulnerability<br /><a href="https://github.com/n8n-io/n8n/security/advisories/GHSA-6cqr-8cfr-67f8" target="_blank" rel="noreferrer noopener">https://github.com/n8n-io/n8n/security/advisories/GHSA-6cqr-8cfr-67f8</a><br /> Android February Update<br /><a href="https://source.android.com/docs/security/bulletin/pixel/2026/2026-02-01?hl=en" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/pixel/2026/2026-02-01?hl=en</a><br /> Watchguard Firebox LDAP Injection<br /><a href="https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00001" target="_blank" rel="noreferrer noopener">https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00001</a><br />]]></itunes:summary><itunes:duration>283</itunes:duration><itunes:keywords>android,business,computer,cyber,cybersecurity,daily,firebox,hacking,infosec,internet,it,ldap,n8n,network,news,phishing,security,watchguard</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9798</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, February 5th, 2026: Malicious Scripts; Synectix Vuln; Google Chrome; Google Looker;</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-february-5th-2026-malicious-scripts-synectix-vuln-google-chrome-google-looker--69797994</link><description><![CDATA[<br /> Malicious Script Delivering More Maliciousness<br /><a href="https://isc.sans.edu/diary/Malicious+Script+Delivering+More+Maliciousness/32682" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Malicious+Script+Delivering+More+Maliciousness/32682</a><br /> Synectix LAN 232 TRIO Unauthenticated Web Admin CVE-2026-1633<br /><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-034-04" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/ics-advisories/icsa-26-034-04</a><br /> Google Chrome Patches<br /><a href="https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop.html</a><br /> LookOut: Discovering RCE and Internal Access on Looker (Google Cloud &amp; On-Prem)<br /><a href="https://www.tenable.com/blog/google-looker-vulnerabilities-rce-internal-access-lookout" target="_blank" rel="noreferrer noopener">https://www.tenable.com/blog/google-looker-vulnerabilities-rce-internal-access-lookout</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9796.mp3</guid><pubDate>Thu, 05 Feb 2026 02:10:11 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69797994/9796.mp3" length="5285449" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9796" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Malicious Script Delivering More Maliciousness
https://isc.sans.edu/diary/Malicious+Script+Delivering+More+Maliciousness/32682
 Synectix LAN 232 TRIO Unauthenticated Web Admin CVE-2026-1633...</itunes:subtitle><itunes:summary><![CDATA[<br /> Malicious Script Delivering More Maliciousness<br /><a href="https://isc.sans.edu/diary/Malicious+Script+Delivering+More+Maliciousness/32682" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Malicious+Script+Delivering+More+Maliciousness/32682</a><br /> Synectix LAN 232 TRIO Unauthenticated Web Admin CVE-2026-1633<br /><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-034-04" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/ics-advisories/icsa-26-034-04</a><br /> Google Chrome Patches<br /><a href="https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop.html</a><br /> LookOut: Discovering RCE and Internal Access on Looker (Google Cloud &amp; On-Prem)<br /><a href="https://www.tenable.com/blog/google-looker-vulnerabilities-rce-internal-access-lookout" target="_blank" rel="noreferrer noopener">https://www.tenable.com/blog/google-looker-vulnerabilities-rce-internal-access-lookout</a><br />]]></itunes:summary><itunes:duration>378</itunes:duration><itunes:keywords>business,chrome,computer,cyber,cybersecurity,daily,google,hacking,infosec,infostealer,it,looker,lookup,malicious script,network,news,patches,security,synectix,xworm</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9796</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, February 4th, 2026: Detecting OpenClaw; Synology telnetd Patch; More GlassWorm</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-february-4th-2026-detecting-openclaw-synology-telnetd-patch-more-glassworm--69775149</link><description><![CDATA[<br /> Detecting and Monitoring OpenClaw (clawdbot, moltbot)<br /><a href="https://isc.sans.edu/diary.html/Detecting+and+Monitoring+OpenClaw+%28clawdbot%2C+moltbot%29/32678/#comment" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary.html/Detecting+and+Monitoring+OpenClaw+%28clawdbot%2C+moltbot%29/32678/#comment</a><br /> Synology telnetd Patch<br /><a href="https://www.synology.com/en-us/releaseNote/DSM" target="_blank" rel="noreferrer noopener">https://www.synology.com/en-us/releaseNote/DSM</a><br /> GlassWorm Loader Hits Open VSX via Developer Account Compromise<br /><a href="https://socket.dev/blog/glassworm-loader-hits-open-vsx-via-suspected-developer-account-compromise" target="_blank" rel="noreferrer noopener">https://socket.dev/blog/glassworm-loader-hits-open-vsx-via-suspected-developer-account-compromise</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9794.mp3</guid><pubDate>Wed, 04 Feb 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69775149/9794.mp3" length="4144396" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9794" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Detecting and Monitoring OpenClaw (clawdbot, moltbot)
https://isc.sans.edu/diary.html/Detecting+and+Monitoring+OpenClaw+%28clawdbot%2C+moltbot%29/32678/#comment
 Synology telnetd Patch
https://www.synology.com/en-us/releaseNote/DSM
 GlassWorm Loader...</itunes:subtitle><itunes:summary><![CDATA[<br /> Detecting and Monitoring OpenClaw (clawdbot, moltbot)<br /><a href="https://isc.sans.edu/diary.html/Detecting+and+Monitoring+OpenClaw+%28clawdbot%2C+moltbot%29/32678/#comment" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary.html/Detecting+and+Monitoring+OpenClaw+%28clawdbot%2C+moltbot%29/32678/#comment</a><br /> Synology telnetd Patch<br /><a href="https://www.synology.com/en-us/releaseNote/DSM" target="_blank" rel="noreferrer noopener">https://www.synology.com/en-us/releaseNote/DSM</a><br /> GlassWorm Loader Hits Open VSX via Developer Account Compromise<br /><a href="https://socket.dev/blog/glassworm-loader-hits-open-vsx-via-suspected-developer-account-compromise" target="_blank" rel="noreferrer noopener">https://socket.dev/blog/glassworm-loader-hits-open-vsx-via-suspected-developer-account-compromise</a><br />]]></itunes:summary><itunes:duration>296</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,glssworm,hacking,infosec,internet,it,network,news,openclaw,security,synology,telnetd,vsx</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9794</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, February 3rd, 2026: Scanning for AI; Notepad++ Compromise; OpenClaw Vulnerabilities</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-february-3rd-2026-scanning-for-ai-notepad-compromise-openclaw-vulnerabilities--69751366</link><description><![CDATA[<br /> Scanning for exposed Anthropic Models <a href="https://isc.sans.edu/diary/Scanning%20for%20exposed%20Anthropic%20Models/32674" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scanning%20for%20exposed%20Anthropic%20Models/32674</a><br /> Notepad++ Hijacked by State-Sponsored Hackers <a href="https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/" target="_blank" rel="noreferrer noopener">https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/</a><br /><a href="https://notepad-plus-plus.org/news/hijacked-incident-info-update/" target="_blank" rel="noreferrer noopener">https://notepad-plus-plus.org/news/hijacked-incident-info-update/</a><br /> Insecure Websockets in OpenClaw<br /><a href="https://zeropath.com/blog/openclaw-clawdbot-credential-theft-vulnerability" target="_blank" rel="noreferrer noopener">https://zeropath.com/blog/openclaw-clawdbot-credential-theft-vulnerability</a><br /> Malicious OpenClaw Skills<br /><a href="https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting" target="_blank" rel="noreferrer noopener">https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting</a><br /> Exposed OpenClaw Instances<br /><a href="https://censys.com/blog/openclaw-in-the-wild-mapping-the-public-exposure-of-a-viral-ai-assistant" target="_blank" rel="noreferrer noopener">https://censys.com/blog/openclaw-in-the-wild-mapping-the-public-exposure-of-a-viral-ai-assistant</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9792.mp3</guid><pubDate>Tue, 03 Feb 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69751366/9792.mp3" length="5392240" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9792" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Scanning for exposed Anthropic Models https://isc.sans.edu/diary/Scanning%20for%20exposed%20Anthropic%20Models/32674
 Notepad++ Hijacked by State-Sponsored Hackers...</itunes:subtitle><itunes:summary><![CDATA[<br /> Scanning for exposed Anthropic Models <a href="https://isc.sans.edu/diary/Scanning%20for%20exposed%20Anthropic%20Models/32674" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scanning%20for%20exposed%20Anthropic%20Models/32674</a><br /> Notepad++ Hijacked by State-Sponsored Hackers <a href="https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/" target="_blank" rel="noreferrer noopener">https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/</a><br /><a href="https://notepad-plus-plus.org/news/hijacked-incident-info-update/" target="_blank" rel="noreferrer noopener">https://notepad-plus-plus.org/news/hijacked-incident-info-update/</a><br /> Insecure Websockets in OpenClaw<br /><a href="https://zeropath.com/blog/openclaw-clawdbot-credential-theft-vulnerability" target="_blank" rel="noreferrer noopener">https://zeropath.com/blog/openclaw-clawdbot-credential-theft-vulnerability</a><br /> Malicious OpenClaw Skills<br /><a href="https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting" target="_blank" rel="noreferrer noopener">https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting</a><br /> Exposed OpenClaw Instances<br /><a href="https://censys.com/blog/openclaw-in-the-wild-mapping-the-public-exposure-of-a-viral-ai-assistant" target="_blank" rel="noreferrer noopener">https://censys.com/blog/openclaw-in-the-wild-mapping-the-public-exposure-of-a-viral-ai-assistant</a><br />]]></itunes:summary><itunes:duration>385</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,notpad++,openclaw,security,websockets</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9792</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, February 2nd, 2026: Google Presentation Abuse; Ivanti Vuln Exploited; Microsoft NTLM Strategy</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-february-2nd-2026-google-presentation-abuse-ivanti-vuln-exploited-microsoft-ntlm-strategy--69727981</link><description><![CDATA[<br /> Google Presentation Abuse<br /><a href="https://isc.sans.edu/diary/Google+Presentations+Abused+for+Phishing/32668/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Google+Presentations+Abused+for+Phishing/32668/</a><br /> Security Advisory Ivanti Endpoint Manager Mobile (EPMM) (CVE-2026-1281 &amp; CVE-2026-1340)<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US</a><br /> Microsoft NTLM Strategy<br /><a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/advancing-windows-security-disabling-ntlm-by-default/4489526" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/blog/windows-itpro-blog/advancing-windows-security-disabling-ntlm-by-default/4489526</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9790.mp3</guid><pubDate>Mon, 02 Feb 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69727981/9790.mp3" length="6091172" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9790" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Google Presentation Abuse
https://isc.sans.edu/diary/Google+Presentations+Abused+for+Phishing/32668/
 Security Advisory Ivanti Endpoint Manager Mobile (EPMM) (CVE-2026-1281 &amp;amp; CVE-2026-1340)...</itunes:subtitle><itunes:summary><![CDATA[<br /> Google Presentation Abuse<br /><a href="https://isc.sans.edu/diary/Google+Presentations+Abused+for+Phishing/32668/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Google+Presentations+Abused+for+Phishing/32668/</a><br /> Security Advisory Ivanti Endpoint Manager Mobile (EPMM) (CVE-2026-1281 &amp; CVE-2026-1340)<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US</a><br /> Microsoft NTLM Strategy<br /><a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/advancing-windows-security-disabling-ntlm-by-default/4489526" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/blog/windows-itpro-blog/advancing-windows-security-disabling-ntlm-by-default/4489526</a><br />]]></itunes:summary><itunes:duration>435</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,google,hacking,infosec,internet,it,ivanti,microsoft,network,news,ntlm,phishing,presentation,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9790</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, January 30th, 2026: Residential Proxy Networks; Clowdbot/Moltbot Themed Malware; eScan Malicious Updates</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-january-30th-2026-residential-proxy-networks-clowdbot-moltbot-themed-malware-escan-malicious-updates--69676473</link><description><![CDATA[<br /> No Place Like Home Network: Disrupting the World's Largest Residential Proxy Network<br /> Google dismantled the IPIDEA network that used residential proxies to route malicious traffic.<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network</a><br /> Fake Clawdbot VS Code Extension Installs ScreenConnect RAT<br /> The news about Clawdbot (now Moltbot) is used to distribute malware, in particular malicious VS Code extensions.<br /><a href="https://www.aikido.dev/blog/fake-clawdbot-vscode-extension-malware" target="_blank" rel="noreferrer noopener">https://www.aikido.dev/blog/fake-clawdbot-vscode-extension-malware</a><br /> Threat Bulletin: Critical eScan Supply Chain Compromise<br /> Anti-virus vendor eScan was compromised, and its update servers were used to install malware on some customer systems.<br /><a href="https://www.morphisec.com/blog/critical-escan-threat-bulletin/" target="_blank" rel="noreferrer noopener">https://www.morphisec.com/blog/critical-escan-threat-bulletin/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9788.mp3</guid><pubDate>Fri, 30 Jan 2026 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69676473/9788.mp3" length="5310678" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9788" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 No Place Like Home Network: Disrupting the World's Largest Residential Proxy Network
 Google dismantled the IPIDEA network that used residential proxies to route malicious traffic....</itunes:subtitle><itunes:summary><![CDATA[<br /> No Place Like Home Network: Disrupting the World's Largest Residential Proxy Network<br /> Google dismantled the IPIDEA network that used residential proxies to route malicious traffic.<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network</a><br /> Fake Clawdbot VS Code Extension Installs ScreenConnect RAT<br /> The news about Clawdbot (now Moltbot) is used to distribute malware, in particular malicious VS Code extensions.<br /><a href="https://www.aikido.dev/blog/fake-clawdbot-vscode-extension-malware" target="_blank" rel="noreferrer noopener">https://www.aikido.dev/blog/fake-clawdbot-vscode-extension-malware</a><br /> Threat Bulletin: Critical eScan Supply Chain Compromise<br /> Anti-virus vendor eScan was compromised, and its update servers were used to install malware on some customer systems.<br /><a href="https://www.morphisec.com/blog/critical-escan-threat-bulletin/" target="_blank" rel="noreferrer noopener">https://www.morphisec.com/blog/critical-escan-threat-bulletin/</a><br />]]></itunes:summary><itunes:duration>379</itunes:duration><itunes:keywords>anti virus,business,clawdbot,computer,cyber,cybersecurity,daily,escan,hacking,infosec,it,malcious,moltbot,network,news,proxy,residential,security,update,vs code</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9788</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, January 29th, 2026: WebLogic AI Slop; Fortinet Patches; WebLogic AI Slop; Fortinet Patches</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-january-29th-2026-weblogic-ai-slop-fortinet-patches-weblogic-ai-slop-fortinet-patches--69664764</link><description><![CDATA[<br /> Odd WebLogic Request. Possible CVE-2026-21962 Exploit Attempt or AI Slop?<br /> We are seeing attempts to attack CVE-2026-21962, a recent weblog vulnerability, using a non-working AI slop exploit<br /><a href="https://isc.sans.edu/diary/Odd%20WebLogic%20Request.%20Possible%20CVE-2026-21962%20Exploit%20Attempt%20or%20AI%20Slop%3F/32662" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Odd%20WebLogic%20Request.%20Possible%20CVE-2026-21962%20Exploit%20Attempt%20or%20AI%20Slop%3F/32662</a><br /> Fortinet Patches are Rolling Out<br /> Fortinet is starting to roll out patches for the recent SSO vulnerability<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-060" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-26-060</a><br /> SolarWinds Web Helpdesk Vulnerability<br /> Another set of vulnerabilities in SolarWinds Web Helpdesk may result in unauthenticated system access<br /><a href="https://horizon3.ai/attack-research/cve-2025-40551-another-solarwinds-web-help-desk-deserialization-issue/" target="_blank" rel="noreferrer noopener">https://horizon3.ai/attack-research/cve-2025-40551-another-solarwinds-web-help-desk-deserialization-issue/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9786.mp3</guid><pubDate>Thu, 29 Jan 2026 12:40:11 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69664764/9786.mp3" length="5062964" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9786" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Odd WebLogic Request. Possible CVE-2026-21962 Exploit Attempt or AI Slop?
 We are seeing attempts to attack CVE-2026-21962, a recent weblog vulnerability, using a non-working AI slop exploit...</itunes:subtitle><itunes:summary><![CDATA[<br /> Odd WebLogic Request. Possible CVE-2026-21962 Exploit Attempt or AI Slop?<br /> We are seeing attempts to attack CVE-2026-21962, a recent weblog vulnerability, using a non-working AI slop exploit<br /><a href="https://isc.sans.edu/diary/Odd%20WebLogic%20Request.%20Possible%20CVE-2026-21962%20Exploit%20Attempt%20or%20AI%20Slop%3F/32662" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Odd%20WebLogic%20Request.%20Possible%20CVE-2026-21962%20Exploit%20Attempt%20or%20AI%20Slop%3F/32662</a><br /> Fortinet Patches are Rolling Out<br /> Fortinet is starting to roll out patches for the recent SSO vulnerability<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-060" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-26-060</a><br /> SolarWinds Web Helpdesk Vulnerability<br /> Another set of vulnerabilities in SolarWinds Web Helpdesk may result in unauthenticated system access<br /><a href="https://horizon3.ai/attack-research/cve-2025-40551-another-solarwinds-web-help-desk-deserialization-issue/" target="_blank" rel="noreferrer noopener">https://horizon3.ai/attack-research/cve-2025-40551-another-solarwinds-web-help-desk-deserialization-issue/</a><br />]]></itunes:summary><itunes:duration>362</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,fortinet,hacking,infosec,internet,it,network,news,security,solarwinds,weblogic</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9786</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, January 28th, 2026: Romance Scams; DoS Vuln in React Server Components; OpenSSL Patch; Kubernetes Priv Confusion</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-january-28th-2026-romance-scams-dos-vuln-in-react-server-components-openssl-patch-kubernetes-priv-confusion--69634323</link><description><![CDATA[<br /> Initial Stages of Romance Scams [Guest Diary]<br /> Romance scams often start with random text messages that appear to be  misrouted . This guest diary by Faris Azhari is following some of the initial stages of such a scam.<br /><a href="https://isc.sans.edu/diary/Initial%20Stages%20of%20Romance%20Scams%20%5BGuest%20Diary%5D/32650" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Initial%20Stages%20of%20Romance%20Scams%20%5BGuest%20Diary%5D/32650</a><br /> Denial of Service Vulnerabilities in React Server Components<br /> Another folowup fix for the severe React vulnerability from last year, but now only fixing a DoS condition.<br /><a href="https://github.com/facebook/react/security/advisories/GHSA-83fc-fqcc-2hmg" target="_blank" rel="noreferrer noopener">https://github.com/facebook/react/security/advisories/GHSA-83fc-fqcc-2hmg</a><br /> OpenSSL Updates<br /> OpenSSL released its monthly updates, fixing a potential RCE.<br /><a href="https://openssl-library.org/news/vulnerabilities/" target="_blank" rel="noreferrer noopener">https://openssl-library.org/news/vulnerabilities/</a><br /> Kubernetes Remote Code Execution Via Nodes/Proxy GET Permission<br /> Many Kubernetes Helm Charts are vulnerable to possible remote code executions due to unclear defined access controls.<br /><a href="https://grahamhelton.com/blog/nodes-proxy-rce" target="_blank" rel="noreferrer noopener">https://grahamhelton.com/blog/nodes-proxy-rce</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9784.mp3</guid><pubDate>Wed, 28 Jan 2026 02:05:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69634323/9784.mp3" length="6423745" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9784" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Initial Stages of Romance Scams [Guest Diary]
 Romance scams often start with random text messages that appear to be  misrouted . This guest diary by Faris Azhari is following some of the initial stages of such a scam....</itunes:subtitle><itunes:summary><![CDATA[<br /> Initial Stages of Romance Scams [Guest Diary]<br /> Romance scams often start with random text messages that appear to be  misrouted . This guest diary by Faris Azhari is following some of the initial stages of such a scam.<br /><a href="https://isc.sans.edu/diary/Initial%20Stages%20of%20Romance%20Scams%20%5BGuest%20Diary%5D/32650" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Initial%20Stages%20of%20Romance%20Scams%20%5BGuest%20Diary%5D/32650</a><br /> Denial of Service Vulnerabilities in React Server Components<br /> Another folowup fix for the severe React vulnerability from last year, but now only fixing a DoS condition.<br /><a href="https://github.com/facebook/react/security/advisories/GHSA-83fc-fqcc-2hmg" target="_blank" rel="noreferrer noopener">https://github.com/facebook/react/security/advisories/GHSA-83fc-fqcc-2hmg</a><br /> OpenSSL Updates<br /> OpenSSL released its monthly updates, fixing a potential RCE.<br /><a href="https://openssl-library.org/news/vulnerabilities/" target="_blank" rel="noreferrer noopener">https://openssl-library.org/news/vulnerabilities/</a><br /> Kubernetes Remote Code Execution Via Nodes/Proxy GET Permission<br /> Many Kubernetes Helm Charts are vulnerable to possible remote code executions due to unclear defined access controls.<br /><a href="https://grahamhelton.com/blog/nodes-proxy-rce" target="_blank" rel="noreferrer noopener">https://grahamhelton.com/blog/nodes-proxy-rce</a><br />]]></itunes:summary><itunes:duration>459</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dos,hacking,infosec,internet,it,kubernetes,network,news,openssl,proxy,rce,react,romance scam,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9784</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, January 27th, 2026: PWD scanning; MSFT Office OOB Patch; Exposed Clawdbot</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-january-27th-2026-pwd-scanning-msft-office-oob-patch-exposed-clawdbot--69608948</link><description><![CDATA[<br /> Scanning Webserver with  pwd  as a Starting Path<br /> Attackers are adding the output of the pwd command to their web scans.<br /><a href="https://isc.sans.edu/diary/x/32654" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/x/32654</a><br /> Microsoft Office Security Feature Bypass Vulnerability CVE-2026-21509<br /> Microsoft released an out-of-band patch for Office fixing a currently exploited vulnerability.<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509</a><br /> Exposed Clawdbot Instances<br /> Many users of the AI tool clawdbot expose instances without access control.<br /><a href="https://x.com/theonejvo/status/2015485025266098536" target="_blank" rel="noreferrer noopener">https://x.com/theonejvo/status/2015485025266098536</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9782.mp3</guid><pubDate>Tue, 27 Jan 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69608948/9782.mp3" length="4900196" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9782" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Scanning Webserver with  pwd  as a Starting Path
 Attackers are adding the output of the pwd command to their web scans.
https://isc.sans.edu/diary/x/32654
 Microsoft Office Security Feature Bypass Vulnerability CVE-2026-21509
 Microsoft released an...</itunes:subtitle><itunes:summary><![CDATA[<br /> Scanning Webserver with  pwd  as a Starting Path<br /> Attackers are adding the output of the pwd command to their web scans.<br /><a href="https://isc.sans.edu/diary/x/32654" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/x/32654</a><br /> Microsoft Office Security Feature Bypass Vulnerability CVE-2026-21509<br /> Microsoft released an out-of-band patch for Office fixing a currently exploited vulnerability.<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509</a><br /> Exposed Clawdbot Instances<br /> Many users of the AI tool clawdbot expose instances without access control.<br /><a href="https://x.com/theonejvo/status/2015485025266098536" target="_blank" rel="noreferrer noopener">https://x.com/theonejvo/status/2015485025266098536</a><br />]]></itunes:summary><itunes:duration>350</itunes:duration><itunes:keywords>business,clwadbot,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microsoft,network,news,office,patch,pwd,scan,security,webserver</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9782</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, January 26th, 2026: FortiOS SSO Vuln Updates; Outlook OOB Update; VMware vCenter Exploited</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-january-26th-2026-fortios-sso-vuln-updates-outlook-oob-update-vmware-vcenter-exploited--69585752</link><description><![CDATA[<br /> Analysis of Single Sign-On Abuse on FortiOS<br /> Fortinet released an advisory. FortiOS devices are vulnerable if configured with any SAML integration, not just FortiCloud<br /><a href="https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios" target="_blank" rel="noreferrer noopener">https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios</a><br /> Outlook OOB Update<br /> Microsoft released a non-security OOB Update for Outlook, fixing an issue introduced with this months security patches.<br /><a href="https://support.microsoft.com/en-us/topic/january-24-2026-kb5078127-os-builds-26200-7628-and-26100-7628-out-of-band-cf5777f6-bb4e-4adb-b9cd-2b64df577491" target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-us/topic/january-24-2026-kb5078127-os-builds-26200-7628-and-26100-7628-out-of-band-cf5777f6-bb4e-4adb-b9cd-2b64df577491</a><br /> VMware vCenter Server Vulnerabilities Exploited (CVE-2024-37079, CVE-2024-37080, CVE-2024-37081)<br /> A VMWare vCenter vulnerability patched last June is now actively exploited.<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9780.mp3</guid><pubDate>Mon, 26 Jan 2026 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69585752/9780.mp3" length="3659840" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9780" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Analysis of Single Sign-On Abuse on FortiOS
 Fortinet released an advisory. FortiOS devices are vulnerable if configured with any SAML integration, not just FortiCloud
https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios...</itunes:subtitle><itunes:summary><![CDATA[<br /> Analysis of Single Sign-On Abuse on FortiOS<br /> Fortinet released an advisory. FortiOS devices are vulnerable if configured with any SAML integration, not just FortiCloud<br /><a href="https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios" target="_blank" rel="noreferrer noopener">https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios</a><br /> Outlook OOB Update<br /> Microsoft released a non-security OOB Update for Outlook, fixing an issue introduced with this months security patches.<br /><a href="https://support.microsoft.com/en-us/topic/january-24-2026-kb5078127-os-builds-26200-7628-and-26100-7628-out-of-band-cf5777f6-bb4e-4adb-b9cd-2b64df577491" target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-us/topic/january-24-2026-kb5078127-os-builds-26200-7628-and-26100-7628-out-of-band-cf5777f6-bb4e-4adb-b9cd-2b64df577491</a><br /> VMware vCenter Server Vulnerabilities Exploited (CVE-2024-37079, CVE-2024-37080, CVE-2024-37081)<br /> A VMWare vCenter vulnerability patched last June is now actively exploited.<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453</a><br />]]></itunes:summary><itunes:duration>261</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,fortios,hacking,infosec,internet,it,microsoft,network,news,oob,outlook,security,update,vcenter,vmware</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9780</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, January 23rd, 2026: Scanning AI Code; FortiGate Update; ISC BIND DoS; Trivial SmaterMail Vulnerability</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-january-23rd-2026-scanning-ai-code-fortigate-update-isc-bind-dos-trivial-smatermail-vulnerability--69553929</link><description><![CDATA[<br /> Is AI-Generated Code Secure?<br /> Xavier used the free static code analysis tool Bandit to review code he wrote with heavy AI support.<br /><a href="https://isc.sans.edu/diary/Is%20AI-Generated%20Code%20Secure%3F/32648" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Is%20AI-Generated%20Code%20Secure%3F/32648</a><br /> Malicious Configuration Changes On Fortinet FortiGate Devices via SSO Accounts<br /> Arctic Wolf summarized some of the attacks it is seeing against FortiGate devices via the insufficiently patched SSL vulnerability.<br /><a href="https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-configuration-changes-fortinet-fortigate-devices-via-sso-accounts/" target="_blank" rel="noreferrer noopener">https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-configuration-changes-fortinet-fortigate-devices-via-sso-accounts/</a><br /> ISC BIND DoS vulnerability in Drone ID Records<br /> HHIT and BRID records, which are used as part of Drone ID, can be used to crash named if their length is 3 bytes.<br /><a href="https://marlink.com/resources/knowledge-hub/isc-bind-vulnerability-discovered-and-disclosed-by-marlink-cyber/" target="_blank" rel="noreferrer noopener">https://marlink.com/resources/knowledge-hub/isc-bind-vulnerability-discovered-and-disclosed-by-marlink-cyber/</a><br /> SmarterTools SmarterMail Password Reset Vulnerability<br /> SmarterTools recently patched a trivial vulnerability in SmarterMail that would allow anybody without authentication to reset administrator passwords.<br /><a href="https://labs.watchtowr.com/attackers-with-decompilers-strike-again-smartertools-smartermail-wt-2026-0001-auth-bypass/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/attackers-with-decompilers-strike-again-smartertools-smartermail-wt-2026-0001-auth-bypass/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9778.mp3</guid><pubDate>Fri, 23 Jan 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69553929/9778.mp3" length="5926241" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9778" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Is AI-Generated Code Secure?
 Xavier used the free static code analysis tool Bandit to review code he wrote with heavy AI support.
https://isc.sans.edu/diary/Is%20AI-Generated%20Code%20Secure%3F/32648
 Malicious Configuration Changes On Fortinet...</itunes:subtitle><itunes:summary><![CDATA[<br /> Is AI-Generated Code Secure?<br /> Xavier used the free static code analysis tool Bandit to review code he wrote with heavy AI support.<br /><a href="https://isc.sans.edu/diary/Is%20AI-Generated%20Code%20Secure%3F/32648" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Is%20AI-Generated%20Code%20Secure%3F/32648</a><br /> Malicious Configuration Changes On Fortinet FortiGate Devices via SSO Accounts<br /> Arctic Wolf summarized some of the attacks it is seeing against FortiGate devices via the insufficiently patched SSL vulnerability.<br /><a href="https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-configuration-changes-fortinet-fortigate-devices-via-sso-accounts/" target="_blank" rel="noreferrer noopener">https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-configuration-changes-fortinet-fortigate-devices-via-sso-accounts/</a><br /> ISC BIND DoS vulnerability in Drone ID Records<br /> HHIT and BRID records, which are used as part of Drone ID, can be used to crash named if their length is 3 bytes.<br /><a href="https://marlink.com/resources/knowledge-hub/isc-bind-vulnerability-discovered-and-disclosed-by-marlink-cyber/" target="_blank" rel="noreferrer noopener">https://marlink.com/resources/knowledge-hub/isc-bind-vulnerability-discovered-and-disclosed-by-marlink-cyber/</a><br /> SmarterTools SmarterMail Password Reset Vulnerability<br /> SmarterTools recently patched a trivial vulnerability in SmarterMail that would allow anybody without authentication to reset administrator passwords.<br /><a href="https://labs.watchtowr.com/attackers-with-decompilers-strike-again-smartertools-smartermail-wt-2026-0001-auth-bypass/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/attackers-with-decompilers-strike-again-smartertools-smartermail-wt-2026-0001-auth-bypass/</a><br />]]></itunes:summary><itunes:duration>423</itunes:duration><itunes:keywords>bandit,bind,business,cyber,cybersecurity,daily,dos,drone,drone id,fortigate,fortinet,hacking,infosec,isc,it,network,news,python,smartermail,smartertools</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9778</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, January 22nd, 2026: Visual Studio Code Scripts; Cisco Unified Comm and Zoom Vuln; Insufficient Fortinet Patch; SANS</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-january-22nd-2026-visual-studio-code-scripts-cisco-unified-comm-and-zoom-vuln-insufficient-fortinet-patch-sans--69540462</link><description><![CDATA[<br /> Automatic Script Execution In Visual Studio Code<br /> Visual Studio Code will read configuration files within the source code that may lead to code execution.<br /><a href="https://isc.sans.edu/diary/Automatic%20Script%20Execution%20In%20Visual%20Studio%20Code/32644" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Automatic%20Script%20Execution%20In%20Visual%20Studio%20Code/32644</a><br /> Cisco Unified Communications Products Remote Code Execution Vulnerability A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device.<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voice-rce-mORhqY4b" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voice-rce-mORhqY4b</a><br /> Zoom Vulnerability<br /> A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to execute remote code on the MMR via network access.<br /><a href="https://www.zoom.com/en/trust/security-bulletin/zsb-26001/" target="_blank" rel="noreferrer noopener">https://www.zoom.com/en/trust/security-bulletin/zsb-26001/</a><br /> Possible new SSO Exploit (CVE-2025-59718) on 7.4.9<br /><a href="https://www.reddit.com/r/fortinet/comments/1qibdcb/possible_new_sso_exploit_cve202559718_on_749/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/fortinet/comments/1qibdcb/possible_new_sso_exploit_cve202559718_on_749/</a><br /> SANS SOC Survey<br /> The 2026 SOC Survey is open, and we need your input to create a meaningful report. Please share your experience so we can advocate for what actually works in the trenches.<br /><a href="https://survey.sans.org/jfe/form/SV_3ViqWZgWnfQAzkO?is=socsurveystormcenter" target="_blank" rel="noreferrer noopener">https://survey.sans.org/jfe/form/SV_3ViqWZgWnfQAzkO?is=socsurveystormcenter</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9776.mp3</guid><pubDate>Thu, 22 Jan 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69540462/9776.mp3" length="5510247" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9776" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Automatic Script Execution In Visual Studio Code
 Visual Studio Code will read configuration files within the source code that may lead to code execution.
https://isc.sans.edu/diary/Automatic%20Script%20Execution%20In%20Visual%20Studio%20Code/32644...</itunes:subtitle><itunes:summary><![CDATA[<br /> Automatic Script Execution In Visual Studio Code<br /> Visual Studio Code will read configuration files within the source code that may lead to code execution.<br /><a href="https://isc.sans.edu/diary/Automatic%20Script%20Execution%20In%20Visual%20Studio%20Code/32644" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Automatic%20Script%20Execution%20In%20Visual%20Studio%20Code/32644</a><br /> Cisco Unified Communications Products Remote Code Execution Vulnerability A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device.<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voice-rce-mORhqY4b" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voice-rce-mORhqY4b</a><br /> Zoom Vulnerability<br /> A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to execute remote code on the MMR via network access.<br /><a href="https://www.zoom.com/en/trust/security-bulletin/zsb-26001/" target="_blank" rel="noreferrer noopener">https://www.zoom.com/en/trust/security-bulletin/zsb-26001/</a><br /> Possible new SSO Exploit (CVE-2025-59718) on 7.4.9<br /><a href="https://www.reddit.com/r/fortinet/comments/1qibdcb/possible_new_sso_exploit_cve202559718_on_749/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/fortinet/comments/1qibdcb/possible_new_sso_exploit_cve202559718_on_749/</a><br /> SANS SOC Survey<br /> The 2026 SOC Survey is open, and we need your input to create a meaningful report. Please share your experience so we can advocate for what actually works in the trenches.<br /><a href="https://survey.sans.org/jfe/form/SV_3ViqWZgWnfQAzkO?is=socsurveystormcenter" target="_blank" rel="noreferrer noopener">https://survey.sans.org/jfe/form/SV_3ViqWZgWnfQAzkO?is=socsurveystormcenter</a><br />]]></itunes:summary><itunes:duration>393</itunes:duration><itunes:keywords>business,cisco,code,computer,cyber,cybersecurity,daily,fortinet,hacking,infosec,internet,it,network,news,security,soc,sso,survey,visual studio,zoom</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9776</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, January 21st, 2026: Punycode Hunting; telnetd vuln; 6 day Certs and IP Certs; Oracle Patches</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-january-21st-2026-punycode-hunting-telnetd-vuln-6-day-certs-and-ip-certs-oracle-patches--69526497</link><description><![CDATA[<br /> Add Punycode to your Threat Hunting Routine<br /> Punycode patterns in DNS queries make excellent hunting opportunities.<br /><a href="https://isc.sans.edu/diary/Add%20Punycode%20to%20your%20Threat%20Hunting%20Routine/32640" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Add%20Punycode%20to%20your%20Threat%20Hunting%20Routine/32640</a><br /> GNU InetUtils Security Advisory: remote authentication by-pass intelnetd<br /> telnetd shipping with InetUtils suffers from a critical authentication by-pass vulnerability.<br /><a href="https://www.openwall.com/lists/oss-security/2026/01/20/2" target="_blank" rel="noreferrer noopener">https://www.openwall.com/lists/oss-security/2026/01/20/2</a><br /> 6-day and IP Address Certificates are Generally Available<br /> Let s Encrypt will now offer 6-day certificates as an option. These short-lived certificates can be used for IP addresses.<br /><a href="https://letsencrypt.org/2026/01/15/6day-and-ip-general-availability" target="_blank" rel="noreferrer noopener">https://letsencrypt.org/2026/01/15/6day-and-ip-general-availability</a><br /> Oracle Quarterly Critical Patch Update<br /> Oracle released its first quarterly patches for 2026, fixing 337 vulnerabilities<br /><a href="https://www.oracle.com/security-alerts/cpujan2026.html#AppendixFMW" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpujan2026.html#AppendixFMW</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9774.mp3</guid><pubDate>Wed, 21 Jan 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69526497/9774.mp3" length="5661964" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9774" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Add Punycode to your Threat Hunting Routine
 Punycode patterns in DNS queries make excellent hunting opportunities.
https://isc.sans.edu/diary/Add%20Punycode%20to%20your%20Threat%20Hunting%20Routine/32640
 GNU InetUtils Security Advisory: remote...</itunes:subtitle><itunes:summary><![CDATA[<br /> Add Punycode to your Threat Hunting Routine<br /> Punycode patterns in DNS queries make excellent hunting opportunities.<br /><a href="https://isc.sans.edu/diary/Add%20Punycode%20to%20your%20Threat%20Hunting%20Routine/32640" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Add%20Punycode%20to%20your%20Threat%20Hunting%20Routine/32640</a><br /> GNU InetUtils Security Advisory: remote authentication by-pass intelnetd<br /> telnetd shipping with InetUtils suffers from a critical authentication by-pass vulnerability.<br /><a href="https://www.openwall.com/lists/oss-security/2026/01/20/2" target="_blank" rel="noreferrer noopener">https://www.openwall.com/lists/oss-security/2026/01/20/2</a><br /> 6-day and IP Address Certificates are Generally Available<br /> Let s Encrypt will now offer 6-day certificates as an option. These short-lived certificates can be used for IP addresses.<br /><a href="https://letsencrypt.org/2026/01/15/6day-and-ip-general-availability" target="_blank" rel="noreferrer noopener">https://letsencrypt.org/2026/01/15/6day-and-ip-general-availability</a><br /> Oracle Quarterly Critical Patch Update<br /> Oracle released its first quarterly patches for 2026, fixing 337 vulnerabilities<br /><a href="https://www.oracle.com/security-alerts/cpujan2026.html#AppendixFMW" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpujan2026.html#AppendixFMW</a><br />]]></itunes:summary><itunes:duration>404</itunes:duration><itunes:keywords>business,certificates,computer,cyber,cybersecurity,daily,hacking,inetutils,infosec,internet,it,letsencrypt,network,news,oracle,punycode,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9774</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, January 20th, 2026: Scans Against LLMs; NTLM Rainbow Table; OOB MSFT Patch</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-january-20th-2026-scans-against-llms-ntlm-rainbow-table-oob-msft-patch--69513292</link><description><![CDATA[<br /> "How many states are there in the United States?"<br /> Attackers are actively scanning for LLMs, fingerprinting them using the query  How many states are there in the United States? .<br /><a href="https://isc.sans.edu/diary/%22How%20many%20states%20are%20there%20in%20the%20United%20States%3F%22/32618" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%22How%20many%20states%20are%20there%20in%20the%20United%20States%3F%22/32618</a><br /> Closing the Door on Net-NTLMv1: Releasing Rainbow Tables to Accelerate Protocol Deprecation<br /> Mandiant is publicly releasing a comprehensive dataset of Net-NTLMv1 rainbow tables to underscore the urgency of migrating away from this outdated protocol.<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/net-ntlmv1-deprecation-rainbow-tables" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/net-ntlmv1-deprecation-rainbow-tables</a><br /> Out-of-band update to address issues observed with the January 2026 Windows security update<br /> Microsoft has identified issues upon installing the January 2026 Windows security update. To address these issues, an out-of-band (OOB) update was released today, January 17, 2026<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/windows-message-center" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/windows-message-center</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9772.mp3</guid><pubDate>Tue, 20 Jan 2026 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69513292/9772.mp3" length="5041285" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9772" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 "How many states are there in the United States?"
 Attackers are actively scanning for LLMs, fingerprinting them using the query  How many states are there in the United States? ....</itunes:subtitle><itunes:summary><![CDATA[<br /> "How many states are there in the United States?"<br /> Attackers are actively scanning for LLMs, fingerprinting them using the query  How many states are there in the United States? .<br /><a href="https://isc.sans.edu/diary/%22How%20many%20states%20are%20there%20in%20the%20United%20States%3F%22/32618" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%22How%20many%20states%20are%20there%20in%20the%20United%20States%3F%22/32618</a><br /> Closing the Door on Net-NTLMv1: Releasing Rainbow Tables to Accelerate Protocol Deprecation<br /> Mandiant is publicly releasing a comprehensive dataset of Net-NTLMv1 rainbow tables to underscore the urgency of migrating away from this outdated protocol.<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/net-ntlmv1-deprecation-rainbow-tables" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/net-ntlmv1-deprecation-rainbow-tables</a><br /> Out-of-band update to address issues observed with the January 2026 Windows security update<br /> Microsoft has identified issues upon installing the January 2026 Windows security update. To address these issues, an out-of-band (OOB) update was released today, January 17, 2026<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/windows-message-center" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/windows-message-center</a><br />]]></itunes:summary><itunes:duration>360</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,llm,llms,network,news,ntlm,patch,rainbow table,scans,security,windows</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9772</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, January 16th, 2026: Cryptojacking Hidden Gifts; Bluetooth Vulnerability; Reprompt in MSFT Copilot</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-january-16th-2026-cryptojacking-hidden-gifts-bluetooth-vulnerability-reprompt-in-msft-copilot--69462926</link><description><![CDATA[<br /> Battling Cryptojacking, Botnets, and IABs<br /> Cryptojacking often comes with less obvious addons, like SSH backdoors<br /><a href="https://isc.sans.edu/diary/Battling%20Cryptojacking%2C%20Botnets%2C%20and%20IABs%20%5BGuest%20Diary%5D/32632" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Battling%20Cryptojacking%2C%20Botnets%2C%20and%20IABs%20%5BGuest%20Diary%5D/32632</a><br /> Microsoft Copilot Reprompt Attacks<br /> Adding a query parameter to the URL may prefill a Copilot prompt, altering the meaning of the prompts that follow.<br /><a href="https://www.varonis.com/blog/reprompt" target="_blank" rel="noreferrer noopener">https://www.varonis.com/blog/reprompt</a><br /> Hijacking Bluetooth Accessories Using Google Fast Pair<br /> Google s fast pair protocol is often not implemented correctly, allowing the Hijacking of Bluetooth accessories<br /><a href="https://whisperpair.eu/#about" target="_blank" rel="noreferrer noopener">https://whisperpair.eu/#about</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9770.mp3</guid><pubDate>Fri, 16 Jan 2026 03:10:11 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69462926/9770.mp3" length="6292882" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9770" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Battling Cryptojacking, Botnets, and IABs
 Cryptojacking often comes with less obvious addons, like SSH backdoors
https://isc.sans.edu/diary/Battling%20Cryptojacking%2C%20Botnets%2C%20and%20IABs%20%5BGuest%20Diary%5D/32632
 Microsoft Copilot...</itunes:subtitle><itunes:summary><![CDATA[<br /> Battling Cryptojacking, Botnets, and IABs<br /> Cryptojacking often comes with less obvious addons, like SSH backdoors<br /><a href="https://isc.sans.edu/diary/Battling%20Cryptojacking%2C%20Botnets%2C%20and%20IABs%20%5BGuest%20Diary%5D/32632" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Battling%20Cryptojacking%2C%20Botnets%2C%20and%20IABs%20%5BGuest%20Diary%5D/32632</a><br /> Microsoft Copilot Reprompt Attacks<br /> Adding a query parameter to the URL may prefill a Copilot prompt, altering the meaning of the prompts that follow.<br /><a href="https://www.varonis.com/blog/reprompt" target="_blank" rel="noreferrer noopener">https://www.varonis.com/blog/reprompt</a><br /> Hijacking Bluetooth Accessories Using Google Fast Pair<br /> Google s fast pair protocol is often not implemented correctly, allowing the Hijacking of Bluetooth accessories<br /><a href="https://whisperpair.eu/#about" target="_blank" rel="noreferrer noopener">https://whisperpair.eu/#about</a><br />]]></itunes:summary><itunes:duration>450</itunes:duration><itunes:keywords>bluetooth,business,computer,copilot,cryptojacking,cyber,cybersecurity,daily,fast pair,hacking,infosec,internet,it,network,news,security,ssh</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9770</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, January 15th, 2026: Luma Streal Repeat Infection; ServiceNow Broken Auth; Starlink/GPS Jamming</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-january-15th-2026-luma-streal-repeat-infection-servicenow-broken-auth-starlink-gps-jamming--69448100</link><description><![CDATA[<br /> Infection repeatedly adds scheduled tasks and increases traffic to the same C2 domain<br /><a href="https://isc.sans.edu/diary/Infection%20repeatedly%20adds%20scheduled%20tasks%20and%20increases%20traffic%20to%20the%20same%20C2%20domain/32628" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Infection%20repeatedly%20adds%20scheduled%20tasks%20and%20increases%20traffic%20to%20the%20same%20C2%20domain/32628</a><br /> BodySnatcher (CVE-2025-12420): A Broken Authentication and Agentic Hijacking Vulnerability in ServiceNow<br /><a href="https://appomni.com/ao-labs/bodysnatcher-agentic-ai-security-vulnerability-in-servicenow/" target="_blank" rel="noreferrer noopener">https://appomni.com/ao-labs/bodysnatcher-agentic-ai-security-vulnerability-in-servicenow/</a><br /> Starlink Terminal GPS Spoofing/Jamming Detection in Iran<br /><a href="https://github.com/narimangharib/starlink-iran-gps-spoofing/blob/main/starlink-iran.md" target="_blank" rel="noreferrer noopener">https://github.com/narimangharib/starlink-iran-gps-spoofing/blob/main/starlink-iran.md</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9768.mp3</guid><pubDate>Thu, 15 Jan 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69448100/9768.mp3" length="5188687" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9768" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Infection repeatedly adds scheduled tasks and increases traffic to the same C2 domain
https://isc.sans.edu/diary/Infection%20repeatedly%20adds%20scheduled%20tasks%20and%20increases%20traffic%20to%20the%20same%20C2%20domain/32628
 BodySnatcher...</itunes:subtitle><itunes:summary><![CDATA[<br /> Infection repeatedly adds scheduled tasks and increases traffic to the same C2 domain<br /><a href="https://isc.sans.edu/diary/Infection%20repeatedly%20adds%20scheduled%20tasks%20and%20increases%20traffic%20to%20the%20same%20C2%20domain/32628" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Infection%20repeatedly%20adds%20scheduled%20tasks%20and%20increases%20traffic%20to%20the%20same%20C2%20domain/32628</a><br /> BodySnatcher (CVE-2025-12420): A Broken Authentication and Agentic Hijacking Vulnerability in ServiceNow<br /><a href="https://appomni.com/ao-labs/bodysnatcher-agentic-ai-security-vulnerability-in-servicenow/" target="_blank" rel="noreferrer noopener">https://appomni.com/ao-labs/bodysnatcher-agentic-ai-security-vulnerability-in-servicenow/</a><br /> Starlink Terminal GPS Spoofing/Jamming Detection in Iran<br /><a href="https://github.com/narimangharib/starlink-iran-gps-spoofing/blob/main/starlink-iran.md" target="_blank" rel="noreferrer noopener">https://github.com/narimangharib/starlink-iran-gps-spoofing/blob/main/starlink-iran.md</a><br />]]></itunes:summary><itunes:duration>371</itunes:duration><itunes:keywords>agentic,bodysnatcher,business,computer,cyber,cybersecurity,daily,gps,hacking,infosec,internet,it,lumastealer,network,news,security,servicenow,starlink</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9768</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, January 14th, 2026: Microsoft, Adobe and Fortinet Patches; ConsentFix</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-january-14th-2026-microsoft-adobe-and-fortinet-patches-consentfix--69430582</link><description><![CDATA[<br /> Microsoft Patch Tuesday January 2026<br /> Microsoft released patches for 113 vulnerabilities. This includes one already exploited vulnerability, one that was made public before today and eight critical vulnerabilities.<br /><a href="https://isc.sans.edu/diary/January%202026%20Microsoft%20Patch%20Tuesday%20Summary/32624" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/January%202026%20Microsoft%20Patch%20Tuesday%20Summary/32624</a><br /> Adobe Patches<br /> Adobe released patches for five products. The code execution vulnerabilities in ColdFusion and Acrobat Reader deserve special attention.<br /><a href="https://helpx.adobe.com/security.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security.html</a><br /> Fortinet Patches<br /> Fortnet patched two products today, one suffering from an SSRF vulnerability.<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-783" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-25-783</a><br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-084" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-25-084</a><br /> ConsentFix: Analysing a browser-native ClickFix-style attack that hijacks OAuth consent grants<br /> Attackers are tricking victims to copy/paste OAUTH URLs, including credentials, to a fake CAPTCHA<br /><a href="https://pushsecurity.com/blog/consentfix" target="_blank" rel="noreferrer noopener">https://pushsecurity.com/blog/consentfix</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9766.mp3</guid><pubDate>Wed, 14 Jan 2026 02:30:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69430582/9766.mp3" length="6697289" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9766" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Microsoft Patch Tuesday January 2026
 Microsoft released patches for 113 vulnerabilities. This includes one already exploited vulnerability, one that was made public before today and eight critical vulnerabilities....</itunes:subtitle><itunes:summary><![CDATA[<br /> Microsoft Patch Tuesday January 2026<br /> Microsoft released patches for 113 vulnerabilities. This includes one already exploited vulnerability, one that was made public before today and eight critical vulnerabilities.<br /><a href="https://isc.sans.edu/diary/January%202026%20Microsoft%20Patch%20Tuesday%20Summary/32624" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/January%202026%20Microsoft%20Patch%20Tuesday%20Summary/32624</a><br /> Adobe Patches<br /> Adobe released patches for five products. The code execution vulnerabilities in ColdFusion and Acrobat Reader deserve special attention.<br /><a href="https://helpx.adobe.com/security.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security.html</a><br /> Fortinet Patches<br /> Fortnet patched two products today, one suffering from an SSRF vulnerability.<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-783" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-25-783</a><br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-084" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-25-084</a><br /> ConsentFix: Analysing a browser-native ClickFix-style attack that hijacks OAuth consent grants<br /> Attackers are tricking victims to copy/paste OAUTH URLs, including credentials, to a fake CAPTCHA<br /><a href="https://pushsecurity.com/blog/consentfix" target="_blank" rel="noreferrer noopener">https://pushsecurity.com/blog/consentfix</a><br />]]></itunes:summary><itunes:duration>478</itunes:duration><itunes:keywords>adobe,business,computer,cyber,cybersecurity,daily,fortinet,hacking,infosec,internet,it,microsoft,network,news,oatuh,security,ssrf</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9766</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, January 13th, 2026: n8n got npm’ed; Gogs exploit; telegram proxy links</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-january-13th-2026-n8n-got-npm-ed-gogs-exploit-telegram-proxy-links--69413468</link><description><![CDATA[<br /> n8n supply chain attack<br /> Malicious npm pagackages were used to attempt to obtain user OAUTH credentials for NPM.<br /><a href="https://www.endorlabs.com/learn/n8mare-on-auth-street-supply-chain-attack-targets-n8n-ecosystem" target="_blank" rel="noreferrer noopener">https://www.endorlabs.com/learn/n8mare-on-auth-street-supply-chain-attack-targets-n8n-ecosystem</a><br /> Gogs 0-Day Exploited in the Wild<br /> An at the time unpachted flaw in Gogs was exploited to compromise git repos.<br /><a href="https://www.wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploit" target="_blank" rel="noreferrer noopener">https://www.wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploit</a><br /> Telegram Proxy Link Abuse<br /> Telegram proxy links have been abused to deanonymize users<br /><a href="https://x.com/GangExposed_RU/status/2009961417781457129" target="_blank" rel="noreferrer noopener">https://x.com/GangExposed_RU/status/2009961417781457129</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9764.mp3</guid><pubDate>Tue, 13 Jan 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69413468/9764.mp3" length="4841104" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9764" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 n8n supply chain attack
 Malicious npm pagackages were used to attempt to obtain user OAUTH credentials for NPM.
https://www.endorlabs.com/learn/n8mare-on-auth-street-supply-chain-attack-targets-n8n-ecosystem
 Gogs 0-Day Exploited in the Wild
 An at...</itunes:subtitle><itunes:summary><![CDATA[<br /> n8n supply chain attack<br /> Malicious npm pagackages were used to attempt to obtain user OAUTH credentials for NPM.<br /><a href="https://www.endorlabs.com/learn/n8mare-on-auth-street-supply-chain-attack-targets-n8n-ecosystem" target="_blank" rel="noreferrer noopener">https://www.endorlabs.com/learn/n8mare-on-auth-street-supply-chain-attack-targets-n8n-ecosystem</a><br /> Gogs 0-Day Exploited in the Wild<br /> An at the time unpachted flaw in Gogs was exploited to compromise git repos.<br /><a href="https://www.wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploit" target="_blank" rel="noreferrer noopener">https://www.wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploit</a><br /> Telegram Proxy Link Abuse<br /> Telegram proxy links have been abused to deanonymize users<br /><a href="https://x.com/GangExposed_RU/status/2009961417781457129" target="_blank" rel="noreferrer noopener">https://x.com/GangExposed_RU/status/2009961417781457129</a><br />]]></itunes:summary><itunes:duration>346</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,gogs,hacking,infosec,internet,it,n8n,network,news,npm,security,telegram</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9764</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, January 12th, 2026: PEB Manipulation; YARA Update; VideoLAND and Apache NimBLE Patches</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-january-12th-2026-peb-manipulation-yara-update-videoland-and-apache-nimble-patches--69396309</link><description><![CDATA[<br /> Malicious Process Environment Block Manipulation<br /> The process environment block contains metadata about particular processes, but can be manipulated.<br /><a href="https://isc.sans.edu/diary/Malicious+Process+Environment+Block+Manipulation/32614/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Malicious+Process+Environment+Block+Manipulation/32614/</a><br /> YARA-X 1.11.0 Release: Hash Function Warnings<br /> The latest version of YARA will warn users if a hash rule attempts to match an invalid hash.<br /><a href="https://isc.sans.edu/diary/YARA-X%201.11.0%20Release%3A%20Hash%20Function%20Warnings/32616" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/YARA-X%201.11.0%20Release%3A%20Hash%20Function%20Warnings/32616</a><br /> VideoLAN Security Bulletin VLC 3.0.22 CVE-2025-51602<br /> VideoLAN fixed several vulnerabilities in its VLC software.<br /><a href="https://www.videolan.org/security/sb-vlc3022.html" target="_blank" rel="noreferrer noopener">https://www.videolan.org/security/sb-vlc3022.html</a><br /> Apache NimBLE Bluetooth vulnerabilities<br /> NimBLE is a Bluetooth stack popular in IoT devices. An update fixes some eavesdropping and pairing vulnerabilities.<br /><a href="https://mynewt.apache.org/cve/" target="_blank" rel="noreferrer noopener">https://mynewt.apache.org/cve/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9762.mp3</guid><pubDate>Mon, 12 Jan 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69396309/9762.mp3" length="5271443" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9762" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Malicious Process Environment Block Manipulation
 The process environment block contains metadata about particular processes, but can be manipulated.
https://isc.sans.edu/diary/Malicious+Process+Environment+Block+Manipulation/32614/
 YARA-X 1.11.0...</itunes:subtitle><itunes:summary><![CDATA[<br /> Malicious Process Environment Block Manipulation<br /> The process environment block contains metadata about particular processes, but can be manipulated.<br /><a href="https://isc.sans.edu/diary/Malicious+Process+Environment+Block+Manipulation/32614/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Malicious+Process+Environment+Block+Manipulation/32614/</a><br /> YARA-X 1.11.0 Release: Hash Function Warnings<br /> The latest version of YARA will warn users if a hash rule attempts to match an invalid hash.<br /><a href="https://isc.sans.edu/diary/YARA-X%201.11.0%20Release%3A%20Hash%20Function%20Warnings/32616" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/YARA-X%201.11.0%20Release%3A%20Hash%20Function%20Warnings/32616</a><br /> VideoLAN Security Bulletin VLC 3.0.22 CVE-2025-51602<br /> VideoLAN fixed several vulnerabilities in its VLC software.<br /><a href="https://www.videolan.org/security/sb-vlc3022.html" target="_blank" rel="noreferrer noopener">https://www.videolan.org/security/sb-vlc3022.html</a><br /> Apache NimBLE Bluetooth vulnerabilities<br /> NimBLE is a Bluetooth stack popular in IoT devices. An update fixes some eavesdropping and pairing vulnerabilities.<br /><a href="https://mynewt.apache.org/cve/" target="_blank" rel="noreferrer noopener">https://mynewt.apache.org/cve/</a><br />]]></itunes:summary><itunes:duration>377</itunes:duration><itunes:keywords>apache,bluetooth,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,nimble,security,videolan,vlc,yara</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9762</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, January 9th, 2026: Gephi Analysis; zlib vuln; GnuPG Vulns; Cisco/Cloudflare DNS Issue</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-january-9th-2026-gephi-analysis-zlib-vuln-gnupg-vulns-cisco-cloudflare-dns-issue--69364449</link><description><![CDATA[<br /> Analysis using Gephi with DShield Sensor Data<br /> Gephi is a neat tool to create interactive data visualizations. It can be applied to honeypot data to find data clusters.<br /><a href="https://isc.sans.edu/diary/Analysis%20using%20Gephi%20with%20DShield%20Sensor%20Data/32608" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analysis%20using%20Gephi%20with%20DShield%20Sensor%20Data/32608</a><br /> zlib v1.3.1.2 Global Buffer Overflow in TGZfname() of zlib untgz Utility<br /> The untgz utility that is part of zlib suffers from a straightforward buffer overflow in the filename parameter<br /><a href="https://seclists.org/fulldisclosure/2026/Jan/3" target="_blank" rel="noreferrer noopener">https://seclists.org/fulldisclosure/2026/Jan/3</a><br /> GnuPG Vulnerabilities<br /> Several vulnerabilities in GnuPG were disclosed during a recent talk at the CCC congress.<br /><a href="https://gpg.fail" target="_blank" rel="noreferrer noopener">https://gpg.fail</a><br /> Cisco DNS Bug Reboot<br /> Last night, several Cisco users reported that their switches rebooted. The issue appears to be related to a change Cloudflare made in the order of CNAME records.  Only users using 1.1.1.1 as a recursive resolver appear to be affected.<br /><a href="https://community.cisco.com/t5/switches-small-business/got-fatal-error-cbs350-24t-4g/td-p/5359883?utm_source=chatgpt.com" target="_blank" rel="noreferrer noopener">https://community.cisco.com/t5/switches-small-business/got-fatal-error-cbs350-24t-4g/td-p/5359883?utm_source=chatgpt.com</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9760.mp3</guid><pubDate>Fri, 09 Jan 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69364449/9760.mp3" length="6053806" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9760" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Analysis using Gephi with DShield Sensor Data
 Gephi is a neat tool to create interactive data visualizations. It can be applied to honeypot data to find data clusters....</itunes:subtitle><itunes:summary><![CDATA[<br /> Analysis using Gephi with DShield Sensor Data<br /> Gephi is a neat tool to create interactive data visualizations. It can be applied to honeypot data to find data clusters.<br /><a href="https://isc.sans.edu/diary/Analysis%20using%20Gephi%20with%20DShield%20Sensor%20Data/32608" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analysis%20using%20Gephi%20with%20DShield%20Sensor%20Data/32608</a><br /> zlib v1.3.1.2 Global Buffer Overflow in TGZfname() of zlib untgz Utility<br /> The untgz utility that is part of zlib suffers from a straightforward buffer overflow in the filename parameter<br /><a href="https://seclists.org/fulldisclosure/2026/Jan/3" target="_blank" rel="noreferrer noopener">https://seclists.org/fulldisclosure/2026/Jan/3</a><br /> GnuPG Vulnerabilities<br /> Several vulnerabilities in GnuPG were disclosed during a recent talk at the CCC congress.<br /><a href="https://gpg.fail" target="_blank" rel="noreferrer noopener">https://gpg.fail</a><br /> Cisco DNS Bug Reboot<br /> Last night, several Cisco users reported that their switches rebooted. The issue appears to be related to a change Cloudflare made in the order of CNAME records.  Only users using 1.1.1.1 as a recursive resolver appear to be affected.<br /><a href="https://community.cisco.com/t5/switches-small-business/got-fatal-error-cbs350-24t-4g/td-p/5359883?utm_source=chatgpt.com" target="_blank" rel="noreferrer noopener">https://community.cisco.com/t5/switches-small-business/got-fatal-error-cbs350-24t-4g/td-p/5359883?utm_source=chatgpt.com</a><br />]]></itunes:summary><itunes:duration>432</itunes:duration><itunes:keywords>business,ccc,cisco,cloudflare,cyber,cybersecurity,daily,dns,dshield,gephi,gnupg,hacking,honeypot,infosec,it,network,news,security,untgz,zlib</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9760</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, January 8th, 2026: HTML QR Code Phishing; n8n vulnerability; Powerbank Feature Creep</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-january-8th-2026-html-qr-code-phishing-n8n-vulnerability-powerbank-feature-creep--69347810</link><description><![CDATA[<br /> A phishing campaign with QR codes rendered using an HTML table<br /> Phishing emails are bypassing filters by encoding QR codes as HTML tables.<br /><a href="https://isc.sans.edu/diary/A%20phishing%20campaign%20with%20QR%20codes%20rendered%20using%20an%20HTML%20table/32606" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20phishing%20campaign%20with%20QR%20codes%20rendered%20using%20an%20HTML%20table/32606</a><br /> n8n vulnerabilities<br /> In recent days, several new n8n vulnerabilities were disclosed. Ensure that you update any on-premises installations and carefully consider what to use n8n for.<br /><a href="https://www.cyera.com/research-labs/ni8mare-unauthenticated-remote-code-execution-in-n8n-cve-2026-21858" target="_blank" rel="noreferrer noopener">https://www.cyera.com/research-labs/ni8mare-unauthenticated-remote-code-execution-in-n8n-cve-2026-21858</a><br /><a href="https://github.com/n8n-io/n8n/security/advisories/GHSA-v4pr-fm98-w9pg" target="_blank" rel="noreferrer noopener">https://github.com/n8n-io/n8n/security/advisories/GHSA-v4pr-fm98-w9pg</a><br /> Power bank feature creep is out of control <br /> Simple power banks are increasingly equipped with advanced features, including networking, which may expose them to security risks.<br /><a href="https://www.theverge.com/tech/856225/power-banks-are-the-latest-victims-of-feature-creep" target="_blank" rel="noreferrer noopener">https://www.theverge.com/tech/856225/power-banks-are-the-latest-victims-of-feature-creep</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9758.mp3</guid><pubDate>Thu, 08 Jan 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69347810/9758.mp3" length="6206838" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9758" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 A phishing campaign with QR codes rendered using an HTML table
 Phishing emails are bypassing filters by encoding QR codes as HTML tables....</itunes:subtitle><itunes:summary><![CDATA[<br /> A phishing campaign with QR codes rendered using an HTML table<br /> Phishing emails are bypassing filters by encoding QR codes as HTML tables.<br /><a href="https://isc.sans.edu/diary/A%20phishing%20campaign%20with%20QR%20codes%20rendered%20using%20an%20HTML%20table/32606" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20phishing%20campaign%20with%20QR%20codes%20rendered%20using%20an%20HTML%20table/32606</a><br /> n8n vulnerabilities<br /> In recent days, several new n8n vulnerabilities were disclosed. Ensure that you update any on-premises installations and carefully consider what to use n8n for.<br /><a href="https://www.cyera.com/research-labs/ni8mare-unauthenticated-remote-code-execution-in-n8n-cve-2026-21858" target="_blank" rel="noreferrer noopener">https://www.cyera.com/research-labs/ni8mare-unauthenticated-remote-code-execution-in-n8n-cve-2026-21858</a><br /><a href="https://github.com/n8n-io/n8n/security/advisories/GHSA-v4pr-fm98-w9pg" target="_blank" rel="noreferrer noopener">https://github.com/n8n-io/n8n/security/advisories/GHSA-v4pr-fm98-w9pg</a><br /> Power bank feature creep is out of control <br /> Simple power banks are increasingly equipped with advanced features, including networking, which may expose them to security risks.<br /><a href="https://www.theverge.com/tech/856225/power-banks-are-the-latest-victims-of-feature-creep" target="_blank" rel="noreferrer noopener">https://www.theverge.com/tech/856225/power-banks-are-the-latest-victims-of-feature-creep</a><br />]]></itunes:summary><itunes:duration>443</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,html,infosec,internet,it,n8n,network,news,phishing,power banks,qr code,security,table</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9758</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, January 7th, 2026: Tailsnitch Review; D-Link DSL EoL Vuln; TOTOLINK Unpatched Vuln</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-january-7th-2026-tailsnitch-review-d-link-dsl-eol-vuln-totolink-unpatched-vuln--69331868</link><description><![CDATA[<br /> Tool Review: Tailsnitch<br /> Tailsnitch is a tool to audit your Tailscale configuration. It does a comprehensive analysis of your configuration and suggests (or even applies) fixes.<br /><a href="https://isc.sans.edu/diary/Tool%20Review%3A%20Tailsnitch/32602" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Tool%20Review%3A%20Tailsnitch/32602</a><br /> D-Link DSL Command Injection via DNS Configuration Endpoint<br /> A new vulnerability in very old D-Link DSL modems is currently being exploited.<br /><a href="https://www.vulncheck.com/advisories/dlink-dsl-command-injection-via-dns-configuration-endpoint" target="_blank" rel="noreferrer noopener">https://www.vulncheck.com/advisories/dlink-dsl-command-injection-via-dns-configuration-endpoint</a><br /> TOTOLINK EX200 firmware-upload error handling can activate an unauthenticated root telnet service<br /> TOTOLINK extenders may start a telnet server and allow unauthenticated access if a firmware update fails.<br /><a href="https://kb.cert.org/vuls/id/295169" target="_blank" rel="noreferrer noopener">https://kb.cert.org/vuls/id/295169</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9756.mp3</guid><pubDate>Wed, 07 Jan 2026 02:05:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69331868/9756.mp3" length="4815379" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9756" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Tool Review: Tailsnitch
 Tailsnitch is a tool to audit your Tailscale configuration. It does a comprehensive analysis of your configuration and suggests (or even applies) fixes.
https://isc.sans.edu/diary/Tool%20Review%3A%20Tailsnitch/32602
 D-Link...</itunes:subtitle><itunes:summary><![CDATA[<br /> Tool Review: Tailsnitch<br /> Tailsnitch is a tool to audit your Tailscale configuration. It does a comprehensive analysis of your configuration and suggests (or even applies) fixes.<br /><a href="https://isc.sans.edu/diary/Tool%20Review%3A%20Tailsnitch/32602" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Tool%20Review%3A%20Tailsnitch/32602</a><br /> D-Link DSL Command Injection via DNS Configuration Endpoint<br /> A new vulnerability in very old D-Link DSL modems is currently being exploited.<br /><a href="https://www.vulncheck.com/advisories/dlink-dsl-command-injection-via-dns-configuration-endpoint" target="_blank" rel="noreferrer noopener">https://www.vulncheck.com/advisories/dlink-dsl-command-injection-via-dns-configuration-endpoint</a><br /> TOTOLINK EX200 firmware-upload error handling can activate an unauthenticated root telnet service<br /> TOTOLINK extenders may start a telnet server and allow unauthenticated access if a firmware update fails.<br /><a href="https://kb.cert.org/vuls/id/295169" target="_blank" rel="noreferrer noopener">https://kb.cert.org/vuls/id/295169</a><br />]]></itunes:summary><itunes:duration>344</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,d-link,dsl,ex200,hacking,infosec,internet,it,network,news,security,tailscale,tailsnitch,totolink</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9756</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, January 6th, 2026: IPKVM Risks; Tailsnitch; Net-SNMP Vuln;</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-january-6th-2026-ipkvm-risks-tailsnitch-net-snmp-vuln--69314616</link><description><![CDATA[<br /> Risks of OOB Access via IP KVM Devices<br /> Recently, cheap IP KVMs have become popular. But their deployment needs to be secured.<br /><a href="https://isc.sans.edu/diary/Risks%20of%20OOB%20Access%20via%20IP%20KVM%20Devices/32598" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Risks%20of%20OOB%20Access%20via%20IP%20KVM%20Devices/32598</a><br /> Tailsnitch<br /> Tailsnitch is a tool to review your Tailscale configuration for vulnerabilities<br /><a href="https://github.com/Adversis/tailsnitch" target="_blank" rel="noreferrer noopener">https://github.com/Adversis/tailsnitch</a><br /> Net-SNMP snmptrapd vulnerability<br /> A new vulnerability in snmptrapd may lead to remote code execution<br /><a href="https://github.com/net-snmp/net-snmp/security/advisories/GHSA-4389-rwqf-q9gq" target="_blank" rel="noreferrer noopener">https://github.com/net-snmp/net-snmp/security/advisories/GHSA-4389-rwqf-q9gq</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9754.mp3</guid><pubDate>Tue, 06 Jan 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69314616/9754.mp3" length="5156016" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9754" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Risks of OOB Access via IP KVM Devices
 Recently, cheap IP KVMs have become popular. But their deployment needs to be secured.
https://isc.sans.edu/diary/Risks%20of%20OOB%20Access%20via%20IP%20KVM%20Devices/32598
 Tailsnitch
 Tailsnitch is a tool to...</itunes:subtitle><itunes:summary><![CDATA[<br /> Risks of OOB Access via IP KVM Devices<br /> Recently, cheap IP KVMs have become popular. But their deployment needs to be secured.<br /><a href="https://isc.sans.edu/diary/Risks%20of%20OOB%20Access%20via%20IP%20KVM%20Devices/32598" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Risks%20of%20OOB%20Access%20via%20IP%20KVM%20Devices/32598</a><br /> Tailsnitch<br /> Tailsnitch is a tool to review your Tailscale configuration for vulnerabilities<br /><a href="https://github.com/Adversis/tailsnitch" target="_blank" rel="noreferrer noopener">https://github.com/Adversis/tailsnitch</a><br /> Net-SNMP snmptrapd vulnerability<br /> A new vulnerability in snmptrapd may lead to remote code execution<br /><a href="https://github.com/net-snmp/net-snmp/security/advisories/GHSA-4389-rwqf-q9gq" target="_blank" rel="noreferrer noopener">https://github.com/net-snmp/net-snmp/security/advisories/GHSA-4389-rwqf-q9gq</a><br />]]></itunes:summary><itunes:duration>368</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,ipkvm,it,kvm,nanokvm,net-snmp,network,news,pikvm,security,snmp,tailscale,tailsnitch</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9754</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, January 5th, 2026: MongoBleed/React2Shell Recap; Crypto Scams; DNS Stats; Old Fortinet Vulns</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-january-5th-2026-mongobleed-react2shell-recap-crypto-scams-dns-stats-old-fortinet-vulns--69302136</link><description><![CDATA[<br /> Cryptocurrency Scam Emails and Web Pages As We Enter 2026<br /> Scam emails are directing victims to confidence scams attempting to steal cryptocurrencies.<br /><a href="https://isc.sans.edu/diary/Cryptocurrency%20Scam%20Emails%20and%20Web%20Pages%20As%20We%20Enter%202026/32594" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Cryptocurrency%20Scam%20Emails%20and%20Web%20Pages%20As%20We%20Enter%202026/32594</a><br /> Debugging DNS response times with tshark<br /> tshark is a powerful tool to debug DNS timing issues.<br /><a href="https://isc.sans.edu/diary/Debugging+DNS+response+times+with+tshark/32592/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Debugging+DNS+response+times+with+tshark/32592/</a><br /> Old Fortinet Devices Have not been updated<br /> Over 10,000 Fortinet devices are still vulnerable to a five year old vulnerability<br /><a href="https://www.bleepingcomputer.com/news/security/over-10-000-fortinet-firewalls-exposed-to-ongoing-2fa-bypass-attacks/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/over-10-000-fortinet-firewalls-exposed-to-ongoing-2fa-bypass-attacks/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9752.mp3</guid><pubDate>Mon, 05 Jan 2026 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69302136/9752.mp3" length="5842462" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9752" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Cryptocurrency Scam Emails and Web Pages As We Enter 2026
 Scam emails are directing victims to confidence scams attempting to steal cryptocurrencies....</itunes:subtitle><itunes:summary><![CDATA[<br /> Cryptocurrency Scam Emails and Web Pages As We Enter 2026<br /> Scam emails are directing victims to confidence scams attempting to steal cryptocurrencies.<br /><a href="https://isc.sans.edu/diary/Cryptocurrency%20Scam%20Emails%20and%20Web%20Pages%20As%20We%20Enter%202026/32594" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Cryptocurrency%20Scam%20Emails%20and%20Web%20Pages%20As%20We%20Enter%202026/32594</a><br /> Debugging DNS response times with tshark<br /> tshark is a powerful tool to debug DNS timing issues.<br /><a href="https://isc.sans.edu/diary/Debugging+DNS+response+times+with+tshark/32592/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Debugging+DNS+response+times+with+tshark/32592/</a><br /> Old Fortinet Devices Have not been updated<br /> Over 10,000 Fortinet devices are still vulnerable to a five year old vulnerability<br /><a href="https://www.bleepingcomputer.com/news/security/over-10-000-fortinet-firewalls-exposed-to-ongoing-2fa-bypass-attacks/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/over-10-000-fortinet-firewalls-exposed-to-ongoing-2fa-bypass-attacks/</a><br />]]></itunes:summary><itunes:duration>417</itunes:duration><itunes:keywords>business,computer,crypto,cyber,cybersecurity,daily,dns,fortinet,hacking,infosec,internet,it,network,news,security,tshark</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9752</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Sunday, December 28th, 2025: MongoDB Unauthenticated Memory Leak CVE-2025-14847</title><link>https://www.spreaker.com/episode/sans-stormcast-sunday-december-28th-2025-mongodb-unauthenticated-memory-leak-cve-2025-14847--69224827</link><description><![CDATA[<br /> MongoDB Unauthenticated Attacker Sensitive Memory Leak CVE-2025-14847<br /> Over the Christmas holiday, MongoDB patched a sensitive memory leak vulnerability that is now actively being exploited<br /><a href="https://www.mongodb.com/community/forums/t/important-mongodb-patch-available/332977" target="_blank" rel="noreferrer noopener">https://www.mongodb.com/community/forums/t/important-mongodb-patch-available/332977</a><br /><a href="https://github.com/mongodb/mongo/commit/505b660a14698bd2b5233bd94da3917b585c5728" target="_blank" rel="noreferrer noopener">https://github.com/mongodb/mongo/commit/505b660a14698bd2b5233bd94da3917b585c5728</a><br /><a href="https://www.ox.security/blog/attackers-could-exploit-zlib-to-exfiltrate-data-cve-2025-14847/" target="_blank" rel="noreferrer noopener">https://www.ox.security/blog/attackers-could-exploit-zlib-to-exfiltrate-data-cve-2025-14847/</a><br /><a href="https://github.com/joe-desimone/mongobleed/" target="_blank" rel="noreferrer noopener">https://github.com/joe-desimone/mongobleed/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9750.mp3</guid><pubDate>Sun, 28 Dec 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69224827/9750.mp3" length="4905326" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9750" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 MongoDB Unauthenticated Attacker Sensitive Memory Leak CVE-2025-14847
 Over the Christmas holiday, MongoDB patched a sensitive memory leak vulnerability that is now actively being exploited...</itunes:subtitle><itunes:summary><![CDATA[<br /> MongoDB Unauthenticated Attacker Sensitive Memory Leak CVE-2025-14847<br /> Over the Christmas holiday, MongoDB patched a sensitive memory leak vulnerability that is now actively being exploited<br /><a href="https://www.mongodb.com/community/forums/t/important-mongodb-patch-available/332977" target="_blank" rel="noreferrer noopener">https://www.mongodb.com/community/forums/t/important-mongodb-patch-available/332977</a><br /><a href="https://github.com/mongodb/mongo/commit/505b660a14698bd2b5233bd94da3917b585c5728" target="_blank" rel="noreferrer noopener">https://github.com/mongodb/mongo/commit/505b660a14698bd2b5233bd94da3917b585c5728</a><br /><a href="https://www.ox.security/blog/attackers-could-exploit-zlib-to-exfiltrate-data-cve-2025-14847/" target="_blank" rel="noreferrer noopener">https://www.ox.security/blog/attackers-could-exploit-zlib-to-exfiltrate-data-cve-2025-14847/</a><br /><a href="https://github.com/joe-desimone/mongobleed/" target="_blank" rel="noreferrer noopener">https://github.com/joe-desimone/mongobleed/</a><br />]]></itunes:summary><itunes:duration>351</itunes:duration><itunes:keywords>bleed,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,memory leak,mongodb,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9750</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, December 22nd, 2025: TLS Callbacks; FreeBSD RCE; NIST Time Server Issues</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-december-22nd-2025-tls-callbacks-freebsd-rce-nist-time-server-issues--69162179</link><description><![CDATA[<br /> DLLs &amp; TLS Callbacks<br /> As a follow-up to last week's diary about DLL Entrypoints, Didier is looking at TLS ( Thread Local Storage ) and how it can be abused.<br /><a href="https://isc.sans.edu/diary/DLLs%20%26%20TLS%20Callbacks/32580" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/DLLs%20%26%20TLS%20Callbacks/32580</a><br /> FreeBSD Remote code execution via ND6 Router Advertisements<br /> A critical vulnerability in FreeBSD allows for remote code execution. But an attacker must be on the same network.<br /><a href="https://www.freebsd.org/security/advisories/FreeBSD-SA-25:12.rtsold.asc" target="_blank" rel="noreferrer noopener">https://www.freebsd.org/security/advisories/FreeBSD-SA-25:12.rtsold.asc</a><br /> NIST Time Server Problems<br /> The atomic ensemble time scale at the NIST Boulder campus has failed due to a prolonged utility power outage. One impact is that the Boulder Internet Time Services no longer have an accurate time reference. <br /><a href="https://tf.nist.gov/tf-cgi/servers.cgi" target="_blank" rel="noreferrer noopener">https://tf.nist.gov/tf-cgi/servers.cgi</a> <a href="https://groups.google.com/a/list.nist.gov/g/internet-time-service/c/o0dDDcr1a8I" target="_blank" rel="noreferrer noopener">https://groups.google.com/a/list.nist.gov/g/internet-time-service/c/o0dDDcr1a8I</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9748.mp3</guid><pubDate>Mon, 22 Dec 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69162179/9748.mp3" length="5046389" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9748" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 DLLs &amp;amp; TLS Callbacks
 As a follow-up to last week's diary about DLL Entrypoints, Didier is looking at TLS ( Thread Local Storage ) and how it can be abused.
https://isc.sans.edu/diary/DLLs%20%26%20TLS%20Callbacks/32580
 FreeBSD Remote code...</itunes:subtitle><itunes:summary><![CDATA[<br /> DLLs &amp; TLS Callbacks<br /> As a follow-up to last week's diary about DLL Entrypoints, Didier is looking at TLS ( Thread Local Storage ) and how it can be abused.<br /><a href="https://isc.sans.edu/diary/DLLs%20%26%20TLS%20Callbacks/32580" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/DLLs%20%26%20TLS%20Callbacks/32580</a><br /> FreeBSD Remote code execution via ND6 Router Advertisements<br /> A critical vulnerability in FreeBSD allows for remote code execution. But an attacker must be on the same network.<br /><a href="https://www.freebsd.org/security/advisories/FreeBSD-SA-25:12.rtsold.asc" target="_blank" rel="noreferrer noopener">https://www.freebsd.org/security/advisories/FreeBSD-SA-25:12.rtsold.asc</a><br /> NIST Time Server Problems<br /> The atomic ensemble time scale at the NIST Boulder campus has failed due to a prolonged utility power outage. One impact is that the Boulder Internet Time Services no longer have an accurate time reference. <br /><a href="https://tf.nist.gov/tf-cgi/servers.cgi" target="_blank" rel="noreferrer noopener">https://tf.nist.gov/tf-cgi/servers.cgi</a> <a href="https://groups.google.com/a/list.nist.gov/g/internet-time-service/c/o0dDDcr1a8I" target="_blank" rel="noreferrer noopener">https://groups.google.com/a/list.nist.gov/g/internet-time-service/c/o0dDDcr1a8I</a><br />]]></itunes:summary><itunes:duration>361</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dll,freebsd,hacking,infosec,internet,ipv6,it,network,news,nist,rtsol,security,tls</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9748</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, December 19th, 2025: Less Vulnerabie Devices; Critical OneView Vulnerablity; Trufflehog finds JWTs</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-december-19th-2025-less-vulnerabie-devices-critical-oneview-vulnerablity-trufflehog-finds-jwts--69127321</link><description><![CDATA[<br /> Positive trends related to public IP range from the year 2025<br /> Fewer ICS systems, as well as fewer systems with outdated SSL versions, are exposed to the internet than before. The trend isn t quite clean for ISC, but SSL2 and SSL3 systems have been cut down by about half.<br /><a href="https://isc.sans.edu/diary/Positive%20trends%20related%20to%20public%20IP%20ranges%20from%20the%20year%202025/32584" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Positive%20trends%20related%20to%20public%20IP%20ranges%20from%20the%20year%202025/32584</a><br /> Hewlett-Packard Enterprise OneView Software, Remote Code Execution<br /> HPs OneView Software allows for unauthenticated code execution<br /><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04985en_us&amp;docLocale=en_US#vulnerability-summary-1" target="_blank" rel="noreferrer noopener">https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04985en_us&amp;docLocale=en_US#vulnerability-summary-1</a><br /> Trufflehog Detecting JWTs with Public Keys<br /> Trufflehog added the ability to detect JWT tokens and validate them using public keys.<br /><a href="https://trufflesecurity.com/blog/trufflehog-now-detects-jwts-with-public-key-signatures-and-verifies-them-for-liveness" target="_blank" rel="noreferrer noopener">https://trufflesecurity.com/blog/trufflehog-now-detects-jwts-with-public-key-signatures-and-verifies-them-for-liveness</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9746.mp3</guid><pubDate>Fri, 19 Dec 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69127321/9746.mp3" length="3886052" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9746" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Positive trends related to public IP range from the year 2025
 Fewer ICS systems, as well as fewer systems with outdated SSL versions, are exposed to the internet than before. The trend isn t quite clean for ISC, but SSL2 and SSL3 systems have been...</itunes:subtitle><itunes:summary><![CDATA[<br /> Positive trends related to public IP range from the year 2025<br /> Fewer ICS systems, as well as fewer systems with outdated SSL versions, are exposed to the internet than before. The trend isn t quite clean for ISC, but SSL2 and SSL3 systems have been cut down by about half.<br /><a href="https://isc.sans.edu/diary/Positive%20trends%20related%20to%20public%20IP%20ranges%20from%20the%20year%202025/32584" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Positive%20trends%20related%20to%20public%20IP%20ranges%20from%20the%20year%202025/32584</a><br /> Hewlett-Packard Enterprise OneView Software, Remote Code Execution<br /> HPs OneView Software allows for unauthenticated code execution<br /><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04985en_us&amp;docLocale=en_US#vulnerability-summary-1" target="_blank" rel="noreferrer noopener">https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04985en_us&amp;docLocale=en_US#vulnerability-summary-1</a><br /> Trufflehog Detecting JWTs with Public Keys<br /> Trufflehog added the ability to detect JWT tokens and validate them using public keys.<br /><a href="https://trufflesecurity.com/blog/trufflehog-now-detects-jwts-with-public-key-signatures-and-verifies-them-for-liveness" target="_blank" rel="noreferrer noopener">https://trufflesecurity.com/blog/trufflehog-now-detects-jwts-with-public-key-signatures-and-verifies-them-for-liveness</a><br />]]></itunes:summary><itunes:duration>278</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,hp,ics,infosec,internet,it,jwt,network,news,oneview,security,trufflehog</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9746</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, December 18th, 2025: More React2Shell; Donicwall and Cisco Patch; Updated Chrome Advisory</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-december-18th-2025-more-react2shell-donicwall-and-cisco-patch-updated-chrome-advisory--69109968</link><description><![CDATA[<br /> Maybe a Little Bit More Interesting React2Shell Exploit<br /> Attackers are branching out to attack applications that initial exploits may have missed. The latest wave of attacks is going after less common endpoints and attempting to exploit applications that do not have Next.js exposed.<br /><a href="https://isc.sans.edu/diary/Maybe%20a%20Little%20Bit%20More%20Interesting%20React2Shell%20Exploit/32578" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Maybe%20a%20Little%20Bit%20More%20Interesting%20React2Shell%20Exploit/32578</a><br /> UAT-9686 actively targets Cisco Secure Email Gateway and Secure Email and Web Manager<br /> Cisco s Security Email Gateway and Secure Email and Web Manager patch an already-exploited vulnerability.<br /><a href="https://blog.talosintelligence.com/uat-9686/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/uat-9686/</a><br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-attack-N9bf4" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-attack-N9bf4</a><br /> SONICWALL SMA1000 APPLIANCE LOCAL PRIVILEGE ESCALATION VULNERABILITY<br /> A local privilege escalation vulnerability, which SonicWall patched today, is already being exploited.<br /><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0019" target="_blank" rel="noreferrer noopener">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0019</a><br /> Google releases vulnerability details<br /> Google updated last week s advisory by adding a CVE to the  mystery vulnerability  and adding a statement that it affects WebGPU. No new patch was released.<br /><a href="https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_16.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_16.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9744.mp3</guid><pubDate>Thu, 18 Dec 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69109968/9744.mp3" length="5192416" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9744" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Maybe a Little Bit More Interesting React2Shell Exploit
 Attackers are branching out to attack applications that initial exploits may have missed. The latest wave of attacks is going after less common endpoints and attempting to exploit applications...</itunes:subtitle><itunes:summary><![CDATA[<br /> Maybe a Little Bit More Interesting React2Shell Exploit<br /> Attackers are branching out to attack applications that initial exploits may have missed. The latest wave of attacks is going after less common endpoints and attempting to exploit applications that do not have Next.js exposed.<br /><a href="https://isc.sans.edu/diary/Maybe%20a%20Little%20Bit%20More%20Interesting%20React2Shell%20Exploit/32578" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Maybe%20a%20Little%20Bit%20More%20Interesting%20React2Shell%20Exploit/32578</a><br /> UAT-9686 actively targets Cisco Secure Email Gateway and Secure Email and Web Manager<br /> Cisco s Security Email Gateway and Secure Email and Web Manager patch an already-exploited vulnerability.<br /><a href="https://blog.talosintelligence.com/uat-9686/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/uat-9686/</a><br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-attack-N9bf4" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-attack-N9bf4</a><br /> SONICWALL SMA1000 APPLIANCE LOCAL PRIVILEGE ESCALATION VULNERABILITY<br /> A local privilege escalation vulnerability, which SonicWall patched today, is already being exploited.<br /><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0019" target="_blank" rel="noreferrer noopener">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0019</a><br /> Google releases vulnerability details<br /> Google updated last week s advisory by adding a CVE to the  mystery vulnerability  and adding a statement that it affects WebGPU. No new patch was released.<br /><a href="https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_16.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_16.html</a><br />]]></itunes:summary><itunes:duration>371</itunes:duration><itunes:keywords>business,chrome,cisco,computer,cyber,cybersecurity,daily,google,hacking,infosec,internet,it,network,news,react2shell,security,sonicwall,webgpu</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9744</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, December 17th, 2025: Beyond RC4; Forticloud SSO Vuln Exploited; FortiGate SSO Exploited;</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-december-17th-2025-beyond-rc4-forticloud-sso-vuln-exploited-fortigate-sso-exploited--69088388</link><description><![CDATA[<br /> Beyond RC4 for Windows authentication<br /> Microsoft outlined its transition plan to move away from RC4 for authentication and published guidance and tools to facilitate this change.<br /><a href="https://www.microsoft.com/en-us/windows-server/blog/2025/12/03/beyond-rc4-for-windows-authentication" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/windows-server/blog/2025/12/03/beyond-rc4-for-windows-authentication</a><br /> FortiCloud SSO Login Vuln Exploited<br /> Arctic Wolf observed exploit attempts against vulnerable FortiGate appliances.<br /><a href="https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-sso-logins-following-disclosure-cve-2025-59718-cve-2025-59719/" target="_blank" rel="noreferrer noopener">https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-sso-logins-following-disclosure-cve-2025-59718-cve-2025-59719/</a><br /> FrePBX Vulnerability<br /> Horizon3.ai identified three distinct vulnerabilities in FreePBX. In particular, the authentication by-pass issue should be of concern, but default FreePBX installs do not use the vulnerable web authentication feature.<br /><a href="https://horizon3.ai/attack-research/the-freepbx-rabbit-hole-cve-2025-66039-and-others/" target="_blank" rel="noreferrer noopener">https://horizon3.ai/attack-research/the-freepbx-rabbit-hole-cve-2025-66039-and-others/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9742.mp3</guid><pubDate>Wed, 17 Dec 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69088388/9742.mp3" length="5577348" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9742" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Beyond RC4 for Windows authentication
 Microsoft outlined its transition plan to move away from RC4 for authentication and published guidance and tools to facilitate this change....</itunes:subtitle><itunes:summary><![CDATA[<br /> Beyond RC4 for Windows authentication<br /> Microsoft outlined its transition plan to move away from RC4 for authentication and published guidance and tools to facilitate this change.<br /><a href="https://www.microsoft.com/en-us/windows-server/blog/2025/12/03/beyond-rc4-for-windows-authentication" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/windows-server/blog/2025/12/03/beyond-rc4-for-windows-authentication</a><br /> FortiCloud SSO Login Vuln Exploited<br /> Arctic Wolf observed exploit attempts against vulnerable FortiGate appliances.<br /><a href="https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-sso-logins-following-disclosure-cve-2025-59718-cve-2025-59719/" target="_blank" rel="noreferrer noopener">https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-sso-logins-following-disclosure-cve-2025-59718-cve-2025-59719/</a><br /> FrePBX Vulnerability<br /> Horizon3.ai identified three distinct vulnerabilities in FreePBX. In particular, the authentication by-pass issue should be of concern, but default FreePBX installs do not use the vulnerable web authentication feature.<br /><a href="https://horizon3.ai/attack-research/the-freepbx-rabbit-hole-cve-2025-66039-and-others/" target="_blank" rel="noreferrer noopener">https://horizon3.ai/attack-research/the-freepbx-rabbit-hole-cve-2025-66039-and-others/</a><br />]]></itunes:summary><itunes:duration>398</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,fortinet,freepbx,hacking,infosec,internet,it,microsoft,network,news,rc4,saml,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9742</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, December 16th, 2025: Current React2Shell Example; SAML woes; MSMQ issues after patch;</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-december-16th-2025-current-react2shell-example-saml-woes-msmq-issues-after-patch--69068268</link><description><![CDATA[<br /> More React2Shell Exploits CVE-2025-55182<br /> Our honeypots continue to detect numerous React2Shell variants. Some using slightly modified exploits<br /><a href="https://isc.sans.edu/diary/More%20React2Shell%20Exploits%20CVE-2025-55182/32572" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/More%20React2Shell%20Exploits%20CVE-2025-55182/32572</a><br /> The Fragile Lock: Novel Bypasses For SAML Authentication<br /> SAML is a tricky protocol to implement correctly, in particular if different XML parsers are used that may not always agree on how to parse a specific message<br /><a href="https://portswigger.net/research/the-fragile-lock" target="_blank" rel="noreferrer noopener">https://portswigger.net/research/the-fragile-lock</a><br /> December Updates Causes issues with Microsoft Message Queuing<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-22h2#message-queuing--msmq--might-fail-with-the-december-2025-windows-security-update" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-22h2#message-queuing--msmq--might-fail-with-the-december-2025-windows-security-update</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9740.mp3</guid><pubDate>Tue, 16 Dec 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69068268/9740.mp3" length="4836586" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9740" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 More React2Shell Exploits CVE-2025-55182
 Our honeypots continue to detect numerous React2Shell variants. Some using slightly modified exploits
https://isc.sans.edu/diary/More%20React2Shell%20Exploits%20CVE-2025-55182/32572
 The Fragile Lock: Novel...</itunes:subtitle><itunes:summary><![CDATA[<br /> More React2Shell Exploits CVE-2025-55182<br /> Our honeypots continue to detect numerous React2Shell variants. Some using slightly modified exploits<br /><a href="https://isc.sans.edu/diary/More%20React2Shell%20Exploits%20CVE-2025-55182/32572" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/More%20React2Shell%20Exploits%20CVE-2025-55182/32572</a><br /> The Fragile Lock: Novel Bypasses For SAML Authentication<br /> SAML is a tricky protocol to implement correctly, in particular if different XML parsers are used that may not always agree on how to parse a specific message<br /><a href="https://portswigger.net/research/the-fragile-lock" target="_blank" rel="noreferrer noopener">https://portswigger.net/research/the-fragile-lock</a><br /> December Updates Causes issues with Microsoft Message Queuing<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-22h2#message-queuing--msmq--might-fail-with-the-december-2025-windows-security-update" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-22h2#message-queuing--msmq--might-fail-with-the-december-2025-windows-security-update</a><br />]]></itunes:summary><itunes:duration>346</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,message queue,msmq,network,news,patch,react2shell,ruby,saml,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9740</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, December 15th, 2025: DLL Entry Points; ClickFix and Finger; Apple Patches</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-december-15th-2025-dll-entry-points-clickfix-and-finger-apple-patches--69048381</link><description><![CDATA[<br /> Abusing DLLs EntryPoint for the Fun<br /> DLLs will not just execute code when some of their functions are called, but also as they are loaded.<br /><a href="https://isc.sans.edu/diary/Abusing%20DLLs%20EntryPoint%20for%20the%20Fun/32562" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Abusing%20DLLs%20EntryPoint%20for%20the%20Fun/32562</a><br /> Apple Patches Everything: December 2025 Edition<br /> Apple released patches for all of its operating systems, fixing two already exploited vulnerabilities.<br /> ClickFix Attacks Still Using the Finger<br /> ClickFix Attacks Still Using the Finger<br /> Two examples of ClickFix attacks abusing the finger protocol to load additional malware<br /> Denial of Service and Source Code Exposure in React Server Components<br /> Denial of Service and Source Code Exposure in React Server Components<br /> After last week's critical patch, three more, but less critical, vulnerabilities were identified in React Server Components.<br /><a href="https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components" target="_blank" rel="noreferrer noopener">https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9738.mp3</guid><pubDate>Mon, 15 Dec 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69048381/9738.mp3" length="5669242" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9738" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Abusing DLLs EntryPoint for the Fun
 DLLs will not just execute code when some of their functions are called, but also as they are loaded.
https://isc.sans.edu/diary/Abusing%20DLLs%20EntryPoint%20for%20the%20Fun/32562
 Apple Patches Everything:...</itunes:subtitle><itunes:summary><![CDATA[<br /> Abusing DLLs EntryPoint for the Fun<br /> DLLs will not just execute code when some of their functions are called, but also as they are loaded.<br /><a href="https://isc.sans.edu/diary/Abusing%20DLLs%20EntryPoint%20for%20the%20Fun/32562" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Abusing%20DLLs%20EntryPoint%20for%20the%20Fun/32562</a><br /> Apple Patches Everything: December 2025 Edition<br /> Apple released patches for all of its operating systems, fixing two already exploited vulnerabilities.<br /> ClickFix Attacks Still Using the Finger<br /> ClickFix Attacks Still Using the Finger<br /> Two examples of ClickFix attacks abusing the finger protocol to load additional malware<br /> Denial of Service and Source Code Exposure in React Server Components<br /> Denial of Service and Source Code Exposure in React Server Components<br /> After last week's critical patch, three more, but less critical, vulnerabilities were identified in React Server Components.<br /><a href="https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components" target="_blank" rel="noreferrer noopener">https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components</a><br />]]></itunes:summary><itunes:duration>405</itunes:duration><itunes:keywords>apple,business,clickfix,computer,cyber,cybersecurity,daily,dll,entrypoint,finger,hacking,infosec,internet,it,network,news,react,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9738</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, December 12th, 2025: Local AI Models; Mystery Chrome 0-Day; SOAPwn Attack</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-december-12th-2025-local-ai-models-mystery-chrome-0-day-soapwn-attack--69000880</link><description><![CDATA[<br /> Using AI Gemma 3 Locally with a Single CPU<br /> Installing AI models on modes hardware is possible and can be useful to experiment with these models on premise<br /><a href="https://isc.sans.edu/diary/Using%20AI%20Gemma%203%20Locally%20with%20a%20Single%20CPU%20/32556" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Using%20AI%20Gemma%203%20Locally%20with%20a%20Single%20CPU%20/32556</a><br />  Mystery  Google Chrome 0-Day Vulnerability<br /> Google released an update for Google Chrome fixing a vulnerability that is already being exploited, but has not CVE number assigned to it yet<br /><a href="https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_10.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_10.html</a><br /> SOAPwn: Pwning NET Framework Applications Through HTTP Client Proxies And WSDL<br /> Watchtwr identified a common vulnerability in SOAP implementations using .Net<br /><a href="https://labs.watchtowr.com/soapwn-pwning-net-framework-applications-through-http-client-proxies-and-wsdl/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/soapwn-pwning-net-framework-applications-through-http-client-proxies-and-wsdl/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9736.mp3</guid><pubDate>Fri, 12 Dec 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69000880/9736.mp3" length="5825280" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9736" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Using AI Gemma 3 Locally with a Single CPU
 Installing AI models on modes hardware is possible and can be useful to experiment with these models on premise...</itunes:subtitle><itunes:summary><![CDATA[<br /> Using AI Gemma 3 Locally with a Single CPU<br /> Installing AI models on modes hardware is possible and can be useful to experiment with these models on premise<br /><a href="https://isc.sans.edu/diary/Using%20AI%20Gemma%203%20Locally%20with%20a%20Single%20CPU%20/32556" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Using%20AI%20Gemma%203%20Locally%20with%20a%20Single%20CPU%20/32556</a><br />  Mystery  Google Chrome 0-Day Vulnerability<br /> Google released an update for Google Chrome fixing a vulnerability that is already being exploited, but has not CVE number assigned to it yet<br /><a href="https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_10.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_10.html</a><br /> SOAPwn: Pwning NET Framework Applications Through HTTP Client Proxies And WSDL<br /> Watchtwr identified a common vulnerability in SOAP implementations using .Net<br /><a href="https://labs.watchtowr.com/soapwn-pwning-net-framework-applications-through-http-client-proxies-and-wsdl/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/soapwn-pwning-net-framework-applications-through-http-client-proxies-and-wsdl/</a><br />]]></itunes:summary><itunes:duration>416</itunes:duration><itunes:keywords>ai,business,chrome,computer,cyber,cybersecurity,daily,gemma,google,hacking,infosec,internet,it,net,network,news,security,soap,soapwn</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9736</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, December 11th, 2025: Possible CVE-2024-9042 variant; react2shell exploits; notepad++ update hijacking; macOS priv e</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-december-11th-2025-possible-cve-2024-9042-variant-react2shell-exploits-notepad-update-hijacking-macos-priv-e--68984948</link><description><![CDATA[<br /> Possible exploit variant for CVE-2024-9042 (Kubernetes OS Command Injection)<br /> We observed HTTP requests with our honeypot that may be indicative of a new version of an exploit against an older vulnerability. Help us figure out what is going on.<br /><a href="https://isc.sans.edu/diary/Possible%20exploit%20variant%20for%20CVE-2024-9042%20%28Kubernetes%20OS%20Command%20Injection%29/32554" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Possible%20exploit%20variant%20for%20CVE-2024-9042%20%28Kubernetes%20OS%20Command%20Injection%29/32554</a><br /> React2Shell: Technical Deep-Dive &amp; In-the-Wild Exploitation of CVE-2025-55182<br /> Wiz has a writeup with more background on the React2Shell vulnerability and current attacks<br /><a href="https://www.wiz.io/blog/nextjs-cve-2025-55182-react2shell-deep-dive" target="_blank" rel="noreferrer noopener">https://www.wiz.io/blog/nextjs-cve-2025-55182-react2shell-deep-dive</a><br /> Notepad++ Update Hijacking<br /> Notepad++ s vulnerable update process was exploited <br /><a href="https://notepad-plus-plus.org/news/v889-released/" target="_blank" rel="noreferrer noopener">https://notepad-plus-plus.org/news/v889-released/</a><br /> New macOS PackageKit Privilege Escalation<br /> A PoC was released for a new privilege escalation vulnerability in macOS. Currently, there is no patch.<br /><a href="https://khronokernel.com/macos/2024/06/03/CVE-2024-27822.html" target="_blank" rel="noreferrer noopener">https://khronokernel.com/macos/2024/06/03/CVE-2024-27822.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9734.mp3</guid><pubDate>Thu, 11 Dec 2025 01:48:20 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68984948/9734.mp3" length="5855058" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9734" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Possible exploit variant for CVE-2024-9042 (Kubernetes OS Command Injection)
 We observed HTTP requests with our honeypot that may be indicative of a new version of an exploit against an older vulnerability. Help us figure out what is going on....</itunes:subtitle><itunes:summary><![CDATA[<br /> Possible exploit variant for CVE-2024-9042 (Kubernetes OS Command Injection)<br /> We observed HTTP requests with our honeypot that may be indicative of a new version of an exploit against an older vulnerability. Help us figure out what is going on.<br /><a href="https://isc.sans.edu/diary/Possible%20exploit%20variant%20for%20CVE-2024-9042%20%28Kubernetes%20OS%20Command%20Injection%29/32554" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Possible%20exploit%20variant%20for%20CVE-2024-9042%20%28Kubernetes%20OS%20Command%20Injection%29/32554</a><br /> React2Shell: Technical Deep-Dive &amp; In-the-Wild Exploitation of CVE-2025-55182<br /> Wiz has a writeup with more background on the React2Shell vulnerability and current attacks<br /><a href="https://www.wiz.io/blog/nextjs-cve-2025-55182-react2shell-deep-dive" target="_blank" rel="noreferrer noopener">https://www.wiz.io/blog/nextjs-cve-2025-55182-react2shell-deep-dive</a><br /> Notepad++ Update Hijacking<br /> Notepad++ s vulnerable update process was exploited <br /><a href="https://notepad-plus-plus.org/news/v889-released/" target="_blank" rel="noreferrer noopener">https://notepad-plus-plus.org/news/v889-released/</a><br /> New macOS PackageKit Privilege Escalation<br /> A PoC was released for a new privilege escalation vulnerability in macOS. Currently, there is no patch.<br /><a href="https://khronokernel.com/macos/2024/06/03/CVE-2024-27822.html" target="_blank" rel="noreferrer noopener">https://khronokernel.com/macos/2024/06/03/CVE-2024-27822.html</a><br />]]></itunes:summary><itunes:duration>418</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,evilgrade,exploit,hacking,infosec,internet,it,kubernetes,macos,network,news,notepad++,privilege escalation,react2shell,security,zsh</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9734</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, December 10th, 2025: Microsoft, Adobe, Ivanti, Fortinet, and Ruby patches.</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-december-10th-2025-microsoft-adobe-ivanti-fortinet-and-ruby-patches--68968600</link><description><![CDATA[<br /> Microsoft Patch Tuesday<br /> Microsoft released its regular monthly patch on Tuesday, addressing 57 flaws.<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20December%202025/32550" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20December%202025/32550</a><br /> Adobe Patches<br /> Adobe patched five products. The remote code execution in ColdFusion, as well as the code execution issue in Acrobat, will very likely see exploits soon.<br /><a href="https://helpx.adobe.com/security.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security.html</a><br /> Ivanti Endpoint Manager Patches<br /> Ivanti patched four vulnerabilities in End Point Manager.<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-EPM-December-2025-for-EPM-2024?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-EPM-December-2025-for-EPM-2024?language=en_US</a><br /> Fortinet FortiCloud SSO Vulnerability<br /> Due to a cryptographic vulnerability, Forinet s FortiCloud SSO authentication is bypassable.<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-647" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-25-647</a><br /> ruby-saml vulnerability<br /> Ruby fixed a vulnerability in ruby-saml. The issue is due to an incomplete patch for another vulnerability a few months ago.<br /><a href="https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-9v8j-x534-2fx3" target="_blank" rel="noreferrer noopener">https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-9v8j-x534-2fx3</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9732.mp3</guid><pubDate>Wed, 10 Dec 2025 00:35:23 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68968600/9732.mp3" length="6775273" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9732" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Microsoft Patch Tuesday
 Microsoft released its regular monthly patch on Tuesday, addressing 57 flaws.
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20December%202025/32550
 Adobe Patches
 Adobe patched five products. The remote code...</itunes:subtitle><itunes:summary><![CDATA[<br /> Microsoft Patch Tuesday<br /> Microsoft released its regular monthly patch on Tuesday, addressing 57 flaws.<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20December%202025/32550" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20December%202025/32550</a><br /> Adobe Patches<br /> Adobe patched five products. The remote code execution in ColdFusion, as well as the code execution issue in Acrobat, will very likely see exploits soon.<br /><a href="https://helpx.adobe.com/security.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security.html</a><br /> Ivanti Endpoint Manager Patches<br /> Ivanti patched four vulnerabilities in End Point Manager.<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-EPM-December-2025-for-EPM-2024?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-EPM-December-2025-for-EPM-2024?language=en_US</a><br /> Fortinet FortiCloud SSO Vulnerability<br /> Due to a cryptographic vulnerability, Forinet s FortiCloud SSO authentication is bypassable.<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-647" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-25-647</a><br /> ruby-saml vulnerability<br /> Ruby fixed a vulnerability in ruby-saml. The issue is due to an incomplete patch for another vulnerability a few months ago.<br /><a href="https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-9v8j-x534-2fx3" target="_blank" rel="noreferrer noopener">https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-9v8j-x534-2fx3</a><br />]]></itunes:summary><itunes:duration>484</itunes:duration><itunes:keywords>adobe,business,computer,cyber,cybersecurity,daily,forticloud,fortinet,hacking,infosec,it,ivanti,microsoft,network,news,patches,ruby,saml,security,sso</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9732</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, December 9th, 2025: nanoKVM Vulnerabilities; Ghostframe Phishing; WatchGuard Advisory</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-december-9th-2025-nanokvm-vulnerabilities-ghostframe-phishing-watchguard-advisory--68953046</link><description><![CDATA[<br /> nanoKVM Vulnerabilities<br /> The nanoKVM device updates firmware insecurely; however, the microphone that the authors of the advisory referred to as  undocumented  may actually be documented in the underlying hardware description.<br /><a href="https://www.tomshardware.com/tech-industry/cyber-security/researcher-finds-undocumented-microphone-and-major-security-flaws-in-sipeed-nanokvm" target="_blank" rel="noreferrer noopener">https://www.tomshardware.com/tech-industry/cyber-security/researcher-finds-undocumented-microphone-and-major-security-flaws-in-sipeed-nanokvm</a><br /> Ghostframe Phishing Kit<br /> The Ghostframe phishing kit uses iFrames and random subdomains to evade detection<br /><a href="https://blog.barracuda.com/2025/12/04/threat-spotlight-ghostframe-phishing-kit" target="_blank" rel="noreferrer noopener">https://blog.barracuda.com/2025/12/04/threat-spotlight-ghostframe-phishing-kit</a><br /> WatchGuard Advisory<br /> WatchGuard released an update for its Firebox appliance, fixing ten vulnerabilities. Five of these are rated as  High. <br /><a href="https://www.watchguard.com/wgrd-psirt/advisories" target="_blank" rel="noreferrer noopener">https://www.watchguard.com/wgrd-psirt/advisories</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9730.mp3</guid><pubDate>Tue, 09 Dec 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68953046/9730.mp3" length="5407924" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9730" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 nanoKVM Vulnerabilities
 The nanoKVM device updates firmware insecurely; however, the microphone that the authors of the advisory referred to as  undocumented  may actually be documented in the underlying hardware description....</itunes:subtitle><itunes:summary><![CDATA[<br /> nanoKVM Vulnerabilities<br /> The nanoKVM device updates firmware insecurely; however, the microphone that the authors of the advisory referred to as  undocumented  may actually be documented in the underlying hardware description.<br /><a href="https://www.tomshardware.com/tech-industry/cyber-security/researcher-finds-undocumented-microphone-and-major-security-flaws-in-sipeed-nanokvm" target="_blank" rel="noreferrer noopener">https://www.tomshardware.com/tech-industry/cyber-security/researcher-finds-undocumented-microphone-and-major-security-flaws-in-sipeed-nanokvm</a><br /> Ghostframe Phishing Kit<br /> The Ghostframe phishing kit uses iFrames and random subdomains to evade detection<br /><a href="https://blog.barracuda.com/2025/12/04/threat-spotlight-ghostframe-phishing-kit" target="_blank" rel="noreferrer noopener">https://blog.barracuda.com/2025/12/04/threat-spotlight-ghostframe-phishing-kit</a><br /> WatchGuard Advisory<br /> WatchGuard released an update for its Firebox appliance, fixing ten vulnerabilities. Five of these are rated as  High. <br /><a href="https://www.watchguard.com/wgrd-psirt/advisories" target="_blank" rel="noreferrer noopener">https://www.watchguard.com/wgrd-psirt/advisories</a><br />]]></itunes:summary><itunes:duration>386</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,ghostframe,hacking,infosec,internet,it,kvm,nanokvm,network,news,security,sipeed,watchguard</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9730</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, December 8th, 2025: AutoIT3 FileInstall; React2Shell Update; Tika Vuln</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-december-8th-2025-autoit3-fileinstall-react2shell-update-tika-vuln--68942976</link><description><![CDATA[<br /> AutoIT3 Compiled Scripts Dropping Shellcodes<br /> Malicious AutoIT3 scripts are usign the  FileInstall  function to include additional scripts at compile time that are dropped as temporary files during execution.<br /><a href="https://isc.sans.edu/diary/AutoIT3%20Compiled%20Scripts%20Dropping%20Shellcodes/32542" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/AutoIT3%20Compiled%20Scripts%20Dropping%20Shellcodes/32542</a><br /> React2Shell Update<br /> The race is on to patch vulnerable systems. Various groups are aggressively scanning the internet with different exploit variants. Some attempt to bypass WAFs. <br /><a href="https://blog.cloudflare.com/5-december-2025-outage/" target="_blank" rel="noreferrer noopener">https://blog.cloudflare.com/5-december-2025-outage/</a><br /><a href="https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/" target="_blank" rel="noreferrer noopener">https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/</a><br /> Apache Tika XXE Flaw<br /> Apache s Tika library patched a XXE flaw.<br /><a href="https://lists.apache.org/thread/s5x3k93nhbkqzztp1olxotoyjpdlps9k" target="_blank" rel="noreferrer noopener">https://lists.apache.org/thread/s5x3k93nhbkqzztp1olxotoyjpdlps9k</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9728.mp3</guid><pubDate>Mon, 08 Dec 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68942976/9728.mp3" length="4682717" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9728" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 AutoIT3 Compiled Scripts Dropping Shellcodes
 Malicious AutoIT3 scripts are usign the  FileInstall  function to include additional scripts at compile time that are dropped as temporary files during execution....</itunes:subtitle><itunes:summary><![CDATA[<br /> AutoIT3 Compiled Scripts Dropping Shellcodes<br /> Malicious AutoIT3 scripts are usign the  FileInstall  function to include additional scripts at compile time that are dropped as temporary files during execution.<br /><a href="https://isc.sans.edu/diary/AutoIT3%20Compiled%20Scripts%20Dropping%20Shellcodes/32542" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/AutoIT3%20Compiled%20Scripts%20Dropping%20Shellcodes/32542</a><br /> React2Shell Update<br /> The race is on to patch vulnerable systems. Various groups are aggressively scanning the internet with different exploit variants. Some attempt to bypass WAFs. <br /><a href="https://blog.cloudflare.com/5-december-2025-outage/" target="_blank" rel="noreferrer noopener">https://blog.cloudflare.com/5-december-2025-outage/</a><br /><a href="https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/" target="_blank" rel="noreferrer noopener">https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/</a><br /> Apache Tika XXE Flaw<br /> Apache s Tika library patched a XXE flaw.<br /><a href="https://lists.apache.org/thread/s5x3k93nhbkqzztp1olxotoyjpdlps9k" target="_blank" rel="noreferrer noopener">https://lists.apache.org/thread/s5x3k93nhbkqzztp1olxotoyjpdlps9k</a><br />]]></itunes:summary><itunes:duration>335</itunes:duration><itunes:keywords>apache,autoit,autoit3,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,react,security,tika</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9728</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, December 5th, 2025: Compromised Govt System; React Vuln Update; Array Networks VPN Attacks</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-december-5th-2025-compromised-govt-system-react-vuln-update-array-networks-vpn-attacks--68898761</link><description><![CDATA[<br /> Nation-State Attack or Compromised Government? [Guest Diary]<br /> An IP address associated with the Indonesian Government attacked one of our interns' honeypots. <br /><a href="https://isc.sans.edu/diary/Nation-State%20Attack%20or%20Compromised%20Government%3F%20%5BGuest%20Diary%5D/32536" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Nation-State%20Attack%20or%20Compromised%20Government%3F%20%5BGuest%20Diary%5D/32536</a><br /> React Update<br /> Working exploits for the React vulnerability patched yesterday are not widely available<br /> Array Networks Array AG Vulnerablity<br /> A recently patched vulnerability in Array Networks  Array AG VPN gateways is actively exploited.<br /><a href="https://www.jpcert.or.jp/at/2025/at250024.html" target="_blank" rel="noreferrer noopener">https://www.jpcert.or.jp/at/2025/at250024.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9726.mp3</guid><pubDate>Fri, 05 Dec 2025 02:05:17 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68898761/9726.mp3" length="3849929" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9726" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Nation-State Attack or Compromised Government? [Guest Diary]
 An IP address associated with the Indonesian Government attacked one of our interns' honeypots....</itunes:subtitle><itunes:summary><![CDATA[<br /> Nation-State Attack or Compromised Government? [Guest Diary]<br /> An IP address associated with the Indonesian Government attacked one of our interns' honeypots. <br /><a href="https://isc.sans.edu/diary/Nation-State%20Attack%20or%20Compromised%20Government%3F%20%5BGuest%20Diary%5D/32536" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Nation-State%20Attack%20or%20Compromised%20Government%3F%20%5BGuest%20Diary%5D/32536</a><br /> React Update<br /> Working exploits for the React vulnerability patched yesterday are not widely available<br /> Array Networks Array AG Vulnerablity<br /> A recently patched vulnerability in Array Networks  Array AG VPN gateways is actively exploited.<br /><a href="https://www.jpcert.or.jp/at/2025/at250024.html" target="_blank" rel="noreferrer noopener">https://www.jpcert.or.jp/at/2025/at250024.html</a><br />]]></itunes:summary><itunes:duration>275</itunes:duration><itunes:keywords>array networks,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,react,security,ssh,vpn</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9726</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, December 4th, 2025: CDN Headers; React Vulnerabiity; PickleScan Patch</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-december-4th-2025-cdn-headers-react-vulnerabiity-picklescan-patch--68868562</link><description><![CDATA[<br /> Attempts to Bypass CDNs<br /> Our honeypots recently started receiving scans that included CDN specific headers.<br /><a href="https://isc.sans.edu/diary/Attempts%20to%20Bypass%20CDNs/32532" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Attempts%20to%20Bypass%20CDNs/32532</a><br /> React Vulnerability CVE-2025-55182<br /> React patched a critical vulnerability in React server components. Exploitation is likely imminent.<br /><a href="https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components" target="_blank" rel="noreferrer noopener">https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components</a><br /> Unveiling 3 PickleScan Vulnerabilities<br /> The PyTorch AI model security tool, PickleScan, has patched three critical vulnerabilities.<br /><a href="https://jfrog.com/blog/unveiling-3-zero-day-vulnerabilities-in-picklescan/" target="_blank" rel="noreferrer noopener">https://jfrog.com/blog/unveiling-3-zero-day-vulnerabilities-in-picklescan/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9724.mp3</guid><pubDate>Thu, 04 Dec 2025 03:10:12 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68868562/9724.mp3" length="5664008" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9724" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Attempts to Bypass CDNs
 Our honeypots recently started receiving scans that included CDN specific headers.
https://isc.sans.edu/diary/Attempts%20to%20Bypass%20CDNs/32532
 React Vulnerability CVE-2025-55182
 React patched a critical vulnerability in...</itunes:subtitle><itunes:summary><![CDATA[<br /> Attempts to Bypass CDNs<br /> Our honeypots recently started receiving scans that included CDN specific headers.<br /><a href="https://isc.sans.edu/diary/Attempts%20to%20Bypass%20CDNs/32532" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Attempts%20to%20Bypass%20CDNs/32532</a><br /> React Vulnerability CVE-2025-55182<br /> React patched a critical vulnerability in React server components. Exploitation is likely imminent.<br /><a href="https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components" target="_blank" rel="noreferrer noopener">https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components</a><br /> Unveiling 3 PickleScan Vulnerabilities<br /> The PyTorch AI model security tool, PickleScan, has patched three critical vulnerabilities.<br /><a href="https://jfrog.com/blog/unveiling-3-zero-day-vulnerabilities-in-picklescan/" target="_blank" rel="noreferrer noopener">https://jfrog.com/blog/unveiling-3-zero-day-vulnerabilities-in-picklescan/</a><br />]]></itunes:summary><itunes:duration>405</itunes:duration><itunes:keywords>business,cdn,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,picklescan,pytorch,react,security,server components</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9724</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, December 3rd, 2025: SmartTube Compromise; NPM Malware Prompt Injection Attempt; Angular XSS Vulnerability</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-december-3rd-2025-smarttube-compromise-npm-malware-prompt-injection-attempt-angular-xss-vulnerability--68842455</link><description><![CDATA[<br /> SmartTube Android App Compromise<br /> The key a developer used to sign the Android YouTube player SmartTube was compromised and used to publish a malicious version.<br /><a href="https://github.com/yuliskov/SmartTube/issues/5131#issue-3670629826" target="_blank" rel="noreferrer noopener">https://github.com/yuliskov/SmartTube/issues/5131#issue-3670629826</a><br /><a href="https://github.com/yuliskov/SmartTube/releases/tag/notification" target="_blank" rel="noreferrer noopener">https://github.com/yuliskov/SmartTube/releases/tag/notification</a><br /> Two Years, 17K Downloads: The NPM Malware That Tried to Gaslight Security Scanners<br /> Over the course of two years, a malicious NPM package was updated to evade detection and has now been identified, in part, due to its attempt to bypass AI scanners through prompt injection.<br /><a href="https://www.koi.ai/blog/two-years-17k-downloads-the-npm-malware-that-tried-to-gaslight-security-scanners" target="_blank" rel="noreferrer noopener">https://www.koi.ai/blog/two-years-17k-downloads-the-npm-malware-that-tried-to-gaslight-security-scanners</a><br /> Stored XSS Vulnerability via SVG Animation, SVG URL, and MathML Attributes<br /> Angular fixed a store XSS vulnerability.<br /><a href="https://github.com/angular/angular/security/advisories/GHSA-v4hv-rgfq-gp49" target="_blank" rel="noreferrer noopener">https://github.com/angular/angular/security/advisories/GHSA-v4hv-rgfq-gp49</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9722.mp3</guid><pubDate>Wed, 03 Dec 2025 02:45:11 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68842455/9722.mp3" length="5125863" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9722" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 SmartTube Android App Compromise
 The key a developer used to sign the Android YouTube player SmartTube was compromised and used to publish a malicious version.
https://github.com/yuliskov/SmartTube/issues/5131#issue-3670629826...</itunes:subtitle><itunes:summary><![CDATA[<br /> SmartTube Android App Compromise<br /> The key a developer used to sign the Android YouTube player SmartTube was compromised and used to publish a malicious version.<br /><a href="https://github.com/yuliskov/SmartTube/issues/5131#issue-3670629826" target="_blank" rel="noreferrer noopener">https://github.com/yuliskov/SmartTube/issues/5131#issue-3670629826</a><br /><a href="https://github.com/yuliskov/SmartTube/releases/tag/notification" target="_blank" rel="noreferrer noopener">https://github.com/yuliskov/SmartTube/releases/tag/notification</a><br /> Two Years, 17K Downloads: The NPM Malware That Tried to Gaslight Security Scanners<br /> Over the course of two years, a malicious NPM package was updated to evade detection and has now been identified, in part, due to its attempt to bypass AI scanners through prompt injection.<br /><a href="https://www.koi.ai/blog/two-years-17k-downloads-the-npm-malware-that-tried-to-gaslight-security-scanners" target="_blank" rel="noreferrer noopener">https://www.koi.ai/blog/two-years-17k-downloads-the-npm-malware-that-tried-to-gaslight-security-scanners</a><br /> Stored XSS Vulnerability via SVG Animation, SVG URL, and MathML Attributes<br /> Angular fixed a store XSS vulnerability.<br /><a href="https://github.com/angular/angular/security/advisories/GHSA-v4hv-rgfq-gp49" target="_blank" rel="noreferrer noopener">https://github.com/angular/angular/security/advisories/GHSA-v4hv-rgfq-gp49</a><br />]]></itunes:summary><itunes:duration>366</itunes:duration><itunes:keywords>angular,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,mathml,network,news,npm,security,smarttube,svg,xss</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9722</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, December 2nd, 2025: Analyzing ToolShell from Packdets; Android Update; Long Game Malicious Browser Ext.</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-december-2nd-2025-analyzing-toolshell-from-packdets-android-update-long-game-malicious-browser-ext--68826314</link><description><![CDATA[<br /> Hunting for SharePoint In-Memory ToolShell Payloads<br /> A walk-through showing how to analyze ToolShell payloads, starting with acquiring packets all the way to decoding embedded PowerShell commands.<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Hunting%20for%20SharePoint%20In-Memory%20ToolShell%20Payloads/32524" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Hunting%20for%20SharePoint%20In-Memory%20ToolShell%20Payloads/32524</a><br /> Android Security Bulletin December 2025<br /> Google fixed numerous vulnerabilities with its December Android update. Two of these vulnerabilities are already being exploited.<br /><a href="https://source.android.com/docs/security/bulletin/2025-12-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2025-12-01</a><br /> 4.3 Million Browsers Infected: Inside ShadyPanda's 7-Year Malware Campaign<br /> A group or individual released several browser extensions that worked fine for years until an update injected malicious code into the extension<br /><a href="https://www.koi.ai/blog/4-million-browsers-infected-inside-shadypanda-7-year-malware-campaign" target="_blank" rel="noreferrer noopener">https://www.koi.ai/blog/4-million-browsers-infected-inside-shadypanda-7-year-malware-campaign</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9720.mp3</guid><pubDate>Tue, 02 Dec 2025 02:05:12 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68826314/9720.mp3" length="4887859" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9720" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Hunting for SharePoint In-Memory ToolShell Payloads
 A walk-through showing how to analyze ToolShell payloads, starting with acquiring packets all the way to decoding embedded PowerShell commands....</itunes:subtitle><itunes:summary><![CDATA[<br /> Hunting for SharePoint In-Memory ToolShell Payloads<br /> A walk-through showing how to analyze ToolShell payloads, starting with acquiring packets all the way to decoding embedded PowerShell commands.<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Hunting%20for%20SharePoint%20In-Memory%20ToolShell%20Payloads/32524" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Hunting%20for%20SharePoint%20In-Memory%20ToolShell%20Payloads/32524</a><br /> Android Security Bulletin December 2025<br /> Google fixed numerous vulnerabilities with its December Android update. Two of these vulnerabilities are already being exploited.<br /><a href="https://source.android.com/docs/security/bulletin/2025-12-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2025-12-01</a><br /> 4.3 Million Browsers Infected: Inside ShadyPanda's 7-Year Malware Campaign<br /> A group or individual released several browser extensions that worked fine for years until an update injected malicious code into the extension<br /><a href="https://www.koi.ai/blog/4-million-browsers-infected-inside-shadypanda-7-year-malware-campaign" target="_blank" rel="noreferrer noopener">https://www.koi.ai/blog/4-million-browsers-infected-inside-shadypanda-7-year-malware-campaign</a><br />]]></itunes:summary><itunes:duration>349</itunes:duration><itunes:keywords>android,browser,business,computer,cyber,cybersecurity,daily,extension,hacking,infosec,internet,it,long game,network,news,security,sharepoint,toolshell,zero-day</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9720</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, December 1st, 2025: More ClickFix; Teams Guest Access; Geoserver XXE Vulnerablity</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-december-1st-2025-more-clickfix-teams-guest-access-geoserver-xxe-vulnerablity--68812673</link><description><![CDATA[<br /> Fake adult websites pop realistic Windows Update screen to deliver stealers via ClickFix<br /> The latest variant of ClickFix tricks users into copy/pasting commands by displaying a fake blue screen of death.<br /><a href="https://www.acronis.com/en/tru/posts/fake-adult-websites-pop-realistic-windows-update-screen-to-deliver-stealers-via-clickfix/" target="_blank" rel="noreferrer noopener">https://www.acronis.com/en/tru/posts/fake-adult-websites-pop-realistic-windows-update-screen-to-deliver-stealers-via-clickfix/</a><br /> B2B Guest Access Creates an Unprotected Attack Vector<br /> Users may be tricked into joining an external Teams workspace as a guest, bypassing protections typically enabled for Teams workspaces.<br /><a href="https://www.ontinue.com/resource/blog-microsoft-chat-with-anyone-understanding-phishing-risk/" target="_blank" rel="noreferrer noopener">https://www.ontinue.com/resource/blog-microsoft-chat-with-anyone-understanding-phishing-risk/</a><br /> Geoserver XXE Vulnerability CVE-2025-58360<br /> Geoserver patched an external XML entity (XXE) vulnerability.<br /><a href="https://helixguard.ai/blog/CVE-2025-58360" target="_blank" rel="noreferrer noopener">https://helixguard.ai/blog/CVE-2025-58360</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9718.mp3</guid><pubDate>Mon, 01 Dec 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68812673/9718.mp3" length="4791696" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9718" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Fake adult websites pop realistic Windows Update screen to deliver stealers via ClickFix
 The latest variant of ClickFix tricks users into copy/pasting commands by displaying a fake blue screen of death....</itunes:subtitle><itunes:summary><![CDATA[<br /> Fake adult websites pop realistic Windows Update screen to deliver stealers via ClickFix<br /> The latest variant of ClickFix tricks users into copy/pasting commands by displaying a fake blue screen of death.<br /><a href="https://www.acronis.com/en/tru/posts/fake-adult-websites-pop-realistic-windows-update-screen-to-deliver-stealers-via-clickfix/" target="_blank" rel="noreferrer noopener">https://www.acronis.com/en/tru/posts/fake-adult-websites-pop-realistic-windows-update-screen-to-deliver-stealers-via-clickfix/</a><br /> B2B Guest Access Creates an Unprotected Attack Vector<br /> Users may be tricked into joining an external Teams workspace as a guest, bypassing protections typically enabled for Teams workspaces.<br /><a href="https://www.ontinue.com/resource/blog-microsoft-chat-with-anyone-understanding-phishing-risk/" target="_blank" rel="noreferrer noopener">https://www.ontinue.com/resource/blog-microsoft-chat-with-anyone-understanding-phishing-risk/</a><br /> Geoserver XXE Vulnerability CVE-2025-58360<br /> Geoserver patched an external XML entity (XXE) vulnerability.<br /><a href="https://helixguard.ai/blog/CVE-2025-58360" target="_blank" rel="noreferrer noopener">https://helixguard.ai/blog/CVE-2025-58360</a><br />]]></itunes:summary><itunes:duration>342</itunes:duration><itunes:keywords>business,clickfix,computer,cyber,cybersecurity,daily,geoserver,hacking,infosec,internet,it,network,news,security,teams,xml,xxe</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9718</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, November 26th, 2025: Attacks Against Messaging; Passwords in Random Websites; Fluentbit Vuln; #thanksgiving</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-november-26th-2025-attacks-against-messaging-passwords-in-random-websites-fluentbit-vuln-thanksgiving--68749678</link><description><![CDATA[<br /> Spyware Allows Cyber Threat Actors to Target Users of Messaging Applications<br /> Spyware attacks messaging applications in part by triggering vulnerabilities in messaging applications but also by deploying tools like keystroke loggers and screenshot applications.<br /><a href="https://www.cisa.gov/news-events/alerts/2025/11/24/spyware-allows-cyber-threat-actors-target-users-messaging-applications" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2025/11/24/spyware-allows-cyber-threat-actors-target-users-messaging-applications</a><br /> Stop Putting Your Passwords Into Random Websites Yes. Just Stop!<br /><a href="https://labs.watchtowr.com/stop-putting-your-passwords-into-random-websites-yes-seriously-you-are-the-problem/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/stop-putting-your-passwords-into-random-websites-yes-seriously-you-are-the-problem/</a><br /> Fluentbit Vulnerability<br /><a href="https://www.oligo.security/blog/critical-vulnerabilities-in-fluent-bit-expose-cloud-environments-to-remote-takeover" target="_blank" rel="noreferrer noopener">https://www.oligo.security/blog/critical-vulnerabilities-in-fluent-bit-expose-cloud-environments-to-remote-takeover</a><br /> Happy Thanksgiving. Next podcast on Monday after Thanksgiving.<br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9716.mp3</guid><pubDate>Wed, 26 Nov 2025 03:10:10 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68749678/9716.mp3" length="5141209" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9716" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Spyware Allows Cyber Threat Actors to Target Users of Messaging Applications
 Spyware attacks messaging applications in part by triggering vulnerabilities in messaging applications but also by deploying tools like keystroke loggers and screenshot...</itunes:subtitle><itunes:summary><![CDATA[<br /> Spyware Allows Cyber Threat Actors to Target Users of Messaging Applications<br /> Spyware attacks messaging applications in part by triggering vulnerabilities in messaging applications but also by deploying tools like keystroke loggers and screenshot applications.<br /><a href="https://www.cisa.gov/news-events/alerts/2025/11/24/spyware-allows-cyber-threat-actors-target-users-messaging-applications" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2025/11/24/spyware-allows-cyber-threat-actors-target-users-messaging-applications</a><br /> Stop Putting Your Passwords Into Random Websites Yes. Just Stop!<br /><a href="https://labs.watchtowr.com/stop-putting-your-passwords-into-random-websites-yes-seriously-you-are-the-problem/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/stop-putting-your-passwords-into-random-websites-yes-seriously-you-are-the-problem/</a><br /> Fluentbit Vulnerability<br /><a href="https://www.oligo.security/blog/critical-vulnerabilities-in-fluent-bit-expose-cloud-environments-to-remote-takeover" target="_blank" rel="noreferrer noopener">https://www.oligo.security/blog/critical-vulnerabilities-in-fluent-bit-expose-cloud-environments-to-remote-takeover</a><br /> Happy Thanksgiving. Next podcast on Monday after Thanksgiving.<br />]]></itunes:summary><itunes:duration>367</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,fluentbit,hacking,infosec,internet,it,messaging,network,news,passwords,security,spyware,thanksgiving</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9716</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, November 25th, 2025: URL Mapping and Authentication; SHA1-Hulud; Hacklore</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-november-25th-2025-url-mapping-and-authentication-sha1-hulud-hacklore--68732480</link><description><![CDATA[<br /> Conflicts between URL mapping and URL based access control.<br /> Mapping different URLs to the same script, and relying on URL based authentication at the same time, may lead to dangerous authentication and access control gaps.<br /><a href="https://isc.sans.edu/diary/Conflicts%20between%20URL%20mapping%20and%20URL%20based%20access%20control./32518" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Conflicts%20between%20URL%20mapping%20and%20URL%20based%20access%20control./32518</a><br /> Sha1-Hulud, The Second Coming<br /> A new, destructive variant of the Shai-Hulud worm is currently spreading through NPM/Github repos.<br /><a href="https://www.koi.ai/incident/live-updates-sha1-hulud-the-second-coming-hundred-npm-packages-compromised" target="_blank" rel="noreferrer noopener">https://www.koi.ai/incident/live-updates-sha1-hulud-the-second-coming-hundred-npm-packages-compromised</a><br /> Hacklore: Cleaning up Outdated Security Advice<br /> A new website, hacklore.org, has published an open letter from former CISOs and other security leaders aimed at addressing some outdated security advice that is often repeated.<br /><a href="https://www.hacklore.org" target="_blank" rel="noreferrer noopener">https://www.hacklore.org</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9714.mp3</guid><pubDate>Tue, 25 Nov 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68732480/9714.mp3" length="5197934" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9714" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Conflicts between URL mapping and URL based access control.
 Mapping different URLs to the same script, and relying on URL based authentication at the same time, may lead to dangerous authentication and access control gaps....</itunes:subtitle><itunes:summary><![CDATA[<br /> Conflicts between URL mapping and URL based access control.<br /> Mapping different URLs to the same script, and relying on URL based authentication at the same time, may lead to dangerous authentication and access control gaps.<br /><a href="https://isc.sans.edu/diary/Conflicts%20between%20URL%20mapping%20and%20URL%20based%20access%20control./32518" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Conflicts%20between%20URL%20mapping%20and%20URL%20based%20access%20control./32518</a><br /> Sha1-Hulud, The Second Coming<br /> A new, destructive variant of the Shai-Hulud worm is currently spreading through NPM/Github repos.<br /><a href="https://www.koi.ai/incident/live-updates-sha1-hulud-the-second-coming-hundred-npm-packages-compromised" target="_blank" rel="noreferrer noopener">https://www.koi.ai/incident/live-updates-sha1-hulud-the-second-coming-hundred-npm-packages-compromised</a><br /> Hacklore: Cleaning up Outdated Security Advice<br /> A new website, hacklore.org, has published an open letter from former CISOs and other security leaders aimed at addressing some outdated security advice that is often repeated.<br /><a href="https://www.hacklore.org" target="_blank" rel="noreferrer noopener">https://www.hacklore.org</a><br />]]></itunes:summary><itunes:duration>371</itunes:duration><itunes:keywords>access control,authentication,business,computer,cyber,cybersecurity,daily,hacking,hacklore,infosec,internet,it,mapping,network,news,npm,security,sha1-hulud,url</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9714</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, November 24th, 2025: CSS Padding in Phishing; Oracle Identity Manager Scans Update;</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-november-24th-2025-css-padding-in-phishing-oracle-identity-manager-scans-update--68714045</link><description><![CDATA[<br /> Use of CSS stuffing as an obfuscation technique?<br /> Phishing sites stuff their HTML with benign CSS code. This is likely supposed to throw of simple detection engines<br /><a href="https://isc.sans.edu/diary/Use%20of%20CSS%20stuffing%20as%20an%20obfuscation%20technique%3F/32510" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Use%20of%20CSS%20stuffing%20as%20an%20obfuscation%20technique%3F/32510</a><br /> Critical Oracle Identity Manager Flaw Possibly Exploited as Zero-Day<br /> Early exploit attempts for the vulnerability were part of Searchlight Cyber s research effort<br /><a href="https://www.securityweek.com/critical-oracle-identity-manager-flaw-possibly-exploited-as-zero-day/" target="_blank" rel="noreferrer noopener">https://www.securityweek.com/critical-oracle-identity-manager-flaw-possibly-exploited-as-zero-day/</a><br /> ClamAV Cleaning Signature Database<br /> ClamAV will significantly clean up its signature database<br /><a href="https://blog.clamav.net/2025/11/clamav-signature-retirement-announcement.html" target="_blank" rel="noreferrer noopener">https://blog.clamav.net/2025/11/clamav-signature-retirement-announcement.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9712.mp3</guid><pubDate>Mon, 24 Nov 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68714045/9712.mp3" length="4195675" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9712" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Use of CSS stuffing as an obfuscation technique?
 Phishing sites stuff their HTML with benign CSS code. This is likely supposed to throw of simple detection engines...</itunes:subtitle><itunes:summary><![CDATA[<br /> Use of CSS stuffing as an obfuscation technique?<br /> Phishing sites stuff their HTML with benign CSS code. This is likely supposed to throw of simple detection engines<br /><a href="https://isc.sans.edu/diary/Use%20of%20CSS%20stuffing%20as%20an%20obfuscation%20technique%3F/32510" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Use%20of%20CSS%20stuffing%20as%20an%20obfuscation%20technique%3F/32510</a><br /> Critical Oracle Identity Manager Flaw Possibly Exploited as Zero-Day<br /> Early exploit attempts for the vulnerability were part of Searchlight Cyber s research effort<br /><a href="https://www.securityweek.com/critical-oracle-identity-manager-flaw-possibly-exploited-as-zero-day/" target="_blank" rel="noreferrer noopener">https://www.securityweek.com/critical-oracle-identity-manager-flaw-possibly-exploited-as-zero-day/</a><br /> ClamAV Cleaning Signature Database<br /> ClamAV will significantly clean up its signature database<br /><a href="https://blog.clamav.net/2025/11/clamav-signature-retirement-announcement.html" target="_blank" rel="noreferrer noopener">https://blog.clamav.net/2025/11/clamav-signature-retirement-announcement.html</a><br />]]></itunes:summary><itunes:duration>300</itunes:duration><itunes:keywords>business,clamav,computer,css,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,oracle,phishing,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9712</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, November 21st, 2025: Oracle Idendity Manager Scans; SonicWall DoS Vuln; Adam Wilson (@sans_edu) reducing prompt injec</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-november-21st-2025-oracle-idendity-manager-scans-sonicwall-dos-vuln-adam-wilson-sans-edu-reducing-prompt-injec--68667972</link><description><![CDATA[<br /> Oracle Identity Manager Exploit Observation from September (CVE-2025-61757)<br /> We observed some exploit attempts in September against an Oracle Identity Manager vulnerability that was patched in October, indicating that exploitation may have occurred prior to the patch being released.<br /><a href="https://isc.sans.edu/diary/Oracle%20Identity%20Manager%20Exploit%20Observation%20from%20September%20%28CVE-2025-61757%29/32506" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Oracle%20Identity%20Manager%20Exploit%20Observation%20from%20September%20%28CVE-2025-61757%29/32506</a><br /><a href="https://slcyber.io/research-center/breaking-oracles-identity-manager-pre-auth-rce/" target="_blank" rel="noreferrer noopener">https://slcyber.io/research-center/breaking-oracles-identity-manager-pre-auth-rce/</a><br /> DigitStealer: a JXA-based infostealer that leaves little footprint<br /><a href="https://www.jamf.com/blog/jtl-digitstealer-macos-infostealer-analysis/" target="_blank" rel="noreferrer noopener">https://www.jamf.com/blog/jtl-digitstealer-macos-infostealer-analysis/</a><br /> SonicWall DoS Vulnerability<br /> Sonicwall patched a DoS vulnerability in SonicOS<br /><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0016" target="_blank" rel="noreferrer noopener">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0016</a><br /> Adam Wilson: Automating Generative AI Guidelines: Reducing Prompt Injection Risk with 'Shift-Left' MITRE ATLAS Mitigation Testing<br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9710.mp3</guid><pubDate>Fri, 21 Nov 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68667972/9710.mp3" length="11889144" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9710" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Oracle Identity Manager Exploit Observation from September (CVE-2025-61757)
 We observed some exploit attempts in September against an Oracle Identity Manager vulnerability that was patched in October, indicating that exploitation may have occurred...</itunes:subtitle><itunes:summary><![CDATA[<br /> Oracle Identity Manager Exploit Observation from September (CVE-2025-61757)<br /> We observed some exploit attempts in September against an Oracle Identity Manager vulnerability that was patched in October, indicating that exploitation may have occurred prior to the patch being released.<br /><a href="https://isc.sans.edu/diary/Oracle%20Identity%20Manager%20Exploit%20Observation%20from%20September%20%28CVE-2025-61757%29/32506" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Oracle%20Identity%20Manager%20Exploit%20Observation%20from%20September%20%28CVE-2025-61757%29/32506</a><br /><a href="https://slcyber.io/research-center/breaking-oracles-identity-manager-pre-auth-rce/" target="_blank" rel="noreferrer noopener">https://slcyber.io/research-center/breaking-oracles-identity-manager-pre-auth-rce/</a><br /> DigitStealer: a JXA-based infostealer that leaves little footprint<br /><a href="https://www.jamf.com/blog/jtl-digitstealer-macos-infostealer-analysis/" target="_blank" rel="noreferrer noopener">https://www.jamf.com/blog/jtl-digitstealer-macos-infostealer-analysis/</a><br /> SonicWall DoS Vulnerability<br /> Sonicwall patched a DoS vulnerability in SonicOS<br /><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0016" target="_blank" rel="noreferrer noopener">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0016</a><br /> Adam Wilson: Automating Generative AI Guidelines: Reducing Prompt Injection Risk with 'Shift-Left' MITRE ATLAS Mitigation Testing<br />]]></itunes:summary><itunes:duration>849</itunes:duration><itunes:keywords>ai,atlas,business,computer,cyber,cybersecurity,daily,digitstealer,hacking,identity manager,infosec,it,mitre,network,news,oracle,prompt injection,security,sonicos,sonicwall</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9710</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, November 20th, 2025: Unicode Issues; FortiWeb More Vulns; DLink DIR-878 Vuln; Operation WrtHug and ASUS Routers</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-november-20th-2025-unicode-issues-fortiweb-more-vulns-dlink-dir-878-vuln-operation-wrthug-and-asus-routers--68648782</link><description><![CDATA[<br /> Unicode: It is more than funny domain names.<br /> Unicode can cause a number of issues due to odd features like variance selectors and text direction issues.<br /><a href="https://isc.sans.edu/diary/Unicode%3A%20It%20is%20more%20than%20funny%20domain%20names./32472" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Unicode%3A%20It%20is%20more%20than%20funny%20domain%20names./32472</a><br /> FortiWeb Multiple OS command injection in API and CLI<br /> A second silently patched vulnerability in FortiWeb is already being exploited in the wild.<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-513" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-25-513</a><br /> DLink DIR-878 Vulnerability<br /> DLink disclosed four different vulnerabilities in its popular DIR-878 router. The router is end-of-life and DLink will not release patches<br /><a href="https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10475" target="_blank" rel="noreferrer noopener">https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10475</a><br /> Operation WrtHug, The Global Espionage Campaign Hiding in Your Home Router<br /> A new report,  Operation WrtHug,  has uncovered a massive, coordinated effort that has compromised thousands of ASUS routers worldwide.<br /><a href="https://securityscorecard.com/blog/operation-wrthug-the-global-espionage-campaign-hiding-in-your-home-router/" target="_blank" rel="noreferrer noopener">https://securityscorecard.com/blog/operation-wrthug-the-global-espionage-campaign-hiding-in-your-home-router/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9708.mp3</guid><pubDate>Thu, 20 Nov 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68648782/9708.mp3" length="5524806" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9708" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Unicode: It is more than funny domain names.
 Unicode can cause a number of issues due to odd features like variance selectors and text direction issues.
https://isc.sans.edu/diary/Unicode%3A%20It%20is%20more%20than%20funny%20domain%20names./32472...</itunes:subtitle><itunes:summary><![CDATA[<br /> Unicode: It is more than funny domain names.<br /> Unicode can cause a number of issues due to odd features like variance selectors and text direction issues.<br /><a href="https://isc.sans.edu/diary/Unicode%3A%20It%20is%20more%20than%20funny%20domain%20names./32472" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Unicode%3A%20It%20is%20more%20than%20funny%20domain%20names./32472</a><br /> FortiWeb Multiple OS command injection in API and CLI<br /> A second silently patched vulnerability in FortiWeb is already being exploited in the wild.<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-513" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-25-513</a><br /> DLink DIR-878 Vulnerability<br /> DLink disclosed four different vulnerabilities in its popular DIR-878 router. The router is end-of-life and DLink will not release patches<br /><a href="https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10475" target="_blank" rel="noreferrer noopener">https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10475</a><br /> Operation WrtHug, The Global Espionage Campaign Hiding in Your Home Router<br /> A new report,  Operation WrtHug,  has uncovered a massive, coordinated effort that has compromised thousands of ASUS routers worldwide.<br /><a href="https://securityscorecard.com/blog/operation-wrthug-the-global-espionage-campaign-hiding-in-your-home-router/" target="_blank" rel="noreferrer noopener">https://securityscorecard.com/blog/operation-wrthug-the-global-espionage-campaign-hiding-in-your-home-router/</a><br />]]></itunes:summary><itunes:duration>395</itunes:duration><itunes:keywords>asus,business,computer,cyber,cybersecurity,daily,dir-878,dlink,fortiweb,hacking,infosec,internet,it,network,news,security,unicode,wrthug</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9708</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, November 19th, 2025: Kong Tuke; Cloudflare Outage</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-november-19th-2025-kong-tuke-cloudflare-outage--68631688</link><description><![CDATA[<br /> KongTuke Activity<br /> This diary investigates how a recent Kong Tuke infections evolved all the way from starting with a ClickFix attack.<br /><a href="https://isc.sans.edu/diary/KongTuke%20activity/32498" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/KongTuke%20activity/32498</a><br /> Cloudflare Outage<br /> Cloudflare suffered a large outage today after an oversized configuration file was loaded into its bot protection service<br /><a href="https://x.com/dok2001" target="_blank" rel="noreferrer noopener">https://x.com/dok2001</a><br /> Google Patches Chrome 0-Day<br /> Google patched two vulnerabilities in Chrome. One of them is already being exploited.<br /><a href="https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop_17.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop_17.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9706.mp3</guid><pubDate>Wed, 19 Nov 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68631688/9706.mp3" length="3897645" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9706" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 KongTuke Activity
 This diary investigates how a recent Kong Tuke infections evolved all the way from starting with a ClickFix attack.
https://isc.sans.edu/diary/KongTuke%20activity/32498
 Cloudflare Outage
 Cloudflare suffered a large outage today...</itunes:subtitle><itunes:summary><![CDATA[<br /> KongTuke Activity<br /> This diary investigates how a recent Kong Tuke infections evolved all the way from starting with a ClickFix attack.<br /><a href="https://isc.sans.edu/diary/KongTuke%20activity/32498" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/KongTuke%20activity/32498</a><br /> Cloudflare Outage<br /> Cloudflare suffered a large outage today after an oversized configuration file was loaded into its bot protection service<br /><a href="https://x.com/dok2001" target="_blank" rel="noreferrer noopener">https://x.com/dok2001</a><br /> Google Patches Chrome 0-Day<br /> Google patched two vulnerabilities in Chrome. One of them is already being exploited.<br /><a href="https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop_17.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop_17.html</a><br />]]></itunes:summary><itunes:duration>279</itunes:duration><itunes:keywords>business,chrome,clickfix,cloudflare,computer,cyber,cybersecurity,daily,google,hacking,infosec,internet,it,kongtuke,network,news,outages,security,v8</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9706</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, November 18th, 2025: Binary Expression Decoding. Tea NPM Pollution; IBM AIX NIMSH Vulnerability</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-november-18th-2025-binary-expression-decoding-tea-npm-pollution-ibm-aix-nimsh-vulnerability--68610508</link><description><![CDATA[<br /> Decoding Binary Numeric Expressions<br /> Didier updated his number to hex script to support simple arithmetic operations in the text.<br /><a href="https://isc.sans.edu/diary/Decoding%20Binary%20Numeric%20Expressions/32490" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Decoding%20Binary%20Numeric%20Expressions/32490</a><br /> Tea Token NPM Pollution<br /> The NPM repository was hit with around 150,000 submissions that did not contain any useful contributions, but instead attempted to fake contributions to earn a new  tea  coin.<br /><a href="https://aws.amazon.com/blogs/security/amazon-inspector-detects-over-150000-malicious-packages-linked-to-token-farming-campaign/" target="_blank" rel="noreferrer noopener">https://aws.amazon.com/blogs/security/amazon-inspector-detects-over-150000-malicious-packages-linked-to-token-farming-campaign/</a><br /> IBM AIX NIMSH Vulnerabilities<br /> IBM patched several critical vulnerablities in the NIMSH daemon<br /><a href="https://www.ibm.com/support/pages/node/7251173" target="_blank" rel="noreferrer noopener">https://www.ibm.com/support/pages/node/7251173</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9704.mp3</guid><pubDate>Tue, 18 Nov 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68610508/9704.mp3" length="4177859" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9704" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Decoding Binary Numeric Expressions
 Didier updated his number to hex script to support simple arithmetic operations in the text.
https://isc.sans.edu/diary/Decoding%20Binary%20Numeric%20Expressions/32490
 Tea Token NPM Pollution
 The NPM repository...</itunes:subtitle><itunes:summary><![CDATA[<br /> Decoding Binary Numeric Expressions<br /> Didier updated his number to hex script to support simple arithmetic operations in the text.<br /><a href="https://isc.sans.edu/diary/Decoding%20Binary%20Numeric%20Expressions/32490" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Decoding%20Binary%20Numeric%20Expressions/32490</a><br /> Tea Token NPM Pollution<br /> The NPM repository was hit with around 150,000 submissions that did not contain any useful contributions, but instead attempted to fake contributions to earn a new  tea  coin.<br /><a href="https://aws.amazon.com/blogs/security/amazon-inspector-detects-over-150000-malicious-packages-linked-to-token-farming-campaign/" target="_blank" rel="noreferrer noopener">https://aws.amazon.com/blogs/security/amazon-inspector-detects-over-150000-malicious-packages-linked-to-token-farming-campaign/</a><br /> IBM AIX NIMSH Vulnerabilities<br /> IBM patched several critical vulnerablities in the NIMSH daemon<br /><a href="https://www.ibm.com/support/pages/node/7251173" target="_blank" rel="noreferrer noopener">https://www.ibm.com/support/pages/node/7251173</a><br />]]></itunes:summary><itunes:duration>299</itunes:duration><itunes:keywords>aix,binary,business,computer,cyber,cybersecurity,daily,decoding,hacking,ibm,infosec,internet,it,network,news,nimsh,npm,numeric,security,tea</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9704</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, November 17th, 2025: New(isch) Fortiweb Vulnerability; Finger and ClickFix</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-november-17th-2025-new-isch-fortiweb-vulnerability-finger-and-clickfix--68596506</link><description><![CDATA[<br /> Fortiweb Vulnerability<br /> Fortinet, with significant delay, acknowledged a recently patched vulnerability after exploit attempts were seen publicly.<br /><a href="https://isc.sans.edu/diary/Honeypot+FortiWeb+CVE202564446+Exploits/32486" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Honeypot+FortiWeb+CVE202564446+Exploits/32486</a><br /><a href="https://labs.watchtowr.com/when-the-impersonation-function-gets-used-to-impersonate-users-fortinet-fortiweb-auth-bypass/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/when-the-impersonation-function-gets-used-to-impersonate-users-fortinet-fortiweb-auth-bypass/</a><br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-910?ref=labs.watchtowr.com" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-25-910?ref=labs.watchtowr.com</a><br /> Flnger.exe and ClickFix<br /> Attackers started to use the finger.exe binary to retrieve additional payload in ClickFix attacks<br /><a href="https://isc.sans.edu/diary/Finger.exe%20%26%20ClickFix/32492" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Finger.exe%20%26%20ClickFix/32492</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9702.mp3</guid><pubDate>Mon, 17 Nov 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68596506/9702.mp3" length="6031165" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9702" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Fortiweb Vulnerability
 Fortinet, with significant delay, acknowledged a recently patched vulnerability after exploit attempts were seen publicly.
https://isc.sans.edu/diary/Honeypot+FortiWeb+CVE202564446+Exploits/32486...</itunes:subtitle><itunes:summary><![CDATA[<br /> Fortiweb Vulnerability<br /> Fortinet, with significant delay, acknowledged a recently patched vulnerability after exploit attempts were seen publicly.<br /><a href="https://isc.sans.edu/diary/Honeypot+FortiWeb+CVE202564446+Exploits/32486" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Honeypot+FortiWeb+CVE202564446+Exploits/32486</a><br /><a href="https://labs.watchtowr.com/when-the-impersonation-function-gets-used-to-impersonate-users-fortinet-fortiweb-auth-bypass/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/when-the-impersonation-function-gets-used-to-impersonate-users-fortinet-fortiweb-auth-bypass/</a><br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-910?ref=labs.watchtowr.com" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-25-910?ref=labs.watchtowr.com</a><br /> Flnger.exe and ClickFix<br /> Attackers started to use the finger.exe binary to retrieve additional payload in ClickFix attacks<br /><a href="https://isc.sans.edu/diary/Finger.exe%20%26%20ClickFix/32492" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Finger.exe%20%26%20ClickFix/32492</a><br />]]></itunes:summary><itunes:duration>431</itunes:duration><itunes:keywords>business,clickfix,computer,cyber,cybersecurity,daily,finger,finger.exe,fortinet,fortiweb,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9702</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, November 14th, 2025: SmartApeSG and ClickFix; Formbook Obfuscation Tricks; Sudo-rs Vulnerabilities; SANS Holiday Hack</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-november-14th-2025-smartapesg-and-clickfix-formbook-obfuscation-tricks-sudo-rs-vulnerabilities-sans-holiday-hack--68560864</link><description><![CDATA[<br /> SmartApeSG campaign uses ClickFix page to push NetSupport RAT<br /> A detailed analysis of a recent SamtApeSG campaign taking advantage of ClickFix<br /><a href="https://isc.sans.edu/diary/32474" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/32474</a><br /> Formbook Delivered Through Multiple Scripts<br /> An analysis of a recent version of Formbook showing how it takes advantage of multiple obfuscation tricks<br /><a href="https://isc.sans.edu/diary/32480" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/32480</a><br /> sudo-rs vulnerabilities<br /> Two vulnerabilities were patched in sudo-rs, the version of sudo written in Rust, showing that while Rust does have an advantage when it comes to memory safety, there are plenty of other vulnerabilities to worry about<br /><a href="https://ubuntu.com/security/notices/USN-7867-1" target="_blank" rel="noreferrer noopener">https://ubuntu.com/security/notices/USN-7867-1</a><br /><a href="https://github.com/trifectatechfoundation/sudo-rs/security/advisories/GHSA-c978-wq47-pvvw?ref=itsfoss.com" target="_blank" rel="noreferrer noopener">https://github.com/trifectatechfoundation/sudo-rs/security/advisories/GHSA-c978-wq47-pvvw?ref=itsfoss.com</a><br /> SANS Holiday Hack Challenge<br /><a href="https://sans.org/HolidayHack" target="_blank" rel="noreferrer noopener">https://sans.org/HolidayHack</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9700.mp3</guid><pubDate>Fri, 14 Nov 2025 01:18:18 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68560864/9700.mp3" length="8535124" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9700" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 SmartApeSG campaign uses ClickFix page to push NetSupport RAT
 A detailed analysis of a recent SamtApeSG campaign taking advantage of ClickFix
https://isc.sans.edu/diary/32474
 Formbook Delivered Through Multiple Scripts
 An analysis of a recent...</itunes:subtitle><itunes:summary><![CDATA[<br /> SmartApeSG campaign uses ClickFix page to push NetSupport RAT<br /> A detailed analysis of a recent SamtApeSG campaign taking advantage of ClickFix<br /><a href="https://isc.sans.edu/diary/32474" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/32474</a><br /> Formbook Delivered Through Multiple Scripts<br /> An analysis of a recent version of Formbook showing how it takes advantage of multiple obfuscation tricks<br /><a href="https://isc.sans.edu/diary/32480" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/32480</a><br /> sudo-rs vulnerabilities<br /> Two vulnerabilities were patched in sudo-rs, the version of sudo written in Rust, showing that while Rust does have an advantage when it comes to memory safety, there are plenty of other vulnerabilities to worry about<br /><a href="https://ubuntu.com/security/notices/USN-7867-1" target="_blank" rel="noreferrer noopener">https://ubuntu.com/security/notices/USN-7867-1</a><br /><a href="https://github.com/trifectatechfoundation/sudo-rs/security/advisories/GHSA-c978-wq47-pvvw?ref=itsfoss.com" target="_blank" rel="noreferrer noopener">https://github.com/trifectatechfoundation/sudo-rs/security/advisories/GHSA-c978-wq47-pvvw?ref=itsfoss.com</a><br /> SANS Holiday Hack Challenge<br /><a href="https://sans.org/HolidayHack" target="_blank" rel="noreferrer noopener">https://sans.org/HolidayHack</a><br />]]></itunes:summary><itunes:duration>610</itunes:duration><itunes:keywords>business,challenge,click-fix,computer,cyber,cybersecurity,daily,formbook,hack,hacking,holiday,infosec,internet,it,network,news,security,sudo-rs</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9700</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, November 13th, 2025: OWASP Top 10 Update; Cisco/Citrix Exploits; Test post quantum readiness</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-november-13th-2025-owasp-top-10-update-cisco-citrix-exploits-test-post-quantum-readiness--68548064</link><description><![CDATA[<br /> OWASP Top 10 2025 Release Candidate<br /> OWASP published a release candidate for the 2025 version of its Top 10 list<br /><a href="https://owasp.org/Top10/2025/0x00_2025-Introduction/" target="_blank" rel="noreferrer noopener">https://owasp.org/Top10/2025/0x00_2025-Introduction/</a><br /> Citrix/Cisco Exploitation Details<br /> Amazon detailed how Citrix and Cisco vulnerabilities were used by advanced actors to upload webshells<br /><a href="https://aws.amazon.com/blogs/security/amazon-discovers-apt-exploiting-cisco-and-citrix-zero-days/" target="_blank" rel="noreferrer noopener">https://aws.amazon.com/blogs/security/amazon-discovers-apt-exploiting-cisco-and-citrix-zero-days/</a><br /> Testing Quantum Readyness<br /> A website tests your services for post-quantum computing-resistant cryptographic algorithms<br /><a href="https://qcready.com/" target="_blank" rel="noreferrer noopener">https://qcready.com/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9698.mp3</guid><pubDate>Thu, 13 Nov 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68548064/9698.mp3" length="5511003" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9698" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 OWASP Top 10 2025 Release Candidate
 OWASP published a release candidate for the 2025 version of its Top 10 list
https://owasp.org/Top10/2025/0x00_2025-Introduction/
 Citrix/Cisco Exploitation Details
 Amazon detailed how Citrix and Cisco...</itunes:subtitle><itunes:summary><![CDATA[<br /> OWASP Top 10 2025 Release Candidate<br /> OWASP published a release candidate for the 2025 version of its Top 10 list<br /><a href="https://owasp.org/Top10/2025/0x00_2025-Introduction/" target="_blank" rel="noreferrer noopener">https://owasp.org/Top10/2025/0x00_2025-Introduction/</a><br /> Citrix/Cisco Exploitation Details<br /> Amazon detailed how Citrix and Cisco vulnerabilities were used by advanced actors to upload webshells<br /><a href="https://aws.amazon.com/blogs/security/amazon-discovers-apt-exploiting-cisco-and-citrix-zero-days/" target="_blank" rel="noreferrer noopener">https://aws.amazon.com/blogs/security/amazon-discovers-apt-exploiting-cisco-and-citrix-zero-days/</a><br /> Testing Quantum Readyness<br /> A website tests your services for post-quantum computing-resistant cryptographic algorithms<br /><a href="https://qcready.com/" target="_blank" rel="noreferrer noopener">https://qcready.com/</a><br />]]></itunes:summary><itunes:duration>394</itunes:duration><itunes:keywords>business,cisco,citrix,computer,crypto,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,owasp,quantum,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9698</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, November 12th, 2025: Microsoft Patch Tuesday; Gladinet Triofox Vulnerability; SAP Patches</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-november-12th-2025-microsoft-patch-tuesday-gladinet-triofox-vulnerability-sap-patches--68530741</link><description><![CDATA[<br /> Microsoft Patch Tuesday for November 2025<br /><a href="https://isc.sans.edu/diary/Microsoft+Patch+Tuesday+for+November+2025/32468/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft+Patch+Tuesday+for+November+2025/32468/</a><br /> Gladinet Triofox Vulnerability<br /> Triofox uses the  host  header in lieu of proper access control, allowing an attacker to access the page managing administrators by simply setting the host header to localhost.<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/triofox-vulnerability-cve-2025-12480/" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/triofox-vulnerability-cve-2025-12480/</a><br /> SAP November 2025 Patch Day<br /> SAP fixed a critical vulnerability, fixed default credentials in its SQL Anywhere Monitor<br /><a href="https://onapsis.com/blog/sap-security-patch-day-november-2025/" target="_blank" rel="noreferrer noopener">https://onapsis.com/blog/sap-security-patch-day-november-2025/</a><br /> Ivanti Endpoint Manager Updates<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-EPM-November-2025-for-EPM-2024?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-EPM-November-2025-for-EPM-2024?language=en_US</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9696.mp3</guid><pubDate>Wed, 12 Nov 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68530741/9696.mp3" length="5085734" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9696" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Microsoft Patch Tuesday for November 2025
https://isc.sans.edu/diary/Microsoft+Patch+Tuesday+for+November+2025/32468/
 Gladinet Triofox Vulnerability
 Triofox uses the  host  header in lieu of proper access control, allowing an attacker to access...</itunes:subtitle><itunes:summary><![CDATA[<br /> Microsoft Patch Tuesday for November 2025<br /><a href="https://isc.sans.edu/diary/Microsoft+Patch+Tuesday+for+November+2025/32468/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft+Patch+Tuesday+for+November+2025/32468/</a><br /> Gladinet Triofox Vulnerability<br /> Triofox uses the  host  header in lieu of proper access control, allowing an attacker to access the page managing administrators by simply setting the host header to localhost.<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/triofox-vulnerability-cve-2025-12480/" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/triofox-vulnerability-cve-2025-12480/</a><br /> SAP November 2025 Patch Day<br /> SAP fixed a critical vulnerability, fixed default credentials in its SQL Anywhere Monitor<br /><a href="https://onapsis.com/blog/sap-security-patch-day-november-2025/" target="_blank" rel="noreferrer noopener">https://onapsis.com/blog/sap-security-patch-day-november-2025/</a><br /> Ivanti Endpoint Manager Updates<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-EPM-November-2025-for-EPM-2024?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-EPM-November-2025-for-EPM-2024?language=en_US</a><br />]]></itunes:summary><itunes:duration>363</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,gladinet,hacking,infosec,internet,it,ivanti,microsoft,network,news,sap,security,triofox</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9696</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, November 11th, 2025: 3CX Related Scans; Watchguard Default Password;</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-november-11th-2025-3cx-related-scans-watchguard-default-password--68510918</link><description><![CDATA[<br /> It isn t always defaults: Scans for 3CX Usernames<br /> Our honeypots detected scans for usernames that may be related to 3CX business phone systems<br /><a href="https://isc.sans.edu/diary/It%20isn%27t%20always%20defaults%3A%20Scans%20for%203CX%20usernames/32464" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/It%20isn%27t%20always%20defaults%3A%20Scans%20for%203CX%20usernames/32464</a><br /> Watchguard Default Password Controversy<br /> A CVE number was assigned to a default password commonly used in Watchguard products. This was a documented username and password that was recently removed in a firmware upgrade.<br /><a href="https://github.com/cyberbyte000/CVE-2025-59396/blob/main/CVE-2025-59396.txt" target="_blank" rel="noreferrer noopener">https://github.com/cyberbyte000/CVE-2025-59396/blob/main/CVE-2025-59396.txt</a><br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59396" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2025-59396</a><br /> JavaScript expr-eval Vulnerability<br /> The JavaScript expr-eval library was vulnerable to a code execution issue.<br /><a href="https://www.kb.cert.org/vuls/id/263614" target="_blank" rel="noreferrer noopener">https://www.kb.cert.org/vuls/id/263614</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9694.mp3</guid><pubDate>Tue, 11 Nov 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68510918/9694.mp3" length="6237992" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9694" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 It isn t always defaults: Scans for 3CX Usernames
 Our honeypots detected scans for usernames that may be related to 3CX business phone systems
https://isc.sans.edu/diary/It%20isn%27t%20always%20defaults%3A%20Scans%20for%203CX%20usernames/32464...</itunes:subtitle><itunes:summary><![CDATA[<br /> It isn t always defaults: Scans for 3CX Usernames<br /> Our honeypots detected scans for usernames that may be related to 3CX business phone systems<br /><a href="https://isc.sans.edu/diary/It%20isn%27t%20always%20defaults%3A%20Scans%20for%203CX%20usernames/32464" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/It%20isn%27t%20always%20defaults%3A%20Scans%20for%203CX%20usernames/32464</a><br /> Watchguard Default Password Controversy<br /> A CVE number was assigned to a default password commonly used in Watchguard products. This was a documented username and password that was recently removed in a firmware upgrade.<br /><a href="https://github.com/cyberbyte000/CVE-2025-59396/blob/main/CVE-2025-59396.txt" target="_blank" rel="noreferrer noopener">https://github.com/cyberbyte000/CVE-2025-59396/blob/main/CVE-2025-59396.txt</a><br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59396" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2025-59396</a><br /> JavaScript expr-eval Vulnerability<br /> The JavaScript expr-eval library was vulnerable to a code execution issue.<br /><a href="https://www.kb.cert.org/vuls/id/263614" target="_blank" rel="noreferrer noopener">https://www.kb.cert.org/vuls/id/263614</a><br />]]></itunes:summary><itunes:duration>446</itunes:duration><itunes:keywords>3cx,business,computer,cyber,cybersecurity,daily,eval,expt-eval,hacking,infosec,internet,it,javascript,network,news,security,usernames,watchguard</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9694</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, November 10th, 2025: Code Repo Requests; Time Delayed ICS Attacks; Encrypted LLM Traffic Sidechannel Attacks</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-november-10th-2025-code-repo-requests-time-delayed-ics-attacks-encrypted-llm-traffic-sidechannel-attacks--68490680</link><description><![CDATA[<br /> Honeypot Requests for Code Repository<br /> Attackers continue to scan websites for source code repositories. Keep your repositories outside your document root and proactively scan your own sites.<br /><a href="https://isc.sans.edu/diary/Honeypot%3A%20Requests%20for%20%28Code%29%20Repositories/32460" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Honeypot%3A%20Requests%20for%20%28Code%29%20Repositories/32460</a><br /> Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads<br /> Newly discovered malicious .NET packages attempt to deliver a time-delayed attack targeting ICS systems.<br /><a href="https://socket.dev/blog/9-malicious-nuget-packages-deliver-time-delayed-destructive-payloads" target="_blank" rel="noreferrer noopener">https://socket.dev/blog/9-malicious-nuget-packages-deliver-time-delayed-destructive-payloads</a><br /> Side Channel Leaks in Encrypted Traffic to LLMs<br /> Traffic to LLMs can be profiled to discover the nature of prompts sent by a user based on the amount and structure of the encrypted data.<br /><a href="https://www.microsoft.com/en-us/security/blog/2025/11/07/whisper-leak-a-novel-side-channel-cyberattack-on-remote-language-models/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2025/11/07/whisper-leak-a-novel-side-channel-cyberattack-on-remote-language-models/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9692.mp3</guid><pubDate>Mon, 10 Nov 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68490680/9692.mp3" length="5976309" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9692" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Honeypot Requests for Code Repository
 Attackers continue to scan websites for source code repositories. Keep your repositories outside your document root and proactively scan your own sites....</itunes:subtitle><itunes:summary><![CDATA[<br /> Honeypot Requests for Code Repository<br /> Attackers continue to scan websites for source code repositories. Keep your repositories outside your document root and proactively scan your own sites.<br /><a href="https://isc.sans.edu/diary/Honeypot%3A%20Requests%20for%20%28Code%29%20Repositories/32460" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Honeypot%3A%20Requests%20for%20%28Code%29%20Repositories/32460</a><br /> Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads<br /> Newly discovered malicious .NET packages attempt to deliver a time-delayed attack targeting ICS systems.<br /><a href="https://socket.dev/blog/9-malicious-nuget-packages-deliver-time-delayed-destructive-payloads" target="_blank" rel="noreferrer noopener">https://socket.dev/blog/9-malicious-nuget-packages-deliver-time-delayed-destructive-payloads</a><br /> Side Channel Leaks in Encrypted Traffic to LLMs<br /> Traffic to LLMs can be profiled to discover the nature of prompts sent by a user based on the amount and structure of the encrypted data.<br /><a href="https://www.microsoft.com/en-us/security/blog/2025/11/07/whisper-leak-a-novel-side-channel-cyberattack-on-remote-language-models/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2025/11/07/whisper-leak-a-novel-side-channel-cyberattack-on-remote-language-models/</a><br />]]></itunes:summary><itunes:duration>427</itunes:duration><itunes:keywords>ai,business,computer,control systems,cyber,cybersecurity,daily,hacking,honeypot,ics,infosec,it,llms,network,news,nuget,repositories,security,source code,time</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9692</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, November 7th, 2025: PowerShell Log Correlation; RondoBox Disected; Google Chrome and Cisco Patches</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-november-7th-2025-powershell-log-correlation-rondobox-disected-google-chrome-and-cisco-patches--68455778</link><description><![CDATA[<br /> Binary Breadcrumbs: Correlating Malware Samples with Honeypot Logs Using PowerShell [Guest Diary]<br /> Windows, with PowerShell, has a great scripting platform to match common Linux/Unix command line utilities. <br /><a href="https://isc.sans.edu/diary/Binary%20Breadcrumbs%3A%20Correlating%20Malware%20Samples%20with%20Honeypot%20Logs%20Using%20PowerShell%20%5BGuest%20Diary%5D/32454" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Binary%20Breadcrumbs%3A%20Correlating%20Malware%20Samples%20with%20Honeypot%20Logs%20Using%20PowerShell%20%5BGuest%20Diary%5D/32454</a><br /> RondoDox v2 Increases Exploits<br /> The RondoDox (or RondoWorm) added a substantial amount of new exploits to its repertoire.<br /><a href="https://beelzebub.ai/blog/rondo-dox-v2/" target="_blank" rel="noreferrer noopener">https://beelzebub.ai/blog/rondo-dox-v2/</a><br /> Google Chrome Updates<br /> Google released an update for Google Chrome addressing five vulnerabilities.<br /><a href="https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop.html</a><br /> Cisco Unified Contact Center Express Remote Code Execution Vulnerabilities<br /> Cisco patched two critical vulnerabilities in its Contact Center Express software. These vulnerabilities may lead to a full system compromise.<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cc-unauth-rce-QeN8h7mQ" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cc-unauth-rce-QeN8h7mQ</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9690.mp3</guid><pubDate>Fri, 07 Nov 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68455778/9690.mp3" length="4633560" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9690" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Binary Breadcrumbs: Correlating Malware Samples with Honeypot Logs Using PowerShell [Guest Diary]
 Windows, with PowerShell, has a great scripting platform to match common Linux/Unix command line utilities....</itunes:subtitle><itunes:summary><![CDATA[<br /> Binary Breadcrumbs: Correlating Malware Samples with Honeypot Logs Using PowerShell [Guest Diary]<br /> Windows, with PowerShell, has a great scripting platform to match common Linux/Unix command line utilities. <br /><a href="https://isc.sans.edu/diary/Binary%20Breadcrumbs%3A%20Correlating%20Malware%20Samples%20with%20Honeypot%20Logs%20Using%20PowerShell%20%5BGuest%20Diary%5D/32454" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Binary%20Breadcrumbs%3A%20Correlating%20Malware%20Samples%20with%20Honeypot%20Logs%20Using%20PowerShell%20%5BGuest%20Diary%5D/32454</a><br /> RondoDox v2 Increases Exploits<br /> The RondoDox (or RondoWorm) added a substantial amount of new exploits to its repertoire.<br /><a href="https://beelzebub.ai/blog/rondo-dox-v2/" target="_blank" rel="noreferrer noopener">https://beelzebub.ai/blog/rondo-dox-v2/</a><br /> Google Chrome Updates<br /> Google released an update for Google Chrome addressing five vulnerabilities.<br /><a href="https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop.html</a><br /> Cisco Unified Contact Center Express Remote Code Execution Vulnerabilities<br /> Cisco patched two critical vulnerabilities in its Contact Center Express software. These vulnerabilities may lead to a full system compromise.<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cc-unauth-rce-QeN8h7mQ" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cc-unauth-rce-QeN8h7mQ</a><br />]]></itunes:summary><itunes:duration>331</itunes:duration><itunes:keywords>business,chrome,cisco,computer,cyber,cybersecurity,daily,google,hacking,infosec,internet,it,network,news,powershell,rondodox,security,windows</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9690</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, November 6th, 2025: Domain API Update; Teams Spoofing; VShell Report</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-november-6th-2025-domain-api-update-teams-spoofing-vshell-report--68441064</link><description><![CDATA[<br /> Updates to Domainname API<br /> Some updates to our domainname API will make it more flexible and make it easier and faster to get the complete dataset.<br /><a href="https://isc.sans.edu/diary/Updates%20to%20Domainname%20API/32452" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Updates%20to%20Domainname%20API/32452</a><br /> Microsoft Teams Impersonation and Spoofing Vulnerabilities<br /> Checkpoint released details about recently patched spoofing and impersonation vulnerabilities in Microsoft Teams<br /><a href="https://research.checkpoint.com/2025/microsoft-teams-impersonation-and-spoofing-vulnerabilities-exposed/" target="_blank" rel="noreferrer noopener">https://research.checkpoint.com/2025/microsoft-teams-impersonation-and-spoofing-vulnerabilities-exposed/</a><br /> NViso Report: VSHELL<br /> NViso published an amazingly detailed report describing the remote control implant VSHELL. The report includes details about the inner workings of the tool as well as detection ideas.<br /><a href="https://www.nviso.eu/blog/nviso-analyzes-vshell-post-exploitation-tool" target="_blank" rel="noreferrer noopener">https://www.nviso.eu/blog/nviso-analyzes-vshell-post-exploitation-tool</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9688.mp3</guid><pubDate>Thu, 06 Nov 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68441064/9688.mp3" length="4804066" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9688" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Updates to Domainname API
 Some updates to our domainname API will make it more flexible and make it easier and faster to get the complete dataset.
https://isc.sans.edu/diary/Updates%20to%20Domainname%20API/32452
 Microsoft Teams Impersonation and...</itunes:subtitle><itunes:summary><![CDATA[<br /> Updates to Domainname API<br /> Some updates to our domainname API will make it more flexible and make it easier and faster to get the complete dataset.<br /><a href="https://isc.sans.edu/diary/Updates%20to%20Domainname%20API/32452" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Updates%20to%20Domainname%20API/32452</a><br /> Microsoft Teams Impersonation and Spoofing Vulnerabilities<br /> Checkpoint released details about recently patched spoofing and impersonation vulnerabilities in Microsoft Teams<br /><a href="https://research.checkpoint.com/2025/microsoft-teams-impersonation-and-spoofing-vulnerabilities-exposed/" target="_blank" rel="noreferrer noopener">https://research.checkpoint.com/2025/microsoft-teams-impersonation-and-spoofing-vulnerabilities-exposed/</a><br /> NViso Report: VSHELL<br /> NViso published an amazingly detailed report describing the remote control implant VSHELL. The report includes details about the inner workings of the tool as well as detection ideas.<br /><a href="https://www.nviso.eu/blog/nviso-analyzes-vshell-post-exploitation-tool" target="_blank" rel="noreferrer noopener">https://www.nviso.eu/blog/nviso-analyzes-vshell-post-exploitation-tool</a><br />]]></itunes:summary><itunes:duration>343</itunes:duration><itunes:keywords>api,business,computer,cyber,cybersecurity,daily,domains,hacking,infosec,internet,it,microsoft,network,news,security,teams,vshell</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9688</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, November 5th, 2025: Apple Patches; Exploits against Trucking and Logistic; Google Android Patches</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-november-5th-2025-apple-patches-exploits-against-trucking-and-logistic-google-android-patches--68423720</link><description><![CDATA[<br /> Apple Patches Everything, Again<br /> Apple released a minor OS upgrade across its lineup, fixing a number of security vulnerabilities.<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything%2C%20Again/32448" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Everything%2C%20Again/32448</a><br /> Remote Access Tools Used to Compromise Trucking and Logistics<br /> Attackers infect trucking and logistics companies with regular remote management tools to inject malware into other companies or learn about high-value loads in order to steal them.<br /><a href="https://www.proofpoint.com/us/blog/threat-insight/remote-access-real-cargo-cybercriminals-targeting-trucking-and-logistics" target="_blank" rel="noreferrer noopener">https://www.proofpoint.com/us/blog/threat-insight/remote-access-real-cargo-cybercriminals-targeting-trucking-and-logistics</a><br /> Google Android Patch Day<br /> Google released its usual monthly Android updates this week<br /><a href="https://source.android.com/docs/security/bulletin/2025-11-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2025-11-01</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9686.mp3</guid><pubDate>Wed, 05 Nov 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68423720/9686.mp3" length="5454053" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9686" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Apple Patches Everything, Again
 Apple released a minor OS upgrade across its lineup, fixing a number of security vulnerabilities.
https://isc.sans.edu/diary/Apple%20Patches%20Everything%2C%20Again/32448
 Remote Access Tools Used to Compromise...</itunes:subtitle><itunes:summary><![CDATA[<br /> Apple Patches Everything, Again<br /> Apple released a minor OS upgrade across its lineup, fixing a number of security vulnerabilities.<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything%2C%20Again/32448" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Everything%2C%20Again/32448</a><br /> Remote Access Tools Used to Compromise Trucking and Logistics<br /> Attackers infect trucking and logistics companies with regular remote management tools to inject malware into other companies or learn about high-value loads in order to steal them.<br /><a href="https://www.proofpoint.com/us/blog/threat-insight/remote-access-real-cargo-cybercriminals-targeting-trucking-and-logistics" target="_blank" rel="noreferrer noopener">https://www.proofpoint.com/us/blog/threat-insight/remote-access-real-cargo-cybercriminals-targeting-trucking-and-logistics</a><br /> Google Android Patch Day<br /> Google released its usual monthly Android updates this week<br /><a href="https://source.android.com/docs/security/bulletin/2025-11-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2025-11-01</a><br />]]></itunes:summary><itunes:duration>390</itunes:duration><itunes:keywords>apple,business,computer,cyber,cybersecurity,daily,google,hacking,infosec,internet,it,network,news,patches,security,trucks</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9686</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, November 4th, 2025: XWiki SolrSearch Exploits and Rapper Feud; AMD Zen 5 RDSEED Bug; More Malicious Open VSX Extensi</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-november-4th-2025-xwiki-solrsearch-exploits-and-rapper-feud-amd-zen-5-rdseed-bug-more-malicious-open-vsx-extensi--68406626</link><description><![CDATA[<br /> XWiki SolrSearch Exploit Attempts CVE-2025-24893<br /> We have detected a number of exploit attempts against XWiki taking advantage of a vulnerability that was added to the KEV list on Friday.<br /><a href="https://isc.sans.edu/diary/XWiki%20SolrSearch%20Exploit%20Attempts%20%28CVE-2025-24893%29%20with%20link%20to%20Chicago%20Gangs%20Rappers/32444" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/XWiki%20SolrSearch%20Exploit%20Attempts%20%28CVE-2025-24893%29%20with%20link%20to%20Chicago%20Gangs%20Rappers/32444</a><br /> AMD Zen 5 Random Number Generator Bug<br /> The RDSEED function for AMD s Zen 5 processors does return 0 more often than it should.<br /><a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html" target="_blank" rel="noreferrer noopener">https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html</a><br /> SleepyDuck malware invades Cursor through Open VSX<br /> Yet another Open VSX extension stealing crypto credentials<br /><a href="https://secureannex.com/blog/sleepyduck-malware/" target="_blank" rel="noreferrer noopener">https://secureannex.com/blog/sleepyduck-malware/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9684.mp3</guid><pubDate>Tue, 04 Nov 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68406626/9684.mp3" length="5827960" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9684" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 XWiki SolrSearch Exploit Attempts CVE-2025-24893
 We have detected a number of exploit attempts against XWiki taking advantage of a vulnerability that was added to the KEV list on Friday....</itunes:subtitle><itunes:summary><![CDATA[<br /> XWiki SolrSearch Exploit Attempts CVE-2025-24893<br /> We have detected a number of exploit attempts against XWiki taking advantage of a vulnerability that was added to the KEV list on Friday.<br /><a href="https://isc.sans.edu/diary/XWiki%20SolrSearch%20Exploit%20Attempts%20%28CVE-2025-24893%29%20with%20link%20to%20Chicago%20Gangs%20Rappers/32444" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/XWiki%20SolrSearch%20Exploit%20Attempts%20%28CVE-2025-24893%29%20with%20link%20to%20Chicago%20Gangs%20Rappers/32444</a><br /> AMD Zen 5 Random Number Generator Bug<br /> The RDSEED function for AMD s Zen 5 processors does return 0 more often than it should.<br /><a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html" target="_blank" rel="noreferrer noopener">https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html</a><br /> SleepyDuck malware invades Cursor through Open VSX<br /> Yet another Open VSX extension stealing crypto credentials<br /><a href="https://secureannex.com/blog/sleepyduck-malware/" target="_blank" rel="noreferrer noopener">https://secureannex.com/blog/sleepyduck-malware/</a><br />]]></itunes:summary><itunes:duration>416</itunes:duration><itunes:keywords>amd,business,computer,crypto,cyber,cybersecurity,daily,extensions,hacking,infosec,it,network,news,open vsx,random,rdseed,security,solrsearch,xwikit,zen 5</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9684</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, November 3rd, 2025: Port 8530/8531 Scans; BADCANDY Webshells; Open VSX Security Improvements</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-november-3rd-2025-port-8530-8531-scans-badcandy-webshells-open-vsx-security-improvements--68392751</link><description><![CDATA[<br /> Scans for WSUS: Port 8530/8531 TCP, CVE-2025-59287<br /> We did observe an increase in scans for TCP ports 8530 and 8531. These ports are associated with WSUS and the scans are likely looking for servers vulnerable to CVE-2025-59287<br /><a href="https://isc.sans.edu/diary/Scans%20for%20Port%208530%208531%20%28TCP%29.%20Likely%20related%20to%20WSUS%20Vulnerability%20CVE-2025-59287/32440" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20Port%208530%208531%20%28TCP%29.%20Likely%20related%20to%20WSUS%20Vulnerability%20CVE-2025-59287/32440</a><br /> BADCANDY Webshell Implant Deployed via<br /> The Australian Signals Directorate warns that they still see Cisco IOS XE devices not patches for CVE-2023-20198. A threat actor is now using this vulnerability to deploy the BADCANDY implant for persistent access<br /><a href="https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/badcandy" target="_blank" rel="noreferrer noopener">https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/badcandy</a><br /> Improvements to Open VSX Security<br /> In reference to the Glassworm incident, OpenVSX published a blog post outlining some of the security improvements they will make to prevent a repeat of this incident.<br /><a href="https://blogs.eclipse.org/post/mika" target="_blank" rel="noreferrer noopener">https://blogs.eclipse.org/post/mika</a> l-barbero/open-vsx-security-update-october-2025<br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9682.mp3</guid><pubDate>Mon, 03 Nov 2025 02:35:11 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68392751/9682.mp3" length="5415125" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9682" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Scans for WSUS: Port 8530/8531 TCP, CVE-2025-59287
 We did observe an increase in scans for TCP ports 8530 and 8531. These ports are associated with WSUS and the scans are likely looking for servers vulnerable to CVE-2025-59287...</itunes:subtitle><itunes:summary><![CDATA[<br /> Scans for WSUS: Port 8530/8531 TCP, CVE-2025-59287<br /> We did observe an increase in scans for TCP ports 8530 and 8531. These ports are associated with WSUS and the scans are likely looking for servers vulnerable to CVE-2025-59287<br /><a href="https://isc.sans.edu/diary/Scans%20for%20Port%208530%208531%20%28TCP%29.%20Likely%20related%20to%20WSUS%20Vulnerability%20CVE-2025-59287/32440" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20Port%208530%208531%20%28TCP%29.%20Likely%20related%20to%20WSUS%20Vulnerability%20CVE-2025-59287/32440</a><br /> BADCANDY Webshell Implant Deployed via<br /> The Australian Signals Directorate warns that they still see Cisco IOS XE devices not patches for CVE-2023-20198. A threat actor is now using this vulnerability to deploy the BADCANDY implant for persistent access<br /><a href="https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/badcandy" target="_blank" rel="noreferrer noopener">https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/badcandy</a><br /> Improvements to Open VSX Security<br /> In reference to the Glassworm incident, OpenVSX published a blog post outlining some of the security improvements they will make to prevent a repeat of this incident.<br /><a href="https://blogs.eclipse.org/post/mika" target="_blank" rel="noreferrer noopener">https://blogs.eclipse.org/post/mika</a> l-barbero/open-vsx-security-update-october-2025<br />]]></itunes:summary><itunes:duration>387</itunes:duration><itunes:keywords>badcandy,business,cisco,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,open vsx,security,wsus</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9682</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, October 31st, 2025: Bug Bounty Headers; Exchange hardening; MOVEIt vulnerability</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-october-31st-2025-bug-bounty-headers-exchange-hardening-moveit-vulnerability--68358181</link><description><![CDATA[<br /> X-Request-Purpose: Identifying "research" and bug bounty related scans?<br /> Our honeypots captured a few requests with bug bounty specific headers. These headers are meant to make it easier to identify requests related to bug bounty, and they are supposed to identify the researcher conducting the scans<br /><a href="https://isc.sans.edu/diary/X-Request-Purpose%3A%20Identifying%20%22research%22%20and%20bug%20bounty%20related%20scans%3F/32436" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/X-Request-Purpose%3A%20Identifying%20%22research%22%20and%20bug%20bounty%20related%20scans%3F/32436</a><br /> Proton Breach Observatory<br /> Proton opened up its breach observatory. This website will collect information about breaches affecting companies that have not yet made the breach public.<br /><a href="https://proton.me/blog/introducing-breach-observatory" target="_blank" rel="noreferrer noopener">https://proton.me/blog/introducing-breach-observatory</a><br /> Microsoft Exchange Server Security Best Practices<br /> A new document published by a collaboration of national cyber security agencies summarizes steps that should be taken to harden Exchange Server.<br /><a href="https://www.nsa.gov/Portals/75/documents/resources/cybersecurity-professionals/CSI_Microsoft_Exchange_Server_Security_Best_Practices.pdf?ver=9mpKKyUrwfpb9b9r4drVMg%3D%3D" target="_blank" rel="noreferrer noopener">https://www.nsa.gov/Portals/75/documents/resources/cybersecurity-professionals/CSI_Microsoft_Exchange_Server_Security_Best_Practices.pdf?ver=9mpKKyUrwfpb9b9r4drVMg%3d%3d</a><br /> MOVEit Vulnerability<br /> Progress published an advisory for its file transfer program  MOVEIt . This software has had heavily exploited vulnerabilities in the past.<br /><a href="https://community.progress.com/s/article/MOVEit-Transfer-Vulnerability-CVE-2025-10932-October-29-2025" target="_blank" rel="noreferrer noopener">https://community.progress.com/s/article/MOVEit-Transfer-Vulnerability-CVE-2025-10932-October-29-2025</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9680.mp3</guid><pubDate>Fri, 31 Oct 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68358181/9680.mp3" length="5315770" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9680" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 X-Request-Purpose: Identifying "research" and bug bounty related scans?
 Our honeypots captured a few requests with bug bounty specific headers. These headers are meant to make it easier to identify requests related to bug bounty, and they are...</itunes:subtitle><itunes:summary><![CDATA[<br /> X-Request-Purpose: Identifying "research" and bug bounty related scans?<br /> Our honeypots captured a few requests with bug bounty specific headers. These headers are meant to make it easier to identify requests related to bug bounty, and they are supposed to identify the researcher conducting the scans<br /><a href="https://isc.sans.edu/diary/X-Request-Purpose%3A%20Identifying%20%22research%22%20and%20bug%20bounty%20related%20scans%3F/32436" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/X-Request-Purpose%3A%20Identifying%20%22research%22%20and%20bug%20bounty%20related%20scans%3F/32436</a><br /> Proton Breach Observatory<br /> Proton opened up its breach observatory. This website will collect information about breaches affecting companies that have not yet made the breach public.<br /><a href="https://proton.me/blog/introducing-breach-observatory" target="_blank" rel="noreferrer noopener">https://proton.me/blog/introducing-breach-observatory</a><br /> Microsoft Exchange Server Security Best Practices<br /> A new document published by a collaboration of national cyber security agencies summarizes steps that should be taken to harden Exchange Server.<br /><a href="https://www.nsa.gov/Portals/75/documents/resources/cybersecurity-professionals/CSI_Microsoft_Exchange_Server_Security_Best_Practices.pdf?ver=9mpKKyUrwfpb9b9r4drVMg%3D%3D" target="_blank" rel="noreferrer noopener">https://www.nsa.gov/Portals/75/documents/resources/cybersecurity-professionals/CSI_Microsoft_Exchange_Server_Security_Best_Practices.pdf?ver=9mpKKyUrwfpb9b9r4drVMg%3d%3d</a><br /> MOVEit Vulnerability<br /> Progress published an advisory for its file transfer program  MOVEIt . This software has had heavily exploited vulnerabilities in the past.<br /><a href="https://community.progress.com/s/article/MOVEit-Transfer-Vulnerability-CVE-2025-10932-October-29-2025" target="_blank" rel="noreferrer noopener">https://community.progress.com/s/article/MOVEit-Transfer-Vulnerability-CVE-2025-10932-October-29-2025</a><br />]]></itunes:summary><itunes:duration>380</itunes:duration><itunes:keywords>bug bounty,business,computer,cyber,cybersecurity,daily,exchange,hacking,headers,infosec,internet,it,microsoft,moveit,network,news,proton,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9680</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, October 30th, 2025: Memory Only Filesystems Forensics; Azure Outage; docker-compose patch</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-october-30th-2025-memory-only-filesystems-forensics-azure-outage-docker-compose-patch--68344098</link><description><![CDATA[<br /> How to Collect Memory-Only Filesystems on Linux Systems<br /> Getting forensically sound copies of memory-only file systems on Linux can be tricky, as tools like  dd  do not work.<br /><a href="https://isc.sans.edu/diary/How%20to%20collect%20memory-only%20filesystems%20on%20Linux%20systems/32432" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20to%20collect%20memory-only%20filesystems%20on%20Linux%20systems/32432</a><br /> Microsoft Azure Front Door Outage<br /> Today, Microsoft s Azure Front Door service failed, leading to users not being able to authenticate to various Azure-related services.<br /><a href="https://azure.status.microsoft/en-us/status" target="_blank" rel="noreferrer noopener">https://azure.status.microsoft/en-us/status</a><br /> Docker-Compose Vulnerability<br /> A vulnerability in docker-compose may be used to trick users into creating files outside the docker-compose directory<br /><a href="https://github.com/docker/compose/security/advisories/GHSA-gv8h-7v7w-r22q" target="_blank" rel="noreferrer noopener">https://github.com/docker/compose/security/advisories/GHSA-gv8h-7v7w-r22q</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9678.mp3</guid><pubDate>Thu, 30 Oct 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68344098/9678.mp3" length="5142376" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9678" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 How to Collect Memory-Only Filesystems on Linux Systems
 Getting forensically sound copies of memory-only file systems on Linux can be tricky, as tools like  dd  do not work....</itunes:subtitle><itunes:summary><![CDATA[<br /> How to Collect Memory-Only Filesystems on Linux Systems<br /> Getting forensically sound copies of memory-only file systems on Linux can be tricky, as tools like  dd  do not work.<br /><a href="https://isc.sans.edu/diary/How%20to%20collect%20memory-only%20filesystems%20on%20Linux%20systems/32432" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20to%20collect%20memory-only%20filesystems%20on%20Linux%20systems/32432</a><br /> Microsoft Azure Front Door Outage<br /> Today, Microsoft s Azure Front Door service failed, leading to users not being able to authenticate to various Azure-related services.<br /><a href="https://azure.status.microsoft/en-us/status" target="_blank" rel="noreferrer noopener">https://azure.status.microsoft/en-us/status</a><br /> Docker-Compose Vulnerability<br /> A vulnerability in docker-compose may be used to trick users into creating files outside the docker-compose directory<br /><a href="https://github.com/docker/compose/security/advisories/GHSA-gv8h-7v7w-r22q" target="_blank" rel="noreferrer noopener">https://github.com/docker/compose/security/advisories/GHSA-gv8h-7v7w-r22q</a><br />]]></itunes:summary><itunes:duration>367</itunes:duration><itunes:keywords>azure,business,compose,computer,cyber,cybersecurity,daily,docker,files,hacking,infosec,internet,it,microsoft,network,news,ram,security,temporary</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9678</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, October 29th, 2025: Invisible Subject Character Phishing; Tomcat PUT Vuln; BIND9 Spoofing Vuln PoC</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-october-29th-2025-invisible-subject-character-phishing-tomcat-put-vuln-bind9-spoofing-vuln-poc--68322204</link><description><![CDATA[<br /> Phishing with Invisible Characters in the Subject Line<br /> Phishing emails use invisible UTF-8 encoded characters to break up keywords used to detect phishing (or spam). This is aided by mail clients not rendering some characters that should be rendered.<br /><a href="https://isc.sans.edu/diary/A%20phishing%20with%20invisible%20characters%20in%20the%20subject%20line/32428" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20phishing%20with%20invisible%20characters%20in%20the%20subject%20line/32428</a><br /> Apache Tomcat PUT Directory Traversal<br /> Apache released an update to Tomcat fixing a directory traversal vulnerability in how the PUT method is used. Exploits could upload arbitrary files, leading to remote code execution.<br /><a href="https://lists.apache.org/thread/n05kjcwyj1s45ovs8ll1qrrojhfb1tog" target="_blank" rel="noreferrer noopener">https://lists.apache.org/thread/n05kjcwyj1s45ovs8ll1qrrojhfb1tog</a><br /> BIND9 DNS Spoofing Vulnerability<br /> A PoC exploit is now available for the recently patched BIND9 spoofing vulnerability<br /><a href="https://gist.github.com/N3mes1s/f76b4a606308937b0806a5256bc1f918" target="_blank" rel="noreferrer noopener">https://gist.github.com/N3mes1s/f76b4a606308937b0806a5256bc1f918</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9676.mp3</guid><pubDate>Wed, 29 Oct 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68322204/9676.mp3" length="6788646" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9676" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Phishing with Invisible Characters in the Subject Line
 Phishing emails use invisible UTF-8 encoded characters to break up keywords used to detect phishing (or spam). This is aided by mail clients not rendering some characters that should be...</itunes:subtitle><itunes:summary><![CDATA[<br /> Phishing with Invisible Characters in the Subject Line<br /> Phishing emails use invisible UTF-8 encoded characters to break up keywords used to detect phishing (or spam). This is aided by mail clients not rendering some characters that should be rendered.<br /><a href="https://isc.sans.edu/diary/A%20phishing%20with%20invisible%20characters%20in%20the%20subject%20line/32428" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20phishing%20with%20invisible%20characters%20in%20the%20subject%20line/32428</a><br /> Apache Tomcat PUT Directory Traversal<br /> Apache released an update to Tomcat fixing a directory traversal vulnerability in how the PUT method is used. Exploits could upload arbitrary files, leading to remote code execution.<br /><a href="https://lists.apache.org/thread/n05kjcwyj1s45ovs8ll1qrrojhfb1tog" target="_blank" rel="noreferrer noopener">https://lists.apache.org/thread/n05kjcwyj1s45ovs8ll1qrrojhfb1tog</a><br /> BIND9 DNS Spoofing Vulnerability<br /> A PoC exploit is now available for the recently patched BIND9 spoofing vulnerability<br /><a href="https://gist.github.com/N3mes1s/f76b4a606308937b0806a5256bc1f918" target="_blank" rel="noreferrer noopener">https://gist.github.com/N3mes1s/f76b4a606308937b0806a5256bc1f918</a><br />]]></itunes:summary><itunes:duration>485</itunes:duration><itunes:keywords>apache,bind9,business,computer,cyber,cybersecurity,daily,dns,hacking,infosec,internet,it,network,news,phishing,put,security,subject,tomcat,unicode</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9676</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, October 28th, 2025:  Bytes over DNS; Unifi Access Vuln; OpenAI Atlas Prompt Injection</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-october-28th-2025-bytes-over-dns-unifi-access-vuln-openai-atlas-prompt-injection--68305869</link><description><![CDATA[<br /> Bytes over DNS<br /> Didiear investigated which bytes may be transmitted as part of a hostname in DNS packets, depending on the client resolver and recursive resolver constraints<br /><a href="https://isc.sans.edu/diary/Bytes%20over%20DNS/32420" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Bytes%20over%20DNS/32420</a><br /> Unifi Access Vulnerability<br /> Unifi fixed a critical vulnerability in it s Access product<br /><a href="https://community.ui.com/releases/Security-Advisory-Bulletin-056-056/ce97352d-91cd-40a7-a2f4-2c73b3b30191" target="_blank" rel="noreferrer noopener">https://community.ui.com/releases/Security-Advisory-Bulletin-056-056/ce97352d-91cd-40a7-a2f4-2c73b3b30191</a><br /> OpenAI Atlas Omnibox Prompt Injection<br /> OpenAI s latest browser can be jailbroken by inserting prompts in URLs<br /><a href="https://neuraltrust.ai/blog/openai-atlas-omnibox-prompt-injection" target="_blank" rel="noreferrer noopener">https://neuraltrust.ai/blog/openai-atlas-omnibox-prompt-injection</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9674.mp3</guid><pubDate>Tue, 28 Oct 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68305869/9674.mp3" length="5277452" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9674" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Bytes over DNS
 Didiear investigated which bytes may be transmitted as part of a hostname in DNS packets, depending on the client resolver and recursive resolver constraints
https://isc.sans.edu/diary/Bytes%20over%20DNS/32420
 Unifi Access...</itunes:subtitle><itunes:summary><![CDATA[<br /> Bytes over DNS<br /> Didiear investigated which bytes may be transmitted as part of a hostname in DNS packets, depending on the client resolver and recursive resolver constraints<br /><a href="https://isc.sans.edu/diary/Bytes%20over%20DNS/32420" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Bytes%20over%20DNS/32420</a><br /> Unifi Access Vulnerability<br /> Unifi fixed a critical vulnerability in it s Access product<br /><a href="https://community.ui.com/releases/Security-Advisory-Bulletin-056-056/ce97352d-91cd-40a7-a2f4-2c73b3b30191" target="_blank" rel="noreferrer noopener">https://community.ui.com/releases/Security-Advisory-Bulletin-056-056/ce97352d-91cd-40a7-a2f4-2c73b3b30191</a><br /> OpenAI Atlas Omnibox Prompt Injection<br /> OpenAI s latest browser can be jailbroken by inserting prompts in URLs<br /><a href="https://neuraltrust.ai/blog/openai-atlas-omnibox-prompt-injection" target="_blank" rel="noreferrer noopener">https://neuraltrust.ai/blog/openai-atlas-omnibox-prompt-injection</a><br />]]></itunes:summary><itunes:duration>377</itunes:duration><itunes:keywords>atlas,business,bytes,computer,cyber,cybersecurity,daily,dns,hacking,infosec,internet,it,network,news,openai,security,unifi</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9674</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, October 27th, 2025: Bilingual Phishing; Kaitai Struct WebIDE</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-october-27th-2025-bilingual-phishing-kaitai-struct-webide--68291254</link><description><![CDATA[<br /> Bilingual Phishing for Cloud Credentials<br /> Guy observed identical phishing messages in French and English attempting to phish cloud credentials<br /><a href="https://isc.sans.edu/diary/Phishing%20Cloud%20Account%20for%20Information/32416" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Phishing%20Cloud%20Account%20for%20Information/32416</a><br /> Kaitai Struct WebIDE<br /> The binary file analysis tool Kaitai Struct is now available in a web only version<br /><a href="https://isc.sans.edu/diary/Kaitai%20Struct%20WebIDE/32422" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Kaitai%20Struct%20WebIDE/32422</a><br /> WSUS Emergency Update<br /> Microsoft released an emergency patch for WSUS to fix a currently exploited critical vulnerability<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287</a><br /> Network Security Devices Endanger Orgs with 90s-era Flaws<br /> Attackers increasingly use simple-to-exploit network security device vulnerabilities to compromise organizations.<br /><a href="https://www.csoonline.com/article/4074945/network-security-devices-endanger-orgs-with-90s-era-flaws.html" target="_blank" rel="noreferrer noopener">https://www.csoonline.com/article/4074945/network-security-devices-endanger-orgs-with-90s-era-flaws.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9672.mp3</guid><pubDate>Mon, 27 Oct 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68291254/9672.mp3" length="5327779" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9672" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Bilingual Phishing for Cloud Credentials
 Guy observed identical phishing messages in French and English attempting to phish cloud credentials
https://isc.sans.edu/diary/Phishing%20Cloud%20Account%20for%20Information/32416
 Kaitai Struct WebIDE
 The...</itunes:subtitle><itunes:summary><![CDATA[<br /> Bilingual Phishing for Cloud Credentials<br /> Guy observed identical phishing messages in French and English attempting to phish cloud credentials<br /><a href="https://isc.sans.edu/diary/Phishing%20Cloud%20Account%20for%20Information/32416" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Phishing%20Cloud%20Account%20for%20Information/32416</a><br /> Kaitai Struct WebIDE<br /> The binary file analysis tool Kaitai Struct is now available in a web only version<br /><a href="https://isc.sans.edu/diary/Kaitai%20Struct%20WebIDE/32422" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Kaitai%20Struct%20WebIDE/32422</a><br /> WSUS Emergency Update<br /> Microsoft released an emergency patch for WSUS to fix a currently exploited critical vulnerability<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287</a><br /> Network Security Devices Endanger Orgs with 90s-era Flaws<br /> Attackers increasingly use simple-to-exploit network security device vulnerabilities to compromise organizations.<br /><a href="https://www.csoonline.com/article/4074945/network-security-devices-endanger-orgs-with-90s-era-flaws.html" target="_blank" rel="noreferrer noopener">https://www.csoonline.com/article/4074945/network-security-devices-endanger-orgs-with-90s-era-flaws.html</a><br />]]></itunes:summary><itunes:duration>381</itunes:duration><itunes:keywords>0-day,border security,business,computer,cyber,cybersecurity,daily,exploits,hacking,infosec,internet,it,kaitai,network,network security,news,security,wsus</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9672</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, October 24th, 2025: Android Infostealer; SessionReaper Exploited; BIND/unbound DNS Spoofing fix; WSUS Exploit</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-october-24th-2025-android-infostealer-sessionreaper-exploited-bind-unbound-dns-spoofing-fix-wsus-exploit--68260203</link><description><![CDATA[<br /> Infostealer Targeting Android Devices<br /> This infostealer, written in Python, specifically targets Android phones. It takes advantage of Termux to gain access to data and exfiltrates it via Telegram.<br /><a href="https://isc.sans.edu/diary/Infostealer%20Targeting%20Android%20Devices/32414" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Infostealer%20Targeting%20Android%20Devices/32414</a><br /> Attackers exploit recently patched Adobe Commerce Vulnerability CVE-2025-54236<br /> Six weeks after Adobe's emergency patch, SessionReaper (CVE-2025-54236) has entered active exploitation. E-Commerce security company SanSec has detected multiple exploit attempts.<br /><a href="https://sansec.io/research/sessionreaper-exploitation" target="_blank" rel="noreferrer noopener">https://sansec.io/research/sessionreaper-exploitation</a><br /> Patch for BIND and unbound nameservers CVE-2025-40780<br /> The Internet Systems Consortium (ISC.org), as well as the Unbound project, patched a flaw that may allow for DNS spoofing due to a weak random number generator.<br /><a href="https://kb.isc.org/docs/cve-2025-40780" target="_blank" rel="noreferrer noopener">https://kb.isc.org/docs/cve-2025-40780</a><br /> WSUS Exploit Released CVE-2025-59287<br /> Hawktrace released a walk through showing how to exploit the recently patched WSUS vulnerability<br /><a href="https://hawktrace.com/blog/CVE-2025-59287" target="_blank" rel="noreferrer noopener">https://hawktrace.com/blog/CVE-2025-59287</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9670.mp3</guid><pubDate>Fri, 24 Oct 2025 02:00:04 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68260203/9670.mp3" length="5392144" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9670" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Infostealer Targeting Android Devices
 This infostealer, written in Python, specifically targets Android phones. It takes advantage of Termux to gain access to data and exfiltrates it via Telegram....</itunes:subtitle><itunes:summary><![CDATA[<br /> Infostealer Targeting Android Devices<br /> This infostealer, written in Python, specifically targets Android phones. It takes advantage of Termux to gain access to data and exfiltrates it via Telegram.<br /><a href="https://isc.sans.edu/diary/Infostealer%20Targeting%20Android%20Devices/32414" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Infostealer%20Targeting%20Android%20Devices/32414</a><br /> Attackers exploit recently patched Adobe Commerce Vulnerability CVE-2025-54236<br /> Six weeks after Adobe's emergency patch, SessionReaper (CVE-2025-54236) has entered active exploitation. E-Commerce security company SanSec has detected multiple exploit attempts.<br /><a href="https://sansec.io/research/sessionreaper-exploitation" target="_blank" rel="noreferrer noopener">https://sansec.io/research/sessionreaper-exploitation</a><br /> Patch for BIND and unbound nameservers CVE-2025-40780<br /> The Internet Systems Consortium (ISC.org), as well as the Unbound project, patched a flaw that may allow for DNS spoofing due to a weak random number generator.<br /><a href="https://kb.isc.org/docs/cve-2025-40780" target="_blank" rel="noreferrer noopener">https://kb.isc.org/docs/cve-2025-40780</a><br /> WSUS Exploit Released CVE-2025-59287<br /> Hawktrace released a walk through showing how to exploit the recently patched WSUS vulnerability<br /><a href="https://hawktrace.com/blog/CVE-2025-59287" target="_blank" rel="noreferrer noopener">https://hawktrace.com/blog/CVE-2025-59287</a><br />]]></itunes:summary><itunes:duration>385</itunes:duration><itunes:keywords>adobe,android,bind,business,commerce,computer,cyber,cybersecurity,daily,deserialization,hacking,infosec,infostealer,internet,it,network,news,python,security,wsus</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9670</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, October 23rd, 2025: Blue Angle Software Exploit; Oracle CPU; Rust tar library vulnerability.</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-october-23rd-2025-blue-angle-software-exploit-oracle-cpu-rust-tar-library-vulnerability--68247718</link><description><![CDATA[<br /> webctrl.cgi/Blue Angel Software Suite Exploit Attempts. Maybe CVE-2025-34033 Variant?<br /> Our honeypots detected attacks that appear to exploit CVE-2025-34033 or a similar vulnerability in the Blue Angle Software Suite.<br /><a href="https://isc.sans.edu/diary/webctrlcgiBlue+Angel+Software+Suite+Exploit+Attempts+Maybe+CVE202534033+Variant/32410" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/webctrlcgiBlue+Angel+Software+Suite+Exploit+Attempts+Maybe+CVE202534033+Variant/32410</a><br /> Oracle Critical Patch Update<br /> Oracle released its quarterly critical patch update. The update includes patches for 374 vulnerabilities across all of Oracle s products. There are nine more patches for Oracle s e-Business Suite.<br /><a href="https://www.oracle.com/security-alerts/cpuoct2025.html#AppendixEBS" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpuoct2025.html#AppendixEBS</a><br /> Rust TAR Library Vulnerability<br /> A vulnerability in the popular, but no longer maintained, async-tar vulnerability could lead to arbitrary code execution<br /><a href="https://edera.dev/stories/tarmageddon" target="_blank" rel="noreferrer noopener">https://edera.dev/stories/tarmageddon</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9668.mp3</guid><pubDate>Thu, 23 Oct 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68247718/9668.mp3" length="6276004" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9668" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 webctrl.cgi/Blue Angel Software Suite Exploit Attempts. Maybe CVE-2025-34033 Variant?
 Our honeypots detected attacks that appear to exploit CVE-2025-34033 or a similar vulnerability in the Blue Angle Software Suite....</itunes:subtitle><itunes:summary><![CDATA[<br /> webctrl.cgi/Blue Angel Software Suite Exploit Attempts. Maybe CVE-2025-34033 Variant?<br /> Our honeypots detected attacks that appear to exploit CVE-2025-34033 or a similar vulnerability in the Blue Angle Software Suite.<br /><a href="https://isc.sans.edu/diary/webctrlcgiBlue+Angel+Software+Suite+Exploit+Attempts+Maybe+CVE202534033+Variant/32410" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/webctrlcgiBlue+Angel+Software+Suite+Exploit+Attempts+Maybe+CVE202534033+Variant/32410</a><br /> Oracle Critical Patch Update<br /> Oracle released its quarterly critical patch update. The update includes patches for 374 vulnerabilities across all of Oracle s products. There are nine more patches for Oracle s e-Business Suite.<br /><a href="https://www.oracle.com/security-alerts/cpuoct2025.html#AppendixEBS" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpuoct2025.html#AppendixEBS</a><br /> Rust TAR Library Vulnerability<br /> A vulnerability in the popular, but no longer maintained, async-tar vulnerability could lead to arbitrary code execution<br /><a href="https://edera.dev/stories/tarmageddon" target="_blank" rel="noreferrer noopener">https://edera.dev/stories/tarmageddon</a><br />]]></itunes:summary><itunes:duration>448</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,rust,security,tar,webctrl</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9668</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, October 22nd, 2025: NTP Pool; Xubuntu Compromise; Squid Vulnerability; Lanscope Vuln;</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-october-22nd-2025-ntp-pool-xubuntu-compromise-squid-vulnerability-lanscope-vuln--68234050</link><description><![CDATA[<br /> What time is it? Accuracy of pool.ntp.org.<br /> How accurate and reliable is pool.ntp.org? Turns out it is very good!<br /><a href="https://isc.sans.edu/diary/What%20time%20is%20it%3F%20Accuracy%20of%20pool.ntp.org./32390" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20time%20is%20it%3F%20Accuracy%20of%20pool.ntp.org./32390</a><br /> Xubuntu Compromise<br /> The Xubuntu website was compromised last weekend and served malware<br /><a href="https://floss.social/@bluesabre/115401767635718361" target="_blank" rel="noreferrer noopener">https://floss.social/@bluesabre/115401767635718361</a><br /> Squid Proxy Vulnerability<br /> The Squid team fixed an information disclosure vulnerabilty that may leak authentication credentials.<br /><a href="https://github.com/squid-cache/squid/security/advisories/GHSA-c8cc-phh7-xmxr" target="_blank" rel="noreferrer noopener">https://github.com/squid-cache/squid/security/advisories/GHSA-c8cc-phh7-xmxr</a><br /> Lanscope Endpoint Manager Vulnerablity<br /><a href="https://jvn.jp/en/jp/JVN86318557/index.html" target="_blank" rel="noreferrer noopener">https://jvn.jp/en/jp/JVN86318557/index.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9666.mp3</guid><pubDate>Wed, 22 Oct 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68234050/9666.mp3" length="5558452" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9666" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 What time is it? Accuracy of pool.ntp.org.
 How accurate and reliable is pool.ntp.org? Turns out it is very good!
https://isc.sans.edu/diary/What%20time%20is%20it%3F%20Accuracy%20of%20pool.ntp.org./32390
 Xubuntu Compromise
 The Xubuntu website was...</itunes:subtitle><itunes:summary><![CDATA[<br /> What time is it? Accuracy of pool.ntp.org.<br /> How accurate and reliable is pool.ntp.org? Turns out it is very good!<br /><a href="https://isc.sans.edu/diary/What%20time%20is%20it%3F%20Accuracy%20of%20pool.ntp.org./32390" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20time%20is%20it%3F%20Accuracy%20of%20pool.ntp.org./32390</a><br /> Xubuntu Compromise<br /> The Xubuntu website was compromised last weekend and served malware<br /><a href="https://floss.social/@bluesabre/115401767635718361" target="_blank" rel="noreferrer noopener">https://floss.social/@bluesabre/115401767635718361</a><br /> Squid Proxy Vulnerability<br /> The Squid team fixed an information disclosure vulnerabilty that may leak authentication credentials.<br /><a href="https://github.com/squid-cache/squid/security/advisories/GHSA-c8cc-phh7-xmxr" target="_blank" rel="noreferrer noopener">https://github.com/squid-cache/squid/security/advisories/GHSA-c8cc-phh7-xmxr</a><br /> Lanscope Endpoint Manager Vulnerablity<br /><a href="https://jvn.jp/en/jp/JVN86318557/index.html" target="_blank" rel="noreferrer noopener">https://jvn.jp/en/jp/JVN86318557/index.html</a><br />]]></itunes:summary><itunes:duration>397</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,ntp,security,squid,time,xubuntu</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9666</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, October 21st, 2025: Syscall() Obfuscation; AWS down; Beijing Time Attack</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-october-21st-2025-syscall-obfuscation-aws-down-beijing-time-attack--68219965</link><description><![CDATA[<br /> Using Syscall() for Obfuscation/Fileless Activity<br /> Fileless malware written in Python can uses syscall() to create file descriptors in memory, evading signatures.<br /><a href="https://isc.sans.edu/diary/Using%20Syscall%28%29%20for%20Obfuscation%20Fileless%20Activity/32384" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Using%20Syscall%28%29%20for%20Obfuscation%20Fileless%20Activity/32384</a><br /> AWS Outages<br /> AWS has had issues most of the day on Monday, affecting numerous services.<br /><a href="https://health.aws.amazon.com/health/status" target="_blank" rel="noreferrer noopener">https://health.aws.amazon.com/health/status</a><br /> Time Server Hack<br /> China reports a compromise of its time standard servers. <br /><a href="https://thehackernews.com/2025/10/mss-claims-nsa-used-42-cyber-tools-in.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2025/10/mss-claims-nsa-used-42-cyber-tools-in.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9664.mp3</guid><pubDate>Mon, 20 Oct 2025 22:45:23 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68219965/9664.mp3" length="7800716" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9664" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Using Syscall() for Obfuscation/Fileless Activity
 Fileless malware written in Python can uses syscall() to create file descriptors in memory, evading signatures....</itunes:subtitle><itunes:summary><![CDATA[<br /> Using Syscall() for Obfuscation/Fileless Activity<br /> Fileless malware written in Python can uses syscall() to create file descriptors in memory, evading signatures.<br /><a href="https://isc.sans.edu/diary/Using%20Syscall%28%29%20for%20Obfuscation%20Fileless%20Activity/32384" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Using%20Syscall%28%29%20for%20Obfuscation%20Fileless%20Activity/32384</a><br /> AWS Outages<br /> AWS has had issues most of the day on Monday, affecting numerous services.<br /><a href="https://health.aws.amazon.com/health/status" target="_blank" rel="noreferrer noopener">https://health.aws.amazon.com/health/status</a><br /> Time Server Hack<br /> China reports a compromise of its time standard servers. <br /><a href="https://thehackernews.com/2025/10/mss-claims-nsa-used-42-cyber-tools-in.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2025/10/mss-claims-nsa-used-42-cyber-tools-in.html</a><br />]]></itunes:summary><itunes:duration>557</itunes:duration><itunes:keywords>aws,business,china,computer,cyber,cybersecurity,daily,hacking,infosec,it,malware,network,news,ntp,obfuscation,outage,python,security,syscall,time</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9664</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, October 20th, 2025: Malicious Tiktok; More Google Ad Problems; Satellite Insecurity</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-october-20th-2025-malicious-tiktok-more-google-ad-problems-satellite-insecurity--68206188</link><description><![CDATA[<br /> TikTok Videos Promoting Malware InstallationTikTok Videos Promoting Malware Installation<br /> Tiktok videos advertising ways to obtain software like Photoshop for free will instead trick users into downloading <br /><a href="https://isc.sans.edu/diary/TikTok%20Videos%20Promoting%20Malware%20Installation/32380" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/TikTok%20Videos%20Promoting%20Malware%20Installation/32380</a><br /> Google Ads Advertise Malware Targeting MacOS Developers<br /> Hunt.io discovered Google ads that pretend to advertise tools like Homebrew and password managers to spread malware<br /><a href="https://hunt.io/blog/macos-odyssey-amos-malware-campaign" target="_blank" rel="noreferrer noopener">https://hunt.io/blog/macos-odyssey-amos-malware-campaign</a><br /> Satellite Transmissions are often unencrypted<br /> A large amount of satellite traffic is unencrypted and easily accessible to eavesdropping<br /><a href="https://satcom.sysnet.ucsd.edu" target="_blank" rel="noreferrer noopener">https://satcom.sysnet.ucsd.edu</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9662.mp3</guid><pubDate>Sun, 19 Oct 2025 19:45:21 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68206188/9662.mp3" length="5241626" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9662" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 TikTok Videos Promoting Malware InstallationTikTok Videos Promoting Malware Installation
 Tiktok videos advertising ways to obtain software like Photoshop for free will instead trick users into downloading...</itunes:subtitle><itunes:summary><![CDATA[<br /> TikTok Videos Promoting Malware InstallationTikTok Videos Promoting Malware Installation<br /> Tiktok videos advertising ways to obtain software like Photoshop for free will instead trick users into downloading <br /><a href="https://isc.sans.edu/diary/TikTok%20Videos%20Promoting%20Malware%20Installation/32380" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/TikTok%20Videos%20Promoting%20Malware%20Installation/32380</a><br /> Google Ads Advertise Malware Targeting MacOS Developers<br /> Hunt.io discovered Google ads that pretend to advertise tools like Homebrew and password managers to spread malware<br /><a href="https://hunt.io/blog/macos-odyssey-amos-malware-campaign" target="_blank" rel="noreferrer noopener">https://hunt.io/blog/macos-odyssey-amos-malware-campaign</a><br /> Satellite Transmissions are often unencrypted<br /> A large amount of satellite traffic is unencrypted and easily accessible to eavesdropping<br /><a href="https://satcom.sysnet.ucsd.edu" target="_blank" rel="noreferrer noopener">https://satcom.sysnet.ucsd.edu</a><br />]]></itunes:summary><itunes:duration>375</itunes:duration><itunes:keywords>ads,business,computer,cyber,cybersecurity,daily,google,hacking,infosec,internet,it,malware,network,news,satellite,security,tiktop</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9662</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, October 17th, 2025: New Slack Workspace; Cisco SNMP Exploited; BIOS Backdoor; @sans_edu reseach: Active Defense</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-october-17th-2025-new-slack-workspace-cisco-snmp-exploited-bios-backdoor-sans-edu-reseach-active-defense--68173627</link><description><![CDATA[<br /> New DShield Support Slack Workspace<br /> Due to an error on Salesforce s side, we had to create a new Slack Workspace for DShield support.<br /><a href="https://isc.sans.edu/diary/New%20DShield%20Support%20Slack/32376" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/New%20DShield%20Support%20Slack/32376</a><br /> Attackers Exploiting Recently Patched Cisco SNMP Flaw (CVE-2025-20352)<br />  Trend Micro published details explaining how attackers took advantage of a recently patched Cisco SNMP Vulnerability<br /><a href="https://www.trendmicro.com/en_us/research/25/j/operation-zero-disco-cisco-snmp-vulnerability-exploit.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_us/research/25/j/operation-zero-disco-cisco-snmp-vulnerability-exploit.html</a><br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-x4LPhte" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-x4LPhte</a><br /> Framework BIOS Backdoor<br /> The mm command impleneted in Framework BIOS shells can be used to compromise a device pre-boot.<br /><a href="https://eclypsium.com/blog/bombshell-the-signed-backdoor-hiding-in-plain-sight-on-framework-devices/" target="_blank" rel="noreferrer noopener">https://eclypsium.com/blog/bombshell-the-signed-backdoor-hiding-in-plain-sight-on-framework-devices/</a><br /> SANS.edu Research:  Mark Stephens, Validating the Effectiveness of MITRE Engage and Active Defense<br /><a href="https://www.sans.edu/cyber-research/validating-effectiveness-mitre-engage-active-defense/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/validating-effectiveness-mitre-engage-active-defense/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9660.mp3</guid><pubDate>Fri, 17 Oct 2025 01:45:06 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68173627/9660.mp3" length="18038572" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9660" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 New DShield Support Slack Workspace
 Due to an error on Salesforce s side, we had to create a new Slack Workspace for DShield support.
https://isc.sans.edu/diary/New%20DShield%20Support%20Slack/32376
 Attackers Exploiting Recently Patched Cisco SNMP...</itunes:subtitle><itunes:summary><![CDATA[<br /> New DShield Support Slack Workspace<br /> Due to an error on Salesforce s side, we had to create a new Slack Workspace for DShield support.<br /><a href="https://isc.sans.edu/diary/New%20DShield%20Support%20Slack/32376" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/New%20DShield%20Support%20Slack/32376</a><br /> Attackers Exploiting Recently Patched Cisco SNMP Flaw (CVE-2025-20352)<br />  Trend Micro published details explaining how attackers took advantage of a recently patched Cisco SNMP Vulnerability<br /><a href="https://www.trendmicro.com/en_us/research/25/j/operation-zero-disco-cisco-snmp-vulnerability-exploit.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_us/research/25/j/operation-zero-disco-cisco-snmp-vulnerability-exploit.html</a><br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-x4LPhte" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-x4LPhte</a><br /> Framework BIOS Backdoor<br /> The mm command impleneted in Framework BIOS shells can be used to compromise a device pre-boot.<br /><a href="https://eclypsium.com/blog/bombshell-the-signed-backdoor-hiding-in-plain-sight-on-framework-devices/" target="_blank" rel="noreferrer noopener">https://eclypsium.com/blog/bombshell-the-signed-backdoor-hiding-in-plain-sight-on-framework-devices/</a><br /> SANS.edu Research:  Mark Stephens, Validating the Effectiveness of MITRE Engage and Active Defense<br /><a href="https://www.sans.edu/cyber-research/validating-effectiveness-mitre-engage-active-defense/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/validating-effectiveness-mitre-engage-active-defense/</a><br />]]></itunes:summary><itunes:duration>1288</itunes:duration><itunes:keywords>active defenense,bios,business,cisco,cyber,cybersecurity,daily,engage,framework,hacking,infosec,it,mitre,network,news,salesforce,@sans_edu,security,slack,snmp</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9660</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, October 16th, 2025: Clipboard Image Stealer; F5 Compromise; Adobe Updates; SAP Patchday</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-october-16th-2025-clipboard-image-stealer-f5-compromise-adobe-updates-sap-patchday--68156535</link><description><![CDATA[<br /> Clipboard Image Stealer<br /> Xavier presents an infostealer in Python that steals images from the clipboard.<br /><a href="https://isc.sans.edu/diary/Clipboard%20Pictures%20Exfiltration%20in%20Python%20Infostealer/32372" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Clipboard%20Pictures%20Exfiltration%20in%20Python%20Infostealer/32372</a><br /> F5 Compromise<br /> F5 announced a wide-ranging compromise today. Source code and information about unpatched vulnerabilities were stolen.<br /><a href="https://my.f5.com/manage/s/article/K000157005" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000157005</a> <a href="https://my.f5.com/manage/s/article/K000156572" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000156572</a> <a href="https://my.f5.com/manage/s/article/K000154696" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000154696</a><br /> Adobe Updates<br /> Adobe updated 12 different products yesterday. <br /><a href="https://helpx.adobe.com/security.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security.html</a><br /> SAP Patchday<br /> Among the critical vulnerabilities patched in SAP s products are two deserialization vulnerabilities with a CVSS score of 10.0<br /><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news/october-2025.html" target="_blank" rel="noreferrer noopener">https://support.sap.com/en/my-support/knowledge-base/security-notes-news/october-2025.html</a><br /><a href="https://onapsis.com/blog/sap-security-patch-day-october-2025/" target="_blank" rel="noreferrer noopener">https://onapsis.com/blog/sap-security-patch-day-october-2025/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9658.mp3</guid><pubDate>Wed, 15 Oct 2025 20:45:21 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68156535/9658.mp3" length="7284558" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9658" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Clipboard Image Stealer
 Xavier presents an infostealer in Python that steals images from the clipboard.
https://isc.sans.edu/diary/Clipboard%20Pictures%20Exfiltration%20in%20Python%20Infostealer/32372
 F5 Compromise
 F5 announced a wide-ranging...</itunes:subtitle><itunes:summary><![CDATA[<br /> Clipboard Image Stealer<br /> Xavier presents an infostealer in Python that steals images from the clipboard.<br /><a href="https://isc.sans.edu/diary/Clipboard%20Pictures%20Exfiltration%20in%20Python%20Infostealer/32372" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Clipboard%20Pictures%20Exfiltration%20in%20Python%20Infostealer/32372</a><br /> F5 Compromise<br /> F5 announced a wide-ranging compromise today. Source code and information about unpatched vulnerabilities were stolen.<br /><a href="https://my.f5.com/manage/s/article/K000157005" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000157005</a> <a href="https://my.f5.com/manage/s/article/K000156572" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000156572</a> <a href="https://my.f5.com/manage/s/article/K000154696" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000154696</a><br /> Adobe Updates<br /> Adobe updated 12 different products yesterday. <br /><a href="https://helpx.adobe.com/security.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security.html</a><br /> SAP Patchday<br /> Among the critical vulnerabilities patched in SAP s products are two deserialization vulnerabilities with a CVSS score of 10.0<br /><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news/october-2025.html" target="_blank" rel="noreferrer noopener">https://support.sap.com/en/my-support/knowledge-base/security-notes-news/october-2025.html</a><br /><a href="https://onapsis.com/blog/sap-security-patch-day-october-2025/" target="_blank" rel="noreferrer noopener">https://onapsis.com/blog/sap-security-patch-day-october-2025/</a><br />]]></itunes:summary><itunes:duration>520</itunes:duration><itunes:keywords>adobe,breach,business,clipboard,computer,cyber,cybersecurity,daily,f5,hacking,infosec,internet,it,network,news,nginx,security,stealer</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9658</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, October 15th, 2025: Microsoft Patchday; Ivanti Advisory; Fortinet Patches</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-october-15th-2025-microsoft-patchday-ivanti-advisory-fortinet-patches--68142398</link><description><![CDATA[<br /> Microsoft Patch Tuesday<br /> Microsoft not only released new patches, but also the last patches for Windows 10, Office 2016, Office 2019, Exchange 2016 and Exchange 2019.<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20October%202025/32368" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20October%202025/32368</a><br /> Ivanti Advisory<br /> Ivanti released an advisory with some mitigation steps users can take until the recently made public vulnerablities are patched.<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-EPM-October-2025?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-EPM-October-2025?language=en_US</a><br /> Fortinet Patches<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-010" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-25-010</a><br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-24-361" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-24-361</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9656.mp3</guid><pubDate>Tue, 14 Oct 2025 23:45:28 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68142398/9656.mp3" length="5350630" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9656" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Microsoft Patch Tuesday
 Microsoft not only released new patches, but also the last patches for Windows 10, Office 2016, Office 2019, Exchange 2016 and Exchange 2019.
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20October%202025/32368...</itunes:subtitle><itunes:summary><![CDATA[<br /> Microsoft Patch Tuesday<br /> Microsoft not only released new patches, but also the last patches for Windows 10, Office 2016, Office 2019, Exchange 2016 and Exchange 2019.<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20October%202025/32368" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20October%202025/32368</a><br /> Ivanti Advisory<br /> Ivanti released an advisory with some mitigation steps users can take until the recently made public vulnerablities are patched.<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-EPM-October-2025?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-EPM-October-2025?language=en_US</a><br /> Fortinet Patches<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-010" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-25-010</a><br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-24-361" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-24-361</a><br />]]></itunes:summary><itunes:duration>382</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,fortinet,hacking,infosec,internet,it,ivanti,microsoft,network,news,patches,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9656</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, October 14th, 2025: ESAFENET Scans; Payroll Priates; MSFT Edge IE Mode</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-october-14th-2025-esafenet-scans-payroll-priates-msft-edge-ie-mode--68125268</link><description><![CDATA[<br /> Scans for ESAFENET CDG V5<br /> We do see some increase in scans for the Chinese secure document management system, ESAFENET.<br /><a href="https://isc.sans.edu/diary/Heads%20Up%3A%20Scans%20for%20ESAFENET%20CDG%20V5%20/32364" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Heads%20Up%3A%20Scans%20for%20ESAFENET%20CDG%20V5%20/32364</a><br /> Investigating targeted  payroll pirate  attacks affecting US universities<br /> Microsoft wrote about how payroll pirates redirect employee paychecks via phishing.<br /><a href="https://www.microsoft.com/en-us/security/blog/2025/10/09/investigating-targeted-payroll-pirate-attacks-affecting-us-universities/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2025/10/09/investigating-targeted-payroll-pirate-attacks-affecting-us-universities/</a><br /> Attacks against Edge via IE Mode<br /> Microsoft Edge offers an IE legacy mode to support websites created for Internet Explorer. The old JavaScript engine, which is part of this mode, has been abused in recent attacks, and Microsoft will make it more difficult to enable IE Mode to counter these attacks.<br /><a href="https://microsoftedge.github.io/edgevr/posts/Changes-to-Internet-Explorer-Mode-in-Microsoft-Edge/" target="_blank" rel="noreferrer noopener">https://microsoftedge.github.io/edgevr/posts/Changes-to-Internet-Explorer-Mode-in-Microsoft-Edge/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9654.mp3</guid><pubDate>Mon, 13 Oct 2025 22:45:46 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68125268/9654.mp3" length="5080454" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9654" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Scans for ESAFENET CDG V5
 We do see some increase in scans for the Chinese secure document management system, ESAFENET.
https://isc.sans.edu/diary/Heads%20Up%3A%20Scans%20for%20ESAFENET%20CDG%20V5%20/32364
 Investigating targeted  payroll pirate...</itunes:subtitle><itunes:summary><![CDATA[<br /> Scans for ESAFENET CDG V5<br /> We do see some increase in scans for the Chinese secure document management system, ESAFENET.<br /><a href="https://isc.sans.edu/diary/Heads%20Up%3A%20Scans%20for%20ESAFENET%20CDG%20V5%20/32364" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Heads%20Up%3A%20Scans%20for%20ESAFENET%20CDG%20V5%20/32364</a><br /> Investigating targeted  payroll pirate  attacks affecting US universities<br /> Microsoft wrote about how payroll pirates redirect employee paychecks via phishing.<br /><a href="https://www.microsoft.com/en-us/security/blog/2025/10/09/investigating-targeted-payroll-pirate-attacks-affecting-us-universities/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2025/10/09/investigating-targeted-payroll-pirate-attacks-affecting-us-universities/</a><br /> Attacks against Edge via IE Mode<br /> Microsoft Edge offers an IE legacy mode to support websites created for Internet Explorer. The old JavaScript engine, which is part of this mode, has been abused in recent attacks, and Microsoft will make it more difficult to enable IE Mode to counter these attacks.<br /><a href="https://microsoftedge.github.io/edgevr/posts/Changes-to-Internet-Explorer-Mode-in-Microsoft-Edge/" target="_blank" rel="noreferrer noopener">https://microsoftedge.github.io/edgevr/posts/Changes-to-Internet-Explorer-Mode-in-Microsoft-Edge/</a><br />]]></itunes:summary><itunes:duration>363</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,edge,hacking,ie,infosec,internet,internet explorer,it,javascript,microsoft,network,news,payroll,pirates,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9654</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, October 13th, 2025: More Oracle Patches; Sonicwall Compromisses; Unpatched Gladinet; 7-Zip Patches</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-october-13th-2025-more-oracle-patches-sonicwall-compromisses-unpatched-gladinet-7-zip-patches--68111653</link><description><![CDATA[<br /> New Oracle E-Business Suite Patches<br /> Oracle released one more patch for the e-business suite. Oracle does not state if it is already exploited, but the timing of the patch suggests that it should be expedited.<br /><a href="https://www.oracle.com/security-alerts/alert-cve-2025-61884.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/alert-cve-2025-61884.html</a><br /> Widespread Sonicwall SSLVPN Compromise<br /> Huntress Labs observed the widespread compromise of the Sonicwall SSLVPN appliance.<br /><a href="https://www.huntress.com/blog/sonicwall-sslvpn-compromise" target="_blank" rel="noreferrer noopener">https://www.huntress.com/blog/sonicwall-sslvpn-compromise</a><br /> Active Exploitation of Gladinet CentreStack and Triofox Local File Inclusion Flaw (CVE-2025-11371)<br /> An unpatched vulnerability in the  secure  file sharing solutions Gladinet CentreStack and TrioFox is being exploited.<br /><a href="https://www.huntress.com/blog/gladinet-centrestack-triofox-local-file-inclusion-flaw" target="_blank" rel="noreferrer noopener">https://www.huntress.com/blog/gladinet-centrestack-triofox-local-file-inclusion-flaw</a><br /> Two 7-Zip Vulnerabilities CVE-2025-11002, CVE-2025-11001<br /> 7-Zip patched two vulnerabilities that may lead to arbitrary code execution<br /><a href="https://www.zerodayinitiative.com/advisories/ZDI-25-949/" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/advisories/ZDI-25-949/</a><br /><a href="https://www.zerodayinitiative.com/advisories/ZDI-25-950/" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/advisories/ZDI-25-950/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9652.mp3</guid><pubDate>Sun, 12 Oct 2025 21:45:20 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68111653/9652.mp3" length="4986057" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9652" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 New Oracle E-Business Suite Patches
 Oracle released one more patch for the e-business suite. Oracle does not state if it is already exploited, but the timing of the patch suggests that it should be expedited....</itunes:subtitle><itunes:summary><![CDATA[<br /> New Oracle E-Business Suite Patches<br /> Oracle released one more patch for the e-business suite. Oracle does not state if it is already exploited, but the timing of the patch suggests that it should be expedited.<br /><a href="https://www.oracle.com/security-alerts/alert-cve-2025-61884.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/alert-cve-2025-61884.html</a><br /> Widespread Sonicwall SSLVPN Compromise<br /> Huntress Labs observed the widespread compromise of the Sonicwall SSLVPN appliance.<br /><a href="https://www.huntress.com/blog/sonicwall-sslvpn-compromise" target="_blank" rel="noreferrer noopener">https://www.huntress.com/blog/sonicwall-sslvpn-compromise</a><br /> Active Exploitation of Gladinet CentreStack and Triofox Local File Inclusion Flaw (CVE-2025-11371)<br /> An unpatched vulnerability in the  secure  file sharing solutions Gladinet CentreStack and TrioFox is being exploited.<br /><a href="https://www.huntress.com/blog/gladinet-centrestack-triofox-local-file-inclusion-flaw" target="_blank" rel="noreferrer noopener">https://www.huntress.com/blog/gladinet-centrestack-triofox-local-file-inclusion-flaw</a><br /> Two 7-Zip Vulnerabilities CVE-2025-11002, CVE-2025-11001<br /> 7-Zip patched two vulnerabilities that may lead to arbitrary code execution<br /><a href="https://www.zerodayinitiative.com/advisories/ZDI-25-949/" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/advisories/ZDI-25-949/</a><br /><a href="https://www.zerodayinitiative.com/advisories/ZDI-25-950/" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/advisories/ZDI-25-950/</a><br />]]></itunes:summary><itunes:duration>356</itunes:duration><itunes:keywords>7zip,business,cntrestack,computer,cyber,cybersecurity,daily,ebusiness,gladinet,hacking,infosec,internet,it,network,news,oracle,security,sonicwall,suite,triofox</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9652</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, October 10th, 2025:  RedTail Defenses; SonicWall Breach; Crowdstrike “Issues”; Ivanti 0-days; Mapping Agentic Attack</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-october-10th-2025-redtail-defenses-sonicwall-breach-crowdstrike-issues-ivanti-0-days-mapping-agentic-attack--68086409</link><description><![CDATA[Building Better Defenses: RedTail Observations<br /> Defending against attacks like RedTail is more then blocking IoCs, but instead one must focus on the techniques and tactics attackers use.<br /><a href="https://isc.sans.edu/diary/Guest+Diary+Building+Better+Defenses+RedTail+Observations+from+a+Honeypot/32312" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Guest+Diary+Building+Better+Defenses+RedTail+Observations+from+a+Honeypot/32312</a><br /> Sonicwall: It wasn t the user s fault<br /> Sonicwall admits to a breach resulting in the loss of user configurations stored in its cloud service<br /><a href="https://www.sonicwall.com/support/knowledge-base/mysonicwall-cloud-backup-file-incident/250915160910330" target="_blank" rel="noreferrer noopener">https://www.sonicwall.com/support/knowledge-base/mysonicwall-cloud-backup-file-incident/250915160910330</a><br /> Crowdstrike has Issues<br /> Crowdstrike fixes two vulnerabilities in the Windows version of its Falcon sensor.<br /><a href="https://www.crowdstrike.com/en-us/security-advisories/issues-affecting-crowdstrike-falcon-sensor-for-windows/" target="_blank" rel="noreferrer noopener">https://www.crowdstrike.com/en-us/security-advisories/issues-affecting-crowdstrike-falcon-sensor-for-windows/</a><br /> Interrogators: Attack Surface Mapping in an Agentic World<br /> A SANS.edu master s degree student research paper by Michael Samson<br /><a href="https://isc.sans.edu/researchpapers/pdfs/michael_samson.pdf" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/researchpapers/pdfs/michael_samson.pdf</a><br /> keywords: ai; agentic; attack surface; crowdstrike; sonicwall; ivanti; zero day; initiative; redline]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9650.mp3</guid><pubDate>Fri, 10 Oct 2025 00:45:06 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68086409/9650.mp3" length="12779396" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9650" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Building Better Defenses: RedTail Observations
 Defending against attacks like RedTail is more then blocking IoCs, but instead one must focus on the techniques and tactics attackers use....</itunes:subtitle><itunes:summary><![CDATA[Building Better Defenses: RedTail Observations<br /> Defending against attacks like RedTail is more then blocking IoCs, but instead one must focus on the techniques and tactics attackers use.<br /><a href="https://isc.sans.edu/diary/Guest+Diary+Building+Better+Defenses+RedTail+Observations+from+a+Honeypot/32312" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Guest+Diary+Building+Better+Defenses+RedTail+Observations+from+a+Honeypot/32312</a><br /> Sonicwall: It wasn t the user s fault<br /> Sonicwall admits to a breach resulting in the loss of user configurations stored in its cloud service<br /><a href="https://www.sonicwall.com/support/knowledge-base/mysonicwall-cloud-backup-file-incident/250915160910330" target="_blank" rel="noreferrer noopener">https://www.sonicwall.com/support/knowledge-base/mysonicwall-cloud-backup-file-incident/250915160910330</a><br /> Crowdstrike has Issues<br /> Crowdstrike fixes two vulnerabilities in the Windows version of its Falcon sensor.<br /><a href="https://www.crowdstrike.com/en-us/security-advisories/issues-affecting-crowdstrike-falcon-sensor-for-windows/" target="_blank" rel="noreferrer noopener">https://www.crowdstrike.com/en-us/security-advisories/issues-affecting-crowdstrike-falcon-sensor-for-windows/</a><br /> Interrogators: Attack Surface Mapping in an Agentic World<br /> A SANS.edu master s degree student research paper by Michael Samson<br /><a href="https://isc.sans.edu/researchpapers/pdfs/michael_samson.pdf" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/researchpapers/pdfs/michael_samson.pdf</a><br /> keywords: ai; agentic; attack surface; crowdstrike; sonicwall; ivanti; zero day; initiative; redline]]></itunes:summary><itunes:duration>913</itunes:duration><itunes:keywords>android,apple,business,computer,cyber,cybersecurity,cyber security,daily,firewall,hacking,infosec,internet,ios,it,linux,network,news,security,technology,windows</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9650</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, October 9th, 2025: Polymorphic Python; ssh ProxyCommand Vuln;</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-october-9th-2025-polymorphic-python-ssh-proxycommand-vuln--68071651</link><description><![CDATA[<br /> Polymorphic Python Malware<br /> Xavier discovered self-modifying Python code on Virustotal. The remote access tool takes advantage of the inspect module to modify code on the fly.<br /><a href="https://isc.sans.edu/diary/Polymorphic%20Python%20Malware/32354" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Polymorphic%20Python%20Malware/32354</a><br /> SSH ProxyCommand Vulnerability<br /> A user cloning a git repository may be tricked into executing arbitrary code via the SSH proxycommand option.<br /><a href="https://dgl.cx/2025/10/bash-a-newline-ssh-proxycommand-cve-2025-61984" target="_blank" rel="noreferrer noopener">https://dgl.cx/2025/10/bash-a-newline-ssh-proxycommand-cve-2025-61984</a><br /> Framelink Figma MCP Server CVE-2025-53967<br /> Framelink Figma s MCP server suffers from a remote code execution vulnerability. <br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9648.mp3</guid><pubDate>Thu, 09 Oct 2025 03:10:14 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68071651/9648.mp3" length="5210672" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9648" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Polymorphic Python Malware
 Xavier discovered self-modifying Python code on Virustotal. The remote access tool takes advantage of the inspect module to modify code on the fly.
https://isc.sans.edu/diary/Polymorphic%20Python%20Malware/32354
 SSH...</itunes:subtitle><itunes:summary><![CDATA[<br /> Polymorphic Python Malware<br /> Xavier discovered self-modifying Python code on Virustotal. The remote access tool takes advantage of the inspect module to modify code on the fly.<br /><a href="https://isc.sans.edu/diary/Polymorphic%20Python%20Malware/32354" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Polymorphic%20Python%20Malware/32354</a><br /> SSH ProxyCommand Vulnerability<br /> A user cloning a git repository may be tricked into executing arbitrary code via the SSH proxycommand option.<br /><a href="https://dgl.cx/2025/10/bash-a-newline-ssh-proxycommand-cve-2025-61984" target="_blank" rel="noreferrer noopener">https://dgl.cx/2025/10/bash-a-newline-ssh-proxycommand-cve-2025-61984</a><br /> Framelink Figma MCP Server CVE-2025-53967<br /> Framelink Figma s MCP server suffers from a remote code execution vulnerability. <br />]]></itunes:summary><itunes:duration>372</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,git,hacking,infosec,internet,it,network,news,polymorphic,proxycommand,python,security,ssh</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9648</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, October 8th, 2025: FreePBX Exploits; Disrupting Teams Threats; Kibana and QT SVG Patches</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-october-8th-2025-freepbx-exploits-disrupting-teams-threats-kibana-and-qt-svg-patches--68056697</link><description><![CDATA[<br /> FreePBX Exploit Attempts (CVE-2025-57819)<br /> A FreePBX SQL injection vulnerability disclosed in August is being used to execute code on affected systems.<br /><a href="https://isc.sans.edu/diary/Exploit%20Against%20FreePBX%20%28CVE-2025-57819%29%20with%20code%20execution./32350" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit%20Against%20FreePBX%20%28CVE-2025-57819%29%20with%20code%20execution./32350</a><br /> Disrupting Threats Targeting Microsoft Teams<br /> Microsoft published a blog post outlining how to better secure Teams.<br /><a href="https://www.microsoft.com/en-us/security/blog/2025/10/07/disrupting-threats-targeting-microsoft-teams/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2025/10/07/disrupting-threats-targeting-microsoft-teams/</a><br /> Kibana XSS Patch CVE-2025-25009<br /> Elastic patched a stored XSS vulnerability in Kibana<br /><a href="https://discuss.elastic.co/t/kibana-8-18-8-8-19-5-9-0-8-and-9-1-5-security-update-esa-2025-20/382449" target="_blank" rel="noreferrer noopener">https://discuss.elastic.co/t/kibana-8-18-8-8-19-5-9-0-8-and-9-1-5-security-update-esa-2025-20/382449</a><br /> QT SVG Vulnerabilities CVE-2025-10728, CVE-2025-10729,<br /> The QT group fixed two vulnerabilities in the QT SVG module. One of the vulnerabilities may be used for code execution<br /><a href="https://www.qt.io/blog/security-advisory-uncontrolled-recursion-and-use-after-free-vulnerabilities-in-qt-svg-module-impact-qt" target="_blank" rel="noreferrer noopener">https://www.qt.io/blog/security-advisory-uncontrolled-recursion-and-use-after-free-vulnerabilities-in-qt-svg-module-impact-qt</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9646.mp3</guid><pubDate>Wed, 08 Oct 2025 03:25:14 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68056697/9646.mp3" length="4997540" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9646" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 FreePBX Exploit Attempts (CVE-2025-57819)
 A FreePBX SQL injection vulnerability disclosed in August is being used to execute code on affected systems....</itunes:subtitle><itunes:summary><![CDATA[<br /> FreePBX Exploit Attempts (CVE-2025-57819)<br /> A FreePBX SQL injection vulnerability disclosed in August is being used to execute code on affected systems.<br /><a href="https://isc.sans.edu/diary/Exploit%20Against%20FreePBX%20%28CVE-2025-57819%29%20with%20code%20execution./32350" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit%20Against%20FreePBX%20%28CVE-2025-57819%29%20with%20code%20execution./32350</a><br /> Disrupting Threats Targeting Microsoft Teams<br /> Microsoft published a blog post outlining how to better secure Teams.<br /><a href="https://www.microsoft.com/en-us/security/blog/2025/10/07/disrupting-threats-targeting-microsoft-teams/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2025/10/07/disrupting-threats-targeting-microsoft-teams/</a><br /> Kibana XSS Patch CVE-2025-25009<br /> Elastic patched a stored XSS vulnerability in Kibana<br /><a href="https://discuss.elastic.co/t/kibana-8-18-8-8-19-5-9-0-8-and-9-1-5-security-update-esa-2025-20/382449" target="_blank" rel="noreferrer noopener">https://discuss.elastic.co/t/kibana-8-18-8-8-19-5-9-0-8-and-9-1-5-security-update-esa-2025-20/382449</a><br /> QT SVG Vulnerabilities CVE-2025-10728, CVE-2025-10729,<br /> The QT group fixed two vulnerabilities in the QT SVG module. One of the vulnerabilities may be used for code execution<br /><a href="https://www.qt.io/blog/security-advisory-uncontrolled-recursion-and-use-after-free-vulnerabilities-in-qt-svg-module-impact-qt" target="_blank" rel="noreferrer noopener">https://www.qt.io/blog/security-advisory-uncontrolled-recursion-and-use-after-free-vulnerabilities-in-qt-svg-module-impact-qt</a><br />]]></itunes:summary><itunes:duration>357</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,elastic,freepbx,hacking,infosec,it,kibana,microsoft,network,news,qt,security,sql injection,svg,teams,xss</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9646</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, October 7th, 2025: More About Oracle; Redis Vulnerability; GoAnywhere Exploited</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-october-7th-2025-more-about-oracle-redis-vulnerability-goanywhere-exploited--68039818</link><description><![CDATA[<br /> More Details About Oracle 0-Day<br /> The exploit is now widely distributed and has been analyzed to show the nature of the underlying vulnerabilities.<br /><a href="https://isc.sans.edu/diary/Quick%20and%20Dirty%20Analysis%20of%20Possible%20Oracle%20E-Business%20Suite%20Exploit%20Script%20%28CVE-2025-61882%29%20%5BUPDATED%5B/32346" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Quick%20and%20Dirty%20Analysis%20of%20Possible%20Oracle%20E-Business%20Suite%20Exploit%20Script%20%28CVE-2025-61882%29%20%5BUPDATED%5B/32346</a><br /><a href="https://labs.watchtowr.com/well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882/</a><br />  Redis Vulnerability<br /> Redis patched a ciritcal use after free vulnerability that could lead to arbitrary code execution.<br /><a href="https://redis.io/blog/security-advisory-cve-2025-49844/" target="_blank" rel="noreferrer noopener">https://redis.io/blog/security-advisory-cve-2025-49844/</a><br /> GoAnywhere Bug Exploited<br /> Microsoft is reporting about the exploitation of the recent GoAnywhere vulnerability<br /><a href="https://www.microsoft.com/en-us/security/blog/2025/10/06/investigating-active-exploitation-of-cve-2025-10035-goanywhere-managed-file-transfer-vulnerability/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2025/10/06/investigating-active-exploitation-of-cve-2025-10035-goanywhere-managed-file-transfer-vulnerability/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9644.mp3</guid><pubDate>Tue, 07 Oct 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68039818/9644.mp3" length="4674024" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9644" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 More Details About Oracle 0-Day
 The exploit is now widely distributed and has been analyzed to show the nature of the underlying vulnerabilities....</itunes:subtitle><itunes:summary><![CDATA[<br /> More Details About Oracle 0-Day<br /> The exploit is now widely distributed and has been analyzed to show the nature of the underlying vulnerabilities.<br /><a href="https://isc.sans.edu/diary/Quick%20and%20Dirty%20Analysis%20of%20Possible%20Oracle%20E-Business%20Suite%20Exploit%20Script%20%28CVE-2025-61882%29%20%5BUPDATED%5B/32346" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Quick%20and%20Dirty%20Analysis%20of%20Possible%20Oracle%20E-Business%20Suite%20Exploit%20Script%20%28CVE-2025-61882%29%20%5BUPDATED%5B/32346</a><br /><a href="https://labs.watchtowr.com/well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882/</a><br />  Redis Vulnerability<br /> Redis patched a ciritcal use after free vulnerability that could lead to arbitrary code execution.<br /><a href="https://redis.io/blog/security-advisory-cve-2025-49844/" target="_blank" rel="noreferrer noopener">https://redis.io/blog/security-advisory-cve-2025-49844/</a><br /> GoAnywhere Bug Exploited<br /> Microsoft is reporting about the exploitation of the recent GoAnywhere vulnerability<br /><a href="https://www.microsoft.com/en-us/security/blog/2025/10/06/investigating-active-exploitation-of-cve-2025-10035-goanywhere-managed-file-transfer-vulnerability/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2025/10/06/investigating-active-exploitation-of-cve-2025-10035-goanywhere-managed-file-transfer-vulnerability/</a><br />]]></itunes:summary><itunes:duration>334</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,ebusiness suite,goanywhere,hacking,infosec,internet,it,network,news,oracle,redis,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9644</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, October 6th, 2025: Oracle 0-Day</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-october-6th-2025-oracle-0-day--68030516</link><description><![CDATA[Oracle E-Business Suite 0-Day CVE-2025-61882<br /> Last week, the Cl0p ransomware gang sent messages to many businesses stating that an Oracle E-Business Suite vulnerability was used to exfiltrate data. Initially, Oracle believed the root cause to be a vulnerability patched in June, but now Oracle released a patch for a new vulnerability.<br /><a href="https://www.oracle.com/security-alerts/alert-cve-2025-61882.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/alert-cve-2025-61882.html</a><br /> Zimbra Exploit Analysis<br /> An exploit against a Zimbra system prior to the patch release is analyzed. These exploits take advantage of .ics files to breach vulnerable systems.<br /><a href="https://strikeready.com/blog/0day-ics-attack-in-the-wild/" target="_blank" rel="noreferrer noopener">https://strikeready.com/blog/0day-ics-attack-in-the-wild/</a><br /> Unity Editor Vulnerability CVE-2025-59489<br /> The Unity game editor suffered from a code execution vulnerablity that would also expose software developed with vulnerable versions<br /><a href="https://unity.com/security/sept-2025-01" target="_blank" rel="noreferrer noopener">https://unity.com/security/sept-2025-01</a>]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9642.mp3</guid><pubDate>Mon, 06 Oct 2025 02:45:14 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/68030516/9642.mp3" length="5440818" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9642" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Oracle E-Business Suite 0-Day CVE-2025-61882
 Last week, the Cl0p ransomware gang sent messages to many businesses stating that an Oracle E-Business Suite vulnerability was used to exfiltrate data. Initially, Oracle believed the root cause to be a...</itunes:subtitle><itunes:summary><![CDATA[Oracle E-Business Suite 0-Day CVE-2025-61882<br /> Last week, the Cl0p ransomware gang sent messages to many businesses stating that an Oracle E-Business Suite vulnerability was used to exfiltrate data. Initially, Oracle believed the root cause to be a vulnerability patched in June, but now Oracle released a patch for a new vulnerability.<br /><a href="https://www.oracle.com/security-alerts/alert-cve-2025-61882.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/alert-cve-2025-61882.html</a><br /> Zimbra Exploit Analysis<br /> An exploit against a Zimbra system prior to the patch release is analyzed. These exploits take advantage of .ics files to breach vulnerable systems.<br /><a href="https://strikeready.com/blog/0day-ics-attack-in-the-wild/" target="_blank" rel="noreferrer noopener">https://strikeready.com/blog/0day-ics-attack-in-the-wild/</a><br /> Unity Editor Vulnerability CVE-2025-59489<br /> The Unity game editor suffered from a code execution vulnerablity that would also expose software developed with vulnerable versions<br /><a href="https://unity.com/security/sept-2025-01" target="_blank" rel="noreferrer noopener">https://unity.com/security/sept-2025-01</a>]]></itunes:summary><itunes:duration>389</itunes:duration><itunes:keywords>business,cl0p,computer,cyber,cybersecurity,daily,e-business suite,hacking,infosec,internet,it,network,news,oracle,security,unity,zimbra</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9642</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, October 3rd, 2025: More .well-known Scans; RedHat Openshift Patch; TOTOLINK Vuln;</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-october-3rd-2025-more-well-known-scans-redhat-openshift-patch-totolink-vuln--67994192</link><description><![CDATA[<br /> More .well-known scans<br /> Attackers are using API documentation automatically published in the .well-known directory for reconnaissance. <br /><a href="https://isc.sans.edu/diary/More%20.well-known%20Scans/32340" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/More%20.well-known%20Scans/32340</a><br /> RedHat Patches Openshift AI Services<br /> A flaw was found in Red Hat Openshift AI Service. A low-privileged attacker with access to an authenticated account, for example, as a data scientist using a standard Jupyter notebook, can escalate their privileges to a full cluster administrator. <br /><a href="https://access.redhat.com/security/cve/cve-2025-10725#cve-affected-packages" target="_blank" rel="noreferrer noopener">https://access.redhat.com/security/cve/cve-2025-10725#cve-affected-packages</a><br /> TOTOLINK X6000R Vulnerabilities<br /> Paloalto released details regarding three recently patched vulnerabilities in TotalLink-X6000R routers.<br /><a href="https://unit42.paloaltonetworks.com/totolink-x6000r-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/totolink-x6000r-vulnerabilities/</a><br /> DrayOS Vulnerability Patched<br /> Draytek fixed a single memory corruption vulnerability in its Vigor series router. An unauthenticated user may use it to execute arbitrary code.<br /><a href="https://www.draytek.com/about/security-advisory/use-of-uninitialized-variable-vulnerabilities" target="_blank" rel="noreferrer noopener">https://www.draytek.com/about/security-advisory/use-of-uninitialized-variable-vulnerabilities</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9640.mp3</guid><pubDate>Fri, 03 Oct 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67994192/9640.mp3" length="5530397" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9640" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 More .well-known scans
 Attackers are using API documentation automatically published in the .well-known directory for reconnaissance. 
https://isc.sans.edu/diary/More%20.well-known%20Scans/32340
 RedHat Patches Openshift AI Services
 A flaw was...</itunes:subtitle><itunes:summary><![CDATA[<br /> More .well-known scans<br /> Attackers are using API documentation automatically published in the .well-known directory for reconnaissance. <br /><a href="https://isc.sans.edu/diary/More%20.well-known%20Scans/32340" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/More%20.well-known%20Scans/32340</a><br /> RedHat Patches Openshift AI Services<br /> A flaw was found in Red Hat Openshift AI Service. A low-privileged attacker with access to an authenticated account, for example, as a data scientist using a standard Jupyter notebook, can escalate their privileges to a full cluster administrator. <br /><a href="https://access.redhat.com/security/cve/cve-2025-10725#cve-affected-packages" target="_blank" rel="noreferrer noopener">https://access.redhat.com/security/cve/cve-2025-10725#cve-affected-packages</a><br /> TOTOLINK X6000R Vulnerabilities<br /> Paloalto released details regarding three recently patched vulnerabilities in TotalLink-X6000R routers.<br /><a href="https://unit42.paloaltonetworks.com/totolink-x6000r-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/totolink-x6000r-vulnerabilities/</a><br /> DrayOS Vulnerability Patched<br /> Draytek fixed a single memory corruption vulnerability in its Vigor series router. An unauthenticated user may use it to execute arbitrary code.<br /><a href="https://www.draytek.com/about/security-advisory/use-of-uninitialized-variable-vulnerabilities" target="_blank" rel="noreferrer noopener">https://www.draytek.com/about/security-advisory/use-of-uninitialized-variable-vulnerabilities</a><br />]]></itunes:summary><itunes:duration>395</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,openshift,redhat,security,.well-known</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9640</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, October 2nd, 2025: Honeypot Passwords; OneLogin Vuln; Breaking Intel SGX; OpenSSL Patch</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-october-2nd-2025-honeypot-passwords-onelogin-vuln-breaking-intel-sgx-openssl-patch--67980454</link><description><![CDATA[<br /> Comparing Honeypot Passwords with HIBP<br /> Most passwords used against our honeypots are also found in the  Have I been pwn3d  list. However, the few percent that are not found tend to be variations of known passwords, extending them to find likely mutations.<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Comparing%20Honeypot%20Passwords%20with%20HIBP/32310" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Comparing%20Honeypot%20Passwords%20with%20HIBP/32310</a><br /> Breaking Server SGX via DRAM Inspection<br /> By observing read and write operations to memory, it is possible to derive keys stored in SGX and break the security of systems relying on SGX.<br /><a href="https://wiretap.fail/files/wiretap.pdf" target="_blank" rel="noreferrer noopener">https://wiretap.fail/files/wiretap.pdf</a><br /> OneLogin OIDC Vulnerability<br /> A vulnerability in OneLogin can be used to read secret application keys<br /><a href="https://www.clutch.security/blog/onelogin-many-secrets-clutch-uncovers-vulnerability-exposing-client-credentials" target="_blank" rel="noreferrer noopener">https://www.clutch.security/blog/onelogin-many-secrets-clutch-uncovers-vulnerability-exposing-client-credentials</a><br /> OpenSSL Patch<br /> OpenSSL patched three vulnerabilities. One could lead to remote code execution, but the feature is used infrequently, and the exploit is difficult, according to OpenSSL<br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9638.mp3</guid><pubDate>Thu, 02 Oct 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67980454/9638.mp3" length="6884553" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9638" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Comparing Honeypot Passwords with HIBP
 Most passwords used against our honeypots are also found in the  Have I been pwn3d  list. However, the few percent that are not found tend to be variations of known passwords, extending them to find likely...</itunes:subtitle><itunes:summary><![CDATA[<br /> Comparing Honeypot Passwords with HIBP<br /> Most passwords used against our honeypots are also found in the  Have I been pwn3d  list. However, the few percent that are not found tend to be variations of known passwords, extending them to find likely mutations.<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Comparing%20Honeypot%20Passwords%20with%20HIBP/32310" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Comparing%20Honeypot%20Passwords%20with%20HIBP/32310</a><br /> Breaking Server SGX via DRAM Inspection<br /> By observing read and write operations to memory, it is possible to derive keys stored in SGX and break the security of systems relying on SGX.<br /><a href="https://wiretap.fail/files/wiretap.pdf" target="_blank" rel="noreferrer noopener">https://wiretap.fail/files/wiretap.pdf</a><br /> OneLogin OIDC Vulnerability<br /> A vulnerability in OneLogin can be used to read secret application keys<br /><a href="https://www.clutch.security/blog/onelogin-many-secrets-clutch-uncovers-vulnerability-exposing-client-credentials" target="_blank" rel="noreferrer noopener">https://www.clutch.security/blog/onelogin-many-secrets-clutch-uncovers-vulnerability-exposing-client-credentials</a><br /> OpenSSL Patch<br /> OpenSSL patched three vulnerabilities. One could lead to remote code execution, but the feature is used infrequently, and the exploit is difficult, according to OpenSSL<br />]]></itunes:summary><itunes:duration>492</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dram,hacking,hibp,infosec,internet,it,network,news,onelogin,openssl,passwords,security,sgx</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9638</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, October 1st, 2025: Cookie Auth Issues; Western Digtial Command Injection; sudo exploited;</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-october-1st-2025-cookie-auth-issues-western-digtial-command-injection-sudo-exploited--67959078</link><description><![CDATA[<br /> Sometimes you don t even need to log in<br /> Applications using simple, predictable cookies to verify a user s identity are still exploited, and relatively recent vulnerabilities are still due to this very basic mistake.<br /><a href="https://isc.sans.edu/diary/%22user%3Dadmin%22.%20Sometimes%20you%20don%27t%20even%20need%20to%20log%20in./32334" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%22user%3Dadmin%22.%20Sometimes%20you%20don%27t%20even%20need%20to%20log%20in./32334</a><br /> Western Digital My Cloud Vulnerability<br /> Western Digital patched a critical vulnerability in its  MyCloud  device.<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30247" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2025-30247</a><br /> sudo vulnerability exploited<br /> A recently patched vulnerability in sudo is now being exploited.<br /><a href="https://www.sudo.ws/security/advisories/" target="_blank" rel="noreferrer noopener">https://www.sudo.ws/security/advisories/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9636.mp3</guid><pubDate>Wed, 01 Oct 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67959078/9636.mp3" length="4341419" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9636" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Sometimes you don t even need to log in
 Applications using simple, predictable cookies to verify a user s identity are still exploited, and relatively recent vulnerabilities are still due to this very basic mistake....</itunes:subtitle><itunes:summary><![CDATA[<br /> Sometimes you don t even need to log in<br /> Applications using simple, predictable cookies to verify a user s identity are still exploited, and relatively recent vulnerabilities are still due to this very basic mistake.<br /><a href="https://isc.sans.edu/diary/%22user%3Dadmin%22.%20Sometimes%20you%20don%27t%20even%20need%20to%20log%20in./32334" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%22user%3Dadmin%22.%20Sometimes%20you%20don%27t%20even%20need%20to%20log%20in./32334</a><br /> Western Digital My Cloud Vulnerability<br /> Western Digital patched a critical vulnerability in its  MyCloud  device.<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30247" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2025-30247</a><br /> sudo vulnerability exploited<br /> A recently patched vulnerability in sudo is now being exploited.<br /><a href="https://www.sudo.ws/security/advisories/" target="_blank" rel="noreferrer noopener">https://www.sudo.ws/security/advisories/</a><br />]]></itunes:summary><itunes:duration>310</itunes:duration><itunes:keywords>business,computer,cookies,cyber,cybersecurity,daily,hacking,infosec,internet,it,mycloud,network,news,security,sudo,western digital</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9636</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, September 30th, 2025: Apple Patch; PAN Global Protect Scans; SSL.com signed malware</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-september-30th-2025-apple-patch-pan-global-protect-scans-ssl-com-signed-malware--67950639</link><description><![CDATA[<br /> Apple Patches<br /> Apple released patches for iOS, macOS, and visionOS, fixing a single font parsing vulnerability<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Single%20Vulnerability%20CVE-2025-43400/32330" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Single%20Vulnerability%20CVE-2025-43400/32330</a><br /> Increase in Scans for Palo Alto Global Protect Vulnerability (CVE-2024-3400).<br /> Our honeypots detected an increase in scans for a Palo Alto Global Protect vulnerability.<br /><a href="https://isc.sans.edu/diary/Increase%20in%20Scans%20for%20Palo%20Alto%20Global%20Protect%20Vulnerability%20%28CVE-2024-3400%29/32328" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Increase%20in%20Scans%20for%20Palo%20Alto%20Global%20Protect%20Vulnerability%20%28CVE-2024-3400%29/32328</a><br /> Nimbus Manticore / Charming Kitten Malware update<br /> Checkpoint released a report with details regarding a new Nimbus Manticore exploit kit. The malware in this case uses valid SSL.com-issued certificates.<br /><a href="https://research.checkpoint.com/2025/nimbus-manticore-deploys-new-malware-targeting-europe/" target="_blank" rel="noreferrer noopener">https://research.checkpoint.com/2025/nimbus-manticore-deploys-new-malware-targeting-europe/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9634.mp3</guid><pubDate>Tue, 30 Sep 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67950639/9634.mp3" length="4288761" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9634" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Apple Patches
 Apple released patches for iOS, macOS, and visionOS, fixing a single font parsing vulnerability
https://isc.sans.edu/diary/Apple%20Patches%20Single%20Vulnerability%20CVE-2025-43400/32330
 Increase in Scans for Palo Alto Global Protect...</itunes:subtitle><itunes:summary><![CDATA[<br /> Apple Patches<br /> Apple released patches for iOS, macOS, and visionOS, fixing a single font parsing vulnerability<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Single%20Vulnerability%20CVE-2025-43400/32330" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Single%20Vulnerability%20CVE-2025-43400/32330</a><br /> Increase in Scans for Palo Alto Global Protect Vulnerability (CVE-2024-3400).<br /> Our honeypots detected an increase in scans for a Palo Alto Global Protect vulnerability.<br /><a href="https://isc.sans.edu/diary/Increase%20in%20Scans%20for%20Palo%20Alto%20Global%20Protect%20Vulnerability%20%28CVE-2024-3400%29/32328" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Increase%20in%20Scans%20for%20Palo%20Alto%20Global%20Protect%20Vulnerability%20%28CVE-2024-3400%29/32328</a><br /> Nimbus Manticore / Charming Kitten Malware update<br /> Checkpoint released a report with details regarding a new Nimbus Manticore exploit kit. The malware in this case uses valid SSL.com-issued certificates.<br /><a href="https://research.checkpoint.com/2025/nimbus-manticore-deploys-new-malware-targeting-europe/" target="_blank" rel="noreferrer noopener">https://research.checkpoint.com/2025/nimbus-manticore-deploys-new-malware-targeting-europe/</a><br />]]></itunes:summary><itunes:duration>306</itunes:duration><itunes:keywords>apple,business,charming kitten,computer,cyber,cybersecurity,daily,hacking,infosec,internet,ios,it,macos,manticode,network,news,nimus,pan,security,ssl.com</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9634</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, September 29th, 2025: Convert Timestamps; Cisco Compromises; GitHub Notification Phishing</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-september-29th-2025-convert-timestamps-cisco-compromises-github-notification-phishing--67935003</link><description><![CDATA[<br /> Converting Timestamps in .bash_history<br /> Unix shells offer the ability to add timestamps to commands in the .bash_history file. This is often done in the form of Unix timestamps. This new tool converts these timestamps into a more readable format.<br /><a href="https://isc.sans.edu/diary/New%20tool%3A%20convert-ts-bash-history.py/32324" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/New%20tool%3A%20convert-ts-bash-history.py/32324</a><br /> Cisco ASA/FRD Compromises<br /> Exploitation of the vulnerabilities Cisco patched last week may have bone back about a year. Cisco and CISA have released advisories with help identifying affected devices. <br /><a href="https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks</a><br /><a href="https://www.cisa.gov/news-events/directives/ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/directives/ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices</a><br /> Github Notification Phishing<br /> Github notifications are used to impersonate YCombinator and trick victims into installing a crypto drainer.<br /><a href="https://www.bleepingcomputer.com/news/security/github-notifications-abused-to-impersonate-y-combinator-for-crypto-theft/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/github-notifications-abused-to-impersonate-y-combinator-for-crypto-theft/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9632.mp3</guid><pubDate>Mon, 29 Sep 2025 02:05:18 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67935003/9632.mp3" length="7225153" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9632" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Converting Timestamps in .bash_history
 Unix shells offer the ability to add timestamps to commands in the .bash_history file. This is often done in the form of Unix timestamps. This new tool converts these timestamps into a more readable format....</itunes:subtitle><itunes:summary><![CDATA[<br /> Converting Timestamps in .bash_history<br /> Unix shells offer the ability to add timestamps to commands in the .bash_history file. This is often done in the form of Unix timestamps. This new tool converts these timestamps into a more readable format.<br /><a href="https://isc.sans.edu/diary/New%20tool%3A%20convert-ts-bash-history.py/32324" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/New%20tool%3A%20convert-ts-bash-history.py/32324</a><br /> Cisco ASA/FRD Compromises<br /> Exploitation of the vulnerabilities Cisco patched last week may have bone back about a year. Cisco and CISA have released advisories with help identifying affected devices. <br /><a href="https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks</a><br /><a href="https://www.cisa.gov/news-events/directives/ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/directives/ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices</a><br /> Github Notification Phishing<br /> Github notifications are used to impersonate YCombinator and trick victims into installing a crypto drainer.<br /><a href="https://www.bleepingcomputer.com/news/security/github-notifications-abused-to-impersonate-y-combinator-for-crypto-theft/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/github-notifications-abused-to-impersonate-y-combinator-for-crypto-theft/</a><br />]]></itunes:summary><itunes:duration>516</itunes:duration><itunes:keywords>asa,bash,business,cisco,cyber,cybersecurity,daily,firepower,ftd,github,hacking,history,infosec,it,malware,network,news,phishing,security,timestamp</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9632</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, September 26th, 2025: Webshells in .well-known; Critical Cisco Vulns Exploited; XCSSET Update; GoAnywhere MFT Exploit</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-september-26th-2025-webshells-in-well-known-critical-cisco-vulns-exploited-xcsset-update-goanywhere-mft-exploit--67904662</link><description><![CDATA[<br /> Webshells Hiding in .well-known Places<br /> Our honeypots registered an increase in scans for URLs in the .well-known directory, which appears to be looking for webshells. <br /><a href="https://isc.sans.edu/diary/Webshells%20Hiding%20in%20.well-known%20Places/32320" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Webshells%20Hiding%20in%20.well-known%20Places/32320</a><br /> Cisco Patches Critical Exploited Vulnerabilities<br /> Cisco released updates addressing already-exploited vulnerabilities in the VPN web server for the ASA and FTD appliances.<br /><a href="https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks</a><br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB</a><br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW</a><br /> XCSSET Evolves Again<br /> Microsoft detected a new XCSSET variant, an infostealer infecting X-Code projects.<br /><a href="https://www.microsoft.com/en-us/security/blog/2025/09/25/xcsset-evolves-again-analyzing-the-latest-updates-to-xcssets-inventory/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2025/09/25/xcsset-evolves-again-analyzing-the-latest-updates-to-xcssets-inventory/</a><br /> Exploitation of Fortra GoAnywhere MFT CVE-2025-10035<br /> watchTowr analyzed the latest GoAnywhere MFT vulnerability and exploits used against it.<br /><a href="https://labs.watchtowr.com/it-is-bad-exploitation-of-fortra-goanywhere-mft-cve-2025-10035-part-2/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/it-is-bad-exploitation-of-fortra-goanywhere-mft-cve-2025-10035-part-2/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9630.mp3</guid><pubDate>Fri, 26 Sep 2025 04:05:15 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67904662/9630.mp3" length="5200793" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9630" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Webshells Hiding in .well-known Places
 Our honeypots registered an increase in scans for URLs in the .well-known directory, which appears to be looking for webshells. 
https://isc.sans.edu/diary/Webshells%20Hiding%20in%20.well-known%20Places/32320...</itunes:subtitle><itunes:summary><![CDATA[<br /> Webshells Hiding in .well-known Places<br /> Our honeypots registered an increase in scans for URLs in the .well-known directory, which appears to be looking for webshells. <br /><a href="https://isc.sans.edu/diary/Webshells%20Hiding%20in%20.well-known%20Places/32320" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Webshells%20Hiding%20in%20.well-known%20Places/32320</a><br /> Cisco Patches Critical Exploited Vulnerabilities<br /> Cisco released updates addressing already-exploited vulnerabilities in the VPN web server for the ASA and FTD appliances.<br /><a href="https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks</a><br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB</a><br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW</a><br /> XCSSET Evolves Again<br /> Microsoft detected a new XCSSET variant, an infostealer infecting X-Code projects.<br /><a href="https://www.microsoft.com/en-us/security/blog/2025/09/25/xcsset-evolves-again-analyzing-the-latest-updates-to-xcssets-inventory/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2025/09/25/xcsset-evolves-again-analyzing-the-latest-updates-to-xcssets-inventory/</a><br /> Exploitation of Fortra GoAnywhere MFT CVE-2025-10035<br /> watchTowr analyzed the latest GoAnywhere MFT vulnerability and exploits used against it.<br /><a href="https://labs.watchtowr.com/it-is-bad-exploitation-of-fortra-goanywhere-mft-cve-2025-10035-part-2/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/it-is-bad-exploitation-of-fortra-goanywhere-mft-cve-2025-10035-part-2/</a><br />]]></itunes:summary><itunes:duration>325</itunes:duration><itunes:keywords>asa,business,cisco,computer,cyber,cybersecurity,daily,ftd,goanywhere,hacking,infosec,it,mft,network,news,security,webhsells,.well-known,x-code,xcsset</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9630</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, September 25th, 2025: Hikvision Exploits; Cisco Patches; Sonicawall Anit-Rootkit Patch; Windows 10 Support</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-september-25th-2025-hikvision-exploits-cisco-patches-sonicawall-anit-rootkit-patch-windows-10-support--67887590</link><description><![CDATA[<br /> Exploit Attempts Against Older Hikvision Camera Vulnerability<br /> Out honeypots observed an increase in attacks against some older Hikvision issues. A big part of the problem is weak passwords, and the ability to send credentials as part of the URL.<br /><a href="https://isc.sans.edu/diary/Exploit%20Attempts%20Against%20Older%20Hikvision%20Camera%20Vulnerability/32316" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit%20Attempts%20Against%20Older%20Hikvision%20Camera%20Vulnerability/32316</a><br /> Cisco Patches Already Exploited SNMP Vulnerability<br /> Cisco patched a stack-based buffer overflow in the SNMP subsystem. It is already exploited in the wild, but requires<br /> admin privileges to achieve code execution.<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-x4LPhte" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-x4LPhte</a><br /> SonicWall Anti-Rootkit Update<br /> SonicWall released a firmware update for its SMA100 devices specifically designed to eradicate a commonly deployed rootkit.<br /><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0015" target="_blank" rel="noreferrer noopener">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0015</a><br /> Extended Windows 10 Support<br /> Microsoft will extend free Windows 10 essential support for US and European customers.<br /><a href="https://www.straitstimes.com/world/united-states/microsoft-offers-no-cost-windows-10-lifeline" target="_blank" rel="noreferrer noopener">https://www.straitstimes.com/world/united-states/microsoft-offers-no-cost-windows-10-lifeline</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9628.mp3</guid><pubDate>Thu, 25 Sep 2025 03:40:13 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67887590/9628.mp3" length="4662410" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9628" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Exploit Attempts Against Older Hikvision Camera Vulnerability
 Out honeypots observed an increase in attacks against some older Hikvision issues. A big part of the problem is weak passwords, and the ability to send credentials as part of the URL....</itunes:subtitle><itunes:summary><![CDATA[<br /> Exploit Attempts Against Older Hikvision Camera Vulnerability<br /> Out honeypots observed an increase in attacks against some older Hikvision issues. A big part of the problem is weak passwords, and the ability to send credentials as part of the URL.<br /><a href="https://isc.sans.edu/diary/Exploit%20Attempts%20Against%20Older%20Hikvision%20Camera%20Vulnerability/32316" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit%20Attempts%20Against%20Older%20Hikvision%20Camera%20Vulnerability/32316</a><br /> Cisco Patches Already Exploited SNMP Vulnerability<br /> Cisco patched a stack-based buffer overflow in the SNMP subsystem. It is already exploited in the wild, but requires<br /> admin privileges to achieve code execution.<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-x4LPhte" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-x4LPhte</a><br /> SonicWall Anti-Rootkit Update<br /> SonicWall released a firmware update for its SMA100 devices specifically designed to eradicate a commonly deployed rootkit.<br /><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0015" target="_blank" rel="noreferrer noopener">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0015</a><br /> Extended Windows 10 Support<br /> Microsoft will extend free Windows 10 essential support for US and European customers.<br /><a href="https://www.straitstimes.com/world/united-states/microsoft-offers-no-cost-windows-10-lifeline" target="_blank" rel="noreferrer noopener">https://www.straitstimes.com/world/united-states/microsoft-offers-no-cost-windows-10-lifeline</a><br />]]></itunes:summary><itunes:duration>333</itunes:duration><itunes:keywords>business,cisco,computer,cyber,cybersecurity,daily,hacking,hikvision,infosec,internet,it,network,news,rootkit,security,snmp,sonicwall,support,windows</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9628</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, September 24th, 2025: DoS against the Analyst; GitHub Improvements; Solarwinds and Supermicro BMC vulnerabilities</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-september-24th-2025-dos-against-the-analyst-github-improvements-solarwinds-and-supermicro-bmc-vulnerabilities--67873061</link><description><![CDATA[<br /> Distracting the Analyst for Fun and Profit<br /> Our undergraduate intern, Tyler House analyzed what may have been a small DoS attack that was likely more meant to distract than to actually cause a denial of service<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Distracting%20the%20Analyst%20for%20Fun%20and%20Profit/32308" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Distracting%20the%20Analyst%20for%20Fun%20and%20Profit/32308</a><br /> GitHub s plan for a more secure npm supply chain<br /> GitHub outlined its plan to harden the supply chain, in particular in light of the recent attack against npm packages<br /><a href="https://github.blog/security/supply-chain-security/our-plan-for-a-more-secure-npm-supply-chain/" target="_blank" rel="noreferrer noopener">https://github.blog/security/supply-chain-security/our-plan-for-a-more-secure-npm-supply-chain/</a><br /> SolarWinds Web Help Desk AjaxProxy Deserialization of Untrusted Data Remote Code Execution Vulnerability (CVE-2025-26399)<br /> SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.<br /><a href="https://www.solarwinds.com/trust-center/security-advisories/cve-2025-26399" target="_blank" rel="noreferrer noopener">https://www.solarwinds.com/trust-center/security-advisories/cve-2025-26399</a><br /> Vulnerabilities in Supermicro BMC Firmware CVE-2025-7937 CVE-2025-6198<br /> Supermicro fixed two vulnerabilities that could allow an attacker to compromise the BMC with rogue firmware.<br /><a href="https://www.supermicro.com/en/support/security_BMC_IPMI_Sept_2025" target="_blank" rel="noreferrer noopener">https://www.supermicro.com/en/support/security_BMC_IPMI_Sept_2025</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9626.mp3</guid><pubDate>Wed, 24 Sep 2025 03:15:14 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67873061/9626.mp3" length="6196580" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9626" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Distracting the Analyst for Fun and Profit
 Our undergraduate intern, Tyler House analyzed what may have been a small DoS attack that was likely more meant to distract than to actually cause a denial of service...</itunes:subtitle><itunes:summary><![CDATA[<br /> Distracting the Analyst for Fun and Profit<br /> Our undergraduate intern, Tyler House analyzed what may have been a small DoS attack that was likely more meant to distract than to actually cause a denial of service<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Distracting%20the%20Analyst%20for%20Fun%20and%20Profit/32308" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Distracting%20the%20Analyst%20for%20Fun%20and%20Profit/32308</a><br /> GitHub s plan for a more secure npm supply chain<br /> GitHub outlined its plan to harden the supply chain, in particular in light of the recent attack against npm packages<br /><a href="https://github.blog/security/supply-chain-security/our-plan-for-a-more-secure-npm-supply-chain/" target="_blank" rel="noreferrer noopener">https://github.blog/security/supply-chain-security/our-plan-for-a-more-secure-npm-supply-chain/</a><br /> SolarWinds Web Help Desk AjaxProxy Deserialization of Untrusted Data Remote Code Execution Vulnerability (CVE-2025-26399)<br /> SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.<br /><a href="https://www.solarwinds.com/trust-center/security-advisories/cve-2025-26399" target="_blank" rel="noreferrer noopener">https://www.solarwinds.com/trust-center/security-advisories/cve-2025-26399</a><br /> Vulnerabilities in Supermicro BMC Firmware CVE-2025-7937 CVE-2025-6198<br /> Supermicro fixed two vulnerabilities that could allow an attacker to compromise the BMC with rogue firmware.<br /><a href="https://www.supermicro.com/en/support/security_BMC_IPMI_Sept_2025" target="_blank" rel="noreferrer noopener">https://www.supermicro.com/en/support/security_BMC_IPMI_Sept_2025</a><br />]]></itunes:summary><itunes:duration>443</itunes:duration><itunes:keywords>bmc,business,computer,cyber,cybersecurity,daily,distraction,dos,github,hacking,infosec,internet,it,network,news,npm,security,solarwinds,supermicro</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9626</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, September 23rd, 2025: Ivanti EPMM Exploit; GitHub Impersonation</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-september-23rd-2025-ivanti-epmm-exploit-github-impersonation--67860668</link><description><![CDATA[<br /> CISA Reports Ivanti EPMM Exploit Sightings<br /> Two different organizations submitted backdoors to CISA, which are believed to have been installed using Ivanti vulnerabilities patched in May.<br /><a href="https://www.cisa.gov/news-events/analysis-reports/ar25-261a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/analysis-reports/ar25-261a</a><br /> Lastpass Observes Impersonation on GitHub<br /> Lastpass noted a number of companies being impersonated via fake GitHub repositories in order to trick victims to download Mac malware.<br /><a href="https://blog.lastpass.com/posts/attack-targeting-macs-via-github-pages" target="_blank" rel="noreferrer noopener">https://blog.lastpass.com/posts/attack-targeting-macs-via-github-pages</a><br /> Oracle Scheduler Ransomware<br /> Ransomware has been discovered that gained access to systems via an exposed Oracle Database Scheduler service.<br /><a href="https://labs.yarix.com/2025/09/elons-proxima-black-shadow-related-ransomware-attack-via-oracle-dbs-external-jobs/" target="_blank" rel="noreferrer noopener">https://labs.yarix.com/2025/09/elons-proxima-black-shadow-related-ransomware-attack-via-oracle-dbs-external-jobs/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9624.mp3</guid><pubDate>Tue, 23 Sep 2025 03:50:13 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67860668/9624.mp3" length="4053898" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9624" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 CISA Reports Ivanti EPMM Exploit Sightings
 Two different organizations submitted backdoors to CISA, which are believed to have been installed using Ivanti vulnerabilities patched in May.
https://www.cisa.gov/news-events/analysis-reports/ar25-261a...</itunes:subtitle><itunes:summary><![CDATA[<br /> CISA Reports Ivanti EPMM Exploit Sightings<br /> Two different organizations submitted backdoors to CISA, which are believed to have been installed using Ivanti vulnerabilities patched in May.<br /><a href="https://www.cisa.gov/news-events/analysis-reports/ar25-261a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/analysis-reports/ar25-261a</a><br /> Lastpass Observes Impersonation on GitHub<br /> Lastpass noted a number of companies being impersonated via fake GitHub repositories in order to trick victims to download Mac malware.<br /><a href="https://blog.lastpass.com/posts/attack-targeting-macs-via-github-pages" target="_blank" rel="noreferrer noopener">https://blog.lastpass.com/posts/attack-targeting-macs-via-github-pages</a><br /> Oracle Scheduler Ransomware<br /> Ransomware has been discovered that gained access to systems via an exposed Oracle Database Scheduler service.<br /><a href="https://labs.yarix.com/2025/09/elons-proxima-black-shadow-related-ransomware-attack-via-oracle-dbs-external-jobs/" target="_blank" rel="noreferrer noopener">https://labs.yarix.com/2025/09/elons-proxima-black-shadow-related-ransomware-attack-via-oracle-dbs-external-jobs/</a><br />]]></itunes:summary><itunes:duration>290</itunes:duration><itunes:keywords>business,cisa,computer,cyber,cybersecurity,daily,epmm,github,hacking,infosec,internet,it,ivanti,lastpass,network,news,oracle,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9624</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, September 22nd, 2025: Odd HTTP Reuqest; GoAnywhere MFT Bug; EDR Freeze</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-september-22nd-2025-odd-http-reuqest-goanywhere-mft-bug-edr-freeze--67846845</link><description><![CDATA[<br /> Help Wanted: What are these odd requests about?<br /> An odd request is hitting a number of our honeypots with a somewhat unusual HTTP request<br /> header. Please let me know if you no what the request is about.<br /><a href="https://isc.sans.edu/forums/diary/Help+Wanted+What+are+these+odd+reuqests+about/32302/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Help+Wanted+What+are+these+odd+reuqests+about/32302/</a><br /> Forta GoAnywhere MFT Vulnerability<br /> Forta s GoAnywhere MFT product suffers from a critical deserialization vulnerability. Forta released<br /> an advisory disclosing the vulnerability on Thursday.<br /><a href="https://www.fortra.com/security/advisories/product-security/fi-2025-012" target="_blank" rel="noreferrer noopener">https://www.fortra.com/security/advisories/product-security/fi-2025-012</a><br /> EDR Freeze<br /> A new tool, EDR Freeze, allows regular users to suspend EDR processes.<br /><a href="https://www.zerosalarium.com/2025/09/EDR-Freeze-Puts-EDRs-Antivirus-Into-Coma.html" target="_blank" rel="noreferrer noopener">https://www.zerosalarium.com/2025/09/EDR-Freeze-Puts-EDRs-Antivirus-Into-Coma.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9622.mp3</guid><pubDate>Mon, 22 Sep 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67846845/9622.mp3" length="7598662" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9622" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Help Wanted: What are these odd requests about?
 An odd request is hitting a number of our honeypots with a somewhat unusual HTTP request
 header. Please let me know if you no what the request is about....</itunes:subtitle><itunes:summary><![CDATA[<br /> Help Wanted: What are these odd requests about?<br /> An odd request is hitting a number of our honeypots with a somewhat unusual HTTP request<br /> header. Please let me know if you no what the request is about.<br /><a href="https://isc.sans.edu/forums/diary/Help+Wanted+What+are+these+odd+reuqests+about/32302/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Help+Wanted+What+are+these+odd+reuqests+about/32302/</a><br /> Forta GoAnywhere MFT Vulnerability<br /> Forta s GoAnywhere MFT product suffers from a critical deserialization vulnerability. Forta released<br /> an advisory disclosing the vulnerability on Thursday.<br /><a href="https://www.fortra.com/security/advisories/product-security/fi-2025-012" target="_blank" rel="noreferrer noopener">https://www.fortra.com/security/advisories/product-security/fi-2025-012</a><br /> EDR Freeze<br /> A new tool, EDR Freeze, allows regular users to suspend EDR processes.<br /><a href="https://www.zerosalarium.com/2025/09/EDR-Freeze-Puts-EDRs-Antivirus-Into-Coma.html" target="_blank" rel="noreferrer noopener">https://www.zerosalarium.com/2025/09/EDR-Freeze-Puts-EDRs-Antivirus-Into-Coma.html</a><br />]]></itunes:summary><itunes:duration>543</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,edr,forta,goanywhere mft,hacking,http,infosec,internet,it,network,news,proxy,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9622</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, September 19th, 2025: Honeypot File Analysis (@sans_edu); SonicWall Breach; DeepSeek Bias; Chrome 0-day</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-september-19th-2025-honeypot-file-analysis-sans-edu-sonicwall-breach-deepseek-bias-chrome-0-day--67816434</link><description><![CDATA[<br /> Exploring Uploads in a Dshield Honeypot Environment<br /> This guest diary by one of our SANS.edu undergraduate interns shows how to analyze files uploaded to Cowrie<br /><a href="https://isc.sans.edu/diary/Exploring%20Uploads%20in%20a%20Dshield%20Honeypot%20Environment%20%5BGuest%20Diary%5D/32296" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploring%20Uploads%20in%20a%20Dshield%20Honeypot%20Environment%20%5BGuest%20Diary%5D/32296</a><br /> Sonicwall Breach<br /> SonicWall  MySonicWall  accounts were breached via credential brute forcing<br /><a href="https://www.sonicwall.com/support/knowledge-base/mysonicwall-cloud-backup-file-incident/250915160910330" target="_blank" rel="noreferrer noopener">https://www.sonicwall.com/support/knowledge-base/mysonicwall-cloud-backup-file-incident/250915160910330</a><br /> DeepSeek Bias<br /> Cloudflare found significant biases in code created by the Chinese AI engine DeepSeek. Code for organizations not aligned with China s politics contained significantly more bugs<br /><a href="https://www.washingtonpost.com/technology/2025/09/16/deepseek-ai-security/" target="_blank" rel="noreferrer noopener">https://www.washingtonpost.com/technology/2025/09/16/deepseek-ai-security/</a><br /> Google Chrome 0-day<br /> Google fixed an already-exploited vulnerability in Google Chrome<br /><a href="https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_17.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_17.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9620.mp3</guid><pubDate>Fri, 19 Sep 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67816434/9620.mp3" length="6087952" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9620" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Exploring Uploads in a Dshield Honeypot Environment
 This guest diary by one of our SANS.edu undergraduate interns shows how to analyze files uploaded to Cowrie...</itunes:subtitle><itunes:summary><![CDATA[<br /> Exploring Uploads in a Dshield Honeypot Environment<br /> This guest diary by one of our SANS.edu undergraduate interns shows how to analyze files uploaded to Cowrie<br /><a href="https://isc.sans.edu/diary/Exploring%20Uploads%20in%20a%20Dshield%20Honeypot%20Environment%20%5BGuest%20Diary%5D/32296" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploring%20Uploads%20in%20a%20Dshield%20Honeypot%20Environment%20%5BGuest%20Diary%5D/32296</a><br /> Sonicwall Breach<br /> SonicWall  MySonicWall  accounts were breached via credential brute forcing<br /><a href="https://www.sonicwall.com/support/knowledge-base/mysonicwall-cloud-backup-file-incident/250915160910330" target="_blank" rel="noreferrer noopener">https://www.sonicwall.com/support/knowledge-base/mysonicwall-cloud-backup-file-incident/250915160910330</a><br /> DeepSeek Bias<br /> Cloudflare found significant biases in code created by the Chinese AI engine DeepSeek. Code for organizations not aligned with China s politics contained significantly more bugs<br /><a href="https://www.washingtonpost.com/technology/2025/09/16/deepseek-ai-security/" target="_blank" rel="noreferrer noopener">https://www.washingtonpost.com/technology/2025/09/16/deepseek-ai-security/</a><br /> Google Chrome 0-day<br /> Google fixed an already-exploited vulnerability in Google Chrome<br /><a href="https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_17.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_17.html</a><br />]]></itunes:summary><itunes:duration>435</itunes:duration><itunes:keywords>ai,bias,bugs,business,chrome,computer,cowrie,cyber,cybersecurity,daily,deepseek,google,hacking,infosec,internet,it,network,news,security,sonicwall</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9620</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, September 18th, 2025: DLL Hooking; Entra ID Actor Tokens; Watchguard and NVidia Patches</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-september-18th-2025-dll-hooking-entra-id-actor-tokens-watchguard-and-nvidia-patches--67802148</link><description><![CDATA[<br /> CTRL-Z DLL Hooking<br /> Attackers may use a simple reload trick to overwrite breakpoints left by analysts to reverse malicious binaries.<br /><a href="https://isc.sans.edu/diary/CTRL-Z%20DLL%20Hooking/32294" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CTRL-Z%20DLL%20Hooking/32294</a><br /> Global Admin in every Entra ID tenant via Actor tokens<br /> As part of September s patch Tuesday, Microsoft patched CVE-2025-55241. The discoverer of the vulnerability,<br /> Dirk-jan Mollema has published a blog post showing how this vulnerability could have been exploited.<br /><a href="https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/" target="_blank" rel="noreferrer noopener">https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/</a><br /> WatchGuard  Firebox iked Out of Bounds Write Vulnerability CVE-2025-9242<br /> WatchGuard patched an out-of-bounds write vulnerability, which could allow an unauthenticated attacker to compromise the devices.<br /><a href="https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00015" target="_blank" rel="noreferrer noopener">https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00015</a><br /> NVidia Triton Inference Server<br />  NVIDIA patched critical vulnerabilities in its Triton Inference Server.<br /><a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5691" target="_blank" rel="noreferrer noopener">https://nvidia.custhelp.com/app/answers/detail/a_id/5691</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9618.mp3</guid><pubDate>Thu, 18 Sep 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67802148/9618.mp3" length="5482834" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9618" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 CTRL-Z DLL Hooking
 Attackers may use a simple reload trick to overwrite breakpoints left by analysts to reverse malicious binaries.
https://isc.sans.edu/diary/CTRL-Z%20DLL%20Hooking/32294
 Global Admin in every Entra ID tenant via Actor tokens
 As...</itunes:subtitle><itunes:summary><![CDATA[<br /> CTRL-Z DLL Hooking<br /> Attackers may use a simple reload trick to overwrite breakpoints left by analysts to reverse malicious binaries.<br /><a href="https://isc.sans.edu/diary/CTRL-Z%20DLL%20Hooking/32294" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CTRL-Z%20DLL%20Hooking/32294</a><br /> Global Admin in every Entra ID tenant via Actor tokens<br /> As part of September s patch Tuesday, Microsoft patched CVE-2025-55241. The discoverer of the vulnerability,<br /> Dirk-jan Mollema has published a blog post showing how this vulnerability could have been exploited.<br /><a href="https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/" target="_blank" rel="noreferrer noopener">https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/</a><br /> WatchGuard  Firebox iked Out of Bounds Write Vulnerability CVE-2025-9242<br /> WatchGuard patched an out-of-bounds write vulnerability, which could allow an unauthenticated attacker to compromise the devices.<br /><a href="https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00015" target="_blank" rel="noreferrer noopener">https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00015</a><br /> NVidia Triton Inference Server<br />  NVIDIA patched critical vulnerabilities in its Triton Inference Server.<br /><a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5691" target="_blank" rel="noreferrer noopener">https://nvidia.custhelp.com/app/answers/detail/a_id/5691</a><br />]]></itunes:summary><itunes:duration>392</itunes:duration><itunes:keywords>azure,business,computer,ctrl-z,cyber,cybersecurity,daily,dll,entra,hacking,hooking,infosec,it,network,news,nvidia,security,tokens,triton,watchguard</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9618</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, September 17th, 2025: Phishing Resistants; More npm Attacks; ChatGPT MCP abuse</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-september-17th-2025-phishing-resistants-more-npm-attacks-chatgpt-mcp-abuse--67788035</link><description><![CDATA[<br /> Why You Need Phishing-Resistant Authentication NOW.<br /> The recent compromise of a number of high-profile npmjs.com accounts has yet again shown how dangerous a  simple  phishing email can be.<br /><a href="https://isc.sans.edu/diary/Why%20You%20Need%20Phishing%20Resistant%20Authentication%20NOW./32290" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Why%20You%20Need%20Phishing%20Resistant%20Authentication%20NOW./32290</a><br /> S1ngularity/nx Attackers Strike Again<br /> A second wave of attacks has hit over a hundred npm-related GitHub repositories. The updated payload implements a worm that propagates itself to other repositories.<br /><a href="https://www.aikido.dev/blog/s1ngularity-nx-attackers-strike-again" target="_blank" rel="noreferrer noopener">https://www.aikido.dev/blog/s1ngularity-nx-attackers-strike-again</a><br /> ChatGPT s Calendar Integration Can Be Exploited to Steal Emails<br /> ChatGPT s new MCP integration can be used, via prompt injection, to affect software connected to ChatGPT via MCP.<br /><a href="https://www.linkedin.com/posts/eito-miyamura-157305121_we-got-chatgpt-to-leak-your-private-email-activity-7372306174253256704-xoX1/" target="_blank" rel="noreferrer noopener">https://www.linkedin.com/posts/eito-miyamura-157305121_we-got-chatgpt-to-leak-your-private-email-activity-7372306174253256704-xoX1/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9616.mp3</guid><pubDate>Wed, 17 Sep 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67788035/9616.mp3" length="7385162" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9616" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Why You Need Phishing-Resistant Authentication NOW.
 The recent compromise of a number of high-profile npmjs.com accounts has yet again shown how dangerous a  simple  phishing email can be....</itunes:subtitle><itunes:summary><![CDATA[<br /> Why You Need Phishing-Resistant Authentication NOW.<br /> The recent compromise of a number of high-profile npmjs.com accounts has yet again shown how dangerous a  simple  phishing email can be.<br /><a href="https://isc.sans.edu/diary/Why%20You%20Need%20Phishing%20Resistant%20Authentication%20NOW./32290" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Why%20You%20Need%20Phishing%20Resistant%20Authentication%20NOW./32290</a><br /> S1ngularity/nx Attackers Strike Again<br /> A second wave of attacks has hit over a hundred npm-related GitHub repositories. The updated payload implements a worm that propagates itself to other repositories.<br /><a href="https://www.aikido.dev/blog/s1ngularity-nx-attackers-strike-again" target="_blank" rel="noreferrer noopener">https://www.aikido.dev/blog/s1ngularity-nx-attackers-strike-again</a><br /> ChatGPT s Calendar Integration Can Be Exploited to Steal Emails<br /> ChatGPT s new MCP integration can be used, via prompt injection, to affect software connected to ChatGPT via MCP.<br /><a href="https://www.linkedin.com/posts/eito-miyamura-157305121_we-got-chatgpt-to-leak-your-private-email-activity-7372306174253256704-xoX1/" target="_blank" rel="noreferrer noopener">https://www.linkedin.com/posts/eito-miyamura-157305121_we-got-chatgpt-to-leak-your-private-email-activity-7372306174253256704-xoX1/</a><br />]]></itunes:summary><itunes:duration>528</itunes:duration><itunes:keywords>business,chatgpt,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,mcp,network,news,npm,nx,openai,phishing,prompt injection,s1ngularity,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9616</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, September 16th, 2025: Apple Updates; Rust Phishing; Samsung 0-day</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-september-16th-2025-apple-updates-rust-phishing-samsung-0-day--67773863</link><description><![CDATA[<br /> Apple Updates<br /> Apple released major updates for all of its operating systems. In addition to new features, these updates patch 33 different vulnerabilities.<br /><a href="https://isc.sans.edu/diary/Apple%20Updates%20Everything%20-%20iOS%20macOS%2026%20Edition/32286" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Updates%20Everything%20-%20iOS%20macOS%2026%20Edition/32286</a><br /> Microsoft End of Life<br /> October 14th, support for Windows 10, Exchange 2016, and Exchange 2019 will end.<br /><a href="https://support.microsoft.com/en-us/windows/windows-10-support-ends-on-october-14-2025-2ca8b313-1946-43d3-b55c-2b95b107f281#:~:text=As%20a%20reminder%2C%20Windows%2010,one%20that%20supports%20Windows%2011." target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-us/windows/windows-10-support-ends-on-october-14-2025-2ca8b313-1946-43d3-b55c-2b95b107f281#:~:text=As%20a%20reminder%2C%20Windows%2010,one%20that%20supports%20Windows%2011.</a><br /><a href="https://techcommunity.microsoft.com/blog/exchange/t-9-months-exchange-server-2016-and-exchange-server-2019-end-of-support/4366605" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/blog/exchange/t-9-months-exchange-server-2016-and-exchange-server-2019-end-of-support/4366605</a><br /> Phishing Targeting Rust Developers<br /> Rust developers are reporting similar phishing emails as the emails causing the major NPM compromise last week.<br /><a href="https://github.com/rust-lang/crates.io/discussions/11889#discussion-8886064" target="_blank" rel="noreferrer noopener">https://github.com/rust-lang/crates.io/discussions/11889#discussion-8886064</a><br /> Samsung Patches 0-Day<br /> Samsung released its monthly updates for its flagship phones fixing, among other vulnerability, an already exploited 0-day.<br /><a href="https://security.samsungmobile.com/securityUpdate.smsb" target="_blank" rel="noreferrer noopener">https://security.samsungmobile.com/securityUpdate.smsb</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9614.mp3</guid><pubDate>Tue, 16 Sep 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67773863/9614.mp3" length="5639274" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9614" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Apple Updates
 Apple released major updates for all of its operating systems. In addition to new features, these updates patch 33 different vulnerabilities....</itunes:subtitle><itunes:summary><![CDATA[<br /> Apple Updates<br /> Apple released major updates for all of its operating systems. In addition to new features, these updates patch 33 different vulnerabilities.<br /><a href="https://isc.sans.edu/diary/Apple%20Updates%20Everything%20-%20iOS%20macOS%2026%20Edition/32286" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Updates%20Everything%20-%20iOS%20macOS%2026%20Edition/32286</a><br /> Microsoft End of Life<br /> October 14th, support for Windows 10, Exchange 2016, and Exchange 2019 will end.<br /><a href="https://support.microsoft.com/en-us/windows/windows-10-support-ends-on-october-14-2025-2ca8b313-1946-43d3-b55c-2b95b107f281#:~:text=As%20a%20reminder%2C%20Windows%2010,one%20that%20supports%20Windows%2011." target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-us/windows/windows-10-support-ends-on-october-14-2025-2ca8b313-1946-43d3-b55c-2b95b107f281#:~:text=As%20a%20reminder%2C%20Windows%2010,one%20that%20supports%20Windows%2011.</a><br /><a href="https://techcommunity.microsoft.com/blog/exchange/t-9-months-exchange-server-2016-and-exchange-server-2019-end-of-support/4366605" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/blog/exchange/t-9-months-exchange-server-2016-and-exchange-server-2019-end-of-support/4366605</a><br /> Phishing Targeting Rust Developers<br /> Rust developers are reporting similar phishing emails as the emails causing the major NPM compromise last week.<br /><a href="https://github.com/rust-lang/crates.io/discussions/11889#discussion-8886064" target="_blank" rel="noreferrer noopener">https://github.com/rust-lang/crates.io/discussions/11889#discussion-8886064</a><br /> Samsung Patches 0-Day<br /> Samsung released its monthly updates for its flagship phones fixing, among other vulnerability, an already exploited 0-day.<br /><a href="https://security.samsungmobile.com/securityUpdate.smsb" target="_blank" rel="noreferrer noopener">https://security.samsungmobile.com/securityUpdate.smsb</a><br />]]></itunes:summary><itunes:duration>403</itunes:duration><itunes:keywords>apple,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microsoft,network,news,phishing,rust,samsung,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9614</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, September 15th, 2025: More Archives; Salesforce Attacks; White Cobra; BSides Augusta</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-september-15th-2025-more-archives-salesforce-attacks-white-cobra-bsides-augusta--67759705</link><description><![CDATA[<br /> Web Searches For Archives<br /> Didier observed additional file types being searched for as attackers continue to focus on archive files as they spider web pages<br /><a href="https://isc.sans.edu/diary/Web%20Searches%20For%20Archives/32282" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Web%20Searches%20For%20Archives/32282</a><br /> FBI Flash Alert: Salesforce Attacks<br /> The FBI is alerting users of Salesforce of two different threat actors targeting Salesforce. There are no new vulnerabilities disclosed, but the initial access usually takes advantage of social engineering or leaked data from the Salesdrift compromise.<br /><a href="https://www.ic3.gov/CSA/2025/250912.pdf" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/CSA/2025/250912.pdf</a><br /> VSCode Cursor Extensions Malware<br /> Koe Security unmasked details about a recent malicious cursor extension campaign they call White Cobra.<br /><a href="https://www.koi.security/blog/whitecobra-vscode-cursor-extensions-malware" target="_blank" rel="noreferrer noopener">https://www.koi.security/blog/whitecobra-vscode-cursor-extensions-malware</a><br /> BSides Augusta<br /><a href="https://bsidesaugusta.org/" target="_blank" rel="noreferrer noopener">https://bsidesaugusta.org/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9612.mp3</guid><pubDate>Mon, 15 Sep 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67759705/9612.mp3" length="5126278" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9612" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Web Searches For Archives
 Didier observed additional file types being searched for as attackers continue to focus on archive files as they spider web pages
https://isc.sans.edu/diary/Web%20Searches%20For%20Archives/32282
 FBI Flash Alert:...</itunes:subtitle><itunes:summary><![CDATA[<br /> Web Searches For Archives<br /> Didier observed additional file types being searched for as attackers continue to focus on archive files as they spider web pages<br /><a href="https://isc.sans.edu/diary/Web%20Searches%20For%20Archives/32282" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Web%20Searches%20For%20Archives/32282</a><br /> FBI Flash Alert: Salesforce Attacks<br /> The FBI is alerting users of Salesforce of two different threat actors targeting Salesforce. There are no new vulnerabilities disclosed, but the initial access usually takes advantage of social engineering or leaked data from the Salesdrift compromise.<br /><a href="https://www.ic3.gov/CSA/2025/250912.pdf" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/CSA/2025/250912.pdf</a><br /> VSCode Cursor Extensions Malware<br /> Koe Security unmasked details about a recent malicious cursor extension campaign they call White Cobra.<br /><a href="https://www.koi.security/blog/whitecobra-vscode-cursor-extensions-malware" target="_blank" rel="noreferrer noopener">https://www.koi.security/blog/whitecobra-vscode-cursor-extensions-malware</a><br /> BSides Augusta<br /><a href="https://bsidesaugusta.org/" target="_blank" rel="noreferrer noopener">https://bsidesaugusta.org/</a><br />]]></itunes:summary><itunes:duration>366</itunes:duration><itunes:keywords>archive,bsides,business,computer,cursor,cyber,cybersecurity,daily,fbi,hacking,infosec,it,network,news,salesforce,search,security,vscode,web,zip</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9612</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, September 12th, 2025: DShield SIEM Update; Another Sonicwall Warning;  Website Keystroke Logging</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-september-12th-2025-dshield-siem-update-another-sonicwall-warning-website-keystroke-logging--67730150</link><description><![CDATA[<br /> DShield SIEM Docker Updates<br /> Guy updated the  DShield SIEM  which graphically summarizes what is happening inside your honeypot.<br /><a href="https://isc.sans.edu/diary/DShield%20SIEM%20Docker%20Updates/32276" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/DShield%20SIEM%20Docker%20Updates/32276</a><br /> Again: Sonicwall SSL VPN Compromises<br /> The Australian Government s Signals Directorate noted an increase in compromised Sonicwall devices. <br /><a href="https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/ongoing-active-exploitation-of-sonicwall-ssl-vpns-in-australia" target="_blank" rel="noreferrer noopener">https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/ongoing-active-exploitation-of-sonicwall-ssl-vpns-in-australia</a><br /> Website Keystroke Logging<br /> Many websites log every keystroke, not just data submitted in forms.<br /><a href="https://arxiv.org/pdf/2508.19825" target="_blank" rel="noreferrer noopener">https://arxiv.org/pdf/2508.19825</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9610.mp3</guid><pubDate>Fri, 12 Sep 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67730150/9610.mp3" length="5580805" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9610" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 DShield SIEM Docker Updates
 Guy updated the  DShield SIEM  which graphically summarizes what is happening inside your honeypot.
https://isc.sans.edu/diary/DShield%20SIEM%20Docker%20Updates/32276
 Again: Sonicwall SSL VPN Compromises
 The Australian...</itunes:subtitle><itunes:summary><![CDATA[<br /> DShield SIEM Docker Updates<br /> Guy updated the  DShield SIEM  which graphically summarizes what is happening inside your honeypot.<br /><a href="https://isc.sans.edu/diary/DShield%20SIEM%20Docker%20Updates/32276" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/DShield%20SIEM%20Docker%20Updates/32276</a><br /> Again: Sonicwall SSL VPN Compromises<br /> The Australian Government s Signals Directorate noted an increase in compromised Sonicwall devices. <br /><a href="https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/ongoing-active-exploitation-of-sonicwall-ssl-vpns-in-australia" target="_blank" rel="noreferrer noopener">https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/ongoing-active-exploitation-of-sonicwall-ssl-vpns-in-australia</a><br /> Website Keystroke Logging<br /> Many websites log every keystroke, not just data submitted in forms.<br /><a href="https://arxiv.org/pdf/2508.19825" target="_blank" rel="noreferrer noopener">https://arxiv.org/pdf/2508.19825</a><br />]]></itunes:summary><itunes:duration>399</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dshield,hacking,infosec,internet,it,keystroke,logging,network,news,security,siem,sonicwall,website</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9610</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, September 11th, 2025: BASE64 in DNS; Google Chrome, Ivantii and Sophos Patches; Apple Memory Integrity Feature</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-september-11th-2025-base64-in-dns-google-chrome-ivantii-and-sophos-patches-apple-memory-integrity-feature--67713598</link><description><![CDATA[<br /> BASE64 Over DNS<br /> The base64 character set exceeds what is allowable in DNS. However, some implementations will work even with these  invalid  characters.<br /><a href="https://isc.sans.edu/diary/BASE64%20Over%20DNS/32274" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/BASE64%20Over%20DNS/32274</a><br /> Google Chrome Update<br /> Google released an update for Google Chrome, addressing two vulnerabilities. One of the vulnerabilities is rated critical and may allow code execution.<br /><a href="https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_9.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_9.html</a><br /> Ivanti Updates<br /> Ivanti patched a number of vulnerabilities, several of them critical, across its product portfolio.<br /><a href="https://forums.ivanti.com/s/article/September-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-and-Neurons-for-Secure-Access-Multiple-CVEs" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/September-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-and-Neurons-for-Secure-Access-Multiple-CVEs</a><br /> Sophos Patches<br /> Sophos resolved authentication bypass vulnerability in Sophos AP6 series wireless access point firmware (CVE-2025-10159)<br /><a href="https://www.sophos.com/en-us/security-advisories/sophos-sa-20250909-ap6" target="_blank" rel="noreferrer noopener">https://www.sophos.com/en-us/security-advisories/sophos-sa-20250909-ap6</a><br /> Apple Introduces Memory Integrity Enforcement<br /> With the new hardware promoted in yesterday s event, Apple also introduced new memory integrity features based on this new hardware.<br /><a href="https://security.apple.com/blog/memory-integrity-enforcement/" target="_blank" rel="noreferrer noopener">https://security.apple.com/blog/memory-integrity-enforcement/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9608.mp3</guid><pubDate>Thu, 11 Sep 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67713598/9608.mp3" length="6054147" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9608" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 BASE64 Over DNS
 The base64 character set exceeds what is allowable in DNS. However, some implementations will work even with these  invalid  characters.
https://isc.sans.edu/diary/BASE64%20Over%20DNS/32274
 Google Chrome Update
 Google released an...</itunes:subtitle><itunes:summary><![CDATA[<br /> BASE64 Over DNS<br /> The base64 character set exceeds what is allowable in DNS. However, some implementations will work even with these  invalid  characters.<br /><a href="https://isc.sans.edu/diary/BASE64%20Over%20DNS/32274" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/BASE64%20Over%20DNS/32274</a><br /> Google Chrome Update<br /> Google released an update for Google Chrome, addressing two vulnerabilities. One of the vulnerabilities is rated critical and may allow code execution.<br /><a href="https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_9.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_9.html</a><br /> Ivanti Updates<br /> Ivanti patched a number of vulnerabilities, several of them critical, across its product portfolio.<br /><a href="https://forums.ivanti.com/s/article/September-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-and-Neurons-for-Secure-Access-Multiple-CVEs" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/September-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-and-Neurons-for-Secure-Access-Multiple-CVEs</a><br /> Sophos Patches<br /> Sophos resolved authentication bypass vulnerability in Sophos AP6 series wireless access point firmware (CVE-2025-10159)<br /><a href="https://www.sophos.com/en-us/security-advisories/sophos-sa-20250909-ap6" target="_blank" rel="noreferrer noopener">https://www.sophos.com/en-us/security-advisories/sophos-sa-20250909-ap6</a><br /> Apple Introduces Memory Integrity Enforcement<br /> With the new hardware promoted in yesterday s event, Apple also introduced new memory integrity features based on this new hardware.<br /><a href="https://security.apple.com/blog/memory-integrity-enforcement/" target="_blank" rel="noreferrer noopener">https://security.apple.com/blog/memory-integrity-enforcement/</a><br />]]></itunes:summary><itunes:duration>432</itunes:duration><itunes:keywords>ap6,apple,base64,business,cyber,cybersecurity,daily,dns,google,hacking,infosec,it,ivanti,memory integrity,memory safe,network,news,patches,sophos,updates</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9608</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, September 10th, 2025: Microsoft Patch Tuesday;</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-september-10th-2025-microsoft-patch-tuesday--67696655</link><description><![CDATA[<br /> Microsoft Patch Tuesday<br /> As part of its September patch Tuesday, Microsoft addressed 177 different vulnerabilities, 86 of which affect Microsoft products. None of the vulnerabilities has been exploited before today. Two of the vulnerabilities were already made public. Microsoft rates 13 of the vulnerabilities are critical.<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20September%202025/32270" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20September%202025/32270</a><br /> Adobe Patches<br /> Adobe released patches for nine products, including Adobe Commerce, Coldfusion, and Acrobat.<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> SAP Patches<br /> SAP patched vulnerabilities across its product portfolio. Particularly interesting are a few critical vulnerabilities in Netweaver, one of which scored a perfect 10.0 CVSS score.<br /><a href="https://onapsis.com/blog/sap-security-notes-september-2025-patch-day/" target="_blank" rel="noreferrer noopener">https://onapsis.com/blog/sap-security-notes-september-2025-patch-day/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9606.mp3</guid><pubDate>Wed, 10 Sep 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67696655/9606.mp3" length="7079764" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9606" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Microsoft Patch Tuesday
 As part of its September patch Tuesday, Microsoft addressed 177 different vulnerabilities, 86 of which affect Microsoft products. None of the vulnerabilities has been exploited before today. Two of the vulnerabilities were...</itunes:subtitle><itunes:summary><![CDATA[<br /> Microsoft Patch Tuesday<br /> As part of its September patch Tuesday, Microsoft addressed 177 different vulnerabilities, 86 of which affect Microsoft products. None of the vulnerabilities has been exploited before today. Two of the vulnerabilities were already made public. Microsoft rates 13 of the vulnerabilities are critical.<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20September%202025/32270" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20September%202025/32270</a><br /> Adobe Patches<br /> Adobe released patches for nine products, including Adobe Commerce, Coldfusion, and Acrobat.<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> SAP Patches<br /> SAP patched vulnerabilities across its product portfolio. Particularly interesting are a few critical vulnerabilities in Netweaver, one of which scored a perfect 10.0 CVSS score.<br /><a href="https://onapsis.com/blog/sap-security-notes-september-2025-patch-day/" target="_blank" rel="noreferrer noopener">https://onapsis.com/blog/sap-security-notes-september-2025-patch-day/</a><br />]]></itunes:summary><itunes:duration>506</itunes:duration><itunes:keywords>acrobat,adobe,business,coldfusion,commerce,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microsoft,netweaver,network,news,patches,sap,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9606</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, September 9th, 2025: Major npm compromise; HTTP Request Signature</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-september-9th-2025-major-npm-compromise-http-request-signature--67684208</link><description><![CDATA[<br /> Major npm compromise<br /> A number of high-profile npm libraries were compromised after developers fell for a phishing email. This compromise affected libraries with a total of hundreds of millions of downloads a week.<br /><a href="https://bsky.app/profile/bad-at-computer.bsky.social/post/3lydioq5swk2y" target="_blank" rel="noreferrer noopener">https://bsky.app/profile/bad-at-computer.bsky.social/post/3lydioq5swk2y</a> <a href="https://github.com/orgs/community/discussions/172738" target="_blank" rel="noreferrer noopener">https://github.com/orgs/community/discussions/172738</a> <a href="https://github.com/chalk/chalk/issues/656#issuecomment-3266894253" target="_blank" rel="noreferrer noopener">https://github.com/chalk/chalk/issues/656#issuecomment-3266894253</a><br /><a href="https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised" target="_blank" rel="noreferrer noopener">https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised</a><br /> HTTP Request Signatures<br /> It looks like some search engines and AI bots are starting to use the HTTP request signature. This should make it easier to identify bot traffic.<br /><a href="https://isc.sans.edu/diary/HTTP%20Request%20Signatures/32266" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/HTTP%20Request%20Signatures/32266</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9604.mp3</guid><pubDate>Tue, 09 Sep 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67684208/9604.mp3" length="7340400" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9604" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Major npm compromise
 A number of high-profile npm libraries were compromised after developers fell for a phishing email. This compromise affected libraries with a total of hundreds of millions of downloads a week....</itunes:subtitle><itunes:summary><![CDATA[<br /> Major npm compromise<br /> A number of high-profile npm libraries were compromised after developers fell for a phishing email. This compromise affected libraries with a total of hundreds of millions of downloads a week.<br /><a href="https://bsky.app/profile/bad-at-computer.bsky.social/post/3lydioq5swk2y" target="_blank" rel="noreferrer noopener">https://bsky.app/profile/bad-at-computer.bsky.social/post/3lydioq5swk2y</a> <a href="https://github.com/orgs/community/discussions/172738" target="_blank" rel="noreferrer noopener">https://github.com/orgs/community/discussions/172738</a> <a href="https://github.com/chalk/chalk/issues/656#issuecomment-3266894253" target="_blank" rel="noreferrer noopener">https://github.com/chalk/chalk/issues/656#issuecomment-3266894253</a><br /><a href="https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised" target="_blank" rel="noreferrer noopener">https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised</a><br /> HTTP Request Signatures<br /> It looks like some search engines and AI bots are starting to use the HTTP request signature. This should make it easier to identify bot traffic.<br /><a href="https://isc.sans.edu/diary/HTTP%20Request%20Signatures/32266" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/HTTP%20Request%20Signatures/32266</a><br />]]></itunes:summary><itunes:duration>524</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,debug,hacking,http,infosec,internet,it,network,news,npm,qix,request,security,signature</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9604</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, September 8th, 2025: YARA to Debugger Offsets; SVG JavaScript Phishing; FreePBX Patches;</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-september-8th-2025-yara-to-debugger-offsets-svg-javascript-phishing-freepbx-patches--67669503</link><description><![CDATA[<br /> From YARA Offsets to Virtual Addresses<br /> Xavier explains how to convert offsets reported by YARA into offsets suitable for the use with debuggers.<br /><a href="https://isc.sans.edu/diary/From%20YARA%20Offsets%20to%20Virtual%20Addresses/32262" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/From%20YARA%20Offsets%20to%20Virtual%20Addresses/32262</a><br /> Phishing via JavaScript in SVG Files<br /> Virustotal uncovered a Colombian phishing campaign that takes advantage of JavaScript in SVG files.<br /><a href="https://blog.virustotal.com/2025/09/uncovering-colombian-malware-campaign.html" target="_blank" rel="noreferrer noopener">https://blog.virustotal.com/2025/09/uncovering-colombian-malware-campaign.html</a><br /> FreePBX Patches<br /> FreePBX released details regarding two vulnerabilities patched last week. One of these vulnerabilities was already actively exploited.<br /><a href="https://github.com/FreePBX/security-reporting/security/advisories/GHSA-3r47-p39v-vqqf" target="_blank" rel="noreferrer noopener">https://github.com/FreePBX/security-reporting/security/advisories/GHSA-3r47-p39v-vqqf</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9602.mp3</guid><pubDate>Mon, 08 Sep 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67669503/9602.mp3" length="4685748" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9602" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 From YARA Offsets to Virtual Addresses
 Xavier explains how to convert offsets reported by YARA into offsets suitable for the use with debuggers.
https://isc.sans.edu/diary/From%20YARA%20Offsets%20to%20Virtual%20Addresses/32262
 Phishing via...</itunes:subtitle><itunes:summary><![CDATA[<br /> From YARA Offsets to Virtual Addresses<br /> Xavier explains how to convert offsets reported by YARA into offsets suitable for the use with debuggers.<br /><a href="https://isc.sans.edu/diary/From%20YARA%20Offsets%20to%20Virtual%20Addresses/32262" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/From%20YARA%20Offsets%20to%20Virtual%20Addresses/32262</a><br /> Phishing via JavaScript in SVG Files<br /> Virustotal uncovered a Colombian phishing campaign that takes advantage of JavaScript in SVG files.<br /><a href="https://blog.virustotal.com/2025/09/uncovering-colombian-malware-campaign.html" target="_blank" rel="noreferrer noopener">https://blog.virustotal.com/2025/09/uncovering-colombian-malware-campaign.html</a><br /> FreePBX Patches<br /> FreePBX released details regarding two vulnerabilities patched last week. One of these vulnerabilities was already actively exploited.<br /><a href="https://github.com/FreePBX/security-reporting/security/advisories/GHSA-3r47-p39v-vqqf" target="_blank" rel="noreferrer noopener">https://github.com/FreePBX/security-reporting/security/advisories/GHSA-3r47-p39v-vqqf</a><br />]]></itunes:summary><itunes:duration>335</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,freepbx,hacking,infosec,internet,it,javascript,network,news,offset,security,svg,yara</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9602</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, September 5th, 2025: Cloudflare Response to 1.1.1.1 Certificate; AI Modem Namespace Reuse; macOS Vulnerability Allowe</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-september-5th-2025-cloudflare-response-to-1-1-1-1-certificate-ai-modem-namespace-reuse-macos-vulnerability-allowe--67640484</link><description><![CDATA[<br /> Unauthorized Issuance of Certificate for 1.1.1.1<br /> Cloudflare published a blog post with more details regarding the bad 1.1.1.1 certificate that was issued by Fina.<br /><a href="https://blog.cloudflare.com/unauthorized-issuance-of-certificates-for-1-1-1-1/" target="_blank" rel="noreferrer noopener">https://blog.cloudflare.com/unauthorized-issuance-of-certificates-for-1-1-1-1/</a><br /> AI Model Namespace Reuse<br /> Deleted accounts on Huggingface can be taken over by other entities unrelated to the original owner.<br /><a href="https://unit42.paloaltonetworks.com/model-namespace-reuse/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/model-namespace-reuse/</a><br /> macOS vulnerability allowed Keychain and iOS app decryption without a password<br /> Excessive entitlements for the gcore binary facilitated access to key material that was sufficient to access secrets stored in Apple s keychain.<br /><a href="https://www.helpnetsecurity.com/2025/09/04/macos-gcore-vulnerability-cve-2025-24204/" target="_blank" rel="noreferrer noopener">https://www.helpnetsecurity.com/2025/09/04/macos-gcore-vulnerability-cve-2025-24204/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9600.mp3</guid><pubDate>Fri, 05 Sep 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67640484/9600.mp3" length="6983556" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9600" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Unauthorized Issuance of Certificate for 1.1.1.1
 Cloudflare published a blog post with more details regarding the bad 1.1.1.1 certificate that was issued by Fina.
https://blog.cloudflare.com/unauthorized-issuance-of-certificates-for-1-1-1-1/
 AI...</itunes:subtitle><itunes:summary><![CDATA[<br /> Unauthorized Issuance of Certificate for 1.1.1.1<br /> Cloudflare published a blog post with more details regarding the bad 1.1.1.1 certificate that was issued by Fina.<br /><a href="https://blog.cloudflare.com/unauthorized-issuance-of-certificates-for-1-1-1-1/" target="_blank" rel="noreferrer noopener">https://blog.cloudflare.com/unauthorized-issuance-of-certificates-for-1-1-1-1/</a><br /> AI Model Namespace Reuse<br /> Deleted accounts on Huggingface can be taken over by other entities unrelated to the original owner.<br /><a href="https://unit42.paloaltonetworks.com/model-namespace-reuse/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/model-namespace-reuse/</a><br /> macOS vulnerability allowed Keychain and iOS app decryption without a password<br /> Excessive entitlements for the gcore binary facilitated access to key material that was sufficient to access secrets stored in Apple s keychain.<br /><a href="https://www.helpnetsecurity.com/2025/09/04/macos-gcore-vulnerability-cve-2025-24204/" target="_blank" rel="noreferrer noopener">https://www.helpnetsecurity.com/2025/09/04/macos-gcore-vulnerability-cve-2025-24204/</a><br />]]></itunes:summary><itunes:duration>499</itunes:duration><itunes:keywords>ai model,business,ca,certificate,cloudflare,computer,cyber,cybersecurity,daily,gcore,hacking,infosec,internet,it,keychain,macos,namespace,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9600</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, September 4th, 2025: Dassault DELMIA Apriso Exploit Attempts; Android Updates; 1.1.1.1 Certificate Issued</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-september-4th-2025-dassault-delmia-apriso-exploit-attempts-android-updates-1-1-1-1-certificate-issued--67634189</link><description><![CDATA[<br /> Exploit Attempts for Dassault DELMIA Apriso. CVE-2025-5086<br /> Our honeypots detected attacks against the manufacturing management system DELMIA Apriso. The deserialization vulnerability was patched in June and is one of a few critical vulnerabilities patched in recent months.<br /><a href="https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Dassault%20DELMIA%20Apriso.%20CVE-2025-5086/32256" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Dassault%20DELMIA%20Apriso.%20CVE-2025-5086/32256</a><br /> Android Bulletin<br /> Google released its September update, fixing two already-exploited privilege escalation flaws and some remote code execution issues.<br /><a href="https://source.android.com/docs/security/bulletin/2025-09-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2025-09-01</a><br /> Mis-issued Certificates for SAN iPAddress:1.1.1.1 by Fina RDC 2020<br /> Certificate authority Fina RDC issues a certificate for Cloudflare s IP address 1.1.1.1<br /><a href="https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/SgwC1QsEpvc" target="_blank" rel="noreferrer noopener">https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/SgwC1QsEpvc</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9598.mp3</guid><pubDate>Thu, 04 Sep 2025 13:59:15 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67634189/9598.mp3" length="5350384" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9598" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Exploit Attempts for Dassault DELMIA Apriso. CVE-2025-5086
 Our honeypots detected attacks against the manufacturing management system DELMIA Apriso. The deserialization vulnerability was patched in June and is one of a few critical vulnerabilities...</itunes:subtitle><itunes:summary><![CDATA[<br /> Exploit Attempts for Dassault DELMIA Apriso. CVE-2025-5086<br /> Our honeypots detected attacks against the manufacturing management system DELMIA Apriso. The deserialization vulnerability was patched in June and is one of a few critical vulnerabilities patched in recent months.<br /><a href="https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Dassault%20DELMIA%20Apriso.%20CVE-2025-5086/32256" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Dassault%20DELMIA%20Apriso.%20CVE-2025-5086/32256</a><br /> Android Bulletin<br /> Google released its September update, fixing two already-exploited privilege escalation flaws and some remote code execution issues.<br /><a href="https://source.android.com/docs/security/bulletin/2025-09-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2025-09-01</a><br /> Mis-issued Certificates for SAN iPAddress:1.1.1.1 by Fina RDC 2020<br /> Certificate authority Fina RDC issues a certificate for Cloudflare s IP address 1.1.1.1<br /><a href="https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/SgwC1QsEpvc" target="_blank" rel="noreferrer noopener">https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/SgwC1QsEpvc</a><br />]]></itunes:summary><itunes:duration>382</itunes:duration><itunes:keywords>android,apriso,business,certifiate,computer,cyber,cybersecurity,daily,dassault,demia,fina,fina rdc,hacking,honeypot,infosec,it,network,news,san,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9598</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, September 3rd, 2025: Sextortiion Analysis; Covert Channel DNS/ICMP; Azure AD Secret Theft; Official FreePBX Patche</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-september-3rd-2025-sextortiion-analysis-covert-channel-dns-icmp-azure-ad-secret-theft-official-freepbx-patche--67608434</link><description><![CDATA[<br /> A Quick Look at Sextortion at Scale<br /> Jan analyzed 1900 different sextortion messages using 205 different Bitcoin addresses to look at the success rate, lifetime, and other metrics defining these campaigns.<br /><a href="https://isc.sans.edu/diary/A%20quick%20look%20at%20sextortion%20at%20scale%3A%201%2C900%20messages%20and%20205%20Bitcoin%20addresses%20spanning%20four%20years/32252" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20quick%20look%20at%20sextortion%20at%20scale%3A%201%2C900%20messages%20and%20205%20Bitcoin%20addresses%20spanning%20four%20years/32252</a><br /> Azure AD Client Secret Leak<br /> Attackers are stealing Azure AD client secrets from websites that are leaving them exposed.<br /><a href="https://www.resecurity.com/blog/article/azure-ad-client-secret-leak-the-keys-to-cloud" target="_blank" rel="noreferrer noopener">https://www.resecurity.com/blog/article/azure-ad-client-secret-leak-the-keys-to-cloud</a><br /> Covert Channel via ICMP and DNS<br /> A new bot combines ICMP and DNS in new ways for covert communication. The DNS requests use domains with a fixed prefix followed by a base64 encoded command, and the ICMP echo request packets include commands as a payload.<br /><a href="https://blog.xlab.qianxin.com/mystrodx_covert_dual-mode_backdoor_en/" target="_blank" rel="noreferrer noopener">https://blog.xlab.qianxin.com/mystrodx_covert_dual-mode_backdoor_en/</a><br /> Official Release of Critical FreePBX Patch<br /> Sangoma has announced that the experimental patch released for the exploited FreePBX vulnerability is now considered stable, and users should update to apply it.<br /><a href="https://community.freepbx.org/t/security-advisory-please-lock-down-your-administrator-access/107203" target="_blank" rel="noreferrer noopener">https://community.freepbx.org/t/security-advisory-please-lock-down-your-administrator-access/107203</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9596.mp3</guid><pubDate>Wed, 03 Sep 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67608434/9596.mp3" length="4619454" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9596" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 A Quick Look at Sextortion at Scale
 Jan analyzed 1900 different sextortion messages using 205 different Bitcoin addresses to look at the success rate, lifetime, and other metrics defining these campaigns....</itunes:subtitle><itunes:summary><![CDATA[<br /> A Quick Look at Sextortion at Scale<br /> Jan analyzed 1900 different sextortion messages using 205 different Bitcoin addresses to look at the success rate, lifetime, and other metrics defining these campaigns.<br /><a href="https://isc.sans.edu/diary/A%20quick%20look%20at%20sextortion%20at%20scale%3A%201%2C900%20messages%20and%20205%20Bitcoin%20addresses%20spanning%20four%20years/32252" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20quick%20look%20at%20sextortion%20at%20scale%3A%201%2C900%20messages%20and%20205%20Bitcoin%20addresses%20spanning%20four%20years/32252</a><br /> Azure AD Client Secret Leak<br /> Attackers are stealing Azure AD client secrets from websites that are leaving them exposed.<br /><a href="https://www.resecurity.com/blog/article/azure-ad-client-secret-leak-the-keys-to-cloud" target="_blank" rel="noreferrer noopener">https://www.resecurity.com/blog/article/azure-ad-client-secret-leak-the-keys-to-cloud</a><br /> Covert Channel via ICMP and DNS<br /> A new bot combines ICMP and DNS in new ways for covert communication. The DNS requests use domains with a fixed prefix followed by a base64 encoded command, and the ICMP echo request packets include commands as a payload.<br /><a href="https://blog.xlab.qianxin.com/mystrodx_covert_dual-mode_backdoor_en/" target="_blank" rel="noreferrer noopener">https://blog.xlab.qianxin.com/mystrodx_covert_dual-mode_backdoor_en/</a><br /> Official Release of Critical FreePBX Patch<br /> Sangoma has announced that the experimental patch released for the exploited FreePBX vulnerability is now considered stable, and users should update to apply it.<br /><a href="https://community.freepbx.org/t/security-advisory-please-lock-down-your-administrator-access/107203" target="_blank" rel="noreferrer noopener">https://community.freepbx.org/t/security-advisory-please-lock-down-your-administrator-access/107203</a><br />]]></itunes:summary><itunes:duration>330</itunes:duration><itunes:keywords>ad,azure,azure ad,bitcoin,business,computer,cyber,cybersecurity,daily,dns,freepbx,hacking,icmp,infosec,it,network,news,secrets,security,sextortion</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9596</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, September 2nd, 2025: pdf-parser Patch; Salesloft Compromise; Velociraptor Abuse; NeuVector Default Password</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-september-2nd-2025-pdf-parser-patch-salesloft-compromise-velociraptor-abuse-neuvector-default-password--67589062</link><description><![CDATA[<br /> pdf-parser: All Streams<br /> Didier released a new version of pdf-parser.py. This version fixes a problem with dumping all filtered streams.<br /><a href="https://isc.sans.edu/diary/pdf-parser%3A%20All%20Streams/32248" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/pdf-parser%3A%20All%20Streams/32248</a><br /> Salesloft Drift Putting OAuth Tokens at Risk<br /> OAuth tokens used by Salesloft Drift users to provide access to integrations with Salesforce, Google Workspace, and others have been compromised and heavily abused for additional compromise and large-scale data exfiltration from exposed services.<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift</a><br /> Velociraptor incident response tool abused for remote access<br /> Attackers are using the open source incident response tool Velociraptor to access remote systems in breached networks. Tools like Velocitraptor are ideal for attackers to perform lateral movement. <br /><a href="https://news.sophos.com/en-us/2025/08/26/velociraptor-incident-response-tool-abused-for-remote-access/" target="_blank" rel="noreferrer noopener">https://news.sophos.com/en-us/2025/08/26/velociraptor-incident-response-tool-abused-for-remote-access/</a><br /> Default Password in NeuVector (Rancher Desktop)<br /> SuSE fixed a default password vulnerability in NeuVector, a security tool included in Rancher Desktop.<br /><a href="https://github.com/neuvector/neuvector/security/advisories/GHSA-8pxw-9c75-6w56" target="_blank" rel="noreferrer noopener">https://github.com/neuvector/neuvector/security/advisories/GHSA-8pxw-9c75-6w56</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9594.mp3</guid><pubDate>Tue, 02 Sep 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67589062/9594.mp3" length="4750545" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9594" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 pdf-parser: All Streams
 Didier released a new version of pdf-parser.py. This version fixes a problem with dumping all filtered streams.
https://isc.sans.edu/diary/pdf-parser%3A%20All%20Streams/32248
 Salesloft Drift Putting OAuth Tokens at Risk...</itunes:subtitle><itunes:summary><![CDATA[<br /> pdf-parser: All Streams<br /> Didier released a new version of pdf-parser.py. This version fixes a problem with dumping all filtered streams.<br /><a href="https://isc.sans.edu/diary/pdf-parser%3A%20All%20Streams/32248" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/pdf-parser%3A%20All%20Streams/32248</a><br /> Salesloft Drift Putting OAuth Tokens at Risk<br /> OAuth tokens used by Salesloft Drift users to provide access to integrations with Salesforce, Google Workspace, and others have been compromised and heavily abused for additional compromise and large-scale data exfiltration from exposed services.<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift</a><br /> Velociraptor incident response tool abused for remote access<br /> Attackers are using the open source incident response tool Velociraptor to access remote systems in breached networks. Tools like Velocitraptor are ideal for attackers to perform lateral movement. <br /><a href="https://news.sophos.com/en-us/2025/08/26/velociraptor-incident-response-tool-abused-for-remote-access/" target="_blank" rel="noreferrer noopener">https://news.sophos.com/en-us/2025/08/26/velociraptor-incident-response-tool-abused-for-remote-access/</a><br /> Default Password in NeuVector (Rancher Desktop)<br /> SuSE fixed a default password vulnerability in NeuVector, a security tool included in Rancher Desktop.<br /><a href="https://github.com/neuvector/neuvector/security/advisories/GHSA-8pxw-9c75-6w56" target="_blank" rel="noreferrer noopener">https://github.com/neuvector/neuvector/security/advisories/GHSA-8pxw-9c75-6w56</a><br />]]></itunes:summary><itunes:duration>339</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,neuvector,news,pdf,pdf-parser,salesloft,security,velociraptor</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9594</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, August 29th, 2025: Scans for ZIP Files; FreePBX 0-Day; Passwordstate Patch</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-august-29th-2025-scans-for-zip-files-freepbx-0-day-passwordstate-patch--67549337</link><description><![CDATA[<br /> Increasing Searches for ZIP Files<br /> Attackers are scanning our honeypots more and more for .zip files. They are looking for backups of credential files and the like left behind by careless administrators and developers.<br /><a href="https://isc.sans.edu/diary/Increasing%20Searches%20for%20ZIP%20Files/32242" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Increasing%20Searches%20for%20ZIP%20Files/32242</a><br /> FreePBX Vulnerability<br /> An upatched vulnerability in FreePBX is currently being exploited. FreePBX offers mitigation advice and has also just released a  beta  patch.<br /><a href="https://community.freepbx.org/t/security-advisory-please-lock-down-your-administrator-access/107203" target="_blank" rel="noreferrer noopener">https://community.freepbx.org/t/security-advisory-please-lock-down-your-administrator-access/107203</a><br /> Passwordstate Vulnerability<br /> Clickstudios patched an authentication bypass vulnerability in its password manager, Passwordstate. The vulnerability can be used to access the emergency password page.<br /><a href="https://www.clickstudios.com.au/passwordstate-changelog.aspx" target="_blank" rel="noreferrer noopener">https://www.clickstudios.com.au/passwordstate-changelog.aspx</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9592.mp3</guid><pubDate>Fri, 29 Aug 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67549337/9592.mp3" length="4837960" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9592" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Increasing Searches for ZIP Files
 Attackers are scanning our honeypots more and more for .zip files. They are looking for backups of credential files and the like left behind by careless administrators and developers....</itunes:subtitle><itunes:summary><![CDATA[<br /> Increasing Searches for ZIP Files<br /> Attackers are scanning our honeypots more and more for .zip files. They are looking for backups of credential files and the like left behind by careless administrators and developers.<br /><a href="https://isc.sans.edu/diary/Increasing%20Searches%20for%20ZIP%20Files/32242" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Increasing%20Searches%20for%20ZIP%20Files/32242</a><br /> FreePBX Vulnerability<br /> An upatched vulnerability in FreePBX is currently being exploited. FreePBX offers mitigation advice and has also just released a  beta  patch.<br /><a href="https://community.freepbx.org/t/security-advisory-please-lock-down-your-administrator-access/107203" target="_blank" rel="noreferrer noopener">https://community.freepbx.org/t/security-advisory-please-lock-down-your-administrator-access/107203</a><br /> Passwordstate Vulnerability<br /> Clickstudios patched an authentication bypass vulnerability in its password manager, Passwordstate. The vulnerability can be used to access the emergency password page.<br /><a href="https://www.clickstudios.com.au/passwordstate-changelog.aspx" target="_blank" rel="noreferrer noopener">https://www.clickstudios.com.au/passwordstate-changelog.aspx</a><br />]]></itunes:summary><itunes:duration>346</itunes:duration><itunes:keywords>business,clickstudio,computer,cyber,cybersecurity,daily,freepbx,hacking,infosec,internet,it,network,news,passwordstate,security,zip</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9592</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, August 28th, 2025: Launching Shellcode; NX Compromise; Volt Typhoon Report</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-august-28th-2025-launching-shellcode-nx-compromise-volt-typhoon-report--67538130</link><description><![CDATA[<br /> Interesting Technique to Launch a Shellcode<br /> Xavier came across malware that PowerShell and the CallWindowProcA() API to launch code.<br /><a href="https://isc.sans.edu/diary/Interesting%20Technique%20to%20Launch%20a%20Shellcode/32238" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Interesting%20Technique%20to%20Launch%20a%20Shellcode/32238</a><br /> NX Compromised to Steal Wallets and Credentials<br /> The popular open source NX build package was compromised. Code was added that uses the help of AI tools like Claude and Gemini to steal credentials from affected systems<br /><a href="https://semgrep.dev/blog/2025/security-alert-nx-compromised-to-steal-wallets-and-credentials/" target="_blank" rel="noreferrer noopener">https://semgrep.dev/blog/2025/security-alert-nx-compromised-to-steal-wallets-and-credentials/</a><br /> Countering Chinese State-Sponsored Actors  Compromise of Networks Worldwide to Feed the Global Espionage System<br /> Several law enforcement and cybersecurity agencies worldwide collaborated to release a detailed report on the recent Volt Typhoon incident.<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9590.mp3</guid><pubDate>Thu, 28 Aug 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67538130/9590.mp3" length="5589103" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9590" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Interesting Technique to Launch a Shellcode
 Xavier came across malware that PowerShell and the CallWindowProcA() API to launch code.
https://isc.sans.edu/diary/Interesting%20Technique%20to%20Launch%20a%20Shellcode/32238
 NX Compromised to Steal...</itunes:subtitle><itunes:summary><![CDATA[<br /> Interesting Technique to Launch a Shellcode<br /> Xavier came across malware that PowerShell and the CallWindowProcA() API to launch code.<br /><a href="https://isc.sans.edu/diary/Interesting%20Technique%20to%20Launch%20a%20Shellcode/32238" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Interesting%20Technique%20to%20Launch%20a%20Shellcode/32238</a><br /> NX Compromised to Steal Wallets and Credentials<br /> The popular open source NX build package was compromised. Code was added that uses the help of AI tools like Claude and Gemini to steal credentials from affected systems<br /><a href="https://semgrep.dev/blog/2025/security-alert-nx-compromised-to-steal-wallets-and-credentials/" target="_blank" rel="noreferrer noopener">https://semgrep.dev/blog/2025/security-alert-nx-compromised-to-steal-wallets-and-credentials/</a><br /> Countering Chinese State-Sponsored Actors  Compromise of Networks Worldwide to Feed the Global Espionage System<br /> Several law enforcement and cybersecurity agencies worldwide collaborated to release a detailed report on the recent Volt Typhoon incident.<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a</a><br />]]></itunes:summary><itunes:duration>399</itunes:duration><itunes:keywords>business,callwindowproca,cisa,cisco,computer,credentials,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,nx,security,shellcode,supply chain,volt typhoon</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9590</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, August 27th, 2025: Analyzing IDNs; Netscaler 0-Day Vuln; Git Vuln Exploited;</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-august-27th-2025-analyzing-idns-netscaler-0-day-vuln-git-vuln-exploited--67525011</link><description><![CDATA[<br /> Getting a Better Handle on International Domain Names and Punycode<br /> International Domain names can be used for phishing and other attacks. One way to identify suspect names is to look for mixed script use.<br /><a href="https://isc.sans.edu/diary/Getting%20a%20Better%20Handle%20on%20International%20Domain%20Names%20and%20Punycode/32234" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Getting%20a%20Better%20Handle%20on%20International%20Domain%20Names%20and%20Punycode/32234</a><br /> Citrix Netscaler Vulnerabilities CVE-2025-7775, CVE-2025-7776 and CVE-2025-8424<br /> Citrix patched three vulnerabilities in Netscaler. One is already being exploited<br /><a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938&amp;articleTitle=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2025_7775_CVE_2025_7776_and_CVE_2025_8424" target="_blank" rel="noreferrer noopener">https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938&amp;articleTitle=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2025_7775_CVE_2025_7776_and_CVE_2025_8424</a><br /> git vulnerability exploited (CVE-2025-48384)<br /> A git vulnerability patched in early July is now being exploited<br /><a href="https://github.com/git/git/security/advisories/GHSA-vwqx-4fm8-6qc9" target="_blank" rel="noreferrer noopener">https://github.com/git/git/security/advisories/GHSA-vwqx-4fm8-6qc9</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9588.mp3</guid><pubDate>Wed, 27 Aug 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67525011/9588.mp3" length="4801552" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9588" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Getting a Better Handle on International Domain Names and Punycode
 International Domain names can be used for phishing and other attacks. One way to identify suspect names is to look for mixed script use....</itunes:subtitle><itunes:summary><![CDATA[<br /> Getting a Better Handle on International Domain Names and Punycode<br /> International Domain names can be used for phishing and other attacks. One way to identify suspect names is to look for mixed script use.<br /><a href="https://isc.sans.edu/diary/Getting%20a%20Better%20Handle%20on%20International%20Domain%20Names%20and%20Punycode/32234" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Getting%20a%20Better%20Handle%20on%20International%20Domain%20Names%20and%20Punycode/32234</a><br /> Citrix Netscaler Vulnerabilities CVE-2025-7775, CVE-2025-7776 and CVE-2025-8424<br /> Citrix patched three vulnerabilities in Netscaler. One is already being exploited<br /><a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938&amp;articleTitle=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2025_7775_CVE_2025_7776_and_CVE_2025_8424" target="_blank" rel="noreferrer noopener">https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938&amp;articleTitle=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2025_7775_CVE_2025_7776_and_CVE_2025_8424</a><br /> git vulnerability exploited (CVE-2025-48384)<br /> A git vulnerability patched in early July is now being exploited<br /><a href="https://github.com/git/git/security/advisories/GHSA-vwqx-4fm8-6qc9" target="_blank" rel="noreferrer noopener">https://github.com/git/git/security/advisories/GHSA-vwqx-4fm8-6qc9</a><br />]]></itunes:summary><itunes:duration>343</itunes:duration><itunes:keywords>business,citrix,computer,cyber,cybersecurity,daily,git,hacking,idn,infosec,internet,it,network,news,punycode,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9588</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, August 26th, 2025: Decoding Word Reading Location; Image Downscaling AI Vulnerability; IBM Jazz Team Server Vuln</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-august-26th-2025-decoding-word-reading-location-image-downscaling-ai-vulnerability-ibm-jazz-team-server-vuln--67514033</link><description><![CDATA[<br /> Reading Location Position Value in Microsoft Word Documents<br /> Jessy investigated how Word documents store the last visited document location in the registry.<br /><a href="https://isc.sans.edu/diary/Reading%20Location%20Position%20Value%20in%20Microsoft%20Word%20Documents/32224" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Reading%20Location%20Position%20Value%20in%20Microsoft%20Word%20Documents/32224</a><br /> Weaponizing image scaling against production AI systems<br /> AI systems often downscale images before processing them. An attacker can create a harmless looking image that would reveal text after downscaling leading to prompt injection<br /><a href="https://blog.trailofbits.com/2025/08/21/weaponizing-image-scaling-against-production-ai-systems/" target="_blank" rel="noreferrer noopener">https://blog.trailofbits.com/2025/08/21/weaponizing-image-scaling-against-production-ai-systems/</a><br /> IBM Jazz Team Server Vulnerability  CVE-2025-36157<br /> IBM patched a critical vulnerability in its Jazz Team Server<br /><a href="https://www.ibm.com/support/pages/node/7242925" target="_blank" rel="noreferrer noopener">https://www.ibm.com/support/pages/node/7242925</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9586.mp3</guid><pubDate>Tue, 26 Aug 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67514033/9586.mp3" length="4218945" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9586" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Reading Location Position Value in Microsoft Word Documents
 Jessy investigated how Word documents store the last visited document location in the registry....</itunes:subtitle><itunes:summary><![CDATA[<br /> Reading Location Position Value in Microsoft Word Documents<br /> Jessy investigated how Word documents store the last visited document location in the registry.<br /><a href="https://isc.sans.edu/diary/Reading%20Location%20Position%20Value%20in%20Microsoft%20Word%20Documents/32224" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Reading%20Location%20Position%20Value%20in%20Microsoft%20Word%20Documents/32224</a><br /> Weaponizing image scaling against production AI systems<br /> AI systems often downscale images before processing them. An attacker can create a harmless looking image that would reveal text after downscaling leading to prompt injection<br /><a href="https://blog.trailofbits.com/2025/08/21/weaponizing-image-scaling-against-production-ai-systems/" target="_blank" rel="noreferrer noopener">https://blog.trailofbits.com/2025/08/21/weaponizing-image-scaling-against-production-ai-systems/</a><br /> IBM Jazz Team Server Vulnerability  CVE-2025-36157<br /> IBM patched a critical vulnerability in its Jazz Team Server<br /><a href="https://www.ibm.com/support/pages/node/7242925" target="_blank" rel="noreferrer noopener">https://www.ibm.com/support/pages/node/7242925</a><br />]]></itunes:summary><itunes:duration>301</itunes:duration><itunes:keywords>ai,business,computer,cyber,cybersecurity,daily,downscaling,hacking,ibm,images,infosec,it,jazz,location,network,news,prompt,security,team,word</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9586</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, August 25th, 2025: IP Cleanup; Linux Desktop Attacks; Malicious Go SSH Brute Forcer; Onmicrosoft Domain Restrictions</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-august-25th-2025-ip-cleanup-linux-desktop-attacks-malicious-go-ssh-brute-forcer-onmicrosoft-domain-restrictions--67501459</link><description><![CDATA[<br /> The end of an era: Properly formatted IP addresses in all of our data.<br /> When initiall designing DShield, addresses were  zero padded , an unfortunate choice. As of this week, datafeeds should no longer be  zero padded .<br /><a href="https://isc.sans.edu/diary/The%20end%20of%20an%20era%3A%20Properly%20formated%20IP%20addresses%20in%20all%20of%20our%20data./32228" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20end%20of%20an%20era%3A%20Properly%20formated%20IP%20addresses%20in%20all%20of%20our%20data./32228</a><br /> .desktop files used in an attack against Linux Desktops<br /> Pakistani attackers are using .desktop files to target Indian Linux desktops.<br /><a href="https://www.cyfirma.com/research/apt36-targets-indian-boss-linux-systems-with-weaponized-autostart-files/" target="_blank" rel="noreferrer noopener">https://www.cyfirma.com/research/apt36-targets-indian-boss-linux-systems-with-weaponized-autostart-files/</a><br /> Malicious Go Module Disguised as SSH Brute Forcer Exfiltrates Credentials via Telegram<br /> A go module advertising its ability to quickly brute force passwords against random IP addresses, has been used to exfiltrate credentials from the person running the module.<br /><a href="https://socket.dev/blog/malicious-go-module-disguised-as-ssh-brute-forcer-exfiltrates-credentials" target="_blank" rel="noreferrer noopener">https://socket.dev/blog/malicious-go-module-disguised-as-ssh-brute-forcer-exfiltrates-credentials</a><br /> Limiting Onmicrosoft Domain Usage for Sending Emails<br /> Microsoft is limiting how many emails can be sent by Microsoft 365 users using the  onmicrosoft.com  domain.<br /><a href="https://techcommunity.microsoft.com/blog/exchange/limiting-onmicrosoft-domain-usage-for-sending-emails/4446167" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/blog/exchange/limiting-onmicrosoft-domain-usage-for-sending-emails/4446167</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9584.mp3</guid><pubDate>Mon, 25 Aug 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67501459/9584.mp3" length="5098274" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9584" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 The end of an era: Properly formatted IP addresses in all of our data.
 When initiall designing DShield, addresses were  zero padded , an unfortunate choice. As of this week, datafeeds should no longer be  zero padded ....</itunes:subtitle><itunes:summary><![CDATA[<br /> The end of an era: Properly formatted IP addresses in all of our data.<br /> When initiall designing DShield, addresses were  zero padded , an unfortunate choice. As of this week, datafeeds should no longer be  zero padded .<br /><a href="https://isc.sans.edu/diary/The%20end%20of%20an%20era%3A%20Properly%20formated%20IP%20addresses%20in%20all%20of%20our%20data./32228" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20end%20of%20an%20era%3A%20Properly%20formated%20IP%20addresses%20in%20all%20of%20our%20data./32228</a><br /> .desktop files used in an attack against Linux Desktops<br /> Pakistani attackers are using .desktop files to target Indian Linux desktops.<br /><a href="https://www.cyfirma.com/research/apt36-targets-indian-boss-linux-systems-with-weaponized-autostart-files/" target="_blank" rel="noreferrer noopener">https://www.cyfirma.com/research/apt36-targets-indian-boss-linux-systems-with-weaponized-autostart-files/</a><br /> Malicious Go Module Disguised as SSH Brute Forcer Exfiltrates Credentials via Telegram<br /> A go module advertising its ability to quickly brute force passwords against random IP addresses, has been used to exfiltrate credentials from the person running the module.<br /><a href="https://socket.dev/blog/malicious-go-module-disguised-as-ssh-brute-forcer-exfiltrates-credentials" target="_blank" rel="noreferrer noopener">https://socket.dev/blog/malicious-go-module-disguised-as-ssh-brute-forcer-exfiltrates-credentials</a><br /> Limiting Onmicrosoft Domain Usage for Sending Emails<br /> Microsoft is limiting how many emails can be sent by Microsoft 365 users using the  onmicrosoft.com  domain.<br /><a href="https://techcommunity.microsoft.com/blog/exchange/limiting-onmicrosoft-domain-usage-for-sending-emails/4446167" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/blog/exchange/limiting-onmicrosoft-domain-usage-for-sending-emails/4446167</a><br />]]></itunes:summary><itunes:duration>364</itunes:duration><itunes:keywords>boss,brute forcer,business,computer,cyber,cybersecurity,daily,desktop,go,hacking,infosec,ip addresses,it,linux,network,news,onmicrosoft,padding,security,ssh</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9584</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, August 22nd, 2025: The -n switch; Commvault Exploit; Docker Desktop Escape Vuln;</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-august-22nd-2025-the-n-switch-commvault-exploit-docker-desktop-escape-vuln--67473285</link><description><![CDATA[<br /> Don't Forget The "-n" Command Line Switch<br /> Disabling reverse DNS lookups for IP addresses is important not just for performance, but also for opsec. Xavier is explaining some of the risks.<br /><a href="https://isc.sans.edu/diary/Don%27t%20Forget%20The%20%22-n%22%20Command%20Line%20Switch/32220" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Don%27t%20Forget%20The%20%22-n%22%20Command%20Line%20Switch/32220</a><br /> watchTowr releases details about recent Commvault flaws<br /> Users of the Commvault enterprise backup solution must patch now after watchTowr released details about recent vulnerabilities<br /><a href="https://labs.watchtowr.com/guess-who-would-be-stupid-enough-to-rob-the-same-vault-twice-pre-auth-rce-chains-in-commvault/?123" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/guess-who-would-be-stupid-enough-to-rob-the-same-vault-twice-pre-auth-rce-chains-in-commvault/?123</a><br /> Docker Desktop Vulnerability CVE-2025-9074 <br /> A vulnerability in Docker Desktop allows attackers to escape from containers to attack the host.<br /><a href="https://docs.docker.com/desktop/release-notes/#4443" target="_blank" rel="noreferrer noopener">https://docs.docker.com/desktop/release-notes/#4443</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9582.mp3</guid><pubDate>Fri, 22 Aug 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67473285/9582.mp3" length="5772657" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9582" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Don't Forget The "-n" Command Line Switch
 Disabling reverse DNS lookups for IP addresses is important not just for performance, but also for opsec. Xavier is explaining some of the risks....</itunes:subtitle><itunes:summary><![CDATA[<br /> Don't Forget The "-n" Command Line Switch<br /> Disabling reverse DNS lookups for IP addresses is important not just for performance, but also for opsec. Xavier is explaining some of the risks.<br /><a href="https://isc.sans.edu/diary/Don%27t%20Forget%20The%20%22-n%22%20Command%20Line%20Switch/32220" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Don%27t%20Forget%20The%20%22-n%22%20Command%20Line%20Switch/32220</a><br /> watchTowr releases details about recent Commvault flaws<br /> Users of the Commvault enterprise backup solution must patch now after watchTowr released details about recent vulnerabilities<br /><a href="https://labs.watchtowr.com/guess-who-would-be-stupid-enough-to-rob-the-same-vault-twice-pre-auth-rce-chains-in-commvault/?123" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/guess-who-would-be-stupid-enough-to-rob-the-same-vault-twice-pre-auth-rce-chains-in-commvault/?123</a><br /> Docker Desktop Vulnerability CVE-2025-9074 <br /> A vulnerability in Docker Desktop allows attackers to escape from containers to attack the host.<br /><a href="https://docs.docker.com/desktop/release-notes/#4443" target="_blank" rel="noreferrer noopener">https://docs.docker.com/desktop/release-notes/#4443</a><br />]]></itunes:summary><itunes:duration>412</itunes:duration><itunes:keywords>business,commvault,computer,cyber,cybersecurity,daily,docker,hacking,infosec,internet,it,network,news,security,tcpdump,tshark,watchtowr</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9582</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, August 21st, 2025: Airtel Scans; Apple Patch; Microsoft Copilot Audit Log Issue; Password Manager Clickjacking</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-august-21st-2025-airtel-scans-apple-patch-microsoft-copilot-audit-log-issue-password-manager-clickjacking--67463391</link><description><![CDATA[<br /> Airtel Router Scans and Mislabeled Usernames<br /> A quick summary of some odd usernames that show up in our honeypot logs<br /><a href="https://isc.sans.edu/diary/Airtel%20Router%20Scans%2C%20and%20Mislabeled%20usernames/32216" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Airtel%20Router%20Scans%2C%20and%20Mislabeled%20usernames/32216</a><br /> Apple Patches 0-Day CVE-2025-43300<br /> Apple released an update for iOS, iPadOS and MacOS today patching a single, already exploited, vulnerability in ImageIO.<br /><a href="https://support.apple.com/en-us/124925" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/124925</a><br /> Microsoft Copilot Audit Logs<br /> A user retrieving data via copilot obscures the fact that the user may have had access to data in a specific file<br /><a href="https://pistachioapp.com/blog/copilot-broke-your-audit-log" target="_blank" rel="noreferrer noopener">https://pistachioapp.com/blog/copilot-broke-your-audit-log</a><br /> Password Managers Susceptible to Clickjacking<br /> Many password managers are susceptible to clickjacking, and only few have fixed the problem so far<br /><a href="https://marektoth.com/blog/dom-based-extension-clickjacking/" target="_blank" rel="noreferrer noopener">https://marektoth.com/blog/dom-based-extension-clickjacking/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9580.mp3</guid><pubDate>Thu, 21 Aug 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67463391/9580.mp3" length="5773237" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9580" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Airtel Router Scans and Mislabeled Usernames
 A quick summary of some odd usernames that show up in our honeypot logs
https://isc.sans.edu/diary/Airtel%20Router%20Scans%2C%20and%20Mislabeled%20usernames/32216
 Apple Patches 0-Day CVE-2025-43300...</itunes:subtitle><itunes:summary><![CDATA[<br /> Airtel Router Scans and Mislabeled Usernames<br /> A quick summary of some odd usernames that show up in our honeypot logs<br /><a href="https://isc.sans.edu/diary/Airtel%20Router%20Scans%2C%20and%20Mislabeled%20usernames/32216" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Airtel%20Router%20Scans%2C%20and%20Mislabeled%20usernames/32216</a><br /> Apple Patches 0-Day CVE-2025-43300<br /> Apple released an update for iOS, iPadOS and MacOS today patching a single, already exploited, vulnerability in ImageIO.<br /><a href="https://support.apple.com/en-us/124925" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/124925</a><br /> Microsoft Copilot Audit Logs<br /> A user retrieving data via copilot obscures the fact that the user may have had access to data in a specific file<br /><a href="https://pistachioapp.com/blog/copilot-broke-your-audit-log" target="_blank" rel="noreferrer noopener">https://pistachioapp.com/blog/copilot-broke-your-audit-log</a><br /> Password Managers Susceptible to Clickjacking<br /> Many password managers are susceptible to clickjacking, and only few have fixed the problem so far<br /><a href="https://marektoth.com/blog/dom-based-extension-clickjacking/" target="_blank" rel="noreferrer noopener">https://marektoth.com/blog/dom-based-extension-clickjacking/</a><br />]]></itunes:summary><itunes:duration>412</itunes:duration><itunes:keywords>airtel,apple,business,click jacking,copilot,cyber,cybersecurity,daily,hacking,infosec,it,network,news,password,password manager,patches,security,ssh,telnet,username</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9580</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, August 20th, 2025: Increased Elasticsearch Scans; MSFT Patch Issues</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-august-20th-2025-increased-elasticsearch-scans-msft-patch-issues--67450465</link><description><![CDATA[<br /> Increased Elasticsearch Recognizance Scans<br /> Our honeypots noted an increase in reconnaissance scans for Elasticsearch. In particular, the endpoint /_cluster/settings is hit hard.<br /><a href="https://isc.sans.edu/diary/Increased%20Elasticsearch%20Recognizance%20Scans/32212" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Increased%20Elasticsearch%20Recognizance%20Scans/32212</a><br /> Microsoft Patch Tuesday Issues <br /> Microsoft noted some issues deploying the most recent patches with WSUS. There are also issues with certain SSDs if larger files are transferred.<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-24h2#3635msgdesc" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-24h2#3635msgdesc</a><br /><a href="https://www.tomshardware.com/pc-components/ssds/latest-windows-11-security-patch-might-be-breaking-ssds-under-heavy-workloads-users-report-disappearing-drives-following-file-transfers-including-some-that-cannot-be-recovered-after-a-reboot" target="_blank" rel="noreferrer noopener">https://www.tomshardware.com/pc-components/ssds/latest-windows-11-security-patch-might-be-breaking-ssds-under-heavy-workloads-users-report-disappearing-drives-following-file-transfers-including-some-that-cannot-be-recovered-after-a-reboot</a><br /> SAP Vulnerabilities Exploited CVE-2025-31324, CVE-2025-42999<br /> Details explaining how to take advantage of two SAP vulnerabilities were made public<br /><a href="https://onapsis.com/blog/new-exploit-for-cve-2025-31324/" target="_blank" rel="noreferrer noopener">https://onapsis.com/blog/new-exploit-for-cve-2025-31324/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9578.mp3</guid><pubDate>Wed, 20 Aug 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67450465/9578.mp3" length="5148336" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9578" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Increased Elasticsearch Recognizance Scans
 Our honeypots noted an increase in reconnaissance scans for Elasticsearch. In particular, the endpoint /_cluster/settings is hit hard....</itunes:subtitle><itunes:summary><![CDATA[<br /> Increased Elasticsearch Recognizance Scans<br /> Our honeypots noted an increase in reconnaissance scans for Elasticsearch. In particular, the endpoint /_cluster/settings is hit hard.<br /><a href="https://isc.sans.edu/diary/Increased%20Elasticsearch%20Recognizance%20Scans/32212" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Increased%20Elasticsearch%20Recognizance%20Scans/32212</a><br /> Microsoft Patch Tuesday Issues <br /> Microsoft noted some issues deploying the most recent patches with WSUS. There are also issues with certain SSDs if larger files are transferred.<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-24h2#3635msgdesc" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-24h2#3635msgdesc</a><br /><a href="https://www.tomshardware.com/pc-components/ssds/latest-windows-11-security-patch-might-be-breaking-ssds-under-heavy-workloads-users-report-disappearing-drives-following-file-transfers-including-some-that-cannot-be-recovered-after-a-reboot" target="_blank" rel="noreferrer noopener">https://www.tomshardware.com/pc-components/ssds/latest-windows-11-security-patch-might-be-breaking-ssds-under-heavy-workloads-users-report-disappearing-drives-following-file-transfers-including-some-that-cannot-be-recovered-after-a-reboot</a><br /> SAP Vulnerabilities Exploited CVE-2025-31324, CVE-2025-42999<br /> Details explaining how to take advantage of two SAP vulnerabilities were made public<br /><a href="https://onapsis.com/blog/new-exploit-for-cve-2025-31324/" target="_blank" rel="noreferrer noopener">https://onapsis.com/blog/new-exploit-for-cve-2025-31324/</a><br />]]></itunes:summary><itunes:duration>368</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,elasticsearch,hacking,infosec,internet,it,microsoft,network,news,sap,scans,security,ssd,wsus</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9578</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, August 19th, 2025: MFA Bombing; Cisco Firewall Management Vuln; F5 Access for Android Vuln;</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-august-19th-2025-mfa-bombing-cisco-firewall-management-vuln-f5-access-for-android-vuln--67427850</link><description><![CDATA[<br /> Keeping an Eye on MFA Bombing Attacks<br /> Attackers will attempt to use authentication fatigue by  bombing  users with MFA authentication requests. Rob is talking in this diary about how to investigate these attacks in a Microsoft ecosystem.<br /><a href="https://isc.sans.edu/diary/Keeping+an+Eye+on+MFABombing+Attacks/32208" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Keeping+an+Eye+on+MFABombing+Attacks/32208</a><br /> Critical Cisco Secure Firewall Management Center Software RADIUS Remote Code Execution Vulnerability<br /> An OS command injection vulnerability may be abused to gain access to the Cisco Secure Firewall Management Center software.<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-radius-rce-TNBKf79" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-radius-rce-TNBKf79</a><br /> F5 Access for Android vulnerability<br /> An attacker with a network position that allows them to intercept network traffic may be able to read and/or modify data in transit. The attacker would need to intercept vulnerable clients specifically, since other clients would detect the man-in-the-middle (MITM) attack.<br /><a href="https://my.f5.com/manage/s/article/K000152049" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000152049</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9576.mp3</guid><pubDate>Tue, 19 Aug 2025 02:15:12 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67427850/9576.mp3" length="4350257" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9576" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Keeping an Eye on MFA Bombing Attacks
 Attackers will attempt to use authentication fatigue by  bombing  users with MFA authentication requests. Rob is talking in this diary about how to investigate these attacks in a Microsoft ecosystem....</itunes:subtitle><itunes:summary><![CDATA[<br /> Keeping an Eye on MFA Bombing Attacks<br /> Attackers will attempt to use authentication fatigue by  bombing  users with MFA authentication requests. Rob is talking in this diary about how to investigate these attacks in a Microsoft ecosystem.<br /><a href="https://isc.sans.edu/diary/Keeping+an+Eye+on+MFABombing+Attacks/32208" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Keeping+an+Eye+on+MFABombing+Attacks/32208</a><br /> Critical Cisco Secure Firewall Management Center Software RADIUS Remote Code Execution Vulnerability<br /> An OS command injection vulnerability may be abused to gain access to the Cisco Secure Firewall Management Center software.<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-radius-rce-TNBKf79" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-radius-rce-TNBKf79</a><br /> F5 Access for Android vulnerability<br /> An attacker with a network position that allows them to intercept network traffic may be able to read and/or modify data in transit. The attacker would need to intercept vulnerable clients specifically, since other clients would detect the man-in-the-middle (MITM) attack.<br /><a href="https://my.f5.com/manage/s/article/K000152049" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000152049</a><br />]]></itunes:summary><itunes:duration>311</itunes:duration><itunes:keywords>android,bombing,business,computer,cyber,cybersecurity,daily,f5,fatique,hacking,infosec,internet,it,mfa,microsoft,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9576</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, August 18th, 2025: 5G Attack Framework; Plex Vulnerability; Fortiweb Exploit; Flowise Vuln</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-august-18th-2025-5g-attack-framework-plex-vulnerability-fortiweb-exploit-flowise-vuln--67411137</link><description><![CDATA[<br /> SNI5GECT: Sniffing and Injecting 5G Traffic Without Rogue Base Stations<br /> Researchers from the Singapore University of Technology and Design released a new framework, SNI5GECT, to passively sniff and inject traffic into 5G data streams, leading to DoS, downgrade and other attacks.<br /><a href="https://isc.sans.edu/diary/SNI5GECT%3A%20Sniffing%20and%20Injecting%205G%20Traffic%20Without%20Rogue%20Base%20Stations/32202" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SNI5GECT%3A%20Sniffing%20and%20Injecting%205G%20Traffic%20Without%20Rogue%20Base%20Stations/32202</a><br /> Plex Vulnerability<br /> Plex patched a vulnerability in the Plex Media Server. Make sure you have updated to at least 1.42.1.<br /><a href="https://forums.plex.tv/t/plex-media-server-security-update/928341" target="_blank" rel="noreferrer noopener">https://forums.plex.tv/t/plex-media-server-security-update/928341</a><br /> FortiWeb Exploit Public<br /> A security researcher published details about the recent FortiWeb vulnerability, including demonstrating a PoC exploit.<br /><a href="https://www.bleepingcomputer.com/news/security/researcher-to-release-exploit-for-full-auth-bypass-on-fortiweb/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/researcher-to-release-exploit-for-full-auth-bypass-on-fortiweb/</a><br /> Flowise OS vulnerability<br /><a href="https://research.jfrog.com/vulnerabilities/flowise-os-command-remote-code-execution-jfsa-2025-001380578/" target="_blank" rel="noreferrer noopener">https://research.jfrog.com/vulnerabilities/flowise-os-command-remote-code-execution-jfsa-2025-001380578/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9574.mp3</guid><pubDate>Mon, 18 Aug 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67411137/9574.mp3" length="4805440" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9574" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 SNI5GECT: Sniffing and Injecting 5G Traffic Without Rogue Base Stations
 Researchers from the Singapore University of Technology and Design released a new framework, SNI5GECT, to passively sniff and inject traffic into 5G data streams, leading to...</itunes:subtitle><itunes:summary><![CDATA[<br /> SNI5GECT: Sniffing and Injecting 5G Traffic Without Rogue Base Stations<br /> Researchers from the Singapore University of Technology and Design released a new framework, SNI5GECT, to passively sniff and inject traffic into 5G data streams, leading to DoS, downgrade and other attacks.<br /><a href="https://isc.sans.edu/diary/SNI5GECT%3A%20Sniffing%20and%20Injecting%205G%20Traffic%20Without%20Rogue%20Base%20Stations/32202" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SNI5GECT%3A%20Sniffing%20and%20Injecting%205G%20Traffic%20Without%20Rogue%20Base%20Stations/32202</a><br /> Plex Vulnerability<br /> Plex patched a vulnerability in the Plex Media Server. Make sure you have updated to at least 1.42.1.<br /><a href="https://forums.plex.tv/t/plex-media-server-security-update/928341" target="_blank" rel="noreferrer noopener">https://forums.plex.tv/t/plex-media-server-security-update/928341</a><br /> FortiWeb Exploit Public<br /> A security researcher published details about the recent FortiWeb vulnerability, including demonstrating a PoC exploit.<br /><a href="https://www.bleepingcomputer.com/news/security/researcher-to-release-exploit-for-full-auth-bypass-on-fortiweb/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/researcher-to-release-exploit-for-full-auth-bypass-on-fortiweb/</a><br /> Flowise OS vulnerability<br /><a href="https://research.jfrog.com/vulnerabilities/flowise-os-command-remote-code-execution-jfsa-2025-001380578/" target="_blank" rel="noreferrer noopener">https://research.jfrog.com/vulnerabilities/flowise-os-command-remote-code-execution-jfsa-2025-001380578/</a><br />]]></itunes:summary><itunes:duration>343</itunes:duration><itunes:keywords>5g,business,computer,cyber,cybersecurity,daily,flowise,fortiweb,hacking,infosec,internet,it,network,news,plex,security,sni5gect</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9574</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, August 15th, 2025: Analysing Attack with AI; Proxyware via YouTube; Xerox FreeFlow Vuln; Evaluating Zero Trust @SANS_</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-august-15th-2025-analysing-attack-with-ai-proxyware-via-youtube-xerox-freeflow-vuln-evaluating-zero-trust-sans--67374800</link><description><![CDATA[<br /> AI and Faster Attack Analysis<br /> A few use cases for LLMs to speed up analysis<br /><a href="https://isc.sans.edu/diary/AI%20and%20Faster%20Attack%20Analysis%20%5BGuest%20Diary%5D/32198" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/AI%20and%20Faster%20Attack%20Analysis%20%5BGuest%20Diary%5D/32198</a><br /> Proxyware Malware Being Distributed on YouTube Video Download Site<br /> Popular YouTube download sites will attempt to infect users with proxyware.<br /><a href="https://asec.ahnlab.com/en/89574/" target="_blank" rel="noreferrer noopener">https://asec.ahnlab.com/en/89574/</a><br /> Xerox Freeflow Core Vulnerability<br /> Horizon3.ai discovered XXE Injection (CVE-2025-8355) and Path Traversal (CVE-2025-8356) vulnerabilities in Xerox FreeFlow Core, a print orchestration platform. These vulnerabilities are easily exploitable and enable unauthenticated remote attackers to achieve remote code execution on vulnerable FreeFlow Core instances. <br /><a href="https://horizon3.ai/attack-research/attack-blogs/from-support-ticket-to-zero-day/" target="_blank" rel="noreferrer noopener">https://horizon3.ai/attack-research/attack-blogs/from-support-ticket-to-zero-day/</a><br /> SANS.edu Research: Darren Carstensen Evaluating Zero Trust Network Access: A Framework for Comparative Security Testing<br /> Not all Zero Trust Network Access (ZTNA) solutions are created equal, and despite bold marketing claims, many fall short of delivering proper Zero Trust security.<br /><a href="https://www.sans.edu/cyber-research/evaluating-zero-trust-network-access-framework-comparative-security-testing/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/evaluating-zero-trust-network-access-framework-comparative-security-testing/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9572.mp3</guid><pubDate>Fri, 15 Aug 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67374800/9572.mp3" length="12771141" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9572" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 AI and Faster Attack Analysis
 A few use cases for LLMs to speed up analysis
https://isc.sans.edu/diary/AI%20and%20Faster%20Attack%20Analysis%20%5BGuest%20Diary%5D/32198
 Proxyware Malware Being Distributed on YouTube Video Download Site
 Popular...</itunes:subtitle><itunes:summary><![CDATA[<br /> AI and Faster Attack Analysis<br /> A few use cases for LLMs to speed up analysis<br /><a href="https://isc.sans.edu/diary/AI%20and%20Faster%20Attack%20Analysis%20%5BGuest%20Diary%5D/32198" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/AI%20and%20Faster%20Attack%20Analysis%20%5BGuest%20Diary%5D/32198</a><br /> Proxyware Malware Being Distributed on YouTube Video Download Site<br /> Popular YouTube download sites will attempt to infect users with proxyware.<br /><a href="https://asec.ahnlab.com/en/89574/" target="_blank" rel="noreferrer noopener">https://asec.ahnlab.com/en/89574/</a><br /> Xerox Freeflow Core Vulnerability<br /> Horizon3.ai discovered XXE Injection (CVE-2025-8355) and Path Traversal (CVE-2025-8356) vulnerabilities in Xerox FreeFlow Core, a print orchestration platform. These vulnerabilities are easily exploitable and enable unauthenticated remote attackers to achieve remote code execution on vulnerable FreeFlow Core instances. <br /><a href="https://horizon3.ai/attack-research/attack-blogs/from-support-ticket-to-zero-day/" target="_blank" rel="noreferrer noopener">https://horizon3.ai/attack-research/attack-blogs/from-support-ticket-to-zero-day/</a><br /> SANS.edu Research: Darren Carstensen Evaluating Zero Trust Network Access: A Framework for Comparative Security Testing<br /> Not all Zero Trust Network Access (ZTNA) solutions are created equal, and despite bold marketing claims, many fall short of delivering proper Zero Trust security.<br /><a href="https://www.sans.edu/cyber-research/evaluating-zero-trust-network-access-framework-comparative-security-testing/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/evaluating-zero-trust-network-access-framework-comparative-security-testing/</a><br />]]></itunes:summary><itunes:duration>912</itunes:duration><itunes:keywords>ai,analysis,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,proxyware,sans.edu,security,xerox,youtube,zero trust,ztna</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9572</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, August 14th, 2025: Equation Editor; Kerberos Patch; XZ-Utils Backdoor; ForitSIEM/FortiWeb patches</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-august-14th-2025-equation-editor-kerberos-patch-xz-utils-backdoor-foritsiem-fortiweb-patches--67362544</link><description><![CDATA[<br /> CVE-2017-11882 Will Never Die<br /> The (very) old equation editor vulnerability is still being exploited, as this recent sample analyzed by Xavier shows. The payload of the Excel file attempts to download and execute an infostealer to exfiltrate passwords via email.<br /><a href="https://isc.sans.edu/diary/CVE-2017-11882%20Will%20Never%20Die/32196" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CVE-2017-11882%20Will%20Never%20Die/32196</a><br /> Windows Kerberos Elevation of Privilege Vulnerability<br /> Yesterday, Microsoft released a patch for a vulnerability that had already been made public. This vulnerability refers to the privilege escalation taking advantage of a path traversal issue in Windows Kerberos affecting Exchange Server in hybrid mode.<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53779" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53779</a><br /> Persistent Risk: XZ Utils Backdoor Still Lurking in Docker Images<br /> Some old Debian Docker images containing the xz-utils backdoor are still available for download from Docker Hub via the official Debian account.<br /><a href="https://www.binarly.io/blog/persistent-risk-xz-utils-backdoor-still-lurking-in-docker-images" target="_blank" rel="noreferrer noopener">https://www.binarly.io/blog/persistent-risk-xz-utils-backdoor-still-lurking-in-docker-images</a><br /> FortiSIEM / FortiWeb Vulnerablities<br /> Fortinet patched already exploited vulnerabilities in FortiWeb and FortiSIEM<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-152" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-25-152</a><br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-448" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-25-448</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9570.mp3</guid><pubDate>Thu, 14 Aug 2025 02:00:12 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67362544/9570.mp3" length="6111186" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9570" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 CVE-2017-11882 Will Never Die
 The (very) old equation editor vulnerability is still being exploited, as this recent sample analyzed by Xavier shows. The payload of the Excel file attempts to download and execute an infostealer to exfiltrate...</itunes:subtitle><itunes:summary><![CDATA[<br /> CVE-2017-11882 Will Never Die<br /> The (very) old equation editor vulnerability is still being exploited, as this recent sample analyzed by Xavier shows. The payload of the Excel file attempts to download and execute an infostealer to exfiltrate passwords via email.<br /><a href="https://isc.sans.edu/diary/CVE-2017-11882%20Will%20Never%20Die/32196" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CVE-2017-11882%20Will%20Never%20Die/32196</a><br /> Windows Kerberos Elevation of Privilege Vulnerability<br /> Yesterday, Microsoft released a patch for a vulnerability that had already been made public. This vulnerability refers to the privilege escalation taking advantage of a path traversal issue in Windows Kerberos affecting Exchange Server in hybrid mode.<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53779" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53779</a><br /> Persistent Risk: XZ Utils Backdoor Still Lurking in Docker Images<br /> Some old Debian Docker images containing the xz-utils backdoor are still available for download from Docker Hub via the official Debian account.<br /><a href="https://www.binarly.io/blog/persistent-risk-xz-utils-backdoor-still-lurking-in-docker-images" target="_blank" rel="noreferrer noopener">https://www.binarly.io/blog/persistent-risk-xz-utils-backdoor-still-lurking-in-docker-images</a><br /> FortiSIEM / FortiWeb Vulnerablities<br /> Fortinet patched already exploited vulnerabilities in FortiWeb and FortiSIEM<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-152" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-25-152</a><br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-448" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-25-448</a><br />]]></itunes:summary><itunes:duration>436</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,debian,docker,equation editor,fortinet,fortisiem,fortiweb,hacking,infosec,internet,it,kerberos,network,news,security,xz-utils</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9570</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, August 13th, 2025: Microsoft Patch Tuesday; libarchive vulnerability upgrade; Adobe Patches</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-august-13th-2025-microsoft-patch-tuesday-libarchive-vulnerability-upgrade-adobe-patches--67352443</link><description><![CDATA[<br /> Microsoft Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20August%202025%20Patch%20Tuesday/32192" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20August%202025%20Patch%20Tuesday/32192</a><br /><a href="https://cymulate.com/blog/zero-click-one-ntlm-microsoft-security-patch-bypass-cve-2025-50154/" target="_blank" rel="noreferrer noopener">https://cymulate.com/blog/zero-click-one-ntlm-microsoft-security-patch-bypass-cve-2025-50154/</a><br /> libarchive Vulnerability<br /> A libarchive vulnerability patched in June was upgraded from a low CVSS score to a critical one. Libarchive is used by compression software across various operating systems, making this a difficult vulnerability to patch<br /><a href="https://www.freebsd.org/security/advisories/FreeBSD-SA-25:07.libarchive.asc" target="_blank" rel="noreferrer noopener">https://www.freebsd.org/security/advisories/FreeBSD-SA-25:07.libarchive.asc</a><br /> Adobe Patches<br /> Adobe released patches for 13 different products. <br /><a href="https://helpx.adobe.com/security/Home.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/Home.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9568.mp3</guid><pubDate>Wed, 13 Aug 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67352443/9568.mp3" length="7493526" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9568" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20August%202025%20Patch%20Tuesday/32192
https://cymulate.com/blog/zero-click-one-ntlm-microsoft-security-patch-bypass-cve-2025-50154/
 libarchive Vulnerability
 A libarchive vulnerability...</itunes:subtitle><itunes:summary><![CDATA[<br /> Microsoft Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20August%202025%20Patch%20Tuesday/32192" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20August%202025%20Patch%20Tuesday/32192</a><br /><a href="https://cymulate.com/blog/zero-click-one-ntlm-microsoft-security-patch-bypass-cve-2025-50154/" target="_blank" rel="noreferrer noopener">https://cymulate.com/blog/zero-click-one-ntlm-microsoft-security-patch-bypass-cve-2025-50154/</a><br /> libarchive Vulnerability<br /> A libarchive vulnerability patched in June was upgraded from a low CVSS score to a critical one. Libarchive is used by compression software across various operating systems, making this a difficult vulnerability to patch<br /><a href="https://www.freebsd.org/security/advisories/FreeBSD-SA-25:07.libarchive.asc" target="_blank" rel="noreferrer noopener">https://www.freebsd.org/security/advisories/FreeBSD-SA-25:07.libarchive.asc</a><br /> Adobe Patches<br /> Adobe released patches for 13 different products. <br /><a href="https://helpx.adobe.com/security/Home.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/Home.html</a><br />]]></itunes:summary><itunes:duration>535</itunes:duration><itunes:keywords>adobe,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,libarchive,microsoft,network,news,patches,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9568</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, August 12th, 2025: Erlang OTP SSH Exploits (Palo Alto Networks); Winrar Exploits; Netscaler Exploits; OpenSSH Pushin</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-august-12th-2025-erlang-otp-ssh-exploits-palo-alto-networks-winrar-exploits-netscaler-exploits-openssh-pushin--67339062</link><description><![CDATA[<br /> Erlang OTP SSH Exploits<br /> A recently patched and easily exploited vulnerability in Erlang/OTP SSH is being exploited. Palo Alto collected some of the details about this exploit activity that they observed.<br /><a href="https://unit42.paloaltonetworks.com/erlang-otp-cve-2025-32433/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/erlang-otp-cve-2025-32433/</a><br /> WinRAR Exploited<br /> WinRAR vulnerabilities are actively being exploited by a number of threat actors. The vulnerability allows for the creation of arbitrary files as the archive is extracted.<br /><a href="https://thehackernews.com/2025/08/winrar-zero-day-under-active.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2025/08/winrar-zero-day-under-active.html</a><br /> Citrix Netscaler Exploit Updates<br /> The Dutch Center for Cyber Security is updating its guidance on recent Citrix Netscaler attacks. Note that the attacks started before a patch became available, and attackers are actively hiding their tracks to make it more difficult to detect a compromise.<br /><a href="https://www.ncsc.nl/actueel/nieuws/2025/07/22/casus-citrix-kwetsbaarheid" target="_blank" rel="noreferrer noopener">https://www.ncsc.nl/actueel/nieuws/2025/07/22/casus-citrix-kwetsbaarheid</a> <a href="https://www.bleepingcomputer.com/news/security/netherlands-citrix-netscaler-flaw-cve-2025-6543-exploited-to-breach-orgs/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/netherlands-citrix-netscaler-flaw-cve-2025-6543-exploited-to-breach-orgs/</a><br /> OpenSSH Post Quantum Encryption<br /> Starting in version 10.1, OpenSSH will warn users if they are using quantum-unsafe algorithms<br /><a href="https://www.openssh.com/pq.html" target="_blank" rel="noreferrer noopener">https://www.openssh.com/pq.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9566.mp3</guid><pubDate>Tue, 12 Aug 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67339062/9566.mp3" length="5774621" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9566" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Erlang OTP SSH Exploits
 A recently patched and easily exploited vulnerability in Erlang/OTP SSH is being exploited. Palo Alto collected some of the details about this exploit activity that they observed....</itunes:subtitle><itunes:summary><![CDATA[<br /> Erlang OTP SSH Exploits<br /> A recently patched and easily exploited vulnerability in Erlang/OTP SSH is being exploited. Palo Alto collected some of the details about this exploit activity that they observed.<br /><a href="https://unit42.paloaltonetworks.com/erlang-otp-cve-2025-32433/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/erlang-otp-cve-2025-32433/</a><br /> WinRAR Exploited<br /> WinRAR vulnerabilities are actively being exploited by a number of threat actors. The vulnerability allows for the creation of arbitrary files as the archive is extracted.<br /><a href="https://thehackernews.com/2025/08/winrar-zero-day-under-active.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2025/08/winrar-zero-day-under-active.html</a><br /> Citrix Netscaler Exploit Updates<br /> The Dutch Center for Cyber Security is updating its guidance on recent Citrix Netscaler attacks. Note that the attacks started before a patch became available, and attackers are actively hiding their tracks to make it more difficult to detect a compromise.<br /><a href="https://www.ncsc.nl/actueel/nieuws/2025/07/22/casus-citrix-kwetsbaarheid" target="_blank" rel="noreferrer noopener">https://www.ncsc.nl/actueel/nieuws/2025/07/22/casus-citrix-kwetsbaarheid</a> <a href="https://www.bleepingcomputer.com/news/security/netherlands-citrix-netscaler-flaw-cve-2025-6543-exploited-to-breach-orgs/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/netherlands-citrix-netscaler-flaw-cve-2025-6543-exploited-to-breach-orgs/</a><br /> OpenSSH Post Quantum Encryption<br /> Starting in version 10.1, OpenSSH will warn users if they are using quantum-unsafe algorithms<br /><a href="https://www.openssh.com/pq.html" target="_blank" rel="noreferrer noopener">https://www.openssh.com/pq.html</a><br />]]></itunes:summary><itunes:duration>412</itunes:duration><itunes:keywords>business,citirx,computer,cyber,cybersecurity,daily,erlang,hacking,infosec,internet,it,netscaler,network,news,openssh,otp,security,ssh,winrar</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9566</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, August 11th, 2025: Fake Tesla Preorders; Bad USB Cameras; Win-DoS Epidemic</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-august-11th-2025-fake-tesla-preorders-bad-usb-cameras-win-dos-epidemic--67326177</link><description><![CDATA[<br /> Google Paid Ads for Fake Tesla Websites<br /> Someone is setting up fake Tesla lookalike websites that attempt to collect credit card data from unsuspecting users trying to preorder Tesla products.<br /><a href="https://isc.sans.edu/diary/Google%20Paid%20Ads%20for%20Fake%20Tesla%20Websites/32186" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Google%20Paid%20Ads%20for%20Fake%20Tesla%20Websites/32186</a><br /> Compromising USB Devices for Persistent Stealthy Access<br /> USB devices, like Linux-based web cams, can be compromised to emulate malicious USB devices like keyboards that inject malicious commands.<br /><a href="https://eclypsium.com/blog/badcam-now-weaponizing-linux-webcams/" target="_blank" rel="noreferrer noopener">https://eclypsium.com/blog/badcam-now-weaponizing-linux-webcams/</a><br /> Win-DoS Epidemic: A crash course in abusing RPC for Win-DoS &amp; Win-DDoS<br /> Internet-exposed DCs can be used in very powerful DoS attacks.<br /><a href="https://defcon.org/html/defcon-33/dc-33-speakers.html#content_60389" target="_blank" rel="noreferrer noopener">https://defcon.org/html/defcon-33/dc-33-speakers.html#content_60389</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9564.mp3</guid><pubDate>Mon, 11 Aug 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67326177/9564.mp3" length="5976972" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9564" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Google Paid Ads for Fake Tesla Websites
 Someone is setting up fake Tesla lookalike websites that attempt to collect credit card data from unsuspecting users trying to preorder Tesla products....</itunes:subtitle><itunes:summary><![CDATA[<br /> Google Paid Ads for Fake Tesla Websites<br /> Someone is setting up fake Tesla lookalike websites that attempt to collect credit card data from unsuspecting users trying to preorder Tesla products.<br /><a href="https://isc.sans.edu/diary/Google%20Paid%20Ads%20for%20Fake%20Tesla%20Websites/32186" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Google%20Paid%20Ads%20for%20Fake%20Tesla%20Websites/32186</a><br /> Compromising USB Devices for Persistent Stealthy Access<br /> USB devices, like Linux-based web cams, can be compromised to emulate malicious USB devices like keyboards that inject malicious commands.<br /><a href="https://eclypsium.com/blog/badcam-now-weaponizing-linux-webcams/" target="_blank" rel="noreferrer noopener">https://eclypsium.com/blog/badcam-now-weaponizing-linux-webcams/</a><br /> Win-DoS Epidemic: A crash course in abusing RPC for Win-DoS &amp; Win-DDoS<br /> Internet-exposed DCs can be used in very powerful DoS attacks.<br /><a href="https://defcon.org/html/defcon-33/dc-33-speakers.html#content_60389" target="_blank" rel="noreferrer noopener">https://defcon.org/html/defcon-33/dc-33-speakers.html#content_60389</a><br />]]></itunes:summary><itunes:duration>427</itunes:duration><itunes:keywords>badcam,business,cyber,cybersecurity,daily,dc,dos,google,hacking,infosec,it,ldap,linux,network,news,optimus,rpc,tesla,usb,windows</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9564</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, August 8th, 2025:: ASN43350 Mass Scans; HTTP1.1 Must Die; Hyprid Exchange Vuln; Sonicwall Update; SANS.edu Research:</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-august-8th-2025-asn43350-mass-scans-http1-1-must-die-hyprid-exchange-vuln-sonicwall-update-sans-edu-research--67296897</link><description><![CDATA[<br /> Mass Internet Scanning from ASN 43350<br /> Our undergraduate intern Duncan Woosley wrote up aggressive scans from ASN 43350<br /><a href="https://isc.sans.edu/diary/Mass+Internet+Scanning+from+ASN+43350+Guest+Diary/32180/#comments" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Mass+Internet+Scanning+from+ASN+43350+Guest+Diary/32180/#comments</a><br /> HTTP/1.1 Desync Attacks<br /> Portswigger released details about new types of HTTP/1.1 desync attacks it uncovered. These attacks are particularly critical for organizations using middleboxes to translate from HTTP/2 to HTTP/1.1<br /><a href="https://portswigger.net/research/http1-must-die" target="_blank" rel="noreferrer noopener">https://portswigger.net/research/http1-must-die</a><br /> Microsoft Warns of Exchange Server Vulnerability<br /> An attacker with admin access to an Exchange Server in a hybrid configuration can use this vulnerability to gain full domain access. The issue is mitigated by an April hotfix, but was not noted in the release of the April Hotfix.<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53786" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53786</a><br /> Sonicwall Update<br /> Sonicwall no longer believes that a new vulnerability was used in recent compromises<br /><a href="https://www.sonicwall.com/support/notices/gen-7-and-newer-sonicwall-firewalls-sslvpn-recent-threat-activity/250804095336430" target="_blank" rel="noreferrer noopener">https://www.sonicwall.com/support/notices/gen-7-and-newer-sonicwall-firewalls-sslvpn-recent-threat-activity/250804095336430</a><br /> SANS.edu Research: Wellington Rampazo, Shift Left the Awareness and Detection of Developers Using Vulnerable Open-Source Software Components<br /><a href="https://www.sans.edu/cyber-research/shift-left-awareness-detection-developers-using-vulnerable-open-source-software-components/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/shift-left-awareness-detection-developers-using-vulnerable-open-source-software-components/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9562.mp3</guid><pubDate>Fri, 08 Aug 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67296897/9562.mp3" length="20152665" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9562" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Mass Internet Scanning from ASN 43350
 Our undergraduate intern Duncan Woosley wrote up aggressive scans from ASN 43350
https://isc.sans.edu/diary/Mass+Internet+Scanning+from+ASN+43350+Guest+Diary/32180/#comments
 HTTP/1.1 Desync Attacks...</itunes:subtitle><itunes:summary><![CDATA[<br /> Mass Internet Scanning from ASN 43350<br /> Our undergraduate intern Duncan Woosley wrote up aggressive scans from ASN 43350<br /><a href="https://isc.sans.edu/diary/Mass+Internet+Scanning+from+ASN+43350+Guest+Diary/32180/#comments" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Mass+Internet+Scanning+from+ASN+43350+Guest+Diary/32180/#comments</a><br /> HTTP/1.1 Desync Attacks<br /> Portswigger released details about new types of HTTP/1.1 desync attacks it uncovered. These attacks are particularly critical for organizations using middleboxes to translate from HTTP/2 to HTTP/1.1<br /><a href="https://portswigger.net/research/http1-must-die" target="_blank" rel="noreferrer noopener">https://portswigger.net/research/http1-must-die</a><br /> Microsoft Warns of Exchange Server Vulnerability<br /> An attacker with admin access to an Exchange Server in a hybrid configuration can use this vulnerability to gain full domain access. The issue is mitigated by an April hotfix, but was not noted in the release of the April Hotfix.<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53786" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53786</a><br /> Sonicwall Update<br /> Sonicwall no longer believes that a new vulnerability was used in recent compromises<br /><a href="https://www.sonicwall.com/support/notices/gen-7-and-newer-sonicwall-firewalls-sslvpn-recent-threat-activity/250804095336430" target="_blank" rel="noreferrer noopener">https://www.sonicwall.com/support/notices/gen-7-and-newer-sonicwall-firewalls-sslvpn-recent-threat-activity/250804095336430</a><br /> SANS.edu Research: Wellington Rampazo, Shift Left the Awareness and Detection of Developers Using Vulnerable Open-Source Software Components<br /><a href="https://www.sans.edu/cyber-research/shift-left-awareness-detection-developers-using-vulnerable-open-source-software-components/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/shift-left-awareness-detection-developers-using-vulnerable-open-source-software-components/</a><br />]]></itunes:summary><itunes:duration>1439</itunes:duration><itunes:keywords>asn 43350,business,cyber,cybersecurity,daily,exchange,hacking,http/1.1,http/2,http request smuggeling,infosec,it,network,news,rampazo,research,sans.edu,shiftin left,sonicwall,wellington</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9562</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, August 7th, 2025: Sextortion Update; Adobe and Trend Micro release emergency patches</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-august-7th-2025-sextortion-update-adobe-and-trend-micro-release-emergency-patches--67280405</link><description><![CDATA[<br /> Do Sextortion Scams Still Work in 2025?<br /> Jan looked at recent sextortion emails to check if any of the crypto addresses in these emails received deposits. Sadly, some did, so these scams still work.<br /><a href="https://isc.sans.edu/diary/Do%20sextortion%20scams%20still%20work%20in%202025%3F/32178" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Do%20sextortion%20scams%20still%20work%20in%202025%3F/32178</a><br /> Akira Ransomware Group s use of Drivers<br /> Guidepoint Security observed the Akira ransomware group using specific legitimate drivers for privilege escalation<br /><a href="https://www.guidepointsecurity.com/blog/gritrep-akira-sonicwall/" target="_blank" rel="noreferrer noopener">https://www.guidepointsecurity.com/blog/gritrep-akira-sonicwall/</a><br /> Adobe Patches Critical Experience Manager Vulnerability<br /> Adobe released emergency patches for a vulnerability in Adobe Experience Manager after a PoC exploit was made public.<br /><a href="https://slcyber.io/assetnote-security-research-center/struts-devmode-in-2025-critical-pre-auth-vulnerabilities-in-adobe-experience-manager-forms/" target="_blank" rel="noreferrer noopener">https://slcyber.io/assetnote-security-research-center/struts-devmode-in-2025-critical-pre-auth-vulnerabilities-in-adobe-experience-manager-forms/</a><br /><a href="https://helpx.adobe.com/security/products/aem-forms/apsb25-82.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/products/aem-forms/apsb25-82.html</a><br /> Trend Micro Apex One Vulnerability<br /> Trend Micro released an emergency patch for an actively exploited pre-authentication remote code execution vulnerability in the Apex One management console.<br /><a href="https://success.trendmicro.com/en-US/solution/KA-0020652" target="_blank" rel="noreferrer noopener">https://success.trendmicro.com/en-US/solution/KA-0020652</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9560.mp3</guid><pubDate>Thu, 07 Aug 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67280405/9560.mp3" length="4294637" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9560" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Do Sextortion Scams Still Work in 2025?
 Jan looked at recent sextortion emails to check if any of the crypto addresses in these emails received deposits. Sadly, some did, so these scams still work....</itunes:subtitle><itunes:summary><![CDATA[<br /> Do Sextortion Scams Still Work in 2025?<br /> Jan looked at recent sextortion emails to check if any of the crypto addresses in these emails received deposits. Sadly, some did, so these scams still work.<br /><a href="https://isc.sans.edu/diary/Do%20sextortion%20scams%20still%20work%20in%202025%3F/32178" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Do%20sextortion%20scams%20still%20work%20in%202025%3F/32178</a><br /> Akira Ransomware Group s use of Drivers<br /> Guidepoint Security observed the Akira ransomware group using specific legitimate drivers for privilege escalation<br /><a href="https://www.guidepointsecurity.com/blog/gritrep-akira-sonicwall/" target="_blank" rel="noreferrer noopener">https://www.guidepointsecurity.com/blog/gritrep-akira-sonicwall/</a><br /> Adobe Patches Critical Experience Manager Vulnerability<br /> Adobe released emergency patches for a vulnerability in Adobe Experience Manager after a PoC exploit was made public.<br /><a href="https://slcyber.io/assetnote-security-research-center/struts-devmode-in-2025-critical-pre-auth-vulnerabilities-in-adobe-experience-manager-forms/" target="_blank" rel="noreferrer noopener">https://slcyber.io/assetnote-security-research-center/struts-devmode-in-2025-critical-pre-auth-vulnerabilities-in-adobe-experience-manager-forms/</a><br /><a href="https://helpx.adobe.com/security/products/aem-forms/apsb25-82.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/products/aem-forms/apsb25-82.html</a><br /> Trend Micro Apex One Vulnerability<br /> Trend Micro released an emergency patch for an actively exploited pre-authentication remote code execution vulnerability in the Apex One management console.<br /><a href="https://success.trendmicro.com/en-US/solution/KA-0020652" target="_blank" rel="noreferrer noopener">https://success.trendmicro.com/en-US/solution/KA-0020652</a><br />]]></itunes:summary><itunes:duration>307</itunes:duration><itunes:keywords>adobe,akira,apex one,business,computer,cyber,cybersecurity,daily,driver,experience manager,hacking,infosec,internet,it,network,news,ransomware,security,sextortion,trend micro</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9560</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, August 6th, 2025: Machinekeys and VIEWSTATEs; Perplexity Unethical Learning; SonicWall Updates</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-august-6th-2025-machinekeys-and-viewstates-perplexity-unethical-learning-sonicwall-updates--67265584</link><description><![CDATA[<br /> Stealing Machinekeys for fun and profit (or riding the SharePoint wave)<br /> Bojan explains in detail how .NET uses Machine Keys to protect the VIEWSTATE, and how to abuse the VIEWSTATE for code execution if the Machine Keys are lost.<br /><a href="https://isc.sans.edu/diary/Stealing%20Machine%20Keys%20for%20fun%20and%20profit%20%28or%20riding%20the%20SharePoint%20wave%29/32174" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Stealing%20Machine%20Keys%20for%20fun%20and%20profit%20%28or%20riding%20the%20SharePoint%20wave%29/32174</a><br /> Perplexity is using stealth, undeclared crawlers to evade website no-crawl directives<br /> Perplexity will change its User Agent, or use different originating IP addresses, if it detects being blocked from scanning websites<br /><a href="https://blog.cloudflare.com/perplexity-is-using-stealth-undeclared-crawlers-to-evade-website-no-crawl-directives/" target="_blank" rel="noreferrer noopener">https://blog.cloudflare.com/perplexity-is-using-stealth-undeclared-crawlers-to-evade-website-no-crawl-directives/</a><br /> Gen 7 SonicWall Firewalls   SSLVPN Recent Threat Activity<br /> Over the past 72 hours, there has been a notable increase in both internally and externally reported cyber incidents involving Gen 7 SonicWall firewalls where SSLVPN is enabled. <br /><a href="https://www.sonicwall.com/support/notices/gen-7-sonicwall-firewalls-sslvpn-recent-threat-activity/250804095336430" target="_blank" rel="noreferrer noopener">https://www.sonicwall.com/support/notices/gen-7-sonicwall-firewalls-sslvpn-recent-threat-activity/250804095336430</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9558.mp3</guid><pubDate>Wed, 06 Aug 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67265584/9558.mp3" length="6461384" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9558" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Stealing Machinekeys for fun and profit (or riding the SharePoint wave)
 Bojan explains in detail how .NET uses Machine Keys to protect the VIEWSTATE, and how to abuse the VIEWSTATE for code execution if the Machine Keys are lost....</itunes:subtitle><itunes:summary><![CDATA[<br /> Stealing Machinekeys for fun and profit (or riding the SharePoint wave)<br /> Bojan explains in detail how .NET uses Machine Keys to protect the VIEWSTATE, and how to abuse the VIEWSTATE for code execution if the Machine Keys are lost.<br /><a href="https://isc.sans.edu/diary/Stealing%20Machine%20Keys%20for%20fun%20and%20profit%20%28or%20riding%20the%20SharePoint%20wave%29/32174" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Stealing%20Machine%20Keys%20for%20fun%20and%20profit%20%28or%20riding%20the%20SharePoint%20wave%29/32174</a><br /> Perplexity is using stealth, undeclared crawlers to evade website no-crawl directives<br /> Perplexity will change its User Agent, or use different originating IP addresses, if it detects being blocked from scanning websites<br /><a href="https://blog.cloudflare.com/perplexity-is-using-stealth-undeclared-crawlers-to-evade-website-no-crawl-directives/" target="_blank" rel="noreferrer noopener">https://blog.cloudflare.com/perplexity-is-using-stealth-undeclared-crawlers-to-evade-website-no-crawl-directives/</a><br /> Gen 7 SonicWall Firewalls   SSLVPN Recent Threat Activity<br /> Over the past 72 hours, there has been a notable increase in both internally and externally reported cyber incidents involving Gen 7 SonicWall firewalls where SSLVPN is enabled. <br /><a href="https://www.sonicwall.com/support/notices/gen-7-sonicwall-firewalls-sslvpn-recent-threat-activity/250804095336430" target="_blank" rel="noreferrer noopener">https://www.sonicwall.com/support/notices/gen-7-sonicwall-firewalls-sslvpn-recent-threat-activity/250804095336430</a><br />]]></itunes:summary><itunes:duration>462</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,machinekeys,network,news,perplexity,security,sonicall,viewstate</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9558</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, August 05, 2025: Daily Trends Report; NVidia Triton RCE; Cursor AI Misconfiguration</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-august-05-2025-daily-trends-report-nvidia-triton-rce-cursor-ai-misconfiguration--67253647</link><description><![CDATA[<br /> Daily Trends Report<br /> A new trends report will bring you daily data highlights via e-mail.<br /><a href="https://isc.sans.edu/diary/New%20Feature%3A%20Daily%20Trends%20Report/32170" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/New%20Feature%3A%20Daily%20Trends%20Report/32170</a><br /> NVidia Triton RCE<br /> Wiz found an interesting information leakage vulnerability in NVidia s Triton servers that can be leveraged to remote code execution.<br /><a href="https://www.wiz.io/blog/nvidia-triton-cve-2025-23319-vuln-chain-to-ai-server" target="_blank" rel="noreferrer noopener">https://www.wiz.io/blog/nvidia-triton-cve-2025-23319-vuln-chain-to-ai-server</a><br /> Cursor AI MCP Vulnerability<br /> An attacker could abuse negligent Cursor MCP configurations to implement backdoors into developer machines.<br /><a href="https://www.aim.security/lp/aim-labs-curxecute-blogpost" target="_blank" rel="noreferrer noopener">https://www.aim.security/lp/aim-labs-curxecute-blogpost</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9556.mp3</guid><pubDate>Tue, 05 Aug 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67253647/9556.mp3" length="5713737" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9556" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Daily Trends Report
 A new trends report will bring you daily data highlights via e-mail.
https://isc.sans.edu/diary/New%20Feature%3A%20Daily%20Trends%20Report/32170
 NVidia Triton RCE
 Wiz found an interesting information leakage vulnerability in...</itunes:subtitle><itunes:summary><![CDATA[<br /> Daily Trends Report<br /> A new trends report will bring you daily data highlights via e-mail.<br /><a href="https://isc.sans.edu/diary/New%20Feature%3A%20Daily%20Trends%20Report/32170" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/New%20Feature%3A%20Daily%20Trends%20Report/32170</a><br /> NVidia Triton RCE<br /> Wiz found an interesting information leakage vulnerability in NVidia s Triton servers that can be leveraged to remote code execution.<br /><a href="https://www.wiz.io/blog/nvidia-triton-cve-2025-23319-vuln-chain-to-ai-server" target="_blank" rel="noreferrer noopener">https://www.wiz.io/blog/nvidia-triton-cve-2025-23319-vuln-chain-to-ai-server</a><br /> Cursor AI MCP Vulnerability<br /> An attacker could abuse negligent Cursor MCP configurations to implement backdoors into developer machines.<br /><a href="https://www.aim.security/lp/aim-labs-curxecute-blogpost" target="_blank" rel="noreferrer noopener">https://www.aim.security/lp/aim-labs-curxecute-blogpost</a><br />]]></itunes:summary><itunes:duration>408</itunes:duration><itunes:keywords>business,computer,cursor,cyber,cybersecurity,daily,hacking,infosec,internet,it,mcp,network,news,nvidia,rce,security,trends,triton</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9556</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, August 4th, 2025: Legacy Protocols; Sonicwall SSL VPN Possible 0-Day;</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-august-4th-2025-legacy-protocols-sonicwall-ssl-vpn-possible-0-day--67241489</link><description><![CDATA[<br /> Scans for pop3user with guessable password<br /> A particular IP assigned to a network that calls itself  Unmanaged  has been scanning telnet/ssh for a user called  pop3user  with passwords  pop3user  or  123456 . I assume they are looking for legacy systems that either currently run pop3 or ran pop3 in the past, and left the user enabled.<br /><a href="https://isc.sans.edu/diary/Legacy%20May%20Kill/32166" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Legacy%20May%20Kill/32166</a><br /> Possible Sonicwall SSL VPN 0-Day<br /> Arcticwolf observed compromised Sonicwall SSL VPN devices used by the Akira group to install ransomware. These devices were fully patched, and credentials were recently rotated. <br /><a href="https://arcticwolf.com/resources/blog/arctic-wolf-observes-july-2025-uptick-in-akira-ransomware-activity-targeting-sonicwall-ssl-vpn/" target="_blank" rel="noreferrer noopener">https://arcticwolf.com/resources/blog/arctic-wolf-observes-july-2025-uptick-in-akira-ransomware-activity-targeting-sonicwall-ssl-vpn/</a><br /> PAM Based Linux Backdoor<br /> For over a year, attackers have used a PAM-based Linux backdoor that so far has gotten little attention from anti-malware vendors. PAM-based backdoors can be stealthy, and this one in particular includes various anti-forensics tricks.<br /><a href="https://www.nextron-systems.com/2025/08/01/plague-a-newly-discovered-pam-based-backdoor-for-linux/" target="_blank" rel="noreferrer noopener">https://www.nextron-systems.com/2025/08/01/plague-a-newly-discovered-pam-based-backdoor-for-linux/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9554.mp3</guid><pubDate>Mon, 04 Aug 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67241489/9554.mp3" length="4445873" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9554" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Scans for pop3user with guessable password
 A particular IP assigned to a network that calls itself  Unmanaged  has been scanning telnet/ssh for a user called  pop3user  with passwords  pop3user  or  123456 . I assume they are looking for legacy...</itunes:subtitle><itunes:summary><![CDATA[<br /> Scans for pop3user with guessable password<br /> A particular IP assigned to a network that calls itself  Unmanaged  has been scanning telnet/ssh for a user called  pop3user  with passwords  pop3user  or  123456 . I assume they are looking for legacy systems that either currently run pop3 or ran pop3 in the past, and left the user enabled.<br /><a href="https://isc.sans.edu/diary/Legacy%20May%20Kill/32166" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Legacy%20May%20Kill/32166</a><br /> Possible Sonicwall SSL VPN 0-Day<br /> Arcticwolf observed compromised Sonicwall SSL VPN devices used by the Akira group to install ransomware. These devices were fully patched, and credentials were recently rotated. <br /><a href="https://arcticwolf.com/resources/blog/arctic-wolf-observes-july-2025-uptick-in-akira-ransomware-activity-targeting-sonicwall-ssl-vpn/" target="_blank" rel="noreferrer noopener">https://arcticwolf.com/resources/blog/arctic-wolf-observes-july-2025-uptick-in-akira-ransomware-activity-targeting-sonicwall-ssl-vpn/</a><br /> PAM Based Linux Backdoor<br /> For over a year, attackers have used a PAM-based Linux backdoor that so far has gotten little attention from anti-malware vendors. PAM-based backdoors can be stealthy, and this one in particular includes various anti-forensics tricks.<br /><a href="https://www.nextron-systems.com/2025/08/01/plague-a-newly-discovered-pam-based-backdoor-for-linux/" target="_blank" rel="noreferrer noopener">https://www.nextron-systems.com/2025/08/01/plague-a-newly-discovered-pam-based-backdoor-for-linux/</a><br />]]></itunes:summary><itunes:duration>318</itunes:duration><itunes:keywords>backdoor,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,legacy,linux,network,news,pam,security,sonicwall</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9554</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, August 1st, 2025: Scattered Spider Domains; Excel Blocking Dangerous Links; CISA Releasing Thorium Platform</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-august-1st-2025-scattered-spider-domains-excel-blocking-dangerous-links-cisa-releasing-thorium-platform--67211611</link><description><![CDATA[<br /> Scattered Spider Related Domain Names<br /> A quick demo of our domain feeds and how they can be used to find Scattered Spider related domains<br /><a href="https://isc.sans.edu/diary/Scattered+Spider+Related+Domain+Names/32162" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scattered+Spider+Related+Domain+Names/32162</a><br /> Excel External Workbook Links to Blocked File Types Will Be Disabled by Default<br /> Excel will discontinue allowing links to dangerous file types starting as early as October.<br /><a href="https://support.microsoft.com/en-us/topic/external-workbook-links-to-blocked-file-types-will-be-disabled-by-default-6dd12903-0592-463d-9e68-0741cf62ee58" target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-us/topic/external-workbook-links-to-blocked-file-types-will-be-disabled-by-default-6dd12903-0592-463d-9e68-0741cf62ee58</a><br /> CISA Releases Thorium<br /> CISA announced that it released its malware analysis platform, Thorium, as open-source software.<br /><a href="https://www.cisa.gov/news-events/alerts/2025/07/31/thorium-platform-public-availability" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2025/07/31/thorium-platform-public-availability</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9552.mp3</guid><pubDate>Fri, 01 Aug 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67211611/9552.mp3" length="4781953" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9552" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Scattered Spider Related Domain Names
 A quick demo of our domain feeds and how they can be used to find Scattered Spider related domains
https://isc.sans.edu/diary/Scattered+Spider+Related+Domain+Names/32162
 Excel External Workbook Links to...</itunes:subtitle><itunes:summary><![CDATA[<br /> Scattered Spider Related Domain Names<br /> A quick demo of our domain feeds and how they can be used to find Scattered Spider related domains<br /><a href="https://isc.sans.edu/diary/Scattered+Spider+Related+Domain+Names/32162" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scattered+Spider+Related+Domain+Names/32162</a><br /> Excel External Workbook Links to Blocked File Types Will Be Disabled by Default<br /> Excel will discontinue allowing links to dangerous file types starting as early as October.<br /><a href="https://support.microsoft.com/en-us/topic/external-workbook-links-to-blocked-file-types-will-be-disabled-by-default-6dd12903-0592-463d-9e68-0741cf62ee58" target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-us/topic/external-workbook-links-to-blocked-file-types-will-be-disabled-by-default-6dd12903-0592-463d-9e68-0741cf62ee58</a><br /> CISA Releases Thorium<br /> CISA announced that it released its malware analysis platform, Thorium, as open-source software.<br /><a href="https://www.cisa.gov/news-events/alerts/2025/07/31/thorium-platform-public-availability" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2025/07/31/thorium-platform-public-availability</a><br />]]></itunes:summary><itunes:duration>342</itunes:duration><itunes:keywords>business,cisa,computer,cyber,cybersecurity,daily,excel,hacking,infosec,internet,it,network,news,scattered spider,security,thorium</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9552</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday July 31st, 2025: Firebase Security; WebKit Vuln Exploited; Scattered Spider Update</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-july-31st-2025-firebase-security-webkit-vuln-exploited-scattered-spider-update--67196368</link><description><![CDATA[<br />  Securing Firebase: Lessons Re-Learned from the Tea Breach<br /> Inspried by the breach of the Tea app, Brendon Evans recorded a video to inform of Firebase security issues<br /><a href="https://isc.sans.edu/diary/Securing%20Firebase%3A%20Lessons%20Re-Learned%20from%20the%20Tea%20Breach/32158" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Securing%20Firebase%3A%20Lessons%20Re-Learned%20from%20the%20Tea%20Breach/32158</a><br /> WebKit Vulnerability Exploited before Apple Patch<br /> A WebKit vulnerablity patched by Apple yesterday has already been exploited in Google Chrome. Google noted the exploit with its patch for the same vulnerability in Chrome.<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6558" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2025-6558</a><br /> Scattered Spider Update<br /> CISA released an update for its report on Scattered Spider, noting that the group also calls helpdesks impersonating users, not just the other way around.<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9550.mp3</guid><pubDate>Thu, 31 Jul 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67196368/9550.mp3" length="5605666" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9550" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
  Securing Firebase: Lessons Re-Learned from the Tea Breach
 Inspried by the breach of the Tea app, Brendon Evans recorded a video to inform of Firebase security issues...</itunes:subtitle><itunes:summary><![CDATA[<br />  Securing Firebase: Lessons Re-Learned from the Tea Breach<br /> Inspried by the breach of the Tea app, Brendon Evans recorded a video to inform of Firebase security issues<br /><a href="https://isc.sans.edu/diary/Securing%20Firebase%3A%20Lessons%20Re-Learned%20from%20the%20Tea%20Breach/32158" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Securing%20Firebase%3A%20Lessons%20Re-Learned%20from%20the%20Tea%20Breach/32158</a><br /> WebKit Vulnerability Exploited before Apple Patch<br /> A WebKit vulnerablity patched by Apple yesterday has already been exploited in Google Chrome. Google noted the exploit with its patch for the same vulnerability in Chrome.<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6558" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2025-6558</a><br /> Scattered Spider Update<br /> CISA released an update for its report on Scattered Spider, noting that the group also calls helpdesks impersonating users, not just the other way around.<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a</a><br />]]></itunes:summary><itunes:duration>400</itunes:duration><itunes:keywords>business,chrome,chromium,computer,cyber,cybersecurity,daily,exploit,firebase,hacking,infosec,internet,it,network,news,scattered spider,security,tea,webkit</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9550</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday July 30th, 2025: Apple Updates; Python Triage; Papercut Vuln Exploited</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-july-30th-2025-apple-updates-python-triage-papercut-vuln-exploited--67184308</link><description><![CDATA[<br /> Apple Updates Everything: July 2025 Edition<br /> Apple released updates for all of its operating systems patching 89 different vulnerabilities. Many vulnerabilities apply to multiple operating systems.<br /><a href="https://isc.sans.edu/diary/Apple%20Updates%20Everything%3A%20July%202025/32154" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Updates%20Everything%3A%20July%202025/32154</a><br /> Python Triage<br /> A quick python script by Xavier to efficiently search through files, even compressed once, for indicators of compromise.<br /><a href="https://isc.sans.edu/diary/Triage+is+Key+Python+to+the+Rescue/32152/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Triage+is+Key+Python+to+the+Rescue/32152/</a><br /> PaperCut Attacks<br /> CISA added a 2024 Papercut vulnerability to the known exploited vulnerability list.<br /><a href="https://www.cisa.gov/news-events/alerts/2025/07/28/cisa-adds-three-known-exploited-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2025/07/28/cisa-adds-three-known-exploited-vulnerabilities-catalog</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9548.mp3</guid><pubDate>Wed, 30 Jul 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67184308/9548.mp3" length="5661748" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9548" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Apple Updates Everything: July 2025 Edition
 Apple released updates for all of its operating systems patching 89 different vulnerabilities. Many vulnerabilities apply to multiple operating systems....</itunes:subtitle><itunes:summary><![CDATA[<br /> Apple Updates Everything: July 2025 Edition<br /> Apple released updates for all of its operating systems patching 89 different vulnerabilities. Many vulnerabilities apply to multiple operating systems.<br /><a href="https://isc.sans.edu/diary/Apple%20Updates%20Everything%3A%20July%202025/32154" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Updates%20Everything%3A%20July%202025/32154</a><br /> Python Triage<br /> A quick python script by Xavier to efficiently search through files, even compressed once, for indicators of compromise.<br /><a href="https://isc.sans.edu/diary/Triage+is+Key+Python+to+the+Rescue/32152/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Triage+is+Key+Python+to+the+Rescue/32152/</a><br /> PaperCut Attacks<br /> CISA added a 2024 Papercut vulnerability to the known exploited vulnerability list.<br /><a href="https://www.cisa.gov/news-events/alerts/2025/07/28/cisa-adds-three-known-exploited-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2025/07/28/cisa-adds-three-known-exploited-vulnerabilities-catalog</a><br />]]></itunes:summary><itunes:duration>405</itunes:duration><itunes:keywords>apple,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,papercut,patches,python,security,triage</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9548</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, July 29th, 2025:Parasitic Exploits; Cisco ISE Exploit; MyASUS Vuln</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-july-29th-2025-parasitic-exploits-cisco-ise-exploit-myasus-vuln--67166897</link><description><![CDATA[<br /> Parasitic SharePoint Exploits<br /> We are seeing attacks against SharePoint itself and attempts to exploit backdoors left behind by attackers.<br /><a href="https://isc.sans.edu/diary/Parasitic%20Sharepoint%20Exploits/32148" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Parasitic%20Sharepoint%20Exploits/32148</a><br /> Cisco ISE Vulnerability Exploited<br /> A recently patched vulnerability in Cisco ISE is now being exploited. The Zero Day Initiative has released a blog detailing the exploit chain to obtain code execution as an unauthenticated user.<br /><a href="https://www.zerodayinitiative.com/blog/2025/7/24/cve-2025-20281-cisco-ise-api-unauthenticated-remote-code-execution-vulnerability" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/blog/2025/7/24/cve-2025-20281-cisco-ise-api-unauthenticated-remote-code-execution-vulnerability</a><br /> MyAsus Vulnerablity<br /> The  MyAsus  tool does not store its access tokens correctly, potentially providing an attacker with access to sensitive functions<br /><a href="https://www.asus.com/content/security-advisory/" target="_blank" rel="noreferrer noopener">https://www.asus.com/content/security-advisory/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9546.mp3</guid><pubDate>Tue, 29 Jul 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67166897/9546.mp3" length="4692169" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9546" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Parasitic SharePoint Exploits
 We are seeing attacks against SharePoint itself and attempts to exploit backdoors left behind by attackers.
https://isc.sans.edu/diary/Parasitic%20Sharepoint%20Exploits/32148
 Cisco ISE Vulnerability Exploited
 A...</itunes:subtitle><itunes:summary><![CDATA[<br /> Parasitic SharePoint Exploits<br /> We are seeing attacks against SharePoint itself and attempts to exploit backdoors left behind by attackers.<br /><a href="https://isc.sans.edu/diary/Parasitic%20Sharepoint%20Exploits/32148" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Parasitic%20Sharepoint%20Exploits/32148</a><br /> Cisco ISE Vulnerability Exploited<br /> A recently patched vulnerability in Cisco ISE is now being exploited. The Zero Day Initiative has released a blog detailing the exploit chain to obtain code execution as an unauthenticated user.<br /><a href="https://www.zerodayinitiative.com/blog/2025/7/24/cve-2025-20281-cisco-ise-api-unauthenticated-remote-code-execution-vulnerability" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/blog/2025/7/24/cve-2025-20281-cisco-ise-api-unauthenticated-remote-code-execution-vulnerability</a><br /> MyAsus Vulnerablity<br /> The  MyAsus  tool does not store its access tokens correctly, potentially providing an attacker with access to sensitive functions<br /><a href="https://www.asus.com/content/security-advisory/" target="_blank" rel="noreferrer noopener">https://www.asus.com/content/security-advisory/</a><br />]]></itunes:summary><itunes:duration>335</itunes:duration><itunes:keywords>business,cisco,computer,cyber,cybersecurity,daily,hacking,infosec,internet,ise,it,myasus,network,news,parasitic attacks,security,sharepoint</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9546</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, July 28th, 2025: Linux Namespaces; UI Automation Abuse; Autoswagger</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-july-28th-2025-linux-namespaces-ui-automation-abuse-autoswagger--67148386</link><description><![CDATA[<br /> Linux Namespaces<br /> Linux namespaces can be used to control networking features on a process-by-process basis. This is useful when trying to present a different network environment to a process being analysed.<br /><a href="https://isc.sans.edu/diary/Sinkholing%20Suspicious%20Scripts%20or%20Executables%20on%20Linux/32144" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Sinkholing%20Suspicious%20Scripts%20or%20Executables%20on%20Linux/32144</a><br /> Coyote in the Wild: First-Ever Malware That Abuses UI Automation<br /> Akamai identified malware that takes advantage of Microsoft s UI Automation Framework to programatically interact with the user s system and steal credentials.<br /><a href="https://www.akamai.com/blog/security-research/active-exploitation-coyote-malware-first-ui-automation-abuse-in-the-wild" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/active-exploitation-coyote-malware-first-ui-automation-abuse-in-the-wild</a><br /> Testing REST APIs with Autoswagger<br /> The tool Autoswagger can be used to automate the testing of REST APIs following the OpenAPI/Swagger standard.<br /><a href="https://github.com/intruder-io/autoswagger/" target="_blank" rel="noreferrer noopener">https://github.com/intruder-io/autoswagger/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9544.mp3</guid><pubDate>Mon, 28 Jul 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67148386/9544.mp3" length="4746269" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9544" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Linux Namespaces
 Linux namespaces can be used to control networking features on a process-by-process basis. This is useful when trying to present a different network environment to a process being analysed....</itunes:subtitle><itunes:summary><![CDATA[<br /> Linux Namespaces<br /> Linux namespaces can be used to control networking features on a process-by-process basis. This is useful when trying to present a different network environment to a process being analysed.<br /><a href="https://isc.sans.edu/diary/Sinkholing%20Suspicious%20Scripts%20or%20Executables%20on%20Linux/32144" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Sinkholing%20Suspicious%20Scripts%20or%20Executables%20on%20Linux/32144</a><br /> Coyote in the Wild: First-Ever Malware That Abuses UI Automation<br /> Akamai identified malware that takes advantage of Microsoft s UI Automation Framework to programatically interact with the user s system and steal credentials.<br /><a href="https://www.akamai.com/blog/security-research/active-exploitation-coyote-malware-first-ui-automation-abuse-in-the-wild" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/active-exploitation-coyote-malware-first-ui-automation-abuse-in-the-wild</a><br /> Testing REST APIs with Autoswagger<br /> The tool Autoswagger can be used to automate the testing of REST APIs following the OpenAPI/Swagger standard.<br /><a href="https://github.com/intruder-io/autoswagger/" target="_blank" rel="noreferrer noopener">https://github.com/intruder-io/autoswagger/</a><br />]]></itunes:summary><itunes:duration>339</itunes:duration><itunes:keywords>autoswagger,business,computer,coyote,cyber,cybersecurity,daily,hacking,infosec,internet,it,linux,namespace,network,news,rest,security,ui automation</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9544</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, July 25th, 2025: ficheck.py; Mital and SonicWall Patches</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-july-25th-2025-ficheck-py-mital-and-sonicwall-patches--67107385</link><description><![CDATA[<br /> New File Integrity Tool: ficheck.py<br /> Jim created a new tool, ficheck.py, that can be used to verify file integrity. It is a drop-in replacement for an older tool, fcheck, which was written in Perl and no longer functions well on modern Linux distributions.<br /><a href="https://isc.sans.edu/diary/New%20Tool%3A%20ficheck.py/32136" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/New%20Tool%3A%20ficheck.py/32136</a> <br /> Mitel Vulnerability<br /> Mitel released a patch for a vulnerability in its MX-ONE product. The authentication bypass could provide an attacker with user or even admin privileges.<br /><a href="https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2025-0009" target="_blank" rel="noreferrer noopener">https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2025-0009</a><br /> SonicWall SMA 100 Vulnerability<br /> SonicWall fixed an arbitrary file upload issue in its SMA 100 series firewalls. But exploitation will require credentials.<br /><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0014" target="_blank" rel="noreferrer noopener">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0014</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9542.mp3</guid><pubDate>Fri, 25 Jul 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67107385/9542.mp3" length="4490777" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9542" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 New File Integrity Tool: ficheck.py
 Jim created a new tool, ficheck.py, that can be used to verify file integrity. It is a drop-in replacement for an older tool, fcheck, which was written in Perl and no longer functions well on modern Linux...</itunes:subtitle><itunes:summary><![CDATA[<br /> New File Integrity Tool: ficheck.py<br /> Jim created a new tool, ficheck.py, that can be used to verify file integrity. It is a drop-in replacement for an older tool, fcheck, which was written in Perl and no longer functions well on modern Linux distributions.<br /><a href="https://isc.sans.edu/diary/New%20Tool%3A%20ficheck.py/32136" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/New%20Tool%3A%20ficheck.py/32136</a> <br /> Mitel Vulnerability<br /> Mitel released a patch for a vulnerability in its MX-ONE product. The authentication bypass could provide an attacker with user or even admin privileges.<br /><a href="https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2025-0009" target="_blank" rel="noreferrer noopener">https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2025-0009</a><br /> SonicWall SMA 100 Vulnerability<br /> SonicWall fixed an arbitrary file upload issue in its SMA 100 series firewalls. But exploitation will require credentials.<br /><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0014" target="_blank" rel="noreferrer noopener">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0014</a><br />]]></itunes:summary><itunes:duration>321</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,fcheck.pl,ficheck.py,file integrity,hacking,infosec,internet,it,mitel,network,news,security,sonicwall</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9542</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, July 24th, 2025: Reversing SharePoint Exploit; NPM “is” Compromise;</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-july-24th-2025-reversing-sharepoint-exploit-npm-is-compromise--67094032</link><description><![CDATA[<br /> Reversing SharePoint  Toolshell  Exploits CVE-2025-53770 and CVE-2025-53771<br /> A quick walk-through showing how to decode the payload of recent SharePoint exploits<br /><a href="https://isc.sans.edu/diary/Analyzing%20Sharepoint%20Exploits%20%28CVE-2025-53770%2C%20CVE-2025-53771%29/32138" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analyzing%20Sharepoint%20Exploits%20%28CVE-2025-53770%2C%20CVE-2025-53771%29/32138</a><br /> Compromised JavaScript NPM  is  Package<br /> The popular npm package  is  was compromised by malware. Luckily, the malicious code was found quickly, and it was reversed after about five hours.<br /><a href="https://socket.dev/blog/npm-is-package-hijacked-in-expanding-supply-chain-attack" target="_blank" rel="noreferrer noopener">https://socket.dev/blog/npm-is-package-hijacked-in-expanding-supply-chain-attack</a><br /> Microsoft Quick Machine Recovery<br /> Microsoft added a new quick machine recovery feature to Windows 11. If the system is stuck in a reboot loop, it will boot to a rescue partition and attempt to find fixes from Microsoft.<br /><a href="https://learn.microsoft.com/en-gb/windows/configuration/quick-machine-recovery/?tabs=intune" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-gb/windows/configuration/quick-machine-recovery/?tabs=intune</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9540.mp3</guid><pubDate>Thu, 24 Jul 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67094032/9540.mp3" length="5786798" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9540" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Reversing SharePoint  Toolshell  Exploits CVE-2025-53770 and CVE-2025-53771
 A quick walk-through showing how to decode the payload of recent SharePoint exploits...</itunes:subtitle><itunes:summary><![CDATA[<br /> Reversing SharePoint  Toolshell  Exploits CVE-2025-53770 and CVE-2025-53771<br /> A quick walk-through showing how to decode the payload of recent SharePoint exploits<br /><a href="https://isc.sans.edu/diary/Analyzing%20Sharepoint%20Exploits%20%28CVE-2025-53770%2C%20CVE-2025-53771%29/32138" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analyzing%20Sharepoint%20Exploits%20%28CVE-2025-53770%2C%20CVE-2025-53771%29/32138</a><br /> Compromised JavaScript NPM  is  Package<br /> The popular npm package  is  was compromised by malware. Luckily, the malicious code was found quickly, and it was reversed after about five hours.<br /><a href="https://socket.dev/blog/npm-is-package-hijacked-in-expanding-supply-chain-attack" target="_blank" rel="noreferrer noopener">https://socket.dev/blog/npm-is-package-hijacked-in-expanding-supply-chain-attack</a><br /> Microsoft Quick Machine Recovery<br /> Microsoft added a new quick machine recovery feature to Windows 11. If the system is stuck in a reboot loop, it will boot to a rescue partition and attempt to find fixes from Microsoft.<br /><a href="https://learn.microsoft.com/en-gb/windows/configuration/quick-machine-recovery/?tabs=intune" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-gb/windows/configuration/quick-machine-recovery/?tabs=intune</a><br />]]></itunes:summary><itunes:duration>413</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microsoft,network,news,npm,payload,reversing,security,sharepoint,windows 11</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9540</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, July 23rd, 2025: Sharepoint 2016 Patch; MotW Privacy and WinZip; Interlock Ransomware; Sophos Patches</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-july-23rd-2025-sharepoint-2016-patch-motw-privacy-and-winzip-interlock-ransomware-sophos-patches--67081353</link><description><![CDATA[<br /> Microsoft Updates SharePoint Vulnerability Guidance CVE-2025-53770 and CVE-2025-53771<br /> Microsoft released its update for SharePoint 2016, completing the updates across all currently supported versions.<br /><a href="https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/</a><br /> WinZip MotW Privacy<br /> Starting with version 7.10, WinZip introduced an option to no longer include the download URL in zip files as part of the Mark of the Web (MotW).<br /><a href="https://isc.sans.edu/diary/WinRAR%20MoTW%20Propagation%20Privacy/32130" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/WinRAR%20MoTW%20Propagation%20Privacy/32130</a><br /> Interlock Ransomware<br /> Several government agencies collaborated to create an informative and comprehensive overview of the Interlock ransomware. Just like prior writeups, this writeup is very informative, including many technical details useful to detect and block this ransomware.<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-203a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-203a</a><br /> Sophos Firewall Updates<br /> Sophos patched five different vulnerabilities in its firewalls. Two of them are critical, but these only affect a small percentage of users.<br /><a href="https://www.sophos.com/en-us/security-advisories/sophos-sa-20250721-sfos-rce" target="_blank" rel="noreferrer noopener">https://www.sophos.com/en-us/security-advisories/sophos-sa-20250721-sfos-rce</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9538.mp3</guid><pubDate>Wed, 23 Jul 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67081353/9538.mp3" length="5291173" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9538" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Microsoft Updates SharePoint Vulnerability Guidance CVE-2025-53770 and CVE-2025-53771
 Microsoft released its update for SharePoint 2016, completing the updates across all currently supported versions....</itunes:subtitle><itunes:summary><![CDATA[<br /> Microsoft Updates SharePoint Vulnerability Guidance CVE-2025-53770 and CVE-2025-53771<br /> Microsoft released its update for SharePoint 2016, completing the updates across all currently supported versions.<br /><a href="https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/</a><br /> WinZip MotW Privacy<br /> Starting with version 7.10, WinZip introduced an option to no longer include the download URL in zip files as part of the Mark of the Web (MotW).<br /><a href="https://isc.sans.edu/diary/WinRAR%20MoTW%20Propagation%20Privacy/32130" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/WinRAR%20MoTW%20Propagation%20Privacy/32130</a><br /> Interlock Ransomware<br /> Several government agencies collaborated to create an informative and comprehensive overview of the Interlock ransomware. Just like prior writeups, this writeup is very informative, including many technical details useful to detect and block this ransomware.<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-203a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-203a</a><br /> Sophos Firewall Updates<br /> Sophos patched five different vulnerabilities in its firewalls. Two of them are critical, but these only affect a small percentage of users.<br /><a href="https://www.sophos.com/en-us/security-advisories/sophos-sa-20250721-sfos-rce" target="_blank" rel="noreferrer noopener">https://www.sophos.com/en-us/security-advisories/sophos-sa-20250721-sfos-rce</a><br />]]></itunes:summary><itunes:duration>378</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,interlock,internet,it,microsoft,motw,network,news,security,sharepoint,sophos,winzip</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9538</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, July 22nd, 2025: SharePoint Emergency Patches; How Long Does Patching Take; HPE Wifi Vuln; Zoho WorkDrive Abused</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-july-22nd-2025-sharepoint-emergency-patches-how-long-does-patching-take-hpe-wifi-vuln-zoho-workdrive-abused--67065701</link><description><![CDATA[<br /> Microsoft Released Patches for SharePoint Vulnerability CVE-2025-53770 CVE-2025-53771<br /> Microsoft released a patch for the currently exploited SharePoint vulnerability. It also added a second CVE number identifying the authentication bypass vulnerability.<br /><a href="https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/</a><br /> How Quickly Are Systems Patched?<br /> Jan took Shodan data to check how quickly recent vulnerabilities were patched. The quick answer: Not fast enough.<br /><a href="https://isc.sans.edu/diary/How%20quickly%20do%20we%20patch%3F%20A%20quick%20look%20from%20the%20global%20viewpoint/32126" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20quickly%20do%20we%20patch%3F%20A%20quick%20look%20from%20the%20global%20viewpoint/32126</a><br /> HP Enterprise Instant On Access Points Vulnerability<br /> HPE patched two vulnerabilities in its Instant On access points (aka Aruba). One allows for authentication bypass, while the second one enables arbitrary code execution as admin.<br /><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04894en_us" target="_blank" rel="noreferrer noopener">https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04894en_us</a><br /> Revealing the AppLocker Bypass Risks in The Suggested Block-list Policy<br /> AppLocker sample policies suffer from a simple bug that may enable some rule bypass, but only if signatures are not enforced.<br /> While reviewing Microsoft s suggested configuration, Varonis Threat Labs noticed a subtle but important issue: the MaximumFileVersion field was set to 65355 instead of the expected 65535. <br /><a href="https://www.varonis.com/blog/applocker-bypass-risks" target="_blank" rel="noreferrer noopener">https://www.varonis.com/blog/applocker-bypass-risks</a><br /> Ghost Crypt Malware Leverages Zoho WorkDrive<br /> The Ghost malware tricks users into downloading by sending links to Zoho WorkDrive locations.<br /><a href="https://www.esentire.com/blog/ghost-crypt-powers-purerat-with-hypnosis" target="_blank" rel="noreferrer noopener">https://www.esentire.com/blog/ghost-crypt-powers-purerat-with-hypnosis</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9536.mp3</guid><pubDate>Tue, 22 Jul 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67065701/9536.mp3" length="5055716" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9536" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Microsoft Released Patches for SharePoint Vulnerability CVE-2025-53770 CVE-2025-53771
 Microsoft released a patch for the currently exploited SharePoint vulnerability. It also added a second CVE number identifying the authentication bypass...</itunes:subtitle><itunes:summary><![CDATA[<br /> Microsoft Released Patches for SharePoint Vulnerability CVE-2025-53770 CVE-2025-53771<br /> Microsoft released a patch for the currently exploited SharePoint vulnerability. It also added a second CVE number identifying the authentication bypass vulnerability.<br /><a href="https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/</a><br /> How Quickly Are Systems Patched?<br /> Jan took Shodan data to check how quickly recent vulnerabilities were patched. The quick answer: Not fast enough.<br /><a href="https://isc.sans.edu/diary/How%20quickly%20do%20we%20patch%3F%20A%20quick%20look%20from%20the%20global%20viewpoint/32126" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20quickly%20do%20we%20patch%3F%20A%20quick%20look%20from%20the%20global%20viewpoint/32126</a><br /> HP Enterprise Instant On Access Points Vulnerability<br /> HPE patched two vulnerabilities in its Instant On access points (aka Aruba). One allows for authentication bypass, while the second one enables arbitrary code execution as admin.<br /><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04894en_us" target="_blank" rel="noreferrer noopener">https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04894en_us</a><br /> Revealing the AppLocker Bypass Risks in The Suggested Block-list Policy<br /> AppLocker sample policies suffer from a simple bug that may enable some rule bypass, but only if signatures are not enforced.<br /> While reviewing Microsoft s suggested configuration, Varonis Threat Labs noticed a subtle but important issue: the MaximumFileVersion field was set to 65355 instead of the expected 65535. <br /><a href="https://www.varonis.com/blog/applocker-bypass-risks" target="_blank" rel="noreferrer noopener">https://www.varonis.com/blog/applocker-bypass-risks</a><br /> Ghost Crypt Malware Leverages Zoho WorkDrive<br /> The Ghost malware tricks users into downloading by sending links to Zoho WorkDrive locations.<br /><a href="https://www.esentire.com/blog/ghost-crypt-powers-purerat-with-hypnosis" target="_blank" rel="noreferrer noopener">https://www.esentire.com/blog/ghost-crypt-powers-purerat-with-hypnosis</a><br />]]></itunes:summary><itunes:duration>361</itunes:duration><itunes:keywords>applocker,aruba,business,computer,cyber,cybersecurity,daily,hacking,hpe,infosec,internet,it,network,news,patches,security,sharepoint,workdrive,zoho</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9536</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday July 21st, 2025: Sharepoint Exploited; Veeam Fake Voicemail Phish; Passkey Phishing Attack</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-july-21st-2025-sharepoint-exploited-veeam-fake-voicemail-phish-passkey-phishing-attack--67052082</link><description><![CDATA[<br /> SharePoint Servers Exploited via 0-day CVE-2025-53770<br /> Late last week, CodeWhite found a new remote code execution exploit against SharePoint. This vulnerability is now actively exploited.<br /><a href="https://isc.sans.edu/diary/Critical+Sharepoint+0Day+Vulnerablity+Exploited+CVE202553770+ToolShell/32122/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Critical+Sharepoint+0Day+Vulnerablity+Exploited+CVE202553770+ToolShell/32122/</a><br /> Veeam Voicemail Phishing<br /> Attackers appear to impersonate VEEAM in recent voicemail-themed phishing attempts.<br /><a href="https://isc.sans.edu/diary/Veeam%20Phishing%20via%20Wav%20File/32120" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Veeam%20Phishing%20via%20Wav%20File/32120</a><br /> Passkey Phishing Attack<br /> A currently active phishing attack takes advantage of the ability to use QR codes to complete the Passkey login procedure<br /><a href="https://expel.com/blog/poisonseed-downgrading-fido-key-authentications-to-fetch-user-accounts/" target="_blank" rel="noreferrer noopener">https://expel.com/blog/poisonseed-downgrading-fido-key-authentications-to-fetch-user-accounts/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9534.mp3</guid><pubDate>Mon, 21 Jul 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67052082/9534.mp3" length="6792021" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9534" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 SharePoint Servers Exploited via 0-day CVE-2025-53770
 Late last week, CodeWhite found a new remote code execution exploit against SharePoint. This vulnerability is now actively exploited....</itunes:subtitle><itunes:summary><![CDATA[<br /> SharePoint Servers Exploited via 0-day CVE-2025-53770<br /> Late last week, CodeWhite found a new remote code execution exploit against SharePoint. This vulnerability is now actively exploited.<br /><a href="https://isc.sans.edu/diary/Critical+Sharepoint+0Day+Vulnerablity+Exploited+CVE202553770+ToolShell/32122/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Critical+Sharepoint+0Day+Vulnerablity+Exploited+CVE202553770+ToolShell/32122/</a><br /> Veeam Voicemail Phishing<br /> Attackers appear to impersonate VEEAM in recent voicemail-themed phishing attempts.<br /><a href="https://isc.sans.edu/diary/Veeam%20Phishing%20via%20Wav%20File/32120" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Veeam%20Phishing%20via%20Wav%20File/32120</a><br /> Passkey Phishing Attack<br /> A currently active phishing attack takes advantage of the ability to use QR codes to complete the Passkey login procedure<br /><a href="https://expel.com/blog/poisonseed-downgrading-fido-key-authentications-to-fetch-user-accounts/" target="_blank" rel="noreferrer noopener">https://expel.com/blog/poisonseed-downgrading-fido-key-authentications-to-fetch-user-accounts/</a><br />]]></itunes:summary><itunes:duration>485</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,passkey,phishing,security,sharepoint,veeam</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9534</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, July 18th, 2025: Extended File Attributes; Critical Cisco ISE Patch; VMWare Patches; Quarterly Oracle Patches</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-july-18th-2025-extended-file-attributes-critical-cisco-ise-patch-vmware-patches-quarterly-oracle-patches--67023147</link><description><![CDATA[<br /> Hiding Payloads in Linux Extended File Attributes<br /> Xavier today looked at ways to hide payloads on Linux, similar to how alternate data streams are used on Windows. Turns out that extended file attributes do the trick, and he presents some scripts to either hide data or find hidden data.<br /><a href="https://isc.sans.edu/diary/Hiding%20Payloads%20in%20Linux%20Extended%20File%20Attributes/32116" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Hiding%20Payloads%20in%20Linux%20Extended%20File%20Attributes/32116</a><br /> Cisco Patches Critical Identity Services Engine Flaw CVE-2025-20281, CVE-2025-20337, CVE-2025-20282<br /> An unauthenticated user may execute arbitrary code as root across the network due to improperly validated data in Cisco s Identity Services Engine.<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-rce-ZAd2GnJ6" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-rce-ZAd2GnJ6</a><br /> Oracle Critical Patch Update<br /> Oracle patched 309 flaws across 111 products. 9 of these vulnerabilities have a critical CVSS score of 9.0 or higher. <br /><a href="https://www.oracle.com/security-alerts/cpujul2025.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpujul2025.html</a><br /> Broadcom releases VMware Updates<br /> Broadcom fixed a number of vulnerabilities for ESXi, Workstation, Fusion, and Tools.<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/35877" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/35877</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9532.mp3</guid><pubDate>Fri, 18 Jul 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67023147/9532.mp3" length="4133573" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9532" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Hiding Payloads in Linux Extended File Attributes
 Xavier today looked at ways to hide payloads on Linux, similar to how alternate data streams are used on Windows. Turns out that extended file attributes do the trick, and he presents some scripts...</itunes:subtitle><itunes:summary><![CDATA[<br /> Hiding Payloads in Linux Extended File Attributes<br /> Xavier today looked at ways to hide payloads on Linux, similar to how alternate data streams are used on Windows. Turns out that extended file attributes do the trick, and he presents some scripts to either hide data or find hidden data.<br /><a href="https://isc.sans.edu/diary/Hiding%20Payloads%20in%20Linux%20Extended%20File%20Attributes/32116" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Hiding%20Payloads%20in%20Linux%20Extended%20File%20Attributes/32116</a><br /> Cisco Patches Critical Identity Services Engine Flaw CVE-2025-20281, CVE-2025-20337, CVE-2025-20282<br /> An unauthenticated user may execute arbitrary code as root across the network due to improperly validated data in Cisco s Identity Services Engine.<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-rce-ZAd2GnJ6" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-rce-ZAd2GnJ6</a><br /> Oracle Critical Patch Update<br /> Oracle patched 309 flaws across 111 products. 9 of these vulnerabilities have a critical CVSS score of 9.0 or higher. <br /><a href="https://www.oracle.com/security-alerts/cpujul2025.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpujul2025.html</a><br /> Broadcom releases VMware Updates<br /> Broadcom fixed a number of vulnerabilities for ESXi, Workstation, Fusion, and Tools.<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/35877" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/35877</a><br />]]></itunes:summary><itunes:duration>295</itunes:duration><itunes:keywords>broadcom,business,cisco,computer,cyber,cybersecurity,daily,extended file attributes,hacking,infosec,internet,it,linux,network,news,oracle,security,xattr</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9532</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, July 17th, 2025: catbox.moe abuse; Sonicwall Attacks; Rendering Issues</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-july-17th-2025-catbox-moe-abuse-sonicwall-attacks-rendering-issues--67009423</link><description><![CDATA[<br /> More Free File Sharing Services Abuse<br /> The free file-sharing service catbox.moe is abused by malware. While it officially claims not to allow hosting of executables, it only checks extensions and is easily abused<br /><a href="https://isc.sans.edu/diary/More%20Free%20File%20Sharing%20Services%20Abuse/32112" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/More%20Free%20File%20Sharing%20Services%20Abuse/32112</a><br /> Ongoing SonicWall Secure Mobile Access (SMA) Exploitation Campaign using the OVERSTEP Backdoor<br /> A group Google identifies as UNC6148 is exploiting the Sonicwall SMA 100 series appliance. The devices are end of life, but even fully patched devices are exploited. Google assumes that these devices are compromised because credentials were leaked during prior attacks. The attacker installs the OVERSTEP backdoor after compromising the device.<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/sonicwall-secure-mobile-access-exploitation-overstep-backdoor" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/sonicwall-secure-mobile-access-exploitation-overstep-backdoor</a><br /> Weaponizing Trust in File Rendering Pipelines<br /> RenderShock is a comprehensive zero-click attack strategy that targets passive file preview, indexing, and automation behaviours in modern operating systems and enterprise environments. It leverages built-in trust mechanisms and background processing in file systems, email clients, antivirus tools, and graphical user interfaces to deliver payloads without requiring any user interaction.<br /><a href="https://www.cyfirma.com/research/rendershock-weaponizing-trust-in-file-rendering-pipelines/" target="_blank" rel="noreferrer noopener">https://www.cyfirma.com/research/rendershock-weaponizing-trust-in-file-rendering-pipelines/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9530.mp3</guid><pubDate>Thu, 17 Jul 2025 02:40:13 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/67009423/9530.mp3" length="4332584" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9530" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 More Free File Sharing Services Abuse
 The free file-sharing service catbox.moe is abused by malware. While it officially claims not to allow hosting of executables, it only checks extensions and is easily abused...</itunes:subtitle><itunes:summary><![CDATA[<br /> More Free File Sharing Services Abuse<br /> The free file-sharing service catbox.moe is abused by malware. While it officially claims not to allow hosting of executables, it only checks extensions and is easily abused<br /><a href="https://isc.sans.edu/diary/More%20Free%20File%20Sharing%20Services%20Abuse/32112" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/More%20Free%20File%20Sharing%20Services%20Abuse/32112</a><br /> Ongoing SonicWall Secure Mobile Access (SMA) Exploitation Campaign using the OVERSTEP Backdoor<br /> A group Google identifies as UNC6148 is exploiting the Sonicwall SMA 100 series appliance. The devices are end of life, but even fully patched devices are exploited. Google assumes that these devices are compromised because credentials were leaked during prior attacks. The attacker installs the OVERSTEP backdoor after compromising the device.<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/sonicwall-secure-mobile-access-exploitation-overstep-backdoor" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/sonicwall-secure-mobile-access-exploitation-overstep-backdoor</a><br /> Weaponizing Trust in File Rendering Pipelines<br /> RenderShock is a comprehensive zero-click attack strategy that targets passive file preview, indexing, and automation behaviours in modern operating systems and enterprise environments. It leverages built-in trust mechanisms and background processing in file systems, email clients, antivirus tools, and graphical user interfaces to deliver payloads without requiring any user interaction.<br /><a href="https://www.cyfirma.com/research/rendershock-weaponizing-trust-in-file-rendering-pipelines/" target="_blank" rel="noreferrer noopener">https://www.cyfirma.com/research/rendershock-weaponizing-trust-in-file-rendering-pipelines/</a><br />]]></itunes:summary><itunes:duration>309</itunes:duration><itunes:keywords>business,catbox,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,rendershock,security,sonicwall,unc6148</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9530</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, July 16th, 2025: ADS Keystroke Logger; Fake Homebrew; Broadcom Altiris RCE; Malicious Cursor AI Extensions</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-july-16th-2025-ads-keystroke-logger-fake-homebrew-broadcom-altiris-rce-malicious-cursor-ai-extensions--66992438</link><description><![CDATA[<br /> Keylogger Data Stored in an ADS<br /> Xavier came across a keystroke logger that stores data in alternate data streams. The data includes keystroke logs as well as clipboard data<br /><a href="https://isc.sans.edu/diary/Keylogger%20Data%20Stored%20in%20an%20ADS/32108" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Keylogger%20Data%20Stored%20in%20an%20ADS/32108</a><br /> Malvertising Homebrew<br /> An attacker has been attempting to trick users into installing a malicious version of Homebrew. The fake software is advertised via paid Google ads and directs users to the attacker s GitHub repo.<br /><a href="https://medium.com/deriv-tech/brewing-trouble-dissecting-a-macos-malware-campaign-90c2c24de5dc" target="_blank" rel="noreferrer noopener">https://medium.com/deriv-tech/brewing-trouble-dissecting-a-macos-malware-campaign-90c2c24de5dc</a><br /> CVE-2025-5333: Remote Code Execution in Broadcom Altiris IRM<br /> LRQA have discovered a critical unauthenticated remote code execution (RCE) vulnerability in the Broadcom Symantec Altiris Inventory Rule Management (IRM) component of Symantec Endpoint Management.<br /><a href="https://www.lrqa.com/en/cyber-labs/remote-code-execution-in-broadcom-altiris-irm/" target="_blank" rel="noreferrer noopener">https://www.lrqa.com/en/cyber-labs/remote-code-execution-in-broadcom-altiris-irm/</a><br /> Code highlighting with Cursor AI for $500,000<br /> A syntax highlighting extension for Cursor AI was used to compromise a developer s workstation and steal $500,000 in cryptocurrency.<br /><a href="https://securelist.com/open-source-package-for-cursor-ai-turned-into-a-crypto-heist/116908/" target="_blank" rel="noreferrer noopener">https://securelist.com/open-source-package-for-cursor-ai-turned-into-a-crypto-heist/116908/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9528.mp3</guid><pubDate>Wed, 16 Jul 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66992438/9528.mp3" length="4838722" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9528" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Keylogger Data Stored in an ADS
 Xavier came across a keystroke logger that stores data in alternate data streams. The data includes keystroke logs as well as clipboard data
https://isc.sans.edu/diary/Keylogger%20Data%20Stored%20in%20an%20ADS/32108...</itunes:subtitle><itunes:summary><![CDATA[<br /> Keylogger Data Stored in an ADS<br /> Xavier came across a keystroke logger that stores data in alternate data streams. The data includes keystroke logs as well as clipboard data<br /><a href="https://isc.sans.edu/diary/Keylogger%20Data%20Stored%20in%20an%20ADS/32108" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Keylogger%20Data%20Stored%20in%20an%20ADS/32108</a><br /> Malvertising Homebrew<br /> An attacker has been attempting to trick users into installing a malicious version of Homebrew. The fake software is advertised via paid Google ads and directs users to the attacker s GitHub repo.<br /><a href="https://medium.com/deriv-tech/brewing-trouble-dissecting-a-macos-malware-campaign-90c2c24de5dc" target="_blank" rel="noreferrer noopener">https://medium.com/deriv-tech/brewing-trouble-dissecting-a-macos-malware-campaign-90c2c24de5dc</a><br /> CVE-2025-5333: Remote Code Execution in Broadcom Altiris IRM<br /> LRQA have discovered a critical unauthenticated remote code execution (RCE) vulnerability in the Broadcom Symantec Altiris Inventory Rule Management (IRM) component of Symantec Endpoint Management.<br /><a href="https://www.lrqa.com/en/cyber-labs/remote-code-execution-in-broadcom-altiris-irm/" target="_blank" rel="noreferrer noopener">https://www.lrqa.com/en/cyber-labs/remote-code-execution-in-broadcom-altiris-irm/</a><br /> Code highlighting with Cursor AI for $500,000<br /> A syntax highlighting extension for Cursor AI was used to compromise a developer s workstation and steal $500,000 in cryptocurrency.<br /><a href="https://securelist.com/open-source-package-for-cursor-ai-turned-into-a-crypto-heist/116908/" target="_blank" rel="noreferrer noopener">https://securelist.com/open-source-package-for-cursor-ai-turned-into-a-crypto-heist/116908/</a><br />]]></itunes:summary><itunes:duration>346</itunes:duration><itunes:keywords>ads,altiris,broadcom,business,computer,cursor,cyber,cybersecurity,daily,extensions,hacking,homebrew,infosec,internet,it,keylogger,malvertising,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9528</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, July 14th, 2025: Web Honeypot Log Volume; Browser Extension Malware; RDP Forensics</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-july-14th-2025-web-honeypot-log-volume-browser-extension-malware-rdp-forensics--66980984</link><description><![CDATA[<br /> DShield Honeypot Log Volume Increase<br /> Within the last few months, there has been a dramatic increase in honeypot log volumes and how often these high volumes are seen. This has not just been from Jesse s residential honeypot, which has historically seen higher log volumes, but from all of the honeypots that Jesse runs. <br /><a href="https://isc.sans.edu/diary/DShield+Honeypot+Log+Volume+Increase/32100" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/DShield+Honeypot+Log+Volume+Increase/32100</a><br /> Google and Microsoft Trusted Them. 2.3 Million Users Installed Them. They Were Malware.<br /> Koi Security s investigation of a single  verified  color picker exposed a coordinated campaign of 18 malicious extensions that infected a massive 2.3 million users across Chrome and Edge.<br /><a href="https://blog.koi.security/google-and-microsoft-trusted-them-2-3-million-users-installed-them-they-were-malware-fb4ed4f40ff5" target="_blank" rel="noreferrer noopener">https://blog.koi.security/google-and-microsoft-trusted-them-2-3-million-users-installed-them-they-were-malware-fb4ed4f40ff5</a><br /> RDP Forensics<br /> Comprehensive overview of Windows RDP Forensics<br /><a href="https://medium.com/@mathias.fuchs/chasing-ghosts-over-rdp-lateral-movement-in-tiny-bitmaps-328d2babd8ec" target="_blank" rel="noreferrer noopener">https://medium.com/@mathias.fuchs/chasing-ghosts-over-rdp-lateral-movement-in-tiny-bitmaps-328d2babd8ec</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9526.mp3</guid><pubDate>Tue, 15 Jul 2025 02:05:16 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66980984/9526.mp3" length="5189436" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9526" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 DShield Honeypot Log Volume Increase
 Within the last few months, there has been a dramatic increase in honeypot log volumes and how often these high volumes are seen. This has not just been from Jesse s residential honeypot, which has historically...</itunes:subtitle><itunes:summary><![CDATA[<br /> DShield Honeypot Log Volume Increase<br /> Within the last few months, there has been a dramatic increase in honeypot log volumes and how often these high volumes are seen. This has not just been from Jesse s residential honeypot, which has historically seen higher log volumes, but from all of the honeypots that Jesse runs. <br /><a href="https://isc.sans.edu/diary/DShield+Honeypot+Log+Volume+Increase/32100" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/DShield+Honeypot+Log+Volume+Increase/32100</a><br /> Google and Microsoft Trusted Them. 2.3 Million Users Installed Them. They Were Malware.<br /> Koi Security s investigation of a single  verified  color picker exposed a coordinated campaign of 18 malicious extensions that infected a massive 2.3 million users across Chrome and Edge.<br /><a href="https://blog.koi.security/google-and-microsoft-trusted-them-2-3-million-users-installed-them-they-were-malware-fb4ed4f40ff5" target="_blank" rel="noreferrer noopener">https://blog.koi.security/google-and-microsoft-trusted-them-2-3-million-users-installed-them-they-were-malware-fb4ed4f40ff5</a><br /> RDP Forensics<br /> Comprehensive overview of Windows RDP Forensics<br /><a href="https://medium.com/@mathias.fuchs/chasing-ghosts-over-rdp-lateral-movement-in-tiny-bitmaps-328d2babd8ec" target="_blank" rel="noreferrer noopener">https://medium.com/@mathias.fuchs/chasing-ghosts-over-rdp-lateral-movement-in-tiny-bitmaps-328d2babd8ec</a><br />]]></itunes:summary><itunes:duration>371</itunes:duration><itunes:keywords>browser extension,business,computer,cyber,cybersecurity,daily,dshield,forensics,hacking,honeypot,infosec,internet,it,malware,network,news,rdp,security,sonicwall</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9526</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, July 14th, 2025: Suspect Domain Feed; Wing FTP Exploited; FortiWeb Exploited; NVIDIA GPU Rowhammer</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-july-14th-2025-suspect-domain-feed-wing-ftp-exploited-fortiweb-exploited-nvidia-gpu-rowhammer--66970136</link><description><![CDATA[<br /> Experimental Suspicious Domain Feed<br /> Our new experimental suspicious domain feed uses various criteria to identify domains that may be used for phishing or other malicious purposes.<br /><a href="https://isc.sans.edu/diary/Experimental%20Suspicious%20Domain%20Feed/32102" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Experimental%20Suspicious%20Domain%20Feed/32102</a><br /> Wing FTP Server RCE Vulnerability Exploited CVE-2025-47812<br />  Huntress saw active exploitation of Wing FTP Server remote code execution (CVE-2025-47812) on a customer on July 1, 2025. Organizations running Wing FTP Server should update to the fixed version, version 7.4.4, as soon as possible.<br /><a href="https://www.huntress.com/blog/wing-ftp-server-remote-code-execution-cve-2025-47812-exploited-in-wild" target="_blank" rel="noreferrer noopener">https://www.huntress.com/blog/wing-ftp-server-remote-code-execution-cve-2025-47812-exploited-in-wild</a><br /><a href="https://www.rcesecurity.com/2025/06/what-the-null-wing-ftp-server-rce-cve-2025-47812/" target="_blank" rel="noreferrer noopener">https://www.rcesecurity.com/2025/06/what-the-null-wing-ftp-server-rce-cve-2025-47812/</a><br /> FortiWeb Pre-Auth RCE (CVE-2025-25257)<br /> An exploit for the FortiWeb RCE Vulnerability is now available and is being used in the wild.<br /><a href="https://pwner.gg/blog/2025-07-10-fortiweb-fabric-rce" target="_blank" rel="noreferrer noopener">https://pwner.gg/blog/2025-07-10-fortiweb-fabric-rce</a><br /> NVIDIA Vulnerable to Rowhammer<br /> NVIDIA has received new research related to the industry-wide DRAM issue known as  Rowhammer . The research demonstrates a potential Rowhammer attack against an NVIDIA A6000 GPU with GDDR6 Memory. The purpose of this notice is to reinforce already known mitigations to Rowhammer attacks.<br /><a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5671/~/security-notice%3A-rowhammer---july-2025" target="_blank" rel="noreferrer noopener">https://nvidia.custhelp.com/app/answers/detail/a_id/5671/~/security-notice%3A-rowhammer---july-2025</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9524.mp3</guid><pubDate>Mon, 14 Jul 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66970136/9524.mp3" length="5794584" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9524" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Experimental Suspicious Domain Feed
 Our new experimental suspicious domain feed uses various criteria to identify domains that may be used for phishing or other malicious purposes....</itunes:subtitle><itunes:summary><![CDATA[<br /> Experimental Suspicious Domain Feed<br /> Our new experimental suspicious domain feed uses various criteria to identify domains that may be used for phishing or other malicious purposes.<br /><a href="https://isc.sans.edu/diary/Experimental%20Suspicious%20Domain%20Feed/32102" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Experimental%20Suspicious%20Domain%20Feed/32102</a><br /> Wing FTP Server RCE Vulnerability Exploited CVE-2025-47812<br />  Huntress saw active exploitation of Wing FTP Server remote code execution (CVE-2025-47812) on a customer on July 1, 2025. Organizations running Wing FTP Server should update to the fixed version, version 7.4.4, as soon as possible.<br /><a href="https://www.huntress.com/blog/wing-ftp-server-remote-code-execution-cve-2025-47812-exploited-in-wild" target="_blank" rel="noreferrer noopener">https://www.huntress.com/blog/wing-ftp-server-remote-code-execution-cve-2025-47812-exploited-in-wild</a><br /><a href="https://www.rcesecurity.com/2025/06/what-the-null-wing-ftp-server-rce-cve-2025-47812/" target="_blank" rel="noreferrer noopener">https://www.rcesecurity.com/2025/06/what-the-null-wing-ftp-server-rce-cve-2025-47812/</a><br /> FortiWeb Pre-Auth RCE (CVE-2025-25257)<br /> An exploit for the FortiWeb RCE Vulnerability is now available and is being used in the wild.<br /><a href="https://pwner.gg/blog/2025-07-10-fortiweb-fabric-rce" target="_blank" rel="noreferrer noopener">https://pwner.gg/blog/2025-07-10-fortiweb-fabric-rce</a><br /> NVIDIA Vulnerable to Rowhammer<br /> NVIDIA has received new research related to the industry-wide DRAM issue known as  Rowhammer . The research demonstrates a potential Rowhammer attack against an NVIDIA A6000 GPU with GDDR6 Memory. The purpose of this notice is to reinforce already known mitigations to Rowhammer attacks.<br /><a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5671/~/security-notice%3A-rowhammer---july-2025" target="_blank" rel="noreferrer noopener">https://nvidia.custhelp.com/app/answers/detail/a_id/5671/~/security-notice%3A-rowhammer---july-2025</a><br />]]></itunes:summary><itunes:duration>414</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,domain feed,fortiweb,hacking,infosec,internet,it,network,news,nvidia,rowhammer,security,sql injection,wing ftp</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9524</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, July 11th, 2025: SSH Tunnel; FortiWeb SQL Injection; Ruckus Unpatched Vuln; Missing Motherboard Patches;</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-july-11th-2025-ssh-tunnel-fortiweb-sql-injection-ruckus-unpatched-vuln-missing-motherboard-patches--66939688</link><description><![CDATA[<br /> SSH Tunneling in Action: direct-tcp requests<br /> Attackers are compromising ssh servers to abuse them as relays. The attacker will configure port forwarding direct-tcp connections to forward traffic to a victim. In this particular case, the Yandex mail server was the primary victim of these attacks.<br /><a href="https://isc.sans.edu/diary/SSH%20Tunneling%20in%20Action%3A%20direct-tcp%20requests%20%5BGuest%20Diary%5D/32094" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SSH%20Tunneling%20in%20Action%3A%20direct-tcp%20requests%20%5BGuest%20Diary%5D/32094</a><br /> Fortiguard FortiWeb Unauthenticated SQL injection in GUI (CVE-2025-25257)<br /> An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.<br /><a href="https://www.fortiguard.com/psirt/FG-IR-25-151" target="_blank" rel="noreferrer noopener">https://www.fortiguard.com/psirt/FG-IR-25-151</a><br /> Ruckus Virtual SmartZone (vSZ) and Ruckus Network Director (RND) contain multiple vulnerabilities<br /> Ruckus products suffer from a number of critical vulnerabilities. There is no patch available, and users are advised to restrict access to the vulnerable admin interface.<br /><a href="https://kb.cert.org/vuls/id/613753" target="_blank" rel="noreferrer noopener">https://kb.cert.org/vuls/id/613753</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9522.mp3</guid><pubDate>Fri, 11 Jul 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66939688/9522.mp3" length="4879794" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9522" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 SSH Tunneling in Action: direct-tcp requests
 Attackers are compromising ssh servers to abuse them as relays. The attacker will configure port forwarding direct-tcp connections to forward traffic to a victim. In this particular case, the Yandex mail...</itunes:subtitle><itunes:summary><![CDATA[<br /> SSH Tunneling in Action: direct-tcp requests<br /> Attackers are compromising ssh servers to abuse them as relays. The attacker will configure port forwarding direct-tcp connections to forward traffic to a victim. In this particular case, the Yandex mail server was the primary victim of these attacks.<br /><a href="https://isc.sans.edu/diary/SSH%20Tunneling%20in%20Action%3A%20direct-tcp%20requests%20%5BGuest%20Diary%5D/32094" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SSH%20Tunneling%20in%20Action%3A%20direct-tcp%20requests%20%5BGuest%20Diary%5D/32094</a><br /> Fortiguard FortiWeb Unauthenticated SQL injection in GUI (CVE-2025-25257)<br /> An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.<br /><a href="https://www.fortiguard.com/psirt/FG-IR-25-151" target="_blank" rel="noreferrer noopener">https://www.fortiguard.com/psirt/FG-IR-25-151</a><br /> Ruckus Virtual SmartZone (vSZ) and Ruckus Network Director (RND) contain multiple vulnerabilities<br /> Ruckus products suffer from a number of critical vulnerabilities. There is no patch available, and users are advised to restrict access to the vulnerable admin interface.<br /><a href="https://kb.cert.org/vuls/id/613753" target="_blank" rel="noreferrer noopener">https://kb.cert.org/vuls/id/613753</a><br />]]></itunes:summary><itunes:duration>349</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,forgiguard,hacking,infosec,internet,it,network,news,ruckus,security,ssh,tunnel</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9522</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, July 10th, 2025: Internal CA with ACME; TapJacking on Android; Adobe Patches;</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-july-10th-2025-internal-ca-with-acme-tapjacking-on-android-adobe-patches--66921931</link><description><![CDATA[<br /> Setting up Your Own Certificate Authority for Development: Why and How.<br /> Some tips on setting up your own internal certificate authority using the smallstep CA.<br /><a href="https://isc.sans.edu/diary/Setting%20up%20Your%20Own%20Certificate%20Authority%20for%20Development%3A%20Why%20and%20How./32092" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Setting%20up%20Your%20Own%20Certificate%20Authority%20for%20Development%3A%20Why%20and%20How./32092</a><br /> Animation-Driven Tapjacking on Android<br /> Attackers can use a click-jacking like trick to trick victims into clicking on animated transparent dialogs opened from other applications.<br /><a href="https://taptrap.click/usenix25_taptrap_paper.pdf" target="_blank" rel="noreferrer noopener">https://taptrap.click/usenix25_taptrap_paper.pdf</a><br /> Adobe Patches<br /> Adobe patched 13 different products yesterday. Most concerning are vulnerabilities in Coldfusion that include code execution and arbitrary file disclosure vulnerabilities.<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9520.mp3</guid><pubDate>Thu, 10 Jul 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66921931/9520.mp3" length="4455568" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9520" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Setting up Your Own Certificate Authority for Development: Why and How.
 Some tips on setting up your own internal certificate authority using the smallstep CA....</itunes:subtitle><itunes:summary><![CDATA[<br /> Setting up Your Own Certificate Authority for Development: Why and How.<br /> Some tips on setting up your own internal certificate authority using the smallstep CA.<br /><a href="https://isc.sans.edu/diary/Setting%20up%20Your%20Own%20Certificate%20Authority%20for%20Development%3A%20Why%20and%20How./32092" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Setting%20up%20Your%20Own%20Certificate%20Authority%20for%20Development%3A%20Why%20and%20How./32092</a><br /> Animation-Driven Tapjacking on Android<br /> Attackers can use a click-jacking like trick to trick victims into clicking on animated transparent dialogs opened from other applications.<br /><a href="https://taptrap.click/usenix25_taptrap_paper.pdf" target="_blank" rel="noreferrer noopener">https://taptrap.click/usenix25_taptrap_paper.pdf</a><br /> Adobe Patches<br /> Adobe patched 13 different products yesterday. Most concerning are vulnerabilities in Coldfusion that include code execution and arbitrary file disclosure vulnerabilities.<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br />]]></itunes:summary><itunes:duration>318</itunes:duration><itunes:keywords>acme,adobe,business,ca,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,smallstap,tapjack</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9520</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, July 9th, 2025: Microsoft Patches; Opposum Attack;</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-july-9th-2025-microsoft-patches-opposum-attack--66906128</link><description><![CDATA[<br /> Microsoft Patch Tuesday, July 2025<br /> Today, Microsoft released patches for 130 Microsoft vulnerabilities and 9 additional vulnerabilities not part of Microsoft's portfolio but distributed by Microsoft. 14 of these are rated critical. Only one of the vulnerabilities was disclosed before being patched, and none of the vulnerabilities have so far been exploited.<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%2C%20July%202025/32088" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%2C%20July%202025/32088</a><br /> Opposum Attack<br /> If a TLS server is configured to allow switching from HTTP to HTTPS on a specific port, an attacker may be able to inject a request into the data stream. <br /><a href="https://opossum-attack.com/" target="_blank" rel="noreferrer noopener">https://opossum-attack.com/</a><br /> Ivanti Security Updates<br /> Ivanty fixed vulnerabilities in Ivanty Connect Secure, EPMM, and EPM. In particular the password decryption vulnerabliity may be interesting.<br /><a href="https://www.ivanti.com/blog/july-security-update-2025" target="_blank" rel="noreferrer noopener">https://www.ivanti.com/blog/july-security-update-2025</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9518.mp3</guid><pubDate>Wed, 09 Jul 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66906128/9518.mp3" length="6495698" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9518" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Microsoft Patch Tuesday, July 2025
 Today, Microsoft released patches for 130 Microsoft vulnerabilities and 9 additional vulnerabilities not part of Microsoft's portfolio but distributed by Microsoft. 14 of these are rated critical. Only one of the...</itunes:subtitle><itunes:summary><![CDATA[<br /> Microsoft Patch Tuesday, July 2025<br /> Today, Microsoft released patches for 130 Microsoft vulnerabilities and 9 additional vulnerabilities not part of Microsoft's portfolio but distributed by Microsoft. 14 of these are rated critical. Only one of the vulnerabilities was disclosed before being patched, and none of the vulnerabilities have so far been exploited.<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%2C%20July%202025/32088" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%2C%20July%202025/32088</a><br /> Opposum Attack<br /> If a TLS server is configured to allow switching from HTTP to HTTPS on a specific port, an attacker may be able to inject a request into the data stream. <br /><a href="https://opossum-attack.com/" target="_blank" rel="noreferrer noopener">https://opossum-attack.com/</a><br /> Ivanti Security Updates<br /> Ivanty fixed vulnerabilities in Ivanty Connect Secure, EPMM, and EPM. In particular the password decryption vulnerabliity may be interesting.<br /><a href="https://www.ivanti.com/blog/july-security-update-2025" target="_blank" rel="noreferrer noopener">https://www.ivanti.com/blog/july-security-update-2025</a><br />]]></itunes:summary><itunes:duration>464</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,ivanti,microsoft,network,news,opposum,security,tls</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9518</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, July 8th, 2025: Detecting Filename (Windows); Atomic Stealer now with Backdoor; SEO Scams</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-july-8th-2025-detecting-filename-windows-atomic-stealer-now-with-backdoor-seo-scams--66892651</link><description><![CDATA[<br /> What s My File Name<br /> Malware may use the GetModuleFileName API to detect if it was renamed to a name typical for analysis, like sample.exe or malware.exe<br /><a href="https://isc.sans.edu/diary/What%27s%20My%20%28File%29Name%3F/32084" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%27s%20My%20%28File%29Name%3F/32084</a><br /> Atomic macOS infostealer adds backdoor for persistent attacks<br /> Malware analyst discovered a new version of the Atomic macOS info-stealer (also known as 'AMOS') that comes with a backdoor, to attackers persistent access to compromised systems.<br /><a href="https://moonlock.com/amos-backdoor-persistent-access" target="_blank" rel="noreferrer noopener">https://moonlock.com/amos-backdoor-persistent-access</a><br /> HOUKEN SEEKING A PATH BY LIVING ON THE EDGE WITH ZERO-DAYS<br /> At the beginning of September 2024, an attacker repeatedly exploited vulnerabilities CVE-2024- 8190, CVE-2024-8963, and CVE-2024-9380 vulnerabilities to remotely execute arbitrary code on vulnerable Ivanti Cloud Service Appliance devices.<br /><a href="https://www.cert.ssi.gouv.fr/uploads/CERTFR-2025-CTI-009.pdf" target="_blank" rel="noreferrer noopener">https://www.cert.ssi.gouv.fr/uploads/CERTFR-2025-CTI-009.pdf</a><br /> SEO Scams Targeting Putty, WinSCP, and AI Tools<br /> Paid Google ads are advertising trojaned versions of popuplar tools like ssh and winscp<br /><a href="https://arcticwolf.com/resources/blog-uk/malvertising-campaign-delivers-oyster-broomstick-backdoor-via-seo-poisoning-and-trojanized-tools/" target="_blank" rel="noreferrer noopener">https://arcticwolf.com/resources/blog-uk/malvertising-campaign-delivers-oyster-broomstick-backdoor-via-seo-poisoning-and-trojanized-tools/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9516.mp3</guid><pubDate>Tue, 08 Jul 2025 02:20:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66892651/9516.mp3" length="4606150" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9516" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 What s My File Name
 Malware may use the GetModuleFileName API to detect if it was renamed to a name typical for analysis, like sample.exe or malware.exe
https://isc.sans.edu/diary/What%27s%20My%20%28File%29Name%3F/32084
 Atomic macOS infostealer...</itunes:subtitle><itunes:summary><![CDATA[<br /> What s My File Name<br /> Malware may use the GetModuleFileName API to detect if it was renamed to a name typical for analysis, like sample.exe or malware.exe<br /><a href="https://isc.sans.edu/diary/What%27s%20My%20%28File%29Name%3F/32084" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%27s%20My%20%28File%29Name%3F/32084</a><br /> Atomic macOS infostealer adds backdoor for persistent attacks<br /> Malware analyst discovered a new version of the Atomic macOS info-stealer (also known as 'AMOS') that comes with a backdoor, to attackers persistent access to compromised systems.<br /><a href="https://moonlock.com/amos-backdoor-persistent-access" target="_blank" rel="noreferrer noopener">https://moonlock.com/amos-backdoor-persistent-access</a><br /> HOUKEN SEEKING A PATH BY LIVING ON THE EDGE WITH ZERO-DAYS<br /> At the beginning of September 2024, an attacker repeatedly exploited vulnerabilities CVE-2024- 8190, CVE-2024-8963, and CVE-2024-9380 vulnerabilities to remotely execute arbitrary code on vulnerable Ivanti Cloud Service Appliance devices.<br /><a href="https://www.cert.ssi.gouv.fr/uploads/CERTFR-2025-CTI-009.pdf" target="_blank" rel="noreferrer noopener">https://www.cert.ssi.gouv.fr/uploads/CERTFR-2025-CTI-009.pdf</a><br /> SEO Scams Targeting Putty, WinSCP, and AI Tools<br /> Paid Google ads are advertising trojaned versions of popuplar tools like ssh and winscp<br /><a href="https://arcticwolf.com/resources/blog-uk/malvertising-campaign-delivers-oyster-broomstick-backdoor-via-seo-poisoning-and-trojanized-tools/" target="_blank" rel="noreferrer noopener">https://arcticwolf.com/resources/blog-uk/malvertising-campaign-delivers-oyster-broomstick-backdoor-via-seo-poisoning-and-trojanized-tools/</a><br />]]></itunes:summary><itunes:duration>329</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,getmodulefilename,hacking,houken,infosec,internet,it,malware,network,news,putty,security,seo,winscp</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9516</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, July 7th, 2025: interesting usernames; More sudo issues; CitrixBleed2 PoC; Short Lived Certs</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-july-7th-2025-interesting-usernames-more-sudo-issues-citrixbleed2-poc-short-lived-certs--66882946</link><description><![CDATA[<br /> Interesting ssh/telnet usernames<br /> Some interesting usernames observed in our honeypots<br /><a href="https://isc.sans.edu/diary/A%20few%20interesting%20and%20notable%20ssh%20telnet%20usernames/32080" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20few%20interesting%20and%20notable%20ssh%20telnet%20usernames/32080</a><br /> More sudo trouble<br /> The host option in Sudo can be exploited to execute commands on unauthorized hosts.<br /><a href="https://www.stratascale.com/vulnerability-alert-CVE-2025-32462-sudo-host" target="_blank" rel="noreferrer noopener">https://www.stratascale.com/vulnerability-alert-CVE-2025-32462-sudo-host</a><br /> CitrixBleed2 PoC Posted (CVE-2025-5777)<br /> WatchTwer published additional details about the recently patched CitrixBleed vulnerability, including a PoC exploit.<br /><a href="https://labs.watchtowr.com/how-much-more-must-we-bleed-citrix-netscaler-memory-disclosure-citrixbleed-2-cve-2025-5777/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/how-much-more-must-we-bleed-citrix-netscaler-memory-disclosure-citrixbleed-2-cve-2025-5777/</a><br /> Instagram Using Six Day Certificates<br /> Instagram changes their TLS certificates daily and they use certificates that are just about to expire in a week.<br /><a href="https://hereket.com/posts/instagram-single-day-certificates/" target="_blank" rel="noreferrer noopener">https://hereket.com/posts/instagram-single-day-certificates/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9514.mp3</guid><pubDate>Mon, 07 Jul 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66882946/9514.mp3" length="4875043" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9514" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Interesting ssh/telnet usernames
 Some interesting usernames observed in our honeypots
https://isc.sans.edu/diary/A%20few%20interesting%20and%20notable%20ssh%20telnet%20usernames/32080
 More sudo trouble
 The host option in Sudo can be exploited to...</itunes:subtitle><itunes:summary><![CDATA[<br /> Interesting ssh/telnet usernames<br /> Some interesting usernames observed in our honeypots<br /><a href="https://isc.sans.edu/diary/A%20few%20interesting%20and%20notable%20ssh%20telnet%20usernames/32080" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20few%20interesting%20and%20notable%20ssh%20telnet%20usernames/32080</a><br /> More sudo trouble<br /> The host option in Sudo can be exploited to execute commands on unauthorized hosts.<br /><a href="https://www.stratascale.com/vulnerability-alert-CVE-2025-32462-sudo-host" target="_blank" rel="noreferrer noopener">https://www.stratascale.com/vulnerability-alert-CVE-2025-32462-sudo-host</a><br /> CitrixBleed2 PoC Posted (CVE-2025-5777)<br /> WatchTwer published additional details about the recently patched CitrixBleed vulnerability, including a PoC exploit.<br /><a href="https://labs.watchtowr.com/how-much-more-must-we-bleed-citrix-netscaler-memory-disclosure-citrixbleed-2-cve-2025-5777/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/how-much-more-must-we-bleed-citrix-netscaler-memory-disclosure-citrixbleed-2-cve-2025-5777/</a><br /> Instagram Using Six Day Certificates<br /> Instagram changes their TLS certificates daily and they use certificates that are just about to expire in a week.<br /><a href="https://hereket.com/posts/instagram-single-day-certificates/" target="_blank" rel="noreferrer noopener">https://hereket.com/posts/instagram-single-day-certificates/</a><br />]]></itunes:summary><itunes:duration>348</itunes:duration><itunes:keywords>business,certificates,citrix,citrixbleed,cyber,cybersecurity,daily,gpu001,gpu002,hacking,infosec,instagram,it,netscaler,network,news,scadaadmin,security,sudo,usernames</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9514</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday July 3rd, 2025: sudo problems; polymorphic zip files; cisco vulnerablity</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-july-3rd-2025-sudo-problems-polymorphic-zip-files-cisco-vulnerablity--66845735</link><description><![CDATA[<br /> Sudo chroot Elevation of Privilege<br /> The sudo chroot option can be leveraged by any local user to elevate privileges to root, even if no sudo rules are defined for that user.<br /><a href="https://www.stratascale.com/vulnerability-alert-CVE-2025-32463-sudo-chroot" target="_blank" rel="noreferrer noopener">https://www.stratascale.com/vulnerability-alert-CVE-2025-32463-sudo-chroot</a><br /> Polymorphic ZIP Files<br /> A zip file with a corrupt End of Central Directory Record may extract different data depending on the tool used to extract the files.<br /><a href="https://hackarcana.com/article/yet-another-zip-trick" target="_blank" rel="noreferrer noopener">https://hackarcana.com/article/yet-another-zip-trick</a><br /> Cisco Unified Communications Manager Static SSH Credentials Vulnerability<br /> A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted.<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssh-m4UBdpE7" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssh-m4UBdpE7</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9512.mp3</guid><pubDate>Thu, 03 Jul 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66845735/9512.mp3" length="4489604" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9512" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Sudo chroot Elevation of Privilege
 The sudo chroot option can be leveraged by any local user to elevate privileges to root, even if no sudo rules are defined for that user.
https://www.stratascale.com/vulnerability-alert-CVE-2025-32463-sudo-chroot...</itunes:subtitle><itunes:summary><![CDATA[<br /> Sudo chroot Elevation of Privilege<br /> The sudo chroot option can be leveraged by any local user to elevate privileges to root, even if no sudo rules are defined for that user.<br /><a href="https://www.stratascale.com/vulnerability-alert-CVE-2025-32463-sudo-chroot" target="_blank" rel="noreferrer noopener">https://www.stratascale.com/vulnerability-alert-CVE-2025-32463-sudo-chroot</a><br /> Polymorphic ZIP Files<br /> A zip file with a corrupt End of Central Directory Record may extract different data depending on the tool used to extract the files.<br /><a href="https://hackarcana.com/article/yet-another-zip-trick" target="_blank" rel="noreferrer noopener">https://hackarcana.com/article/yet-another-zip-trick</a><br /> Cisco Unified Communications Manager Static SSH Credentials Vulnerability<br /> A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted.<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssh-m4UBdpE7" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssh-m4UBdpE7</a><br />]]></itunes:summary><itunes:duration>321</itunes:duration><itunes:keywords>business,cisco,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,ssh,sudo,ucm,zip</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9512</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday June 30th, 2025: Scattered Spider; AMI BIOS Exploited; Secure Boot Certs Expiring; Microsoft Resliliency Initiative</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-june-30th-2025-scattered-spider-ami-bios-exploited-secure-boot-certs-expiring-microsoft-resliliency-initiative--66800595</link><description><![CDATA[<br /> Scattered Spider Update<br /> The threat actor known as Scattered Spider is in the news again, this time focusing on airlines. But the techniques used by Scattered Spider, social engineering, are still some of the most dangerous techniques used by various threat actors.<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/unc3944-proactive-hardening-recommendations?e=48754805" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/unc3944-proactive-hardening-recommendations?e=48754805</a><br /> AMI BIOS Vulnerability Exploited CVE-2024-54085<br /> A vulnerability in the Redfish remote access software, including AMI s BIOS, is now being exploited.<br /><a href="https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025003.pdf" target="_blank" rel="noreferrer noopener">https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025003.pdf</a><br /><a href="https://eclypsium.com/blog/ami-megarac-vulnerabilities-bmc-part-3/" target="_blank" rel="noreferrer noopener">https://eclypsium.com/blog/ami-megarac-vulnerabilities-bmc-part-3/</a><br /> Act now: Secure Boot certificates expire in June 2026<br /> The Microsoft certificates used in Secure Boot are the basis of trust for operating system security, and all will be expiring beginning June 2026. <br /><a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/act-now-secure-boot-certificates-expire-in-june-2026/4426856" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/blog/windows-itpro-blog/act-now-secure-boot-certificates-expire-in-june-2026/4426856</a><br /> The Windows Resiliency Initiative: Building resilience for a future-ready enterprise<br /> Microsoft announced more details about its future security and resilience strategy for Windows. In particular, security tools will no longer have kernel access, which is supposed to prevent a repeat of the Cloudflare issue, but may also restrict security tools  functionality.<br /><a href="https://blogs.windows.com/windowsexperience/2025/06/26/the-windows-resiliency-initiative-building-resilience-for-a-future-ready-enterprise/" target="_blank" rel="noreferrer noopener">https://blogs.windows.com/windowsexperience/2025/06/26/the-windows-resiliency-initiative-building-resilience-for-a-future-ready-enterprise/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9510.mp3</guid><pubDate>Mon, 30 Jun 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66800595/9510.mp3" length="6297096" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9510" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Scattered Spider Update
 The threat actor known as Scattered Spider is in the news again, this time focusing on airlines. But the techniques used by Scattered Spider, social engineering, are still some of the most dangerous techniques used by...</itunes:subtitle><itunes:summary><![CDATA[<br /> Scattered Spider Update<br /> The threat actor known as Scattered Spider is in the news again, this time focusing on airlines. But the techniques used by Scattered Spider, social engineering, are still some of the most dangerous techniques used by various threat actors.<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/unc3944-proactive-hardening-recommendations?e=48754805" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/unc3944-proactive-hardening-recommendations?e=48754805</a><br /> AMI BIOS Vulnerability Exploited CVE-2024-54085<br /> A vulnerability in the Redfish remote access software, including AMI s BIOS, is now being exploited.<br /><a href="https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025003.pdf" target="_blank" rel="noreferrer noopener">https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025003.pdf</a><br /><a href="https://eclypsium.com/blog/ami-megarac-vulnerabilities-bmc-part-3/" target="_blank" rel="noreferrer noopener">https://eclypsium.com/blog/ami-megarac-vulnerabilities-bmc-part-3/</a><br /> Act now: Secure Boot certificates expire in June 2026<br /> The Microsoft certificates used in Secure Boot are the basis of trust for operating system security, and all will be expiring beginning June 2026. <br /><a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/act-now-secure-boot-certificates-expire-in-june-2026/4426856" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/blog/windows-itpro-blog/act-now-secure-boot-certificates-expire-in-june-2026/4426856</a><br /> The Windows Resiliency Initiative: Building resilience for a future-ready enterprise<br /> Microsoft announced more details about its future security and resilience strategy for Windows. In particular, security tools will no longer have kernel access, which is supposed to prevent a repeat of the Cloudflare issue, but may also restrict security tools  functionality.<br /><a href="https://blogs.windows.com/windowsexperience/2025/06/26/the-windows-resiliency-initiative-building-resilience-for-a-future-ready-enterprise/" target="_blank" rel="noreferrer noopener">https://blogs.windows.com/windowsexperience/2025/06/26/the-windows-resiliency-initiative-building-resilience-for-a-future-ready-enterprise/</a><br />]]></itunes:summary><itunes:duration>450</itunes:duration><itunes:keywords>ami bios,business,certificate,cloudflare,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,redfish,resiliency,scattered spider,secure boot,security,windows</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9510</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, June 27th, 2025: Open-VSX Flaw; Airoha Bluetooth Vulnerablity; Critical Cisco Identity Service Engine Vuln;</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-june-27th-2025-open-vsx-flaw-airoha-bluetooth-vulnerablity-critical-cisco-identity-service-engine-vuln--66766869</link><description><![CDATA[<br /> Open-VSX Flaw Puts Developers at Risk<br /> A flaw in the open-vsx extension marketplace could have let to the compromise of any extension offered by the marketplace.<br /><a href="https://blog.koi.security/marketplace-takeover-how-we-couldve-taken-over-every-developer-using-a-vscode-fork-f0f8cf104d44" target="_blank" rel="noreferrer noopener">https://blog.koi.security/marketplace-takeover-how-we-couldve-taken-over-every-developer-using-a-vscode-fork-f0f8cf104d44</a><br /> Bluetooth Vulnerability Could Allow Eavesdropping<br /> A vulnerability in the widely used Airoha Bluetooth chipset can be used to compromise devices and use them for eavesdropping.<br /><a href="https://insinuator.net/2025/06/airoha-bluetooth-security-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://insinuator.net/2025/06/airoha-bluetooth-security-vulnerabilities/</a><br /> Critical Cisco Identity Services Engine Vulnerability<br /> Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an unauthenticated, remote attacker to issue commands on the underlying operating system as the root user.<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-rce-ZAd2GnJ6" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-rce-ZAd2GnJ6</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9508.mp3</guid><pubDate>Fri, 27 Jun 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66766869/9508.mp3" length="5710948" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9508" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Open-VSX Flaw Puts Developers at Risk
 A flaw in the open-vsx extension marketplace could have let to the compromise of any extension offered by the marketplace....</itunes:subtitle><itunes:summary><![CDATA[<br /> Open-VSX Flaw Puts Developers at Risk<br /> A flaw in the open-vsx extension marketplace could have let to the compromise of any extension offered by the marketplace.<br /><a href="https://blog.koi.security/marketplace-takeover-how-we-couldve-taken-over-every-developer-using-a-vscode-fork-f0f8cf104d44" target="_blank" rel="noreferrer noopener">https://blog.koi.security/marketplace-takeover-how-we-couldve-taken-over-every-developer-using-a-vscode-fork-f0f8cf104d44</a><br /> Bluetooth Vulnerability Could Allow Eavesdropping<br /> A vulnerability in the widely used Airoha Bluetooth chipset can be used to compromise devices and use them for eavesdropping.<br /><a href="https://insinuator.net/2025/06/airoha-bluetooth-security-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://insinuator.net/2025/06/airoha-bluetooth-security-vulnerabilities/</a><br /> Critical Cisco Identity Services Engine Vulnerability<br /> Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an unauthenticated, remote attacker to issue commands on the underlying operating system as the root user.<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-rce-ZAd2GnJ6" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-rce-ZAd2GnJ6</a><br />]]></itunes:summary><itunes:duration>408</itunes:duration><itunes:keywords>airoha,bluetooth,business,cisco,computer,cyber,cybersecurity,daily,hacking,infosec,internet,ise,it,network,news,open-vsx,security,vs-code</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9508</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, June 26th, 2025: Another Netscaler Vuln; CentOS Web Panel Vuln; IP Based Certs</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-june-26th-2025-another-netscaler-vuln-centos-web-panel-vuln-ip-based-certs--66752064</link><description><![CDATA[<br /> NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2025-6543<br /> Citrix patched a memory overflow vulnerability leading to unintended control flow and denial of service.<br /><a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694788" target="_blank" rel="noreferrer noopener">https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694788</a><br /> Remote code execution in CentOS Web Panel - CVE-2025-48703<br /> An arbitrary file upload vulnerability in the user (not admin) part of Web Panel can be used to execute arbitrary code<br /><a href="https://fenrisk.com/rce-centos-webpanel" target="_blank" rel="noreferrer noopener">https://fenrisk.com/rce-centos-webpanel</a><br /> Gogs Arbitrary File Deletion Vulnerability<br /> Due to the insufficient patch for the CVE-2024-39931, it's still possible to delete files under the .git directory and achieve remote command execution.<br /><a href="https://github.com/gogs/gogs/security/advisories/GHSA-wj44-9vcg-wjq7" target="_blank" rel="noreferrer noopener">https://github.com/gogs/gogs/security/advisories/GHSA-wj44-9vcg-wjq7</a><br /> Let s Encrypt Will Soon Issue IP Address-Based Certs<br /> Let s Encrypt is almost ready to issue certificates for IP address SANs from Let's Encrypt's production environment. They'll only be available under the short-lived profile (which has a 6-day validity period), and that profile will remain allowlist-only for a while.<br /><a href="https://community.letsencrypt.org/t/getting-ready-to-issue-ip-address-certificates/238777" target="_blank" rel="noreferrer noopener">https://community.letsencrypt.org/t/getting-ready-to-issue-ip-address-certificates/238777</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9506.mp3</guid><pubDate>Thu, 26 Jun 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66752064/9506.mp3" length="4948133" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9506" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2025-6543
 Citrix patched a memory overflow vulnerability leading to unintended control flow and denial of service....</itunes:subtitle><itunes:summary><![CDATA[<br /> NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2025-6543<br /> Citrix patched a memory overflow vulnerability leading to unintended control flow and denial of service.<br /><a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694788" target="_blank" rel="noreferrer noopener">https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694788</a><br /> Remote code execution in CentOS Web Panel - CVE-2025-48703<br /> An arbitrary file upload vulnerability in the user (not admin) part of Web Panel can be used to execute arbitrary code<br /><a href="https://fenrisk.com/rce-centos-webpanel" target="_blank" rel="noreferrer noopener">https://fenrisk.com/rce-centos-webpanel</a><br /> Gogs Arbitrary File Deletion Vulnerability<br /> Due to the insufficient patch for the CVE-2024-39931, it's still possible to delete files under the .git directory and achieve remote command execution.<br /><a href="https://github.com/gogs/gogs/security/advisories/GHSA-wj44-9vcg-wjq7" target="_blank" rel="noreferrer noopener">https://github.com/gogs/gogs/security/advisories/GHSA-wj44-9vcg-wjq7</a><br /> Let s Encrypt Will Soon Issue IP Address-Based Certs<br /> Let s Encrypt is almost ready to issue certificates for IP address SANs from Let's Encrypt's production environment. They'll only be available under the short-lived profile (which has a 6-day validity period), and that profile will remain allowlist-only for a while.<br /><a href="https://community.letsencrypt.org/t/getting-ready-to-issue-ip-address-certificates/238777" target="_blank" rel="noreferrer noopener">https://community.letsencrypt.org/t/getting-ready-to-issue-ip-address-certificates/238777</a><br />]]></itunes:summary><itunes:duration>353</itunes:duration><itunes:keywords>adc,business,centos,certificates,citrix,computer,cyber,cybersecurity,daily,dos,gogs,hacking,infosec,it,lets encrypt,netscaler,network,news,security,web panel</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9506</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, June 24th, 2025: Telnet/SSH Scan Evolution; Fake Sonicwall Software; File-Fix vs Click-Fix</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-june-24th-2025-telnet-ssh-scan-evolution-fake-sonicwall-software-file-fix-vs-click-fix--66735005</link><description><![CDATA[<br /> Quick Password Brute Forcing Evolution Statistics<br /> After collecting usernames and passwords from our ssh and telnet honeypots for about a decade, I took a look back at how scans changed. Attackers are attempting more passwords in each scans than they used to, but the average length of passwords did not change.<br /><a href="https://isc.sans.edu/diary/Quick%20Password%20Brute%20Forcing%20Evolution%20Statistics/32068" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Quick%20Password%20Brute%20Forcing%20Evolution%20Statistics/32068</a><br /> Introducing FileFix   A New Alternative to ClickFix Attacks<br /> Attackers may trick the user into copy/pasting strings into file explorer, which will execute commands similar to the ClickFix attack that tricks users into copy pasting the command into the start menu s cmd feature.<br /><a href="https://www.mobile-hacker.com/2025/06/24/introducing-filefix-a-new-alternative-to-clickfix-attacks/" target="_blank" rel="noreferrer noopener">https://www.mobile-hacker.com/2025/06/24/introducing-filefix-a-new-alternative-to-clickfix-attacks/</a><br /> Threat Actors Modify and Re-Create Commercial Software to Steal User s Information<br /> A fake Sonicwall Netextender clone will steal user s credentials<br /><a href="https://www.sonicwall.com/blog/threat-actors-modify-and-re-create-commercial-software-to-steal-users-information" target="_blank" rel="noreferrer noopener">https://www.sonicwall.com/blog/threat-actors-modify-and-re-create-commercial-software-to-steal-users-information</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9504.mp3</guid><pubDate>Wed, 25 Jun 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66735005/9504.mp3" length="3404306" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9504" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Quick Password Brute Forcing Evolution Statistics
 After collecting usernames and passwords from our ssh and telnet honeypots for about a decade, I took a look back at how scans changed. Attackers are attempting more passwords in each scans than...</itunes:subtitle><itunes:summary><![CDATA[<br /> Quick Password Brute Forcing Evolution Statistics<br /> After collecting usernames and passwords from our ssh and telnet honeypots for about a decade, I took a look back at how scans changed. Attackers are attempting more passwords in each scans than they used to, but the average length of passwords did not change.<br /><a href="https://isc.sans.edu/diary/Quick%20Password%20Brute%20Forcing%20Evolution%20Statistics/32068" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Quick%20Password%20Brute%20Forcing%20Evolution%20Statistics/32068</a><br /> Introducing FileFix   A New Alternative to ClickFix Attacks<br /> Attackers may trick the user into copy/pasting strings into file explorer, which will execute commands similar to the ClickFix attack that tricks users into copy pasting the command into the start menu s cmd feature.<br /><a href="https://www.mobile-hacker.com/2025/06/24/introducing-filefix-a-new-alternative-to-clickfix-attacks/" target="_blank" rel="noreferrer noopener">https://www.mobile-hacker.com/2025/06/24/introducing-filefix-a-new-alternative-to-clickfix-attacks/</a><br /> Threat Actors Modify and Re-Create Commercial Software to Steal User s Information<br /> A fake Sonicwall Netextender clone will steal user s credentials<br /><a href="https://www.sonicwall.com/blog/threat-actors-modify-and-re-create-commercial-software-to-steal-users-information" target="_blank" rel="noreferrer noopener">https://www.sonicwall.com/blog/threat-actors-modify-and-re-create-commercial-software-to-steal-users-information</a><br />]]></itunes:summary><itunes:duration>243</itunes:duration><itunes:keywords>brute forcing,business,clickfix,computer,cyber,cybersecurity,daily,filefix,hacking,infosec,internet,it,network,news,password,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9504</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, June 24th, 2025: Ichano ATHome IP Camera Scans; Netscaler Vulnerability; WinRar Vulnerability</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-june-24th-2025-ichano-athome-ip-camera-scans-netscaler-vulnerability-winrar-vulnerability--66717267</link><description><![CDATA[<br /> Scans for Ichano AtHome IP Cameras<br /> A couple days ago, a few sources started scanning for the username super_yg and the password 123. This is associated with Ichano IP Camera software.<br /><a href="https://isc.sans.edu/diary/Scans%20for%20Ichano%20AtHome%20IP%20Cameras/32062" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20Ichano%20AtHome%20IP%20Cameras/32062</a><br /> Critical Netscaler Security Update CVE-2025-5777<br /> CVE 2025-5777 is a critical severity vulnerability impacting NetScaler Gateway, i.e. if NetScaler has been configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.<br /><a href="https://www.netscaler.com/blog/news/critical-security-updates-for-netscaler-netscaler-gateway-and-netscaler-console/" target="_blank" rel="noreferrer noopener">https://www.netscaler.com/blog/news/critical-security-updates-for-netscaler-netscaler-gateway-and-netscaler-console/</a><br /> WinRar Vulnerability CVE-2025-6218<br /> WinRar may be tricked into extracting files into attacker-determined locations, possibly leading to remote code execution<br /><a href="https://www.win-rar.com/singlenewsview.html?&amp;L=0&amp;tx_ttnews%5Btt_news%5D=276&amp;cHash=b5165454d983fc9717bc8748901a64f9" target="_blank" rel="noreferrer noopener">https://www.win-rar.com/singlenewsview.html?&amp;L=0&amp;tx_ttnews%5Btt_news%5D=276&amp;cHash=b5165454d983fc9717bc8748901a64f9</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9502.mp3</guid><pubDate>Tue, 24 Jun 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66717267/9502.mp3" length="4259964" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9502" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Scans for Ichano AtHome IP Cameras
 A couple days ago, a few sources started scanning for the username super_yg and the password 123. This is associated with Ichano IP Camera software....</itunes:subtitle><itunes:summary><![CDATA[<br /> Scans for Ichano AtHome IP Cameras<br /> A couple days ago, a few sources started scanning for the username super_yg and the password 123. This is associated with Ichano IP Camera software.<br /><a href="https://isc.sans.edu/diary/Scans%20for%20Ichano%20AtHome%20IP%20Cameras/32062" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20Ichano%20AtHome%20IP%20Cameras/32062</a><br /> Critical Netscaler Security Update CVE-2025-5777<br /> CVE 2025-5777 is a critical severity vulnerability impacting NetScaler Gateway, i.e. if NetScaler has been configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.<br /><a href="https://www.netscaler.com/blog/news/critical-security-updates-for-netscaler-netscaler-gateway-and-netscaler-console/" target="_blank" rel="noreferrer noopener">https://www.netscaler.com/blog/news/critical-security-updates-for-netscaler-netscaler-gateway-and-netscaler-console/</a><br /> WinRar Vulnerability CVE-2025-6218<br /> WinRar may be tricked into extracting files into attacker-determined locations, possibly leading to remote code execution<br /><a href="https://www.win-rar.com/singlenewsview.html?&amp;L=0&amp;tx_ttnews%5Btt_news%5D=276&amp;cHash=b5165454d983fc9717bc8748901a64f9" target="_blank" rel="noreferrer noopener">https://www.win-rar.com/singlenewsview.html?&amp;L=0&amp;tx_ttnews%5Btt_news%5D=276&amp;cHash=b5165454d983fc9717bc8748901a64f9</a><br />]]></itunes:summary><itunes:duration>304</itunes:duration><itunes:keywords>athome,business,computer,cyber,cybersecurity,daily,hacking,ichano,infosec,internet,ip camera,ip cameras,it,netscaler,network,news,security,winrar</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9502</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, June 23rd, 2025: ADS and Python; More Secure Cloud PCs; Zend.to Path Traversal; Parser Differentials</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-june-23rd-2025-ads-and-python-more-secure-cloud-pcs-zend-to-path-traversal-parser-differentials--66703106</link><description><![CDATA[<br /> ADS &amp; Python Tools<br /> Didier explains how to use his tools cut-bytes.py and filescanner to extract information from alternate data streams.<br /><a href="https://isc.sans.edu/diary/ADS%20%26%20Python%20Tools/32058" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/ADS%20%26%20Python%20Tools/32058</a><br /> Enhanced security defaults for Windows 365 Cloud PCs<br /> Microsoft announced more secure default configurations for its Windows 365 Cloud PC offerings.<br /><a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/enhanced-security-defaults-for-windows-365-cloud-pcs/4424914" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/blog/windows-itpro-blog/enhanced-security-defaults-for-windows-365-cloud-pcs/4424914</a><br /> CVE-2025-34508: Another File Sharing Application, Another Path Traversal<br /> Horizon3 reveals details of a recently patched directory traversal vulnerability in zend.to.<br /><a href="https://horizon3.ai/attack-research/attack-blogs/cve-2025-34508-another-file-sharing-application-another-path-traversal/" target="_blank" rel="noreferrer noopener">https://horizon3.ai/attack-research/attack-blogs/cve-2025-34508-another-file-sharing-application-another-path-traversal/</a><br /> Unexpected security footguns in Go's parsers<br /> Go parsers for JSON and XML are not always compatible and can parse data in unexpected ways. This blog by Trails of Bits goes over the various security implications of this behaviour.<br /><a href="https://blog.trailofbits.com/2025/06/17/unexpected-security-footguns-in-gos-parsers/" target="_blank" rel="noreferrer noopener">https://blog.trailofbits.com/2025/06/17/unexpected-security-footguns-in-gos-parsers/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9500.mp3</guid><pubDate>Mon, 23 Jun 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66703106/9500.mp3" length="4715210" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9500" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 ADS &amp;amp; Python Tools
 Didier explains how to use his tools cut-bytes.py and filescanner to extract information from alternate data streams.
https://isc.sans.edu/diary/ADS%20%26%20Python%20Tools/32058
 Enhanced security defaults for Windows 365...</itunes:subtitle><itunes:summary><![CDATA[<br /> ADS &amp; Python Tools<br /> Didier explains how to use his tools cut-bytes.py and filescanner to extract information from alternate data streams.<br /><a href="https://isc.sans.edu/diary/ADS%20%26%20Python%20Tools/32058" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/ADS%20%26%20Python%20Tools/32058</a><br /> Enhanced security defaults for Windows 365 Cloud PCs<br /> Microsoft announced more secure default configurations for its Windows 365 Cloud PC offerings.<br /><a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/enhanced-security-defaults-for-windows-365-cloud-pcs/4424914" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/blog/windows-itpro-blog/enhanced-security-defaults-for-windows-365-cloud-pcs/4424914</a><br /> CVE-2025-34508: Another File Sharing Application, Another Path Traversal<br /> Horizon3 reveals details of a recently patched directory traversal vulnerability in zend.to.<br /><a href="https://horizon3.ai/attack-research/attack-blogs/cve-2025-34508-another-file-sharing-application-another-path-traversal/" target="_blank" rel="noreferrer noopener">https://horizon3.ai/attack-research/attack-blogs/cve-2025-34508-another-file-sharing-application-another-path-traversal/</a><br /> Unexpected security footguns in Go's parsers<br /> Go parsers for JSON and XML are not always compatible and can parse data in unexpected ways. This blog by Trails of Bits goes over the various security implications of this behaviour.<br /><a href="https://blog.trailofbits.com/2025/06/17/unexpected-security-footguns-in-gos-parsers/" target="_blank" rel="noreferrer noopener">https://blog.trailofbits.com/2025/06/17/unexpected-security-footguns-in-gos-parsers/</a><br />]]></itunes:summary><itunes:duration>337</itunes:duration><itunes:keywords>ads,business,computer,cyber,cybersecurity,daily,go,hacking,infosec,internet,it,json,network,news,parsers,python,security,xml,zend.to</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9500</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, June 20th, 2025: New Employee Phishing; Malicious Tech Support Links; Social Engineering App Sepecific Passwords</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-june-20th-2025-new-employee-phishing-malicious-tech-support-links-social-engineering-app-sepecific-passwords--66644867</link><description><![CDATA[<br /> How Long Until the Phishing Starts? About Two Weeks<br /> After setting up a Google Workspace and adding a new user, it took only two weeks for the new employee to receive somewhat targeted phishing emails.<br /><a href="https://isc.sans.edu/diary/How%20Long%20Until%20the%20Phishing%20Starts%3F%20About%20Two%20Weeks/32052" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20Long%20Until%20the%20Phishing%20Starts%3F%20About%20Two%20Weeks/32052</a><br /> Scammers hijack websites of Bank of America, Netflix, Microsoft, and more to insert fake phone numbers<br /> Scammers are placing Google ads that point to legitimate companies  sites, but are injecting malicious text into the page advertising fake tech support numbers<br /><a href="https://www.malwarebytes.com/blog/news/2025/06/scammers-hijack-websites-of-bank-of-america-netflix-microsoft-and-more-to-insert-fake-phone-number" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/news/2025/06/scammers-hijack-websites-of-bank-of-america-netflix-microsoft-and-more-to-insert-fake-phone-number</a><br /> What s in an ASP? Creative Phishing Attack on Prominent Academics and Critics of Russia<br /> Targeted attacks are tricking victims into creating app-specific passwords to Google resources.<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/creative-phishing-academics-critics-of-russia" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/creative-phishing-academics-critics-of-russia</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9498.mp3</guid><pubDate>Fri, 20 Jun 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66644867/9498.mp3" length="4852953" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9498" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 How Long Until the Phishing Starts? About Two Weeks
 After setting up a Google Workspace and adding a new user, it took only two weeks for the new employee to receive somewhat targeted phishing emails....</itunes:subtitle><itunes:summary><![CDATA[<br /> How Long Until the Phishing Starts? About Two Weeks<br /> After setting up a Google Workspace and adding a new user, it took only two weeks for the new employee to receive somewhat targeted phishing emails.<br /><a href="https://isc.sans.edu/diary/How%20Long%20Until%20the%20Phishing%20Starts%3F%20About%20Two%20Weeks/32052" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20Long%20Until%20the%20Phishing%20Starts%3F%20About%20Two%20Weeks/32052</a><br /> Scammers hijack websites of Bank of America, Netflix, Microsoft, and more to insert fake phone numbers<br /> Scammers are placing Google ads that point to legitimate companies  sites, but are injecting malicious text into the page advertising fake tech support numbers<br /><a href="https://www.malwarebytes.com/blog/news/2025/06/scammers-hijack-websites-of-bank-of-america-netflix-microsoft-and-more-to-insert-fake-phone-number" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/news/2025/06/scammers-hijack-websites-of-bank-of-america-netflix-microsoft-and-more-to-insert-fake-phone-number</a><br /> What s in an ASP? Creative Phishing Attack on Prominent Academics and Critics of Russia<br /> Targeted attacks are tricking victims into creating app-specific passwords to Google resources.<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/creative-phishing-academics-critics-of-russia" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/creative-phishing-academics-critics-of-russia</a><br />]]></itunes:summary><itunes:duration>347</itunes:duration><itunes:keywords>app specific,asp,business,computer,cyber,cybersecurity,daily,google,hacking,infosec,internet,it,network,news,phishing,scammer,security,workspace</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9498</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, June 16th, 2025: Extracing Data from JPEG; Windows Recall Export; Anubis Wiper; Mitel Vuln and PoC</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-june-16th-2025-extracing-data-from-jpeg-windows-recall-export-anubis-wiper-mitel-vuln-and-poc--66585820</link><description><![CDATA[<br /> Extracting Data From JPEGs<br /> Didier shows how to efficiently extract data from JPEGs using his tool jpegdump.py<br /><a href="https://isc.sans.edu/diary/A%20JPEG%20With%20A%20Payload/32048" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20JPEG%20With%20A%20Payload/32048</a><br /> Windows Recall Export in Europe<br /> In its latest insider build for Windows 11, Microsoft is testing an export feature for data stored by Recall. The feature is limited to European users and requires that you note an encryption key that will be displayed only once as Recall is enabled.<br /><a href="https://blogs.windows.com/windows-insider/2025/06/13/announcing-windows-11-insider-preview-build-26120-4441-beta-channel/" target="_blank" rel="noreferrer noopener">https://blogs.windows.com/windows-insider/2025/06/13/announcing-windows-11-insider-preview-build-26120-4441-beta-channel/</a><br /> Anubis Ransomware Now Wipes Data<br /> The Anubis ransomware, usually known for standard double extortion, is now also wiping data preventing any recovery even if you pay the ransom.<br /><a href="https://www.trendmicro.com/en_us/research/25/f/anubis-a-closer-look-at-an-emerging-ransomware.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_us/research/25/f/anubis-a-closer-look-at-an-emerging-ransomware.html</a><br /> Mitel Vulnerabilities CVE-2025-47188<br /> Mitel this week patched a critical path traversal vulnerability (sadly, no CVE), and Infoguard Labs published a PoC exploit for an older file upload vulnerability.<br /><a href="https://labs.infoguard.ch/posts/cve-2025-47188_mitel_phone_unauthenticated_rce/" target="_blank" rel="noreferrer noopener">https://labs.infoguard.ch/posts/cve-2025-47188_mitel_phone_unauthenticated_rce/</a> <a href="https://www.mitel.com/support/mitel-product-security-advisory-misa-2025-0007" target="_blank" rel="noreferrer noopener">https://www.mitel.com/support/mitel-product-security-advisory-misa-2025-0007</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9496.mp3</guid><pubDate>Tue, 17 Jun 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66585820/9496.mp3" length="4857064" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9496" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Extracting Data From JPEGs
 Didier shows how to efficiently extract data from JPEGs using his tool jpegdump.py
https://isc.sans.edu/diary/A%20JPEG%20With%20A%20Payload/32048
 Windows Recall Export in Europe
 In its latest insider build for Windows...</itunes:subtitle><itunes:summary><![CDATA[<br /> Extracting Data From JPEGs<br /> Didier shows how to efficiently extract data from JPEGs using his tool jpegdump.py<br /><a href="https://isc.sans.edu/diary/A%20JPEG%20With%20A%20Payload/32048" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20JPEG%20With%20A%20Payload/32048</a><br /> Windows Recall Export in Europe<br /> In its latest insider build for Windows 11, Microsoft is testing an export feature for data stored by Recall. The feature is limited to European users and requires that you note an encryption key that will be displayed only once as Recall is enabled.<br /><a href="https://blogs.windows.com/windows-insider/2025/06/13/announcing-windows-11-insider-preview-build-26120-4441-beta-channel/" target="_blank" rel="noreferrer noopener">https://blogs.windows.com/windows-insider/2025/06/13/announcing-windows-11-insider-preview-build-26120-4441-beta-channel/</a><br /> Anubis Ransomware Now Wipes Data<br /> The Anubis ransomware, usually known for standard double extortion, is now also wiping data preventing any recovery even if you pay the ransom.<br /><a href="https://www.trendmicro.com/en_us/research/25/f/anubis-a-closer-look-at-an-emerging-ransomware.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_us/research/25/f/anubis-a-closer-look-at-an-emerging-ransomware.html</a><br /> Mitel Vulnerabilities CVE-2025-47188<br /> Mitel this week patched a critical path traversal vulnerability (sadly, no CVE), and Infoguard Labs published a PoC exploit for an older file upload vulnerability.<br /><a href="https://labs.infoguard.ch/posts/cve-2025-47188_mitel_phone_unauthenticated_rce/" target="_blank" rel="noreferrer noopener">https://labs.infoguard.ch/posts/cve-2025-47188_mitel_phone_unauthenticated_rce/</a> <a href="https://www.mitel.com/support/mitel-product-security-advisory-misa-2025-0007" target="_blank" rel="noreferrer noopener">https://www.mitel.com/support/mitel-product-security-advisory-misa-2025-0007</a><br />]]></itunes:summary><itunes:duration>347</itunes:duration><itunes:keywords>anubis,business,computer,cyber,cybersecurity,daily,hacking,infosec,it,jpeg,jpegdump,mitel,network,news,ransomware,recall,ringtone,security,windows,wiper</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9496</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, June 16th, 2025: Katz Stealer in JPG; JavaScript Attacks; Reviving expired Discord Invites for Evil</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-june-16th-2025-katz-stealer-in-jpg-javascript-attacks-reviving-expired-discord-invites-for-evil--66570748</link><description><![CDATA[<br /> Katz Stealer in JPG<br /> Xavier found some multistage malware that uses an Excel Spreadsheet and an HTA file to load an image that includes embeded a copy of Katz stealer.<br /><a href="https://isc.sans.edu/diary/More+Steganography/32044" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/More+Steganography/32044</a><br /><a href="https://unit42.paloaltonetworks.com/malicious-javascript-using-jsfiretruck-as-obfuscation/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/malicious-javascript-using-jsfiretruck-as-obfuscation/</a><br /> JavaScript obfuscated with JSF*CK is being used on over 200,000 websites to direct victims to malware<br /> Expired Discord Invite Links Used for Malware Distribution<br /> Expired discord invite links are revived as vanity links to direct victims to malware sites<br /><a href="https://research.checkpoint.com/2025/from-trust-to-threat-hijacked-discord-invites-used-for-multi-stage-malware-delivery/" target="_blank" rel="noreferrer noopener">https://research.checkpoint.com/2025/from-trust-to-threat-hijacked-discord-invites-used-for-multi-stage-malware-delivery/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9494.mp3</guid><pubDate>Mon, 16 Jun 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66570748/9494.mp3" length="5665299" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9494" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Katz Stealer in JPG
 Xavier found some multistage malware that uses an Excel Spreadsheet and an HTA file to load an image that includes embeded a copy of Katz stealer.
https://isc.sans.edu/diary/More+Steganography/32044...</itunes:subtitle><itunes:summary><![CDATA[<br /> Katz Stealer in JPG<br /> Xavier found some multistage malware that uses an Excel Spreadsheet and an HTA file to load an image that includes embeded a copy of Katz stealer.<br /><a href="https://isc.sans.edu/diary/More+Steganography/32044" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/More+Steganography/32044</a><br /><a href="https://unit42.paloaltonetworks.com/malicious-javascript-using-jsfiretruck-as-obfuscation/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/malicious-javascript-using-jsfiretruck-as-obfuscation/</a><br /> JavaScript obfuscated with JSF*CK is being used on over 200,000 websites to direct victims to malware<br /> Expired Discord Invite Links Used for Malware Distribution<br /> Expired discord invite links are revived as vanity links to direct victims to malware sites<br /><a href="https://research.checkpoint.com/2025/from-trust-to-threat-hijacked-discord-invites-used-for-multi-stage-malware-delivery/" target="_blank" rel="noreferrer noopener">https://research.checkpoint.com/2025/from-trust-to-threat-hijacked-discord-invites-used-for-multi-stage-malware-delivery/</a><br />]]></itunes:summary><itunes:duration>405</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,discord,hacking,infosec,internet,invite,it,javascript,jpeg,jpg,katz,malware,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9494</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, June 13th, 2025: Honeypot Scripts; EchoLeak MSFT Copilot Vuln; Thunderbolt mailbox URL Vuln;</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-june-13th-2025-honeypot-scripts-echoleak-msft-copilot-vuln-thunderbolt-mailbox-url-vuln--66542422</link><description><![CDATA[<br /> Automated Tools to Assist with DShield Honeypot Investigations<br /><a href="https://isc.sans.edu/diary/Automated%20Tools%20to%20Assist%20with%20DShield%20Honeypot%20Investigations%20%5BGuest%20Diary%5D/32038" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Automated%20Tools%20to%20Assist%20with%20DShield%20Honeypot%20Investigations%20%5BGuest%20Diary%5D/32038</a><br /> EchoLeak: Zero-Click Microsoft 365 Copilot Data Leak<br /> Microsoft fixed a vulnerability in Copilot that could have been abused to exfiltrate data from Copilot users. Copilot mishandled instructions an attacker included in documents inspected by Copilot and executed them.<br /><a href="https://www.aim.security/lp/aim-labs-echoleak-blogpost" target="_blank" rel="noreferrer noopener">https://www.aim.security/lp/aim-labs-echoleak-blogpost</a><br /> Thunderbolt Vulnerability<br /> Thunderbolt users may be tricked into downloading arbitrary files if an email includes a mailbox:/// URL.<br /><a href="https://www.mozilla.org/en-US/security/advisories/mfsa2025-49/" target="_blank" rel="noreferrer noopener">https://www.mozilla.org/en-US/security/advisories/mfsa2025-49/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9492.mp3</guid><pubDate>Fri, 13 Jun 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66542422/9492.mp3" length="4801156" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9492" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Automated Tools to Assist with DShield Honeypot Investigations
https://isc.sans.edu/diary/Automated%20Tools%20to%20Assist%20with%20DShield%20Honeypot%20Investigations%20%5BGuest%20Diary%5D/32038
 EchoLeak: Zero-Click Microsoft 365 Copilot Data Leak...</itunes:subtitle><itunes:summary><![CDATA[<br /> Automated Tools to Assist with DShield Honeypot Investigations<br /><a href="https://isc.sans.edu/diary/Automated%20Tools%20to%20Assist%20with%20DShield%20Honeypot%20Investigations%20%5BGuest%20Diary%5D/32038" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Automated%20Tools%20to%20Assist%20with%20DShield%20Honeypot%20Investigations%20%5BGuest%20Diary%5D/32038</a><br /> EchoLeak: Zero-Click Microsoft 365 Copilot Data Leak<br /> Microsoft fixed a vulnerability in Copilot that could have been abused to exfiltrate data from Copilot users. Copilot mishandled instructions an attacker included in documents inspected by Copilot and executed them.<br /><a href="https://www.aim.security/lp/aim-labs-echoleak-blogpost" target="_blank" rel="noreferrer noopener">https://www.aim.security/lp/aim-labs-echoleak-blogpost</a><br /> Thunderbolt Vulnerability<br /> Thunderbolt users may be tricked into downloading arbitrary files if an email includes a mailbox:/// URL.<br /><a href="https://www.mozilla.org/en-US/security/advisories/mfsa2025-49/" target="_blank" rel="noreferrer noopener">https://www.mozilla.org/en-US/security/advisories/mfsa2025-49/</a><br />]]></itunes:summary><itunes:duration>343</itunes:duration><itunes:keywords>business,computer,copilot,cyber,cybersecurity,daily,echoleak,hacking,honeypot tools,infosec,internet,it,network,news,security,thunderbolt</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9492</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, June 12th, 2025: Quasar RAT; Windows 11 24H2 Delay; SMB Client Vuln PoC; Connectwise Signing Keys; KDE Telnet code</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-june-12th-2025-quasar-rat-windows-11-24h2-delay-smb-client-vuln-poc-connectwise-signing-keys-kde-telnet-code--66520821</link><description><![CDATA[<br /> Quasar RAT Delivered Through Bat Files<br /> Xavier is walking you through a quick reverse analysis of a script that will injection code extracted from a PNG image to implement a Quasar RAT.<br /><a href="https://isc.sans.edu/diary/Quasar%20RAT%20Delivered%20Through%20Bat%20Files/32036" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Quasar%20RAT%20Delivered%20Through%20Bat%20Files/32036</a><br /> Delayed Windows 11 24H2 Rollout<br /> Microsoft slightly throttled the rollout of windows 11 24H2 due to issues stemming from the patch Tuesday fixes.<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#3570" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#3570</a><br /> An In-Depth Analysis of CVE-2025-33073<br /> Patch Tuesday fixed an already exploited SMB client vulnerability. A blog by Synacktiv explains the nature of the issue and how to exploit it.<br /><a href="https://www.synacktiv.com/en/publications/ntlm-reflection-is-dead-long-live-ntlm-reflection-an-in-depth-analysis-of-cve-2025" target="_blank" rel="noreferrer noopener">https://www.synacktiv.com/en/publications/ntlm-reflection-is-dead-long-live-ntlm-reflection-an-in-depth-analysis-of-cve-2025</a><br /> Connectwise Rotating Signing Certificates<br /> Connectwise is rotating signing certificates after a recent compromise, and will release a new version of its Screen share software soon to harden its configuration.<br /><a href="https://www.connectwise.com/company/trust/advisories" target="_blank" rel="noreferrer noopener">https://www.connectwise.com/company/trust/advisories</a><br /> KDE Telnet URL Vulnerablity<br /> The Konsole delivered as part of KDE may be abused to execute arbitrary code via  telnet  URLs.<br /><a href="https://kde.org/info/security/advisory-20250609-1.txt" target="_blank" rel="noreferrer noopener">https://kde.org/info/security/advisory-20250609-1.txt</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9490.mp3</guid><pubDate>Thu, 12 Jun 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66520821/9490.mp3" length="5431869" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9490" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Quasar RAT Delivered Through Bat Files
 Xavier is walking you through a quick reverse analysis of a script that will injection code extracted from a PNG image to implement a Quasar RAT....</itunes:subtitle><itunes:summary><![CDATA[<br /> Quasar RAT Delivered Through Bat Files<br /> Xavier is walking you through a quick reverse analysis of a script that will injection code extracted from a PNG image to implement a Quasar RAT.<br /><a href="https://isc.sans.edu/diary/Quasar%20RAT%20Delivered%20Through%20Bat%20Files/32036" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Quasar%20RAT%20Delivered%20Through%20Bat%20Files/32036</a><br /> Delayed Windows 11 24H2 Rollout<br /> Microsoft slightly throttled the rollout of windows 11 24H2 due to issues stemming from the patch Tuesday fixes.<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#3570" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#3570</a><br /> An In-Depth Analysis of CVE-2025-33073<br /> Patch Tuesday fixed an already exploited SMB client vulnerability. A blog by Synacktiv explains the nature of the issue and how to exploit it.<br /><a href="https://www.synacktiv.com/en/publications/ntlm-reflection-is-dead-long-live-ntlm-reflection-an-in-depth-analysis-of-cve-2025" target="_blank" rel="noreferrer noopener">https://www.synacktiv.com/en/publications/ntlm-reflection-is-dead-long-live-ntlm-reflection-an-in-depth-analysis-of-cve-2025</a><br /> Connectwise Rotating Signing Certificates<br /> Connectwise is rotating signing certificates after a recent compromise, and will release a new version of its Screen share software soon to harden its configuration.<br /><a href="https://www.connectwise.com/company/trust/advisories" target="_blank" rel="noreferrer noopener">https://www.connectwise.com/company/trust/advisories</a><br /> KDE Telnet URL Vulnerablity<br /> The Konsole delivered as part of KDE may be abused to execute arbitrary code via  telnet  URLs.<br /><a href="https://kde.org/info/security/advisory-20250609-1.txt" target="_blank" rel="noreferrer noopener">https://kde.org/info/security/advisory-20250609-1.txt</a><br />]]></itunes:summary><itunes:duration>388</itunes:duration><itunes:keywords>bat,business,computer,conectwise,cyber,cybersecurity,daily,hacking,infosec,it,kde,konsole,network,news,quasar,rat,security,smb,telnet,windows</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9490</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, June 11th, 2025: Microsoft Patch Tuesday; Acrobat Patches</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-june-11th-2025-microsoft-patch-tuesday-acrobat-patches--66502695</link><description><![CDATA[<br /> Microsoft Patch Tuesday<br /> Microsoft today released patches for 67 vulnerabilities. 10 of these vulnerabilities are rated critical. One vulnerability has already been exploited and another vulnerability has been publicly disclosed before today.<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20June%202025/32032" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20June%202025/32032</a><br /> Adobe Vulnerabilities<br /> Adobe released patches for 7 different applications. Two significant ones are Adobe Commerce and Adobe Acrobat Reader. All vulnerabilities patched for Adobe Commerce can only be exploited by an authenticated user. The Adobe Acrobat Reader vulnerabilities are exploited by a user opening a crafted PDF, and the exploit may execute arbitrary code.<br /><a href="https://helpx.adobe.com/security/Home.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/Home.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9488.mp3</guid><pubDate>Wed, 11 Jun 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66502695/9488.mp3" length="5861925" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9488" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Microsoft Patch Tuesday
 Microsoft today released patches for 67 vulnerabilities. 10 of these vulnerabilities are rated critical. One vulnerability has already been exploited and another vulnerability has been publicly disclosed before today....</itunes:subtitle><itunes:summary><![CDATA[<br /> Microsoft Patch Tuesday<br /> Microsoft today released patches for 67 vulnerabilities. 10 of these vulnerabilities are rated critical. One vulnerability has already been exploited and another vulnerability has been publicly disclosed before today.<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20June%202025/32032" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20June%202025/32032</a><br /> Adobe Vulnerabilities<br /> Adobe released patches for 7 different applications. Two significant ones are Adobe Commerce and Adobe Acrobat Reader. All vulnerabilities patched for Adobe Commerce can only be exploited by an authenticated user. The Adobe Acrobat Reader vulnerabilities are exploited by a user opening a crafted PDF, and the exploit may execute arbitrary code.<br /><a href="https://helpx.adobe.com/security/Home.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/Home.html</a><br />]]></itunes:summary><itunes:duration>419</itunes:duration><itunes:keywords>acrobat,adobe,business,commerce,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microsoft,network,news,patches,pdf,security,tuesday</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9488</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast June, Tuesday, June 10th, 2025: Octosql; Mirai vs. Wazuh DNS4EU; Wordpress Fair Package Manager</title><link>https://www.spreaker.com/episode/sans-stormcast-june-tuesday-june-10th-2025-octosql-mirai-vs-wazuh-dns4eu-wordpress-fair-package-manager--66486586</link><description><![CDATA[<br /> OctoSQL &amp; Vulnerability Data<br /> OctoSQL is a neat tool to query files in different formats using SQL. This can, for example, be used to query the JSON vulnerability files from CISA or NVD and create interesting joins between different files.<br /><a href="https://isc.sans.edu/diary/OctoSQL+Vulnerability+Data/32026" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/OctoSQL+Vulnerability+Data/32026</a><br /> Mirai vs. Wazuh<br /> The Mirai botnet has now been observed exploiting a vulnerability in the open-source EDR tool Wazuh.<br /><a href="https://www.akamai.com/blog/security-research/botnets-flaw-mirai-spreads-through-wazuh-vulnerability" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/botnets-flaw-mirai-spreads-through-wazuh-vulnerability</a><br /> DNS4EU<br /> The European Union created its own public recursive resolver to offer a public resolver compliant with European privacy laws. This resolver is currently operated by ENISA, but the intent is to have a commercial entity operate and support it by a commercial entity.<br /><a href="https://www.joindns4.eu/" target="_blank" rel="noreferrer noopener">https://www.joindns4.eu/</a><br /> WordPress FAIR Package Manager<br /> Recent legal issues around different WordPress-related entities have made it more difficult to maintain diverse sources of WordPress plugins. With WordPress plugins usually being responsible for many of the security issues, the Linux Foundation has come forward to support the  FAIR Package Manager,  a tool intended to simplify the management of WordPress packages.<br /><a href="https://github.com/fairpm" target="_blank" rel="noreferrer noopener">https://github.com/fairpm</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9486.mp3</guid><pubDate>Tue, 10 Jun 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66486586/9486.mp3" length="5176261" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9486" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 OctoSQL &amp;amp; Vulnerability Data
 OctoSQL is a neat tool to query files in different formats using SQL. This can, for example, be used to query the JSON vulnerability files from CISA or NVD and create interesting joins between different files....</itunes:subtitle><itunes:summary><![CDATA[<br /> OctoSQL &amp; Vulnerability Data<br /> OctoSQL is a neat tool to query files in different formats using SQL. This can, for example, be used to query the JSON vulnerability files from CISA or NVD and create interesting joins between different files.<br /><a href="https://isc.sans.edu/diary/OctoSQL+Vulnerability+Data/32026" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/OctoSQL+Vulnerability+Data/32026</a><br /> Mirai vs. Wazuh<br /> The Mirai botnet has now been observed exploiting a vulnerability in the open-source EDR tool Wazuh.<br /><a href="https://www.akamai.com/blog/security-research/botnets-flaw-mirai-spreads-through-wazuh-vulnerability" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/botnets-flaw-mirai-spreads-through-wazuh-vulnerability</a><br /> DNS4EU<br /> The European Union created its own public recursive resolver to offer a public resolver compliant with European privacy laws. This resolver is currently operated by ENISA, but the intent is to have a commercial entity operate and support it by a commercial entity.<br /><a href="https://www.joindns4.eu/" target="_blank" rel="noreferrer noopener">https://www.joindns4.eu/</a><br /> WordPress FAIR Package Manager<br /> Recent legal issues around different WordPress-related entities have made it more difficult to maintain diverse sources of WordPress plugins. With WordPress plugins usually being responsible for many of the security issues, the Linux Foundation has come forward to support the  FAIR Package Manager,  a tool intended to simplify the management of WordPress packages.<br /><a href="https://github.com/fairpm" target="_blank" rel="noreferrer noopener">https://github.com/fairpm</a><br />]]></itunes:summary><itunes:duration>370</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dns,dns4eu,fair,hacking,infosec,internet,it,mirai,network,news,octosql,security,wazuh,wordpress</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9486</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast June, June 9th, 2025: Extracting PNG Data; GlueStack Packages Backdoor; MacOS targeted by Clickfix; INETPUB restore script</title><link>https://www.spreaker.com/episode/sans-stormcast-june-june-9th-2025-extracting-png-data-gluestack-packages-backdoor-macos-targeted-by-clickfix-inetpub-restore-script--66467092</link><description><![CDATA[<br /> Extracting With pngdump.py<br /> Didier extended his pngdump.py script to make it easier to extract additional data appended to the end of the image file.<br /><a href="https://isc.sans.edu/diary/Extracting%20With%20pngdump.py/32022" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Extracting%20With%20pngdump.py/32022</a><br /> 16 React Native Packages for GlueStack Backdoored Overnight<br /> 16 npm packages with over a million weekly downloads between them were compromised. The compromised packages include a remote admin tool that was seen before in similar attacks.<br /><a href="https://www.aikido.dev/blog/supply-chain-attack-on-react-native-aria-ecosystem" target="_blank" rel="noreferrer noopener">https://www.aikido.dev/blog/supply-chain-attack-on-react-native-aria-ecosystem</a><br /> Atomic MacOS Stealer Exploits Clickfix<br /> MacOS users are now also targeted by fake captchas, tricking users into running exploit code.<br /><a href="https://www.cloudsek.com/blog/amos-variant-distributed-via-clickfix-in-spectrum-themed-dynamic-delivery-campaign-by-russian-speaking-hackers" target="_blank" rel="noreferrer noopener">https://www.cloudsek.com/blog/amos-variant-distributed-via-clickfix-in-spectrum-themed-dynamic-delivery-campaign-by-russian-speaking-hackers</a><br /> Microsoft INETPUB Script<br /> Microsoft published a simple PowerShell script to restore the inetpub folder in case you removed it by mistake.<br /><a href="https://www.powershellgallery.com/packages/Set-InetpubFolderAcl/1.0" target="_blank" rel="noreferrer noopener">https://www.powershellgallery.com/packages/Set-InetpubFolderAcl/1.0</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9484.mp3</guid><pubDate>Mon, 09 Jun 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66467092/9484.mp3" length="4805586" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9484" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Extracting With pngdump.py
 Didier extended his pngdump.py script to make it easier to extract additional data appended to the end of the image file.
https://isc.sans.edu/diary/Extracting%20With%20pngdump.py/32022
 16 React Native Packages for...</itunes:subtitle><itunes:summary><![CDATA[<br /> Extracting With pngdump.py<br /> Didier extended his pngdump.py script to make it easier to extract additional data appended to the end of the image file.<br /><a href="https://isc.sans.edu/diary/Extracting%20With%20pngdump.py/32022" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Extracting%20With%20pngdump.py/32022</a><br /> 16 React Native Packages for GlueStack Backdoored Overnight<br /> 16 npm packages with over a million weekly downloads between them were compromised. The compromised packages include a remote admin tool that was seen before in similar attacks.<br /><a href="https://www.aikido.dev/blog/supply-chain-attack-on-react-native-aria-ecosystem" target="_blank" rel="noreferrer noopener">https://www.aikido.dev/blog/supply-chain-attack-on-react-native-aria-ecosystem</a><br /> Atomic MacOS Stealer Exploits Clickfix<br /> MacOS users are now also targeted by fake captchas, tricking users into running exploit code.<br /><a href="https://www.cloudsek.com/blog/amos-variant-distributed-via-clickfix-in-spectrum-themed-dynamic-delivery-campaign-by-russian-speaking-hackers" target="_blank" rel="noreferrer noopener">https://www.cloudsek.com/blog/amos-variant-distributed-via-clickfix-in-spectrum-themed-dynamic-delivery-campaign-by-russian-speaking-hackers</a><br /> Microsoft INETPUB Script<br /> Microsoft published a simple PowerShell script to restore the inetpub folder in case you removed it by mistake.<br /><a href="https://www.powershellgallery.com/packages/Set-InetpubFolderAcl/1.0" target="_blank" rel="noreferrer noopener">https://www.powershellgallery.com/packages/Set-InetpubFolderAcl/1.0</a><br />]]></itunes:summary><itunes:duration>343</itunes:duration><itunes:keywords>amos,atomix,backdoor,business,clickfix,computer,cyber,cybersecurity,daily,gluestack,hacking,inetpub,infosec,it,microsoft,network,news,pngdump.py,security,stealer</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9484</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, June 6th, 2025: Fake Zoom Clients; Python tarfile vulnerability; HPE Insight Remote Support Patch</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-june-6th-2025-fake-zoom-clients-python-tarfile-vulnerability-hpe-insight-remote-support-patch--66414848</link><description><![CDATA[<br /> Be Careful With Fake Zoom Client Downloads<br /> Miscreants are tricking victims into downloading fake Zoom clients (and likely other meeting software) by first sending them fake meeting invites that direct victims to a page that offers malware for download as an  update  to the Zoom client.<br /><a href="https://isc.sans.edu/diary/Be%20Careful%20With%20Fake%20Zoom%20Client%20Downloads/32014" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Be%20Careful%20With%20Fake%20Zoom%20Client%20Downloads/32014</a><br /> Python tarfile Vulnerability<br /> Recently, the Python tarfile module introduced a  filter  option to help mitigate some of the insecure behavior common to software unpacking archives. This filter is, however, not working quite as well as it should.<br /><a href="https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/" target="_blank" rel="noreferrer noopener">https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/</a><br /> Hewlett Packard Enterprise Insight Remote Support processAttachmentDataStream Directory Traversal Remote Code Execution Vulnerability<br /> HP fixed, among other vulnerabilities, a critical remote code execution vulnerability in Insight Remote Support (IRS)<br /><a href="https://www.zerodayinitiative.com/advisories/ZDI-25-325/" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/advisories/ZDI-25-325/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9482.mp3</guid><pubDate>Fri, 06 Jun 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66414848/9482.mp3" length="4214817" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9482" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Be Careful With Fake Zoom Client Downloads
 Miscreants are tricking victims into downloading fake Zoom clients (and likely other meeting software) by first sending them fake meeting invites that direct victims to a page that offers malware for...</itunes:subtitle><itunes:summary><![CDATA[<br /> Be Careful With Fake Zoom Client Downloads<br /> Miscreants are tricking victims into downloading fake Zoom clients (and likely other meeting software) by first sending them fake meeting invites that direct victims to a page that offers malware for download as an  update  to the Zoom client.<br /><a href="https://isc.sans.edu/diary/Be%20Careful%20With%20Fake%20Zoom%20Client%20Downloads/32014" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Be%20Careful%20With%20Fake%20Zoom%20Client%20Downloads/32014</a><br /> Python tarfile Vulnerability<br /> Recently, the Python tarfile module introduced a  filter  option to help mitigate some of the insecure behavior common to software unpacking archives. This filter is, however, not working quite as well as it should.<br /><a href="https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/" target="_blank" rel="noreferrer noopener">https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/</a><br /> Hewlett Packard Enterprise Insight Remote Support processAttachmentDataStream Directory Traversal Remote Code Execution Vulnerability<br /> HP fixed, among other vulnerabilities, a critical remote code execution vulnerability in Insight Remote Support (IRS)<br /><a href="https://www.zerodayinitiative.com/advisories/ZDI-25-325/" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/advisories/ZDI-25-325/</a><br />]]></itunes:summary><itunes:duration>301</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,hp,infosec,insight,internet,irs,it,network,news,python,remote,security,support,tarfile,zoom</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9482</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, June 5th, 2025: Phishing Comment Trick; AWS default logging mode change; Cisco Backdoor Fixed; Infoblox Vulnerabili</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-june-5th-2025-phishing-comment-trick-aws-default-logging-mode-change-cisco-backdoor-fixed-infoblox-vulnerabili--66402990</link><description><![CDATA[<br /> Phishing e-mail that hides malicious links from Outlook users<br /> Jan found a phishing email that hides the malicious link from Outlook users. The email uses specific HTML comment clauses Outlook interprets to render or not render specific parts of the email s HTML code. Jan suggests that the phishing email is intented to not expose users of <br /><a href="https://isc.sans.edu/diary/Phishing%20e-mail%20that%20hides%20malicious%20link%20from%20Outlook%20users/32010" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Phishing%20e-mail%20that%20hides%20malicious%20link%20from%20Outlook%20users/32010</a><br /> Amazon changing default logging from blocking to non-blocking<br /> Amazon will change the default logging mode from blocking to non-blocking. Non-blocking logging will not stop the application if logging fails, but may result in a loss of logs.<br /><a href="https://aws.amazon.com/blogs/containers/preventing-log-loss-with-non-blocking-mode-in-the-awslogs-container-log-driver/" target="_blank" rel="noreferrer noopener">https://aws.amazon.com/blogs/containers/preventing-log-loss-with-non-blocking-mode-in-the-awslogs-container-log-driver/</a><br /> Cisco Removes Backdoor<br /> Cisco fixed a Cisco Identity Services Engine on Cloud Platforms Static Credential Vulnerability. <br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-aws-static-cred-FPMjUcm7" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-aws-static-cred-FPMjUcm7</a><br /> Infoblox Vulnerability Details disclosed<br /> Details regarding several vulnerabilities recently patched in Infoblox s NetMRI have been made public. In particular an unauthenticated remote code execution issue should be considered critical. <br /><a href="https://rhinosecuritylabs.com/research/infoblox-multiple-cves/" target="_blank" rel="noreferrer noopener">https://rhinosecuritylabs.com/research/infoblox-multiple-cves/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9480.mp3</guid><pubDate>Thu, 05 Jun 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66402990/9480.mp3" length="4567881" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9480" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Phishing e-mail that hides malicious links from Outlook users
 Jan found a phishing email that hides the malicious link from Outlook users. The email uses specific HTML comment clauses Outlook interprets to render or not render specific parts of the...</itunes:subtitle><itunes:summary><![CDATA[<br /> Phishing e-mail that hides malicious links from Outlook users<br /> Jan found a phishing email that hides the malicious link from Outlook users. The email uses specific HTML comment clauses Outlook interprets to render or not render specific parts of the email s HTML code. Jan suggests that the phishing email is intented to not expose users of <br /><a href="https://isc.sans.edu/diary/Phishing%20e-mail%20that%20hides%20malicious%20link%20from%20Outlook%20users/32010" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Phishing%20e-mail%20that%20hides%20malicious%20link%20from%20Outlook%20users/32010</a><br /> Amazon changing default logging from blocking to non-blocking<br /> Amazon will change the default logging mode from blocking to non-blocking. Non-blocking logging will not stop the application if logging fails, but may result in a loss of logs.<br /><a href="https://aws.amazon.com/blogs/containers/preventing-log-loss-with-non-blocking-mode-in-the-awslogs-container-log-driver/" target="_blank" rel="noreferrer noopener">https://aws.amazon.com/blogs/containers/preventing-log-loss-with-non-blocking-mode-in-the-awslogs-container-log-driver/</a><br /> Cisco Removes Backdoor<br /> Cisco fixed a Cisco Identity Services Engine on Cloud Platforms Static Credential Vulnerability. <br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-aws-static-cred-FPMjUcm7" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-aws-static-cred-FPMjUcm7</a><br /> Infoblox Vulnerability Details disclosed<br /> Details regarding several vulnerabilities recently patched in Infoblox s NetMRI have been made public. In particular an unauthenticated remote code execution issue should be considered critical. <br /><a href="https://rhinosecuritylabs.com/research/infoblox-multiple-cves/" target="_blank" rel="noreferrer noopener">https://rhinosecuritylabs.com/research/infoblox-multiple-cves/</a><br />]]></itunes:summary><itunes:duration>326</itunes:duration><itunes:keywords>amazon,backdoor,business,cisco,computer,cyber,cybersecurity,daily,hacking,infoblox,infosec,internet,it,logging,netmri,network,news,outlook,phishing,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9480</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, June 4th, 2025: vBulletin Exploited; Chrome 0-Day Patch; Roundcube RCE Patch; Multiple HP StoreOnce Vulns Patched</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-june-4th-2025-vbulletin-exploited-chrome-0-day-patch-roundcube-rce-patch-multiple-hp-storeonce-vulns-patched--66389422</link><description><![CDATA[<br /> vBulletin Exploits CVE-2025-48827, CVE-2025-48828<br /> We do see exploit attempts for the vBulletin flaw disclosed about a week ago. The flaw is only exploitable if vBulltin is run on PHP 8.1, and was patched over a year ago. However, vBulltin never disclosed the type of vulnerability that was patched.<br /><a href="https://isc.sans.edu/diary/vBulletin%20Exploits%20%28CVE-2025-48827%2C%20CVE-2025-48828%29/32006" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/vBulletin%20Exploits%20%28CVE-2025-48827%2C%20CVE-2025-48828%29/32006</a><br /> Google Chrome 0-Day Patched<br /> Google released a security update for Google Chrome patching three flaws. One of these is already being exploited.<br /><a href="https://chromereleases.googleblog.com/" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/</a><br /> Roundcube Update<br /> Roundcube patched a vulnerability that allows any authenticated user to execute arbitrary code.<br /><a href="https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10" target="_blank" rel="noreferrer noopener">https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10</a><br /> HP Vulnerabilities in StoreOnce<br /> HP patched multiple vulnerabilities in StoreOnce. These issues could lead to remote code execution<br /><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbst04847en_us&amp;docLocale=en_US" target="_blank" rel="noreferrer noopener">https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbst04847en_us&amp;docLocale=en_US</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9478.mp3</guid><pubDate>Wed, 04 Jun 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66389422/9478.mp3" length="6229847" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9478" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 vBulletin Exploits CVE-2025-48827, CVE-2025-48828
 We do see exploit attempts for the vBulletin flaw disclosed about a week ago. The flaw is only exploitable if vBulltin is run on PHP 8.1, and was patched over a year ago. However, vBulltin never...</itunes:subtitle><itunes:summary><![CDATA[<br /> vBulletin Exploits CVE-2025-48827, CVE-2025-48828<br /> We do see exploit attempts for the vBulletin flaw disclosed about a week ago. The flaw is only exploitable if vBulltin is run on PHP 8.1, and was patched over a year ago. However, vBulltin never disclosed the type of vulnerability that was patched.<br /><a href="https://isc.sans.edu/diary/vBulletin%20Exploits%20%28CVE-2025-48827%2C%20CVE-2025-48828%29/32006" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/vBulletin%20Exploits%20%28CVE-2025-48827%2C%20CVE-2025-48828%29/32006</a><br /> Google Chrome 0-Day Patched<br /> Google released a security update for Google Chrome patching three flaws. One of these is already being exploited.<br /><a href="https://chromereleases.googleblog.com/" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/</a><br /> Roundcube Update<br /> Roundcube patched a vulnerability that allows any authenticated user to execute arbitrary code.<br /><a href="https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10" target="_blank" rel="noreferrer noopener">https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10</a><br /> HP Vulnerabilities in StoreOnce<br /> HP patched multiple vulnerabilities in StoreOnce. These issues could lead to remote code execution<br /><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbst04847en_us&amp;docLocale=en_US" target="_blank" rel="noreferrer noopener">https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbst04847en_us&amp;docLocale=en_US</a><br />]]></itunes:summary><itunes:duration>445</itunes:duration><itunes:keywords>0-day,business,chrome,computer,cyber,cybersecurity,daily,google,hacking,hp,infosec,internet,it,network,news,roundcube,security,storeonce,vbulletin</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9478</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, June 3rd, 2025: Windows SSH C2; Google Removes CAs from trusted list; MSFT issues Emergency Patch to fix Crash issue</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-june-3rd-2025-windows-ssh-c2-google-removes-cas-from-trusted-list-msft-issues-emergency-patch-to-fix-crash-issue--66377219</link><description><![CDATA[<br /> Simple SSH Backdoor<br /> Xavier came across a simple SSH backdoor taking advantage of the ssh client preinstalled on recent Windows systems. The backdoor is implemented via an SSH configuration file that instructs the SSH client to connect to a remote system and forward a shell on a random port. This will make the shell accessible to anybody able to connect to the C2 host. <br /><a href="https://isc.sans.edu/diary/Simple%20SSH%20Backdoor/32000" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Simple%20SSH%20Backdoor/32000</a><br /> Google Chrome to Distrust CAs<br /> Google Chrome will remove the Chunghwa Telecom and Netlock certificate authorities from its list of trusted CAs. Any certificates issued after July 31st will not be trusted. Certificates issued before the deadline will be trusted until they expire.<br /><a href="https://security.googleblog.com/2025/05/sustaining-digital-certificate-security-chrome-root-store-changes.html" target="_blank" rel="noreferrer noopener">https://security.googleblog.com/2025/05/sustaining-digital-certificate-security-chrome-root-store-changes.html</a><br /> Microsoft Emergency Update to Fix Crashes Caused by May Patch<br /> Microsoft released an emergency update for a bug caused by one of the patches released in May. Due to the bug, systems may not restart after the patch is applied. This affects, first of all, virtual systems running in Azure and HyperV but apparently has also affected some physical systems.<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-23h2#kb5058405-might-fail-to-install-with-recovery-error-0xc0000098-in-acpi-sys" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-23h2#kb5058405-might-fail-to-install-with-recovery-error-0xc0000098-in-acpi-sys</a><br /> Qualcomm Adreno Graphics Processing Unit Patch (Exploited!) <br /> Qualcomm released an update for the driver for its Adreno GPU. The patched vulnerability is already being exploited against Android devices.<br /><a href="https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2025-bulletin.html" target="_blank" rel="noreferrer noopener">https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2025-bulletin.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9476.mp3</guid><pubDate>Tue, 03 Jun 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66377219/9476.mp3" length="5137952" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9476" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Simple SSH Backdoor
 Xavier came across a simple SSH backdoor taking advantage of the ssh client preinstalled on recent Windows systems. The backdoor is implemented via an SSH configuration file that instructs the SSH client to connect to a remote...</itunes:subtitle><itunes:summary><![CDATA[<br /> Simple SSH Backdoor<br /> Xavier came across a simple SSH backdoor taking advantage of the ssh client preinstalled on recent Windows systems. The backdoor is implemented via an SSH configuration file that instructs the SSH client to connect to a remote system and forward a shell on a random port. This will make the shell accessible to anybody able to connect to the C2 host. <br /><a href="https://isc.sans.edu/diary/Simple%20SSH%20Backdoor/32000" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Simple%20SSH%20Backdoor/32000</a><br /> Google Chrome to Distrust CAs<br /> Google Chrome will remove the Chunghwa Telecom and Netlock certificate authorities from its list of trusted CAs. Any certificates issued after July 31st will not be trusted. Certificates issued before the deadline will be trusted until they expire.<br /><a href="https://security.googleblog.com/2025/05/sustaining-digital-certificate-security-chrome-root-store-changes.html" target="_blank" rel="noreferrer noopener">https://security.googleblog.com/2025/05/sustaining-digital-certificate-security-chrome-root-store-changes.html</a><br /> Microsoft Emergency Update to Fix Crashes Caused by May Patch<br /> Microsoft released an emergency update for a bug caused by one of the patches released in May. Due to the bug, systems may not restart after the patch is applied. This affects, first of all, virtual systems running in Azure and HyperV but apparently has also affected some physical systems.<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-23h2#kb5058405-might-fail-to-install-with-recovery-error-0xc0000098-in-acpi-sys" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-23h2#kb5058405-might-fail-to-install-with-recovery-error-0xc0000098-in-acpi-sys</a><br /> Qualcomm Adreno Graphics Processing Unit Patch (Exploited!) <br /> Qualcomm released an update for the driver for its Adreno GPU. The patched vulnerability is already being exploited against Android devices.<br /><a href="https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2025-bulletin.html" target="_blank" rel="noreferrer noopener">https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2025-bulletin.html</a><br />]]></itunes:summary><itunes:duration>367</itunes:duration><itunes:keywords>adreno,business,chungwa,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,netlock,network,news,qualcom,security,ssh</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9476</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, May 2nd, 2025: PNG with RAT; Cisco IOS XE WLC Exploit; vBulletin Exploit</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-may-2nd-2025-png-with-rat-cisco-ios-xe-wlc-exploit-vbulletin-exploit--66366631</link><description><![CDATA[<br /> A PNG Image With an Embedded Gift<br /> Xavier shows how Python code attached to a PNG image can be used to implement a command and control channel or a complete remote admin kit.<br /><a href="https://isc.sans.edu/diary/A+PNG+Image+With+an+Embedded+Gift/31998" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A+PNG+Image+With+an+Embedded+Gift/31998</a><br /> Cisco IOS XE WLC Arbitrary File Upload Vulnerability (CVE-2025-20188) Analysis<br /> Horizon3 analyzed a recently patched flaw in Cisco Wireless Controllers. This arbitrary file upload flaw can easily be used to execute arbitrary code.<br /><a href="https://horizon3.ai/attack-research/attack-blogs/cisco-ios-xe-wlc-arbitrary-file-upload-vulnerability-cve-2025-20188-analysis/" target="_blank" rel="noreferrer noopener">https://horizon3.ai/attack-research/attack-blogs/cisco-ios-xe-wlc-arbitrary-file-upload-vulnerability-cve-2025-20188-analysis/</a><br /> Don't Call That "Protected" Method: Dissecting an N-Day vBulletin RCE<br /> A change in PHP 8.1 can expose methods previously expected to be  safe . vBulletin fixed a related flaw about a year ago without explicitly highlighting the security impact of the fix. A blog post now exposed the flaw and provided exploit examples. We have seen exploit attempts against honeypots starting May 25th, two days after the blog was published.<br /><a href="https://karmainsecurity.com/dont-call-that-protected-method-vbulletin-rce" target="_blank" rel="noreferrer noopener">https://karmainsecurity.com/dont-call-that-protected-method-vbulletin-rce</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9474.mp3</guid><pubDate>Mon, 02 Jun 2025 09:53:08 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66366631/9474.mp3" length="4788965" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9474" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 A PNG Image With an Embedded Gift
 Xavier shows how Python code attached to a PNG image can be used to implement a command and control channel or a complete remote admin kit.
https://isc.sans.edu/diary/A+PNG+Image+With+an+Embedded+Gift/31998
 Cisco...</itunes:subtitle><itunes:summary><![CDATA[<br /> A PNG Image With an Embedded Gift<br /> Xavier shows how Python code attached to a PNG image can be used to implement a command and control channel or a complete remote admin kit.<br /><a href="https://isc.sans.edu/diary/A+PNG+Image+With+an+Embedded+Gift/31998" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A+PNG+Image+With+an+Embedded+Gift/31998</a><br /> Cisco IOS XE WLC Arbitrary File Upload Vulnerability (CVE-2025-20188) Analysis<br /> Horizon3 analyzed a recently patched flaw in Cisco Wireless Controllers. This arbitrary file upload flaw can easily be used to execute arbitrary code.<br /><a href="https://horizon3.ai/attack-research/attack-blogs/cisco-ios-xe-wlc-arbitrary-file-upload-vulnerability-cve-2025-20188-analysis/" target="_blank" rel="noreferrer noopener">https://horizon3.ai/attack-research/attack-blogs/cisco-ios-xe-wlc-arbitrary-file-upload-vulnerability-cve-2025-20188-analysis/</a><br /> Don't Call That "Protected" Method: Dissecting an N-Day vBulletin RCE<br /> A change in PHP 8.1 can expose methods previously expected to be  safe . vBulletin fixed a related flaw about a year ago without explicitly highlighting the security impact of the fix. A blog post now exposed the flaw and provided exploit examples. We have seen exploit attempts against honeypots starting May 25th, two days after the blog was published.<br /><a href="https://karmainsecurity.com/dont-call-that-protected-method-vbulletin-rce" target="_blank" rel="noreferrer noopener">https://karmainsecurity.com/dont-call-that-protected-method-vbulletin-rce</a><br />]]></itunes:summary><itunes:duration>342</itunes:duration><itunes:keywords>business,cisco,computer,cyber,cybersecurity,daily,exploit,hacking,infosec,internet,it,network,news,php,png,security,vbulletin,wlc</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9474</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, May 30th 2025: Alternate Data Streams; Connectwise Breach; Google Calendar C2;</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-may-30th-2025-alternate-data-streams-connectwise-breach-google-calendar-c2--66335480</link><description><![CDATA[<br /> Alternate Data Streams: Adversary Defense Evasion and Detection<br /> Good Primer of alternate data streams and how they are abused, as well as how to detect and defend against ADS abuse.<br /><a href="https://isc.sans.edu/diary/Alternate%20Data%20Streams%20%3F%20Adversary%20Defense%20Evasion%20and%20Detection%20%5BGuest%20Diary%5D/31990" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Alternate%20Data%20Streams%20%3F%20Adversary%20Defense%20Evasion%20and%20Detection%20%5BGuest%20Diary%5D/31990</a><br /> Connectwise Breach Affects ScreenConnect Customers<br /> Connectwise s ScreenConnect solution was compromised, leading to attacks against a small number of customers. This is yet another example of how attackers are taking advantage of remote access solutions.<br /><a href="https://www.connectwise.com/company/trust/advisories" target="_blank" rel="noreferrer noopener">https://www.connectwise.com/company/trust/advisories</a><br /> Mark Your Calendar: APT41 Innovative Tactics<br /> Google detected attacks leveraging Google s calendar solution as a command and control channel.<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/apt41-innovative-tactics" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/apt41-innovative-tactics</a><br /> Webs of Deception: Using the SANS ICS Kill Chain to Flip the Advantage to the Defender<br /> Defending a small Industrial Control System (ICS) against sophisticated threats can seem futile. The resource disparity between small ICS defenders and sophisticated attackers poses a significant security challenge.<br /><a href="https://www.sans.edu/cyber-research/webs-deception-using-sans-ics-kill-chain-flip-advantage-defender/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/webs-deception-using-sans-ics-kill-chain-flip-advantage-defender/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9472.mp3</guid><pubDate>Fri, 30 May 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66335480/9472.mp3" length="11580837" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9472" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Alternate Data Streams: Adversary Defense Evasion and Detection
 Good Primer of alternate data streams and how they are abused, as well as how to detect and defend against ADS abuse....</itunes:subtitle><itunes:summary><![CDATA[<br /> Alternate Data Streams: Adversary Defense Evasion and Detection<br /> Good Primer of alternate data streams and how they are abused, as well as how to detect and defend against ADS abuse.<br /><a href="https://isc.sans.edu/diary/Alternate%20Data%20Streams%20%3F%20Adversary%20Defense%20Evasion%20and%20Detection%20%5BGuest%20Diary%5D/31990" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Alternate%20Data%20Streams%20%3F%20Adversary%20Defense%20Evasion%20and%20Detection%20%5BGuest%20Diary%5D/31990</a><br /> Connectwise Breach Affects ScreenConnect Customers<br /> Connectwise s ScreenConnect solution was compromised, leading to attacks against a small number of customers. This is yet another example of how attackers are taking advantage of remote access solutions.<br /><a href="https://www.connectwise.com/company/trust/advisories" target="_blank" rel="noreferrer noopener">https://www.connectwise.com/company/trust/advisories</a><br /> Mark Your Calendar: APT41 Innovative Tactics<br /> Google detected attacks leveraging Google s calendar solution as a command and control channel.<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/apt41-innovative-tactics" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/apt41-innovative-tactics</a><br /> Webs of Deception: Using the SANS ICS Kill Chain to Flip the Advantage to the Defender<br /> Defending a small Industrial Control System (ICS) against sophisticated threats can seem futile. The resource disparity between small ICS defenders and sophisticated attackers poses a significant security challenge.<br /><a href="https://www.sans.edu/cyber-research/webs-deception-using-sans-ics-kill-chain-flip-advantage-defender/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/webs-deception-using-sans-ics-kill-chain-flip-advantage-defender/</a><br />]]></itunes:summary><itunes:duration>827</itunes:duration><itunes:keywords>ads,alternate data streams,apt41,business,calendar,computer,connectwise,cyber,cybersecurity,daily,deceptoin,google,hacking,ics,infosec,it,network,news,screenconnect,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9472</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday May 29th 2025: LLM Assisted Analysis; MSP Ransomware; Everetz Vulnerability</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-may-29th-2025-llm-assisted-analysis-msp-ransomware-everetz-vulnerability--66322212</link><description><![CDATA[<br /> Exploring a Use Case of Artificial Intelligence Assistance with Understanding an Attack<br /> Jennifer Wilson took a  weird string  found in a recent honeypot sample and worked with ChatGPT to figure out what it is all about.<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Exploring%20a%20Use%20Case%20of%20Artificial%20Intelligence%20Assistance%20with%20Understanding%20an%20Attack/31980" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Exploring%20a%20Use%20Case%20of%20Artificial%20Intelligence%20Assistance%20with%20Understanding%20an%20Attack/31980</a><br /> Ransomware Deployed via SimpleHelp Vulnerabilities<br /> Ransomware actors are using vulnerabilities in SimpleHelp to gain access to victim s networks via MSPs. The exploited vulnerabilities were patched in January.<br /><a href="https://news.sophos.com/en-us/2025/05/27/dragonforce-actors-target-simplehelp-vulnerabilities-to-attack-msp-customers/" target="_blank" rel="noreferrer noopener">https://news.sophos.com/en-us/2025/05/27/dragonforce-actors-target-simplehelp-vulnerabilities-to-attack-msp-customers/</a><br /> OS Command Injection in Everetz Equipment<br /> Broadcast equipment manufactured by Everetz is susceptible to an OS command injection vulnerability. Everetz has not responded to researchers reporting the vulnerability so far and there is no patch available.<br /><a href="https://www.onekey.com/resource/security-advisory-remote-code-execution-on-evertz-svdn-cve-2025-4009" target="_blank" rel="noreferrer noopener">https://www.onekey.com/resource/security-advisory-remote-code-execution-on-evertz-svdn-cve-2025-4009</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9470.mp3</guid><pubDate>Thu, 29 May 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66322212/9470.mp3" length="5188381" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9470" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Exploring a Use Case of Artificial Intelligence Assistance with Understanding an Attack
 Jennifer Wilson took a  weird string  found in a recent honeypot sample and worked with ChatGPT to figure out what it is all about....</itunes:subtitle><itunes:summary><![CDATA[<br /> Exploring a Use Case of Artificial Intelligence Assistance with Understanding an Attack<br /> Jennifer Wilson took a  weird string  found in a recent honeypot sample and worked with ChatGPT to figure out what it is all about.<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Exploring%20a%20Use%20Case%20of%20Artificial%20Intelligence%20Assistance%20with%20Understanding%20an%20Attack/31980" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Exploring%20a%20Use%20Case%20of%20Artificial%20Intelligence%20Assistance%20with%20Understanding%20an%20Attack/31980</a><br /> Ransomware Deployed via SimpleHelp Vulnerabilities<br /> Ransomware actors are using vulnerabilities in SimpleHelp to gain access to victim s networks via MSPs. The exploited vulnerabilities were patched in January.<br /><a href="https://news.sophos.com/en-us/2025/05/27/dragonforce-actors-target-simplehelp-vulnerabilities-to-attack-msp-customers/" target="_blank" rel="noreferrer noopener">https://news.sophos.com/en-us/2025/05/27/dragonforce-actors-target-simplehelp-vulnerabilities-to-attack-msp-customers/</a><br /> OS Command Injection in Everetz Equipment<br /> Broadcast equipment manufactured by Everetz is susceptible to an OS command injection vulnerability. Everetz has not responded to researchers reporting the vulnerability so far and there is no patch available.<br /><a href="https://www.onekey.com/resource/security-advisory-remote-code-execution-on-evertz-svdn-cve-2025-4009" target="_blank" rel="noreferrer noopener">https://www.onekey.com/resource/security-advisory-remote-code-execution-on-evertz-svdn-cve-2025-4009</a><br />]]></itunes:summary><itunes:duration>371</itunes:duration><itunes:keywords>business,chatgpt,computer,cyber,cybersecurity,daily,everetz,hacking,infosec,internet,it,llm,network,news,os command injection,ransomware,security,simplehelp,telegram</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9470</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday May 28th 2025: Securing authorized_keys; ADAuditPlus SQL Injection; Dero Miner vs Docker API</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-may-28th-2025-securing-authorized-keys-adauditplus-sql-injection-dero-miner-vs-docker-api--66305707</link><description><![CDATA[<br /> SSH authorized_keys File<br /> One of the most common techniques used by many bots is to add rogue keys to the authorized_keys file, implementing an SSH backdoor. Managing these files and detecting unauthorized changes is not hard and should be done if you operate Unix systems.<br /><a href="https://isc.sans.edu/diary/Securing%20Your%20SSH%20authorized_keys%20File/31986" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Securing%20Your%20SSH%20authorized_keys%20File/31986</a><br /> REMOTE COMMAND EXECUTION ON SMARTBEDDED METEOBRIDGE (CVE-2025-4008)<br /> Weatherstation software Meteobridge suffers from an easily exploitable unauthenticated remote code execution vulnerability<br /><a href="https://www.onekey.com/resource/security-advisory-remote-command-execution-on-smartbedded-meteobridge-cve-2025-4008" target="_blank" rel="noreferrer noopener">https://www.onekey.com/resource/security-advisory-remote-command-execution-on-smartbedded-meteobridge-cve-2025-4008</a><br /><a href="https://forum.meteohub.de/viewtopic.php?t=18687" target="_blank" rel="noreferrer noopener">https://forum.meteohub.de/viewtopic.php?t=18687</a><br /> Manageengine ADAuditPlus SQL Injection<br /> Zoho patched two SQL Injection vulnerabilities in its ManageEngine ADAuditPlus product<br /><a href="https://www.manageengine.com/products/active-directory-audit/cve-2025-41407.html" target="_blank" rel="noreferrer noopener">https://www.manageengine.com/products/active-directory-audit/cve-2025-41407.html</a><br /><a href="https://www.manageengine.com/products/active-directory-audit/cve-2025-36527.html" target="_blank" rel="noreferrer noopener">https://www.manageengine.com/products/active-directory-audit/cve-2025-36527.html</a><br /> Dero Miner Infects Containers through Docker API<br /> Kaspersky found yet another botnet infecting docker containers to spread crypto coin miners. The initial access happens via exposed docker APIs.<br /><a href="https://securelist.com/dero-miner-infects-containers-through-docker-api/116546/" target="_blank" rel="noreferrer noopener">https://securelist.com/dero-miner-infects-containers-through-docker-api/116546/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9468.mp3</guid><pubDate>Wed, 28 May 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66305707/9468.mp3" length="5570809" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9468" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 SSH authorized_keys File
 One of the most common techniques used by many bots is to add rogue keys to the authorized_keys file, implementing an SSH backdoor. Managing these files and detecting unauthorized changes is not hard and should be done if...</itunes:subtitle><itunes:summary><![CDATA[<br /> SSH authorized_keys File<br /> One of the most common techniques used by many bots is to add rogue keys to the authorized_keys file, implementing an SSH backdoor. Managing these files and detecting unauthorized changes is not hard and should be done if you operate Unix systems.<br /><a href="https://isc.sans.edu/diary/Securing%20Your%20SSH%20authorized_keys%20File/31986" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Securing%20Your%20SSH%20authorized_keys%20File/31986</a><br /> REMOTE COMMAND EXECUTION ON SMARTBEDDED METEOBRIDGE (CVE-2025-4008)<br /> Weatherstation software Meteobridge suffers from an easily exploitable unauthenticated remote code execution vulnerability<br /><a href="https://www.onekey.com/resource/security-advisory-remote-command-execution-on-smartbedded-meteobridge-cve-2025-4008" target="_blank" rel="noreferrer noopener">https://www.onekey.com/resource/security-advisory-remote-command-execution-on-smartbedded-meteobridge-cve-2025-4008</a><br /><a href="https://forum.meteohub.de/viewtopic.php?t=18687" target="_blank" rel="noreferrer noopener">https://forum.meteohub.de/viewtopic.php?t=18687</a><br /> Manageengine ADAuditPlus SQL Injection<br /> Zoho patched two SQL Injection vulnerabilities in its ManageEngine ADAuditPlus product<br /><a href="https://www.manageengine.com/products/active-directory-audit/cve-2025-41407.html" target="_blank" rel="noreferrer noopener">https://www.manageengine.com/products/active-directory-audit/cve-2025-41407.html</a><br /><a href="https://www.manageengine.com/products/active-directory-audit/cve-2025-36527.html" target="_blank" rel="noreferrer noopener">https://www.manageengine.com/products/active-directory-audit/cve-2025-36527.html</a><br /> Dero Miner Infects Containers through Docker API<br /> Kaspersky found yet another botnet infecting docker containers to spread crypto coin miners. The initial access happens via exposed docker APIs.<br /><a href="https://securelist.com/dero-miner-infects-containers-through-docker-api/116546/" target="_blank" rel="noreferrer noopener">https://securelist.com/dero-miner-infects-containers-through-docker-api/116546/</a><br />]]></itunes:summary><itunes:duration>398</itunes:duration><itunes:keywords>adauditplus,authorized_keys,business,computer,cyber,cybersecurity,daily,dero,docker,hacking,infosec,internet,it,manageengine,miner,network,news,security,sql injection,ssh</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9468</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, May 27th 2025: SVG Steganography; Fortinet PoC; GitLab Duo Prompt Injection</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-may-27th-2025-svg-steganography-fortinet-poc-gitlab-duo-prompt-injection--66289638</link><description><![CDATA[<br /> SVG Steganography<br /> Steganography is not only limited to pixel-based images but can be used to embed messages into vector-based formats like SVG.<br /><a href="https://isc.sans.edu/diary/SVG%20Steganography/31978" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SVG%20Steganography/31978</a><br /> Fortinet Vulnerability Details CVE-2025-32756<br /> Horizon3.ai shows how it was able to find the vulnerability in Fortinet s products, and how to possibly exploit this issue. The vulnerability is already being exploited in the wild and was patched May 13th<br /><a href="https://horizon3.ai/attack-research/attack-blogs/cve-2025-32756-low-rise-jeans-are-back-and-so-are-buffer-overflows/" target="_blank" rel="noreferrer noopener">https://horizon3.ai/attack-research/attack-blogs/cve-2025-32756-low-rise-jeans-are-back-and-so-are-buffer-overflows/</a><br /> Remote Prompt Injection in GitLab Duo Leads to Source Code Theft<br /> An attacker may leave instructions (prompts) for GitLab Duo embedded in the source code. This could be used to exfiltrate source code and secrets or to inject malicious code into an application.<br /><a href="https://www.legitsecurity.com/blog/remote-prompt-injection-in-gitlab-duo" target="_blank" rel="noreferrer noopener">https://www.legitsecurity.com/blog/remote-prompt-injection-in-gitlab-duo</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9466.mp3</guid><pubDate>Tue, 27 May 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66289638/9466.mp3" length="6065717" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9466" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 SVG Steganography
 Steganography is not only limited to pixel-based images but can be used to embed messages into vector-based formats like SVG.
https://isc.sans.edu/diary/SVG%20Steganography/31978
 Fortinet Vulnerability Details CVE-2025-32756...</itunes:subtitle><itunes:summary><![CDATA[<br /> SVG Steganography<br /> Steganography is not only limited to pixel-based images but can be used to embed messages into vector-based formats like SVG.<br /><a href="https://isc.sans.edu/diary/SVG%20Steganography/31978" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SVG%20Steganography/31978</a><br /> Fortinet Vulnerability Details CVE-2025-32756<br /> Horizon3.ai shows how it was able to find the vulnerability in Fortinet s products, and how to possibly exploit this issue. The vulnerability is already being exploited in the wild and was patched May 13th<br /><a href="https://horizon3.ai/attack-research/attack-blogs/cve-2025-32756-low-rise-jeans-are-back-and-so-are-buffer-overflows/" target="_blank" rel="noreferrer noopener">https://horizon3.ai/attack-research/attack-blogs/cve-2025-32756-low-rise-jeans-are-back-and-so-are-buffer-overflows/</a><br /> Remote Prompt Injection in GitLab Duo Leads to Source Code Theft<br /> An attacker may leave instructions (prompts) for GitLab Duo embedded in the source code. This could be used to exfiltrate source code and secrets or to inject malicious code into an application.<br /><a href="https://www.legitsecurity.com/blog/remote-prompt-injection-in-gitlab-duo" target="_blank" rel="noreferrer noopener">https://www.legitsecurity.com/blog/remote-prompt-injection-in-gitlab-duo</a><br />]]></itunes:summary><itunes:duration>433</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,duo,fortinet,gitlab,hacking,infosec,internet,it,network,news,prompt injection,security,steganography,svg</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9466</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, May 23rd 2025: Backup Connectivity; Windows 2025 dMSA Abuse; Samlify Vulnerability</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-may-23rd-2025-backup-connectivity-windows-2025-dmsa-abuse-samlify-vulnerability--66216968</link><description><![CDATA[<br /> Resilient Secure Backup Connectivity for SMB/Home Users<br />  Establishing resilient access to a home network via a second ISP may lead to unintended backdoors. Secure the access and make sure you have the visibility needed to detect abuse.<br /><a href="https://isc.sans.edu/diary/Resilient%20Secure%20Backup%20Connectivity%20for%20SMB%20Home%20Users/31972" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Resilient%20Secure%20Backup%20Connectivity%20for%20SMB%20Home%20Users/31972</a><br /> BadSuccessor: Abusing dMSA to Escalate Privileges in Active Directory<br /> An attacker with the ability to create service accounts may be able to manipulate these accounts to mark them as migrated accounts, inheriting all privileges the original account had access to.<br /><a href="https://www.akamai.com/blog/security-research/abusing-dmsa-for-privilege-escalation-in-active-directory" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/abusing-dmsa-for-privilege-escalation-in-active-directory</a><br /> Flaw in samlify That Opens Door to SAML Single Sign-On Bypass CVE-2025-47949<br /> The samlify Node.js library does not verify SAML assertions correctly. It will consider the entire assertion valid, not just the original one. An attacker may use this to obtain additional privileges or authenticate as a different user<br /><a href="https://www.endorlabs.com/learn/cve-2025-47949-reveals-flaw-in-samlify-that-opens-door-to-saml-single-sign-on-bypass" target="_blank" rel="noreferrer noopener">https://www.endorlabs.com/learn/cve-2025-47949-reveals-flaw-in-samlify-that-opens-door-to-saml-single-sign-on-bypass</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9464.mp3</guid><pubDate>Fri, 23 May 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66216968/9464.mp3" length="6640141" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9464" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Resilient Secure Backup Connectivity for SMB/Home Users
  Establishing resilient access to a home network via a second ISP may lead to unintended backdoors. Secure the access and make sure you have the visibility needed to detect abuse....</itunes:subtitle><itunes:summary><![CDATA[<br /> Resilient Secure Backup Connectivity for SMB/Home Users<br />  Establishing resilient access to a home network via a second ISP may lead to unintended backdoors. Secure the access and make sure you have the visibility needed to detect abuse.<br /><a href="https://isc.sans.edu/diary/Resilient%20Secure%20Backup%20Connectivity%20for%20SMB%20Home%20Users/31972" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Resilient%20Secure%20Backup%20Connectivity%20for%20SMB%20Home%20Users/31972</a><br /> BadSuccessor: Abusing dMSA to Escalate Privileges in Active Directory<br /> An attacker with the ability to create service accounts may be able to manipulate these accounts to mark them as migrated accounts, inheriting all privileges the original account had access to.<br /><a href="https://www.akamai.com/blog/security-research/abusing-dmsa-for-privilege-escalation-in-active-directory" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/abusing-dmsa-for-privilege-escalation-in-active-directory</a><br /> Flaw in samlify That Opens Door to SAML Single Sign-On Bypass CVE-2025-47949<br /> The samlify Node.js library does not verify SAML assertions correctly. It will consider the entire assertion valid, not just the original one. An attacker may use this to obtain additional privileges or authenticate as a different user<br /><a href="https://www.endorlabs.com/learn/cve-2025-47949-reveals-flaw-in-samlify-that-opens-door-to-saml-single-sign-on-bypass" target="_blank" rel="noreferrer noopener">https://www.endorlabs.com/learn/cve-2025-47949-reveals-flaw-in-samlify-that-opens-door-to-saml-single-sign-on-bypass</a><br />]]></itunes:summary><itunes:duration>474</itunes:duration><itunes:keywords>business,cname,computer,cyber,cybersecurity,daily,dns,hacking,infosec,internet,it,javascript,network,news,npm,openpgp,pgp,researchers,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9464</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, May 22nd 2025: Crypto Confidence Scams; Extension Mayhem for VS Code and Chrome</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-may-22nd-2025-crypto-confidence-scams-extension-mayhem-for-vs-code-and-chrome--66196223</link><description><![CDATA[<br /> New Variant of Crypto Confidence Scam<br /> Scammers are offering login credentials for what appears to be high value crypto coin accounts. However, the goal is to trick users into paying for expensive  VIP  memberships to withdraw the money.<br /><a href="https://isc.sans.edu/diary/New%20Variant%20of%20Crypto%20Confidence%20Scam/31968" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/New%20Variant%20of%20Crypto%20Confidence%20Scam/31968</a><br /> Malicious Chrome Extensions<br /> Malicious Chrome extensions mimick popular services like VPNs to trick users into installing them. Once installed, the extensions will exfiltrate browser secrets<br /><a href="https://dti.domaintools.com/dual-function-malware-chrome-extensions/" target="_blank" rel="noreferrer noopener">https://dti.domaintools.com/dual-function-malware-chrome-extensions/</a><br /> Malicious VS Code Extensions<br /> Malicious Visual Studio Code extensions target crypto developers to trick them into installing them to exfiltrate developer secrets.<br /><a href="https://securitylabs.datadoghq.com/articles/mut-9332-malicious-solidity-vscode-extensions/#indicators-of-compromise" target="_blank" rel="noreferrer noopener">https://securitylabs.datadoghq.com/articles/mut-9332-malicious-solidity-vscode-extensions/#indicators-of-compromise</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9462.mp3</guid><pubDate>Thu, 22 May 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66196223/9462.mp3" length="5341081" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9462" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 New Variant of Crypto Confidence Scam
 Scammers are offering login credentials for what appears to be high value crypto coin accounts. However, the goal is to trick users into paying for expensive  VIP  memberships to withdraw the money....</itunes:subtitle><itunes:summary><![CDATA[<br /> New Variant of Crypto Confidence Scam<br /> Scammers are offering login credentials for what appears to be high value crypto coin accounts. However, the goal is to trick users into paying for expensive  VIP  memberships to withdraw the money.<br /><a href="https://isc.sans.edu/diary/New%20Variant%20of%20Crypto%20Confidence%20Scam/31968" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/New%20Variant%20of%20Crypto%20Confidence%20Scam/31968</a><br /> Malicious Chrome Extensions<br /> Malicious Chrome extensions mimick popular services like VPNs to trick users into installing them. Once installed, the extensions will exfiltrate browser secrets<br /><a href="https://dti.domaintools.com/dual-function-malware-chrome-extensions/" target="_blank" rel="noreferrer noopener">https://dti.domaintools.com/dual-function-malware-chrome-extensions/</a><br /> Malicious VS Code Extensions<br /> Malicious Visual Studio Code extensions target crypto developers to trick them into installing them to exfiltrate developer secrets.<br /><a href="https://securitylabs.datadoghq.com/articles/mut-9332-malicious-solidity-vscode-extensions/#indicators-of-compromise" target="_blank" rel="noreferrer noopener">https://securitylabs.datadoghq.com/articles/mut-9332-malicious-solidity-vscode-extensions/#indicators-of-compromise</a><br />]]></itunes:summary><itunes:duration>382</itunes:duration><itunes:keywords>business,chrome,computer,confidence scams,crypto,cyber,cybersecurity,daily,extensions,hacking,infosec,internet,it,network,news,security,vs code</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9462</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, May 21st 2025: Researchers Scanning the Internet; Forgotten DNS Records; openpgp.js Vulneraiblity</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-may-21st-2025-researchers-scanning-the-internet-forgotten-dns-records-openpgp-js-vulneraiblity--66178944</link><description><![CDATA[<br /> Researchers Scanning the Internet<br />  A  newish  RFC, RFC 9511, suggests researchers identify themselves by adding strings to the traffic they send, or by operating web servers on machines from which the scan originates. We do offer lists of researchers and just added three new groups today<br /><a href="https://isc.sans.edu/diary/Researchers%20Scanning%20the%20Internet/31964" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Researchers%20Scanning%20the%20Internet/31964</a><br /> Cloudy with a change of Hijacking: Forgotten DNS Records<br /> Organizations do not always remove unused CNAME records. An attacker may take advantage of this if an attacker is able to take possession of the now unused public cloud resource the name pointed to.<br /><a href="https://blogs.infoblox.com/threat-intelligence/cloudy-with-a-chance-of-hijacking-forgotten-dns-records-enable-scam-actor/" target="_blank" rel="noreferrer noopener">https://blogs.infoblox.com/threat-intelligence/cloudy-with-a-chance-of-hijacking-forgotten-dns-records-enable-scam-actor/</a><br /> Message signature verification can be spoofed CVE-2025-47934<br /> A vulnerability in openpgp.js may be used to spoof message signatures. openpgp.js is a popular library in systems implementing end-to-end encrypted browser applications.<br /><a href="https://github.com/openpgpjs/openpgpjs/security/advisories/GHSA-8qff-qr5q-5pr8" target="_blank" rel="noreferrer noopener">https://github.com/openpgpjs/openpgpjs/security/advisories/GHSA-8qff-qr5q-5pr8</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9460.mp3</guid><pubDate>Wed, 21 May 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66178944/9460.mp3" length="6596782" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9460" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Researchers Scanning the Internet
  A  newish  RFC, RFC 9511, suggests researchers identify themselves by adding strings to the traffic they send, or by operating web servers on machines from which the scan originates. We do offer lists of...</itunes:subtitle><itunes:summary><![CDATA[<br /> Researchers Scanning the Internet<br />  A  newish  RFC, RFC 9511, suggests researchers identify themselves by adding strings to the traffic they send, or by operating web servers on machines from which the scan originates. We do offer lists of researchers and just added three new groups today<br /><a href="https://isc.sans.edu/diary/Researchers%20Scanning%20the%20Internet/31964" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Researchers%20Scanning%20the%20Internet/31964</a><br /> Cloudy with a change of Hijacking: Forgotten DNS Records<br /> Organizations do not always remove unused CNAME records. An attacker may take advantage of this if an attacker is able to take possession of the now unused public cloud resource the name pointed to.<br /><a href="https://blogs.infoblox.com/threat-intelligence/cloudy-with-a-chance-of-hijacking-forgotten-dns-records-enable-scam-actor/" target="_blank" rel="noreferrer noopener">https://blogs.infoblox.com/threat-intelligence/cloudy-with-a-chance-of-hijacking-forgotten-dns-records-enable-scam-actor/</a><br /> Message signature verification can be spoofed CVE-2025-47934<br /> A vulnerability in openpgp.js may be used to spoof message signatures. openpgp.js is a popular library in systems implementing end-to-end encrypted browser applications.<br /><a href="https://github.com/openpgpjs/openpgpjs/security/advisories/GHSA-8qff-qr5q-5pr8" target="_blank" rel="noreferrer noopener">https://github.com/openpgpjs/openpgpjs/security/advisories/GHSA-8qff-qr5q-5pr8</a><br />]]></itunes:summary><itunes:duration>471</itunes:duration><itunes:keywords>business,cname,computer,cyber,cybersecurity,daily,dns,hacking,infosec,internet,it,javascript,network,news,npm,openpgp,pgp,researchers,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9460</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, May 20th 2025: AutoIT Code RAT; Fake Keepass Download; Procolored Printer Software Compromise</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-may-20th-2025-autoit-code-rat-fake-keepass-download-procolored-printer-software-compromise--66163158</link><description><![CDATA[<br /> RAT Dropped By Two Layers of AutoIT Code<br />  Xavier explains how AutoIT was used to install a remote admin tool (RAT) and how to analyse such a tool<br /><a href="https://isc.sans.edu/diary/RAT%20Dropped%20By%20Two%20Layers%20of%20AutoIT%20Code/31960" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/RAT%20Dropped%20By%20Two%20Layers%20of%20AutoIT%20Code/31960</a><br /> RVTools compromise confirmed<br /> Robware.net, the site behind the popular tool RVTools now confirmed that it was compromised. The site is currently offline.<br /><a href="https://www.robware.net/readMore" target="_blank" rel="noreferrer noopener">https://www.robware.net/readMore</a><br /> Trojaned Version of Keepass used to install info stealer and Cobalt Strike beacon<br />  A backdoored version of KeePass was used to trick victims into installing Cobalt Strike and other malware. In this case, Keepass itself was not compromised and the malicious version was advertised via search engine optimization tricks<br /><a href="https://labs.withsecure.com/publications/keepass-trojanised-in-advanced-malware-campaign" target="_blank" rel="noreferrer noopener">https://labs.withsecure.com/publications/keepass-trojanised-in-advanced-malware-campaign</a><br /> Procolored UV Printer Software Compromised<br />  The official software offered by the makers of the Procolored UV printer has been compromised, and versions with malware were distributed for about half a year.<br /><a href="https://www.hackster.io/news/the-maker-s-toolbox-procolored-v11-pro-dto-uv-printer-review-680d491e17e3" target="_blank" rel="noreferrer noopener">https://www.hackster.io/news/the-maker-s-toolbox-procolored-v11-pro-dto-uv-printer-review-680d491e17e3</a><br /><a href="https://www.gdatasoftware.com/blog/2025/05/38200-printer-infected-software-downloads" target="_blank" rel="noreferrer noopener">https://www.gdatasoftware.com/blog/2025/05/38200-printer-infected-software-downloads</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9458.mp3</guid><pubDate>Tue, 20 May 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66163158/9458.mp3" length="5616581" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9458" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 RAT Dropped By Two Layers of AutoIT Code
  Xavier explains how AutoIT was used to install a remote admin tool (RAT) and how to analyse such a tool
https://isc.sans.edu/diary/RAT%20Dropped%20By%20Two%20Layers%20of%20AutoIT%20Code/31960
 RVTools...</itunes:subtitle><itunes:summary><![CDATA[<br /> RAT Dropped By Two Layers of AutoIT Code<br />  Xavier explains how AutoIT was used to install a remote admin tool (RAT) and how to analyse such a tool<br /><a href="https://isc.sans.edu/diary/RAT%20Dropped%20By%20Two%20Layers%20of%20AutoIT%20Code/31960" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/RAT%20Dropped%20By%20Two%20Layers%20of%20AutoIT%20Code/31960</a><br /> RVTools compromise confirmed<br /> Robware.net, the site behind the popular tool RVTools now confirmed that it was compromised. The site is currently offline.<br /><a href="https://www.robware.net/readMore" target="_blank" rel="noreferrer noopener">https://www.robware.net/readMore</a><br /> Trojaned Version of Keepass used to install info stealer and Cobalt Strike beacon<br />  A backdoored version of KeePass was used to trick victims into installing Cobalt Strike and other malware. In this case, Keepass itself was not compromised and the malicious version was advertised via search engine optimization tricks<br /><a href="https://labs.withsecure.com/publications/keepass-trojanised-in-advanced-malware-campaign" target="_blank" rel="noreferrer noopener">https://labs.withsecure.com/publications/keepass-trojanised-in-advanced-malware-campaign</a><br /> Procolored UV Printer Software Compromised<br />  The official software offered by the makers of the Procolored UV printer has been compromised, and versions with malware were distributed for about half a year.<br /><a href="https://www.hackster.io/news/the-maker-s-toolbox-procolored-v11-pro-dto-uv-printer-review-680d491e17e3" target="_blank" rel="noreferrer noopener">https://www.hackster.io/news/the-maker-s-toolbox-procolored-v11-pro-dto-uv-printer-review-680d491e17e3</a><br /><a href="https://www.gdatasoftware.com/blog/2025/05/38200-printer-infected-software-downloads" target="_blank" rel="noreferrer noopener">https://www.gdatasoftware.com/blog/2025/05/38200-printer-infected-software-downloads</a><br />]]></itunes:summary><itunes:duration>401</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dynamic autoit,hacking,infosec,internet,it,keeppass,network,news,procolored,rvtools,security,uv printer</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9458</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, May 18th 2025: xorsearch python functions; pwn2own Berlin; senior govt official impersonation; dynamic domain risk</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-may-18th-2025-xorsearch-python-functions-pwn2own-berlin-senior-govt-official-impersonation-dynamic-domain-risk--66145155</link><description><![CDATA[<br /> xorsearch.py: Python Functions<br /> Didier s xorsearch tool now supports python functions to filter output<br /><a href="https://isc.sans.edu/diary/xorsearch.py%3A%20Python%20Functions/31858" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/xorsearch.py%3A%20Python%20Functions/31858</a><br /> Pwn2Own Berlin 2025<br />  Last weeks Pwn2Own contest in Berlin allowed researchers to demonstrate a number of new exploits with a large focus on privilege escalation and virtual machine escape.<br /><a href="https://www.zerodayinitiative.com/blog/2025/5/17/pwn2own-berlin-2025-day-three-results" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/blog/2025/5/17/pwn2own-berlin-2025-day-three-results</a><br /> Senior US Officials Impersonated in Malicious Messaging Campaign<br /> The FBI warns of senior US officials being impersonated in text and voice messages.<br /><a href="https://www.ic3.gov/PSA/2025/PSA250515" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/PSA/2025/PSA250515</a><br /> Scattered Spider: TTP Evolution in 2025<br /> Pushscurity provided an update on how Scattered Spider evolved. One thing they noted was that Scattered Spider takes advantage of legit dynamic domain name systems to make detection more difficult<br /><a href="https://pushsecurity.com/blog/scattered-spider-ttp-evolution-in-2025/" target="_blank" rel="noreferrer noopener">https://pushsecurity.com/blog/scattered-spider-ttp-evolution-in-2025/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9456.mp3</guid><pubDate>Mon, 19 May 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66145155/9456.mp3" length="5466240" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9456" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 xorsearch.py: Python Functions
 Didier s xorsearch tool now supports python functions to filter output
https://isc.sans.edu/diary/xorsearch.py%3A%20Python%20Functions/31858
 Pwn2Own Berlin 2025
  Last weeks Pwn2Own contest in Berlin allowed...</itunes:subtitle><itunes:summary><![CDATA[<br /> xorsearch.py: Python Functions<br /> Didier s xorsearch tool now supports python functions to filter output<br /><a href="https://isc.sans.edu/diary/xorsearch.py%3A%20Python%20Functions/31858" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/xorsearch.py%3A%20Python%20Functions/31858</a><br /> Pwn2Own Berlin 2025<br />  Last weeks Pwn2Own contest in Berlin allowed researchers to demonstrate a number of new exploits with a large focus on privilege escalation and virtual machine escape.<br /><a href="https://www.zerodayinitiative.com/blog/2025/5/17/pwn2own-berlin-2025-day-three-results" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/blog/2025/5/17/pwn2own-berlin-2025-day-three-results</a><br /> Senior US Officials Impersonated in Malicious Messaging Campaign<br /> The FBI warns of senior US officials being impersonated in text and voice messages.<br /><a href="https://www.ic3.gov/PSA/2025/PSA250515" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/PSA/2025/PSA250515</a><br /> Scattered Spider: TTP Evolution in 2025<br /> Pushscurity provided an update on how Scattered Spider evolved. One thing they noted was that Scattered Spider takes advantage of legit dynamic domain name systems to make detection more difficult<br /><a href="https://pushsecurity.com/blog/scattered-spider-ttp-evolution-in-2025/" target="_blank" rel="noreferrer noopener">https://pushsecurity.com/blog/scattered-spider-ttp-evolution-in-2025/</a><br />]]></itunes:summary><itunes:duration>390</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dynamic domains,hacking,infosec,it,it.com,network,news,phishing,priviledge escalation,python,security,smishing,vipshing,vmware,xorsearch</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9456</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, May 16th: Increase in Sonicwall Scans; RVTools Compromised?; RountPress</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-may-16th-increase-in-sonicwall-scans-rvtools-compromised-rountpress--66112564</link><description><![CDATA[<br /> Web Scanning SonicWall for CVE-2021-20016 - Update<br />  Scans for SonicWall increased by an order of magnitude over the last couple of weeks. Many of the attacks appear to originate from  Global Host , a low-cost virtual hosting provider.<br /><a href="https://isc.sans.edu/diary/Web%20Scanning%20SonicWall%20for%20CVE-2021-20016%20-%20Update/31952" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Web%20Scanning%20SonicWall%20for%20CVE-2021-20016%20-%20Update/31952</a><br /> Google Update Patches Exploited Chrome Flaw<br />  Google released an update for Chrome. The update fixes two specific flaws reported by external researchers, CVE-2025-4664 and CVE-2025-4609. The first flaw is already being exploited in the wild.<br /><a href="https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_14.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_14.html</a><br /><a href="https://x.com/slonser_/status/1919439373986107814" target="_blank" rel="noreferrer noopener">https://x.com/slonser_/status/1919439373986107814</a><br /> RVTools Bumblebee Malware Attack<br /> Zerodaylabs published its analysis of the RV-Tools Backdoor attack. It suggests that this may not be solely a search engine optimization campaign directing victims to the malicious installer, but that the RVTools distribution site was compromised.<br /><a href="https://zerodaylabs.net/rvtools-bumblebee-malware/" target="_blank" rel="noreferrer noopener">https://zerodaylabs.net/rvtools-bumblebee-malware/</a><br /> Operation RoundPress<br /> ESET Security wrote up a report summarizing recent XSS attacks against open-source webmail systems<br /><a href="https://www.welivesecurity.com/en/eset-research/operation-roundpress/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/operation-roundpress/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9454.mp3</guid><pubDate>Fri, 16 May 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66112564/9454.mp3" length="5413771" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9454" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Web Scanning SonicWall for CVE-2021-20016 - Update
  Scans for SonicWall increased by an order of magnitude over the last couple of weeks. Many of the attacks appear to originate from  Global Host , a low-cost virtual hosting provider....</itunes:subtitle><itunes:summary><![CDATA[<br /> Web Scanning SonicWall for CVE-2021-20016 - Update<br />  Scans for SonicWall increased by an order of magnitude over the last couple of weeks. Many of the attacks appear to originate from  Global Host , a low-cost virtual hosting provider.<br /><a href="https://isc.sans.edu/diary/Web%20Scanning%20SonicWall%20for%20CVE-2021-20016%20-%20Update/31952" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Web%20Scanning%20SonicWall%20for%20CVE-2021-20016%20-%20Update/31952</a><br /> Google Update Patches Exploited Chrome Flaw<br />  Google released an update for Chrome. The update fixes two specific flaws reported by external researchers, CVE-2025-4664 and CVE-2025-4609. The first flaw is already being exploited in the wild.<br /><a href="https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_14.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_14.html</a><br /><a href="https://x.com/slonser_/status/1919439373986107814" target="_blank" rel="noreferrer noopener">https://x.com/slonser_/status/1919439373986107814</a><br /> RVTools Bumblebee Malware Attack<br /> Zerodaylabs published its analysis of the RV-Tools Backdoor attack. It suggests that this may not be solely a search engine optimization campaign directing victims to the malicious installer, but that the RVTools distribution site was compromised.<br /><a href="https://zerodaylabs.net/rvtools-bumblebee-malware/" target="_blank" rel="noreferrer noopener">https://zerodaylabs.net/rvtools-bumblebee-malware/</a><br /> Operation RoundPress<br /> ESET Security wrote up a report summarizing recent XSS attacks against open-source webmail systems<br /><a href="https://www.welivesecurity.com/en/eset-research/operation-roundpress/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/operation-roundpress/</a><br />]]></itunes:summary><itunes:duration>387</itunes:duration><itunes:keywords>business,chrome,computer,cyber,cybersecurity,daily,google,hacking,infosec,internet,it,network,news,roundpress,rvtools,security,xss</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9454</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, May 15th: Google Open Redirects; Adobe, Ivanti, and Samsung patches</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-may-15th-google-open-redirects-adobe-ivanti-and-samsung-patches--66094724</link><description><![CDATA[<br /> Another day, another phishing campaign abusing google.com open redirects<br />  Google s links from it s maps page to hotel listings do suffer from an open redirect vulnerability that is actively exploited to direct users to phishing pages.<br /><a href="https://isc.sans.edu/diary/Another%20day%2C%20another%20phishing%20campaign%20abusing%20google.com%20open%20redirects/31950" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Another%20day%2C%20another%20phishing%20campaign%20abusing%20google.com%20open%20redirects/31950</a><br /> Adobe Patches<br /> Adobe patched 12 different applications. Of particular interest is the update to ColdFusion, which fixes several arbitrary code execution and arbitrary file read problems.<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> Samsung Patches magicInfo 9 Again<br /> Samsung released a new patch for the already exploited magicInfo 9 CMS vulnerability. While the description is identical to the patch released last August, a new CVE number is used.<br /><a href="https://security.samsungtv.com/securityUpdates#SVP-MAY-2025" target="_blank" rel="noreferrer noopener">https://security.samsungtv.com/securityUpdates#SVP-MAY-2025</a><br /> Ivanti Patches Critical Ivanti Neurons Flaw<br /> Ivanti released a patch for Ivanti Neurons for ITSM (on-prem only) fixing a critical authentication bypass vulnerability. Ivanti also points to its guidance to secure the underlying IIS server to make exploitation of flaws like this more difficult<br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9452.mp3</guid><pubDate>Thu, 15 May 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66094724/9452.mp3" length="5265782" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9452" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Another day, another phishing campaign abusing google.com open redirects
  Google s links from it s maps page to hotel listings do suffer from an open redirect vulnerability that is actively exploited to direct users to phishing pages....</itunes:subtitle><itunes:summary><![CDATA[<br /> Another day, another phishing campaign abusing google.com open redirects<br />  Google s links from it s maps page to hotel listings do suffer from an open redirect vulnerability that is actively exploited to direct users to phishing pages.<br /><a href="https://isc.sans.edu/diary/Another%20day%2C%20another%20phishing%20campaign%20abusing%20google.com%20open%20redirects/31950" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Another%20day%2C%20another%20phishing%20campaign%20abusing%20google.com%20open%20redirects/31950</a><br /> Adobe Patches<br /> Adobe patched 12 different applications. Of particular interest is the update to ColdFusion, which fixes several arbitrary code execution and arbitrary file read problems.<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> Samsung Patches magicInfo 9 Again<br /> Samsung released a new patch for the already exploited magicInfo 9 CMS vulnerability. While the description is identical to the patch released last August, a new CVE number is used.<br /><a href="https://security.samsungtv.com/securityUpdates#SVP-MAY-2025" target="_blank" rel="noreferrer noopener">https://security.samsungtv.com/securityUpdates#SVP-MAY-2025</a><br /> Ivanti Patches Critical Ivanti Neurons Flaw<br /> Ivanti released a patch for Ivanti Neurons for ITSM (on-prem only) fixing a critical authentication bypass vulnerability. Ivanti also points to its guidance to secure the underlying IIS server to make exploitation of flaws like this more difficult<br />]]></itunes:summary><itunes:duration>376</itunes:duration><itunes:keywords>adobe,business,computer,cyber,cybersecurity,daily,google,hacking,infosec,internet,it,ivanti,network,news,open redirect,samsung,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9452</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, May 14th: Microsoft Patch Tuesday; 0-Days patched for Ivanti Endpoint Manager and Fortinet Products</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-may-14th-microsoft-patch-tuesday-0-days-patched-for-ivanti-endpoint-manager-and-fortinet-products--66079394</link><description><![CDATA[<br /> Microsoft Patch Tuesday<br /> Microsoft patched 70-78 vulnerabilities (depending on how you count them). Five of these vulnerabilities are already being exploited. In particular, a remote code execution vulnerability in the scripting engine should be taken seriously. It requires the Microsoft Edge browser to run in Internet Explorer mode.<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%3A%20May%202025/31946" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%3A%20May%202025/31946</a><br /> Security Advisory Ivanti Endpoint Manager Mobile (EPMM) May 2025 (CVE-2025-4427 and CVE-2025-4428)<br /> Ivanti patched an authentication bypass vulnerability and a remote code execution vulnerability. The authentication bypass can exploit the remote code execution vulnerability without authenticating first.<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM?language=en_US</a><br /> Fortinet Patches Exploited Vulnerability in API (CVE-2025-32756)<br />  Fortinet patched an already exploited stack-based buffer overflow vulnerability in the API of multiple Fortinet products. The vulnerability is exploited via crafted HTTP requests.<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-254" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-25-254</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9450.mp3</guid><pubDate>Wed, 14 May 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66079394/9450.mp3" length="5582137" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9450" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Microsoft Patch Tuesday
 Microsoft patched 70-78 vulnerabilities (depending on how you count them). Five of these vulnerabilities are already being exploited. In particular, a remote code execution vulnerability in the scripting engine should be...</itunes:subtitle><itunes:summary><![CDATA[<br /> Microsoft Patch Tuesday<br /> Microsoft patched 70-78 vulnerabilities (depending on how you count them). Five of these vulnerabilities are already being exploited. In particular, a remote code execution vulnerability in the scripting engine should be taken seriously. It requires the Microsoft Edge browser to run in Internet Explorer mode.<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%3A%20May%202025/31946" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%3A%20May%202025/31946</a><br /> Security Advisory Ivanti Endpoint Manager Mobile (EPMM) May 2025 (CVE-2025-4427 and CVE-2025-4428)<br /> Ivanti patched an authentication bypass vulnerability and a remote code execution vulnerability. The authentication bypass can exploit the remote code execution vulnerability without authenticating first.<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM?language=en_US</a><br /> Fortinet Patches Exploited Vulnerability in API (CVE-2025-32756)<br />  Fortinet patched an already exploited stack-based buffer overflow vulnerability in the API of multiple Fortinet products. The vulnerability is exploited via crafted HTTP requests.<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-254" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-25-254</a><br />]]></itunes:summary><itunes:duration>399</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,fortinet,hacking,infosec,internet,it,ivanti,microsoft,network,news,patches,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9450</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, May 12th: Apple Patches; Unipi Technologies Scans;</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-may-12th-apple-patches-unipi-technologies-scans--66065320</link><description><![CDATA[<br /> Apple Updates Everything<br />  Apple patched all of its operating systems. This update ports a patch for a recently exploited vulnerability to older versions of iOS and macOS.<br /><a href="https://isc.sans.edu/diary/31942" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/31942</a><br /> It Is 2025, And We Are Still Dealing With Default IoT Passwords And Stupid 2013 Router Vulnerabilities<br />   Versions of the Mirai botnet are attacking devices made by Unipi Technology. These devices are using a specific username and password combination. In addition, this version of the Mirai botnet will also attempt exploits against an old Netgear vulnerability.<br /><a href="https://isc.sans.edu/diary/It%20Is%202025%2C%20And%20We%20Are%20Still%20Dealing%20With%20Default%20IoT%20Passwords%20And%20Stupid%202013%20Router%20Vulnerabilities/31940" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/It%20Is%202025%2C%20And%20We%20Are%20Still%20Dealing%20With%20Default%20IoT%20Passwords%20And%20Stupid%202013%20Router%20Vulnerabilities/31940</a><br /> Output Messenger Vulnerability<br />  The internal messenger application  Output Messenger  is currently used in sophisticated attacks. Attackers are exploiting a path traversal vulnerability that has not been fixed.<br /><a href="https://www.outputmessenger.com/cve-2025-27920/" target="_blank" rel="noreferrer noopener">https://www.outputmessenger.com/cve-2025-27920/</a><br /> Commvault Correction<br />  Commvault s patch indeed fixes the recent vulnerability. The  Pioneer Release  Will Dormann used to experiment will only offer patches after it has been registered, which leads to an error when assessing the patch s efficacy. <br /><a href="https://www.darkreading.com/application-security/commvault-patch-works-as-intended" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/application-security/commvault-patch-works-as-intended</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9448.mp3</guid><pubDate>Tue, 13 May 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66065320/9448.mp3" length="5458660" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9448" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Apple Updates Everything
  Apple patched all of its operating systems. This update ports a patch for a recently exploited vulnerability to older versions of iOS and macOS.
https://isc.sans.edu/diary/31942
 It Is 2025, And We Are Still Dealing With...</itunes:subtitle><itunes:summary><![CDATA[<br /> Apple Updates Everything<br />  Apple patched all of its operating systems. This update ports a patch for a recently exploited vulnerability to older versions of iOS and macOS.<br /><a href="https://isc.sans.edu/diary/31942" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/31942</a><br /> It Is 2025, And We Are Still Dealing With Default IoT Passwords And Stupid 2013 Router Vulnerabilities<br />   Versions of the Mirai botnet are attacking devices made by Unipi Technology. These devices are using a specific username and password combination. In addition, this version of the Mirai botnet will also attempt exploits against an old Netgear vulnerability.<br /><a href="https://isc.sans.edu/diary/It%20Is%202025%2C%20And%20We%20Are%20Still%20Dealing%20With%20Default%20IoT%20Passwords%20And%20Stupid%202013%20Router%20Vulnerabilities/31940" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/It%20Is%202025%2C%20And%20We%20Are%20Still%20Dealing%20With%20Default%20IoT%20Passwords%20And%20Stupid%202013%20Router%20Vulnerabilities/31940</a><br /> Output Messenger Vulnerability<br />  The internal messenger application  Output Messenger  is currently used in sophisticated attacks. Attackers are exploiting a path traversal vulnerability that has not been fixed.<br /><a href="https://www.outputmessenger.com/cve-2025-27920/" target="_blank" rel="noreferrer noopener">https://www.outputmessenger.com/cve-2025-27920/</a><br /> Commvault Correction<br />  Commvault s patch indeed fixes the recent vulnerability. The  Pioneer Release  Will Dormann used to experiment will only offer patches after it has been registered, which leads to an error when assessing the patch s efficacy. <br /><a href="https://www.darkreading.com/application-security/commvault-patch-works-as-intended" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/application-security/commvault-patch-works-as-intended</a><br />]]></itunes:summary><itunes:duration>390</itunes:duration><itunes:keywords>apple,business,commvault,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,mirai,network,news,output messenger,security,unipi</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9448</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, May 11th: Steganography Challenge; End-of-Life Routers; ASUS Driverhub; RV-Tools SEO Poisoning</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-may-11th-steganography-challenge-end-of-life-routers-asus-driverhub-rv-tools-seo-poisoning--66048951</link><description><![CDATA[<br /> Steganography Challenge<br />  Didier revealed the solution to last weekend s cryptography challenge. The image used the same encoding scheme as Didier described before, but the columns and rows were transposed.<br /><a href="https://isc.sans.edu/forums/diary/Steganography%20Challenge%3A%20My%20Solution/31912/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Steganography%20Challenge%3A%20My%20Solution/31912/</a><br /> FBI Warns of End-of-life routers<br />  The FBI is tracking larger botnets taking advantage of unpatched routers. Many of these routers are end-of-life, and no patches are available for the exploited vulnerabilities. The attackers are turning the devices into proxies, which are resold for various criminal activities.<br /><a href="https://www.ic3.gov/PSA/2025/PSA250507" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/PSA/2025/PSA250507</a><br /> ASUS Driverhub Vulnerability<br />  ASUS Driverhub software does not properly check the origin of HTTP requests, allowing a CSRF attack from any website leading to arbitrary code execution.<br /><a href="https://mrbruh.com/asusdriverhub/" target="_blank" rel="noreferrer noopener">https://mrbruh.com/asusdriverhub/</a><br /> RV-Tools SEO Poisoning <br />  Varonis Threat Labs observed SEO poisoning being used to trick system administrators into installing a malicious version of RV Tools. The malicious version includes a remote access tool leading to the theft of credentials<br /><a href="https://www.varonis.com/blog/seo-poisoning#initial-access-and-persistence" target="_blank" rel="noreferrer noopener">https://www.varonis.com/blog/seo-poisoning#initial-access-and-persistence</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9446.mp3</guid><pubDate>Mon, 12 May 2025 01:42:54 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66048951/9446.mp3" length="5591950" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9446" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Steganography Challenge
  Didier revealed the solution to last weekend s cryptography challenge. The image used the same encoding scheme as Didier described before, but the columns and rows were transposed....</itunes:subtitle><itunes:summary><![CDATA[<br /> Steganography Challenge<br />  Didier revealed the solution to last weekend s cryptography challenge. The image used the same encoding scheme as Didier described before, but the columns and rows were transposed.<br /><a href="https://isc.sans.edu/forums/diary/Steganography%20Challenge%3A%20My%20Solution/31912/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Steganography%20Challenge%3A%20My%20Solution/31912/</a><br /> FBI Warns of End-of-life routers<br />  The FBI is tracking larger botnets taking advantage of unpatched routers. Many of these routers are end-of-life, and no patches are available for the exploited vulnerabilities. The attackers are turning the devices into proxies, which are resold for various criminal activities.<br /><a href="https://www.ic3.gov/PSA/2025/PSA250507" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/PSA/2025/PSA250507</a><br /> ASUS Driverhub Vulnerability<br />  ASUS Driverhub software does not properly check the origin of HTTP requests, allowing a CSRF attack from any website leading to arbitrary code execution.<br /><a href="https://mrbruh.com/asusdriverhub/" target="_blank" rel="noreferrer noopener">https://mrbruh.com/asusdriverhub/</a><br /> RV-Tools SEO Poisoning <br />  Varonis Threat Labs observed SEO poisoning being used to trick system administrators into installing a malicious version of RV Tools. The malicious version includes a remote access tool leading to the theft of credentials<br /><a href="https://www.varonis.com/blog/seo-poisoning#initial-access-and-persistence" target="_blank" rel="noreferrer noopener">https://www.varonis.com/blog/seo-poisoning#initial-access-and-persistence</a><br />]]></itunes:summary><itunes:duration>399</itunes:duration><itunes:keywords>asus,business,computer,cyber,cybersecurity,daily,driverhub,fbi,hacking,infosec,internet,it,network,news,router,rv-tools,security,seq,steganography</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9446</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, May 9th: SSH Exfil Tricks; magicINFO still vulnerable; SentinelOne Vulnerability; Commvault insufficient patch</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-may-9th-ssh-exfil-tricks-magicinfo-still-vulnerable-sentinelone-vulnerability-commvault-insufficient-patch--66010228</link><description><![CDATA[<br /> No Internet Access: SSH to the Rescue<br />  If faced with restrictive outbound network access policies, a single inbound SSH connection can quickly be turned into a tunnel or a full-blown VPN<br /><a href="https://isc.sans.edu/diary/No%20Internet%20Access%3F%20SSH%20to%20the%20Rescue!/31932" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/No%20Internet%20Access%3F%20SSH%20to%20the%20Rescue!/31932</a><br /> SAMSUNG magicINFO 9 Server Flaw Still exploitable<br />  The SAMSUNG magicINFO 9 Server Vulnerability we found being exploited last week is apparently still not completely patched, and current versions are vulnerable to the exploit observed in the wild.<br /><a href="https://www.huntress.com/blog/rapid-response-samsung-magicinfo9-server-flaw" target="_blank" rel="noreferrer noopener">https://www.huntress.com/blog/rapid-response-samsung-magicinfo9-server-flaw</a><br /> Bring Your Own Installer: Bypassing SentinelOne Through Agent Version Change Interruption<br /> SentinelOne s installer is vulnerable to an exploit allowing attackers to shut down the end point protection software<br /><a href="https://www.aon.com/en/insights/cyber-labs/bring-your-own-installer-bypassing-sentinelone" target="_blank" rel="noreferrer noopener">https://www.aon.com/en/insights/cyber-labs/bring-your-own-installer-bypassing-sentinelone</a><br /> Commvault Still Exploitable<br />  A recent patch for Commvault is apparently ineffective and the PoC exploit published by watchTowr is still working against up to date patched systems<br /><a href="https://infosec.exchange/@wdormann/114458913006792356" target="_blank" rel="noreferrer noopener">https://infosec.exchange/@wdormann/114458913006792356</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9444.mp3</guid><pubDate>Fri, 09 May 2025 03:35:13 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/66010228/9444.mp3" length="4158604" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9444" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 No Internet Access: SSH to the Rescue
  If faced with restrictive outbound network access policies, a single inbound SSH connection can quickly be turned into a tunnel or a full-blown VPN...</itunes:subtitle><itunes:summary><![CDATA[<br /> No Internet Access: SSH to the Rescue<br />  If faced with restrictive outbound network access policies, a single inbound SSH connection can quickly be turned into a tunnel or a full-blown VPN<br /><a href="https://isc.sans.edu/diary/No%20Internet%20Access%3F%20SSH%20to%20the%20Rescue!/31932" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/No%20Internet%20Access%3F%20SSH%20to%20the%20Rescue!/31932</a><br /> SAMSUNG magicINFO 9 Server Flaw Still exploitable<br />  The SAMSUNG magicINFO 9 Server Vulnerability we found being exploited last week is apparently still not completely patched, and current versions are vulnerable to the exploit observed in the wild.<br /><a href="https://www.huntress.com/blog/rapid-response-samsung-magicinfo9-server-flaw" target="_blank" rel="noreferrer noopener">https://www.huntress.com/blog/rapid-response-samsung-magicinfo9-server-flaw</a><br /> Bring Your Own Installer: Bypassing SentinelOne Through Agent Version Change Interruption<br /> SentinelOne s installer is vulnerable to an exploit allowing attackers to shut down the end point protection software<br /><a href="https://www.aon.com/en/insights/cyber-labs/bring-your-own-installer-bypassing-sentinelone" target="_blank" rel="noreferrer noopener">https://www.aon.com/en/insights/cyber-labs/bring-your-own-installer-bypassing-sentinelone</a><br /> Commvault Still Exploitable<br />  A recent patch for Commvault is apparently ineffective and the PoC exploit published by watchTowr is still working against up to date patched systems<br /><a href="https://infosec.exchange/@wdormann/114458913006792356" target="_blank" rel="noreferrer noopener">https://infosec.exchange/@wdormann/114458913006792356</a><br />]]></itunes:summary><itunes:duration>297</itunes:duration><itunes:keywords>business,commvault,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,magicinfo,network,news,patches,samung,security,sentinelone,ssh</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9444</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, May 8th: Modular Malware; Sysaid Vuln; Cisco Wireless Controller Patch; Unifi Protect Camera Patch</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-may-8th-modular-malware-sysaid-vuln-cisco-wireless-controller-patch-unifi-protect-camera-patch--65991558</link><description><![CDATA[<br /> Example of Modular Malware<br />  Xavier analyzes modular malware that downloads DLLs from GitHub if specific features are required. In particular, the webcam module is inspected in detail. <br /><a href="https://isc.sans.edu/diary/Example%20of%20%22Modular%22%20Malware/31928" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Example%20of%20%22Modular%22%20Malware/31928</a><br /> Sysaid XXE Vulnerabilities<br />  IT Service Management Software Sysaid patched a number of XXE vulnerabilities. Without authentication, an attacker is able to obtain confidential data and completely compromise the system. watchTowr published a detailed analysis of the flaws including exploit code. <br /><a href="https://labs.watchtowr.com/sysowned-your-friendly-rce-support-ticket/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/sysowned-your-friendly-rce-support-ticket/</a><br /> Cisco IOS XE Wireless Controller Software Arbitrary File Upload Vulnerability<br />  Cisco Patched a vulnerability in its wireless controller software that may be used to not only upload files but also execute code as root without authentication.<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wlc-file-uplpd-rHZG9UfC" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wlc-file-uplpd-rHZG9UfC</a><br /> Unifi Protect Camera Vulnerability<br />  Ubiquity patched a vulnerability in its Protect camera firmware fixing a buffer overflow flaw.<br /><a href="https://community.ui.com/releases/Security-Advisory-Bulletin-047-047/cef86c37-7421-44fd-b251-84e76475a5bc" target="_blank" rel="noreferrer noopener">https://community.ui.com/releases/Security-Advisory-Bulletin-047-047/cef86c37-7421-44fd-b251-84e76475a5bc</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9442.mp3</guid><pubDate>Thu, 08 May 2025 03:25:14 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65991558/9442.mp3" length="4786152" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9442" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Example of Modular Malware
  Xavier analyzes modular malware that downloads DLLs from GitHub if specific features are required. In particular, the webcam module is inspected in detail....</itunes:subtitle><itunes:summary><![CDATA[<br /> Example of Modular Malware<br />  Xavier analyzes modular malware that downloads DLLs from GitHub if specific features are required. In particular, the webcam module is inspected in detail. <br /><a href="https://isc.sans.edu/diary/Example%20of%20%22Modular%22%20Malware/31928" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Example%20of%20%22Modular%22%20Malware/31928</a><br /> Sysaid XXE Vulnerabilities<br />  IT Service Management Software Sysaid patched a number of XXE vulnerabilities. Without authentication, an attacker is able to obtain confidential data and completely compromise the system. watchTowr published a detailed analysis of the flaws including exploit code. <br /><a href="https://labs.watchtowr.com/sysowned-your-friendly-rce-support-ticket/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/sysowned-your-friendly-rce-support-ticket/</a><br /> Cisco IOS XE Wireless Controller Software Arbitrary File Upload Vulnerability<br />  Cisco Patched a vulnerability in its wireless controller software that may be used to not only upload files but also execute code as root without authentication.<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wlc-file-uplpd-rHZG9UfC" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wlc-file-uplpd-rHZG9UfC</a><br /> Unifi Protect Camera Vulnerability<br />  Ubiquity patched a vulnerability in its Protect camera firmware fixing a buffer overflow flaw.<br /><a href="https://community.ui.com/releases/Security-Advisory-Bulletin-047-047/cef86c37-7421-44fd-b251-84e76475a5bc" target="_blank" rel="noreferrer noopener">https://community.ui.com/releases/Security-Advisory-Bulletin-047-047/cef86c37-7421-44fd-b251-84e76475a5bc</a><br />]]></itunes:summary><itunes:duration>342</itunes:duration><itunes:keywords>business,camera,cisco,cyber,cybersecurity,daily,hacking,infosec,it,malware,modular,network,news,protect,security,sysaid,ubiquity,unifi,wireless,xxe</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9442</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, May 7th: Infostealer with Webserver; Android Update; CISA Warning</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-may-7th-infostealer-with-webserver-android-update-cisa-warning--65962774</link><description><![CDATA[<br /> Python InfoStealer with Embedded Phishing Webserver<br />  Didier found an interesting infostealer that, in addition to implementing typical infostealer functionality, includes a web server suitable to create local phishing sites.<br /><a href="https://isc.sans.edu/diary/Python%20InfoStealer%20with%20Embedded%20Phishing%20Webserver/31924" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Python%20InfoStealer%20with%20Embedded%20Phishing%20Webserver/31924</a><br /> Android Update Fixes Freetype 0-Day<br />  Google released its monthly Android update. As part of the update, it patched a vulnerability in Freetype that is already being exploited. Android is not alone in using Freetype. Freetype is a very commonly used library to parse fonts like Truetype fonts.<br /><a href="https://source.android.com/docs/security/bulletin/2025-05-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2025-05-01</a><br /> CISA Warns of Unsophistacted Cyber Actors<br />  CISA released an interesting title report warning operators of operational technology networks of ubiquitous attacks by unsophisticated actors. It emphasizes how important it is to not forget basic security measures to defend against these attacks.<br /><a href="https://www.cisa.gov/news-events/alerts/2025/05/06/unsophisticated-cyber-actors-targeting-operational-technology" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2025/05/06/unsophisticated-cyber-actors-targeting-operational-technology</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9440.mp3</guid><pubDate>Wed, 07 May 2025 03:35:15 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65962774/9440.mp3" length="5665840" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9440" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Python InfoStealer with Embedded Phishing Webserver
  Didier found an interesting infostealer that, in addition to implementing typical infostealer functionality, includes a web server suitable to create local phishing sites....</itunes:subtitle><itunes:summary><![CDATA[<br /> Python InfoStealer with Embedded Phishing Webserver<br />  Didier found an interesting infostealer that, in addition to implementing typical infostealer functionality, includes a web server suitable to create local phishing sites.<br /><a href="https://isc.sans.edu/diary/Python%20InfoStealer%20with%20Embedded%20Phishing%20Webserver/31924" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Python%20InfoStealer%20with%20Embedded%20Phishing%20Webserver/31924</a><br /> Android Update Fixes Freetype 0-Day<br />  Google released its monthly Android update. As part of the update, it patched a vulnerability in Freetype that is already being exploited. Android is not alone in using Freetype. Freetype is a very commonly used library to parse fonts like Truetype fonts.<br /><a href="https://source.android.com/docs/security/bulletin/2025-05-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2025-05-01</a><br /> CISA Warns of Unsophistacted Cyber Actors<br />  CISA released an interesting title report warning operators of operational technology networks of ubiquitous attacks by unsophisticated actors. It emphasizes how important it is to not forget basic security measures to defend against these attacks.<br /><a href="https://www.cisa.gov/news-events/alerts/2025/05/06/unsophisticated-cyber-actors-targeting-operational-technology" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2025/05/06/unsophisticated-cyber-actors-targeting-operational-technology</a><br />]]></itunes:summary><itunes:duration>405</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,infostealer,internet,it,network,news,phishing,python,security,webserver</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9440</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, May 6th: Mirai Exploiting Samsung magicInfo 9; Kali Signing Key Lost;</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-may-6th-mirai-exploiting-samsung-magicinfo-9-kali-signing-key-lost--65933056</link><description><![CDATA[<br /> Mirai Now Exploits Samsung MagicINFO CMS CVE-2024-7399<br />  The Mirai botnet added a new vulnerability to its arsenal. This vulnerability, a file upload and remote code execution vulnerability in Samsung s MagicInfo 9 CMS, was patched last August but attracted new attention last week after being mostly ignored so far.<br /><a href="https://isc.sans.edu/diary/Mirai+Now+Exploits+Samsung+MagicINFO+CMS+CVE20247399/31920" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Mirai+Now+Exploits+Samsung+MagicINFO+CMS+CVE20247399/31920</a><br /> New Kali Linux Signing Key<br />  The Kali Linux maintainers lost access to the secret key used to sign packages. Users must install a new key that will be used going forward.<br /><a href="https://www.kali.org/blog/new-kali-archive-signing-key/" target="_blank" rel="noreferrer noopener">https://www.kali.org/blog/new-kali-archive-signing-key/</a><br /> The Risk of Default Configuration: How Out-of-the-Box Helm Charts Can Breach Your Cluster<br />  Many out-of-the-box Helm charts for Kubernetes applications deploy vulnerable configurations with exposed ports and no authentication<br /><a href="https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/the-risk-of-default-configuration-how-out-of-the-box-helm-charts-can-breach-your/4409560" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/the-risk-of-default-configuration-how-out-of-the-box-helm-charts-can-breach-your/4409560</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9438.mp3</guid><pubDate>Tue, 06 May 2025 03:20:14 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65933056/9438.mp3" length="5842935" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9438" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Mirai Now Exploits Samsung MagicINFO CMS CVE-2024-7399
  The Mirai botnet added a new vulnerability to its arsenal. This vulnerability, a file upload and remote code execution vulnerability in Samsung s MagicInfo 9 CMS, was patched last August but...</itunes:subtitle><itunes:summary><![CDATA[<br /> Mirai Now Exploits Samsung MagicINFO CMS CVE-2024-7399<br />  The Mirai botnet added a new vulnerability to its arsenal. This vulnerability, a file upload and remote code execution vulnerability in Samsung s MagicInfo 9 CMS, was patched last August but attracted new attention last week after being mostly ignored so far.<br /><a href="https://isc.sans.edu/diary/Mirai+Now+Exploits+Samsung+MagicINFO+CMS+CVE20247399/31920" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Mirai+Now+Exploits+Samsung+MagicINFO+CMS+CVE20247399/31920</a><br /> New Kali Linux Signing Key<br />  The Kali Linux maintainers lost access to the secret key used to sign packages. Users must install a new key that will be used going forward.<br /><a href="https://www.kali.org/blog/new-kali-archive-signing-key/" target="_blank" rel="noreferrer noopener">https://www.kali.org/blog/new-kali-archive-signing-key/</a><br /> The Risk of Default Configuration: How Out-of-the-Box Helm Charts Can Breach Your Cluster<br />  Many out-of-the-box Helm charts for Kubernetes applications deploy vulnerable configurations with exposed ports and no authentication<br /><a href="https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/the-risk-of-default-configuration-how-out-of-the-box-helm-charts-can-breach-your/4409560" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/the-risk-of-default-configuration-how-out-of-the-box-helm-charts-can-breach-your/4409560</a><br />]]></itunes:summary><itunes:duration>417</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,helm,infosec,internet,it,kali,kubernetes,linux,mirai,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9438</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, May 5th: Steganography Challenge; Microsoft Makes Passkeys Default and Moves Away from Authenticator as Password Mana</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-may-5th-steganography-challenge-microsoft-makes-passkeys-default-and-moves-away-from-authenticator-as-password-mana--65913978</link><description><![CDATA[<br /> Steganography Challenge<br />  Didier published a fun steganography challenge. A solution will be offered on Saturday.<br /><a href="https://isc.sans.edu/diary/Steganography+Challenge/31910" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Steganography+Challenge/31910</a><br /> Microsoft Makes Passkeys Default Authentication Method<br />  Microsoft is now encouraging new users to use Passkeys as the  default  and only login method, further moving away from passwords<br /><a href="https://www.microsoft.com/en-us/security/blog/2025/05/01/pushing-passkeys-forward-microsofts-latest-updates-for-simpler-safer-sign-ins/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2025/05/01/pushing-passkeys-forward-microsofts-latest-updates-for-simpler-safer-sign-ins/</a><br /> Microsoft Authenticator Autofill Changes<br />  Microsoft will no longer support the use of Microsoft authenticator as a password safe. Instead, it will move users to the password prefill feature built into Microsoft Edge. This change will start in June and should be completed in August at which point you must have moved your credentials out of Microsoft Authenticator <br /><a href="https://support.microsoft.com/en-gb/account-billing/changes-to-microsoft-authenticator-autofill-09fd75df-dc04-4477-9619-811510805ab6" target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-gb/account-billing/changes-to-microsoft-authenticator-autofill-09fd75df-dc04-4477-9619-811510805ab6</a><br /> Backdoor found in popular e-commerce components<br />  SANSEC identified several backdoored Magento e-commerce components. These backdoors were installed as far back as 2019 but only recently activated, at which point they became known. Affected vendors dispute any compromise at this point.<br /><a href="https://sansec.io/research/license-backdoor" target="_blank" rel="noreferrer noopener">https://sansec.io/research/license-backdoor</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9436.mp3</guid><pubDate>Mon, 05 May 2025 03:50:16 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65913978/9436.mp3" length="5006050" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9436" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Steganography Challenge
  Didier published a fun steganography challenge. A solution will be offered on Saturday.
https://isc.sans.edu/diary/Steganography+Challenge/31910
 Microsoft Makes Passkeys Default Authentication Method
  Microsoft is now...</itunes:subtitle><itunes:summary><![CDATA[<br /> Steganography Challenge<br />  Didier published a fun steganography challenge. A solution will be offered on Saturday.<br /><a href="https://isc.sans.edu/diary/Steganography+Challenge/31910" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Steganography+Challenge/31910</a><br /> Microsoft Makes Passkeys Default Authentication Method<br />  Microsoft is now encouraging new users to use Passkeys as the  default  and only login method, further moving away from passwords<br /><a href="https://www.microsoft.com/en-us/security/blog/2025/05/01/pushing-passkeys-forward-microsofts-latest-updates-for-simpler-safer-sign-ins/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2025/05/01/pushing-passkeys-forward-microsofts-latest-updates-for-simpler-safer-sign-ins/</a><br /> Microsoft Authenticator Autofill Changes<br />  Microsoft will no longer support the use of Microsoft authenticator as a password safe. Instead, it will move users to the password prefill feature built into Microsoft Edge. This change will start in June and should be completed in August at which point you must have moved your credentials out of Microsoft Authenticator <br /><a href="https://support.microsoft.com/en-gb/account-billing/changes-to-microsoft-authenticator-autofill-09fd75df-dc04-4477-9619-811510805ab6" target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-gb/account-billing/changes-to-microsoft-authenticator-autofill-09fd75df-dc04-4477-9619-811510805ab6</a><br /> Backdoor found in popular e-commerce components<br />  SANSEC identified several backdoored Magento e-commerce components. These backdoors were installed as far back as 2019 but only recently activated, at which point they became known. Affected vendors dispute any compromise at this point.<br /><a href="https://sansec.io/research/license-backdoor" target="_blank" rel="noreferrer noopener">https://sansec.io/research/license-backdoor</a><br />]]></itunes:summary><itunes:duration>357</itunes:duration><itunes:keywords>authenticator,backdoor,business,challenge,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,magento,msft,network,news,passkeys,security,stegaonography</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9436</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, May 1st: More Steganography; Malicious Python Packages GMail C2; BEC to Steal Rent Payments</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-may-1st-more-steganography-malicious-python-packages-gmail-c2-bec-to-steal-rent-payments--65843589</link><description><![CDATA[<br /> Steganography Analysis With pngdump.py: Bitstreams<br />  More details from Didiear as to how to extract binary content hidden inside images<br /><a href="https://isc.sans.edu/diary/Steganography%20Analysis%20With%20pngdump.py%3A%20Bitstreams/31904" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Steganography%20Analysis%20With%20pngdump.py%3A%20Bitstreams/31904</a><br /> Using Trusted Protocols Against You: Gmail as a C2 Mechanism<br />  Attackers are using typosquatting to trick developers into installing malicious python packages. These python packages will use GMail as a command and control channel by sending email to hard coded GMail accounts<br /><a href="https://socket.dev/blog/using-trusted-protocols-against-you-gmail-as-a-c2-mechanism" target="_blank" rel="noreferrer noopener">https://socket.dev/blog/using-trusted-protocols-against-you-gmail-as-a-c2-mechanism</a><br /> Security Brief: French BEC Threat Actor Targets Property Payments<br /> A French business email compromise threat actor is targeting property management firms to send emails to tenents tricking them into sending rent payments to fake bank accounts<br /><a href="https://www.proofpoint.com/us/blog/threat-insight/security-brief-french-bec-threat-actor-targets-property-payments" target="_blank" rel="noreferrer noopener">https://www.proofpoint.com/us/blog/threat-insight/security-brief-french-bec-threat-actor-targets-property-payments</a><br /> SANS.edu Research Journal<br /><a href="https://isc.sans.edu/j/research" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/j/research</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9434.mp3</guid><pubDate>Fri, 02 May 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65843589/9434.mp3" length="6104701" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9434" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Steganography Analysis With pngdump.py: Bitstreams
  More details from Didiear as to how to extract binary content hidden inside images
https://isc.sans.edu/diary/Steganography%20Analysis%20With%20pngdump.py%3A%20Bitstreams/31904
 Using Trusted...</itunes:subtitle><itunes:summary><![CDATA[<br /> Steganography Analysis With pngdump.py: Bitstreams<br />  More details from Didiear as to how to extract binary content hidden inside images<br /><a href="https://isc.sans.edu/diary/Steganography%20Analysis%20With%20pngdump.py%3A%20Bitstreams/31904" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Steganography%20Analysis%20With%20pngdump.py%3A%20Bitstreams/31904</a><br /> Using Trusted Protocols Against You: Gmail as a C2 Mechanism<br />  Attackers are using typosquatting to trick developers into installing malicious python packages. These python packages will use GMail as a command and control channel by sending email to hard coded GMail accounts<br /><a href="https://socket.dev/blog/using-trusted-protocols-against-you-gmail-as-a-c2-mechanism" target="_blank" rel="noreferrer noopener">https://socket.dev/blog/using-trusted-protocols-against-you-gmail-as-a-c2-mechanism</a><br /> Security Brief: French BEC Threat Actor Targets Property Payments<br /> A French business email compromise threat actor is targeting property management firms to send emails to tenents tricking them into sending rent payments to fake bank accounts<br /><a href="https://www.proofpoint.com/us/blog/threat-insight/security-brief-french-bec-threat-actor-targets-property-payments" target="_blank" rel="noreferrer noopener">https://www.proofpoint.com/us/blog/threat-insight/security-brief-french-bec-threat-actor-targets-property-payments</a><br /> SANS.edu Research Journal<br /><a href="https://isc.sans.edu/j/research" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/j/research</a><br />]]></itunes:summary><itunes:duration>436</itunes:duration><itunes:keywords>bec,business,computer,cyber,cybersecurity,daily,gmail,hacking,infosec,internet,it,network,news,python,rent,research journal,security,steganograpy,tenants</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9434</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, May 1st: Sonicwall Attacks; Cached Windows RDP Credentials</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-may-1st-sonicwall-attacks-cached-windows-rdp-credentials--65819659</link><description><![CDATA[<br /> Web Scanning for Sonicwall Vulnerabilities CVE-2021-20016<br />  For the last week, scans for Sonicwall API  login  and  domain  endpoints have skyrocketed. These attacks may be exploiting an older vulnerability or just attempting to brute force credentials.<br /><a href="https://isc.sans.edu/diary/Web%20Scanning%20Sonicwall%20for%20CVE-2021-20016/31906" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Web%20Scanning%20Sonicwall%20for%20CVE-2021-20016/31906</a><br /> The Wizards APT Group SLAAC Spoofing Adversary in the Middle Attacks<br />  ESET published an article with details regarding an IPv6-linked attack they have observed. Attackers use router advertisements to inject fake recursive DNS servers that are used to inject IP addresses for hostnames used to update software. This leads to the victim downloading malware instead of legitimate updates.<br /><a href="https://www.welivesecurity.com/en/eset-research/thewizards-apt-group-slaac-spoofing-adversary-in-the-middle-attacks/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/thewizards-apt-group-slaac-spoofing-adversary-in-the-middle-attacks/</a><br /> Windows RDP Access is Possible with Old Credentials<br />  Credential caching may lead to Windows allowing RDP logins with old credentials.<br /><a href="https://arstechnica.com/security/2025/04/windows-rdp-lets-you-log-in-using-revoked-passwords-microsoft-is-ok-with-that/?comments-page=1#comments" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2025/04/windows-rdp-lets-you-log-in-using-revoked-passwords-microsoft-is-ok-with-that/?comments-page=1#comments</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9432.mp3</guid><pubDate>Thu, 01 May 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65819659/9432.mp3" length="5442102" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9432" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Web Scanning for Sonicwall Vulnerabilities CVE-2021-20016
  For the last week, scans for Sonicwall API  login  and  domain  endpoints have skyrocketed. These attacks may be exploiting an older vulnerability or just attempting to brute force...</itunes:subtitle><itunes:summary><![CDATA[<br /> Web Scanning for Sonicwall Vulnerabilities CVE-2021-20016<br />  For the last week, scans for Sonicwall API  login  and  domain  endpoints have skyrocketed. These attacks may be exploiting an older vulnerability or just attempting to brute force credentials.<br /><a href="https://isc.sans.edu/diary/Web%20Scanning%20Sonicwall%20for%20CVE-2021-20016/31906" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Web%20Scanning%20Sonicwall%20for%20CVE-2021-20016/31906</a><br /> The Wizards APT Group SLAAC Spoofing Adversary in the Middle Attacks<br />  ESET published an article with details regarding an IPv6-linked attack they have observed. Attackers use router advertisements to inject fake recursive DNS servers that are used to inject IP addresses for hostnames used to update software. This leads to the victim downloading malware instead of legitimate updates.<br /><a href="https://www.welivesecurity.com/en/eset-research/thewizards-apt-group-slaac-spoofing-adversary-in-the-middle-attacks/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/thewizards-apt-group-slaac-spoofing-adversary-in-the-middle-attacks/</a><br /> Windows RDP Access is Possible with Old Credentials<br />  Credential caching may lead to Windows allowing RDP logins with old credentials.<br /><a href="https://arstechnica.com/security/2025/04/windows-rdp-lets-you-log-in-using-revoked-passwords-microsoft-is-ok-with-that/?comments-page=1#comments" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2025/04/windows-rdp-lets-you-log-in-using-revoked-passwords-microsoft-is-ok-with-that/?comments-page=1#comments</a><br />]]></itunes:summary><itunes:duration>389</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,ipv6,it,network,news,rdp,security,slaac,sonicwall,windows</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9432</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, April 30th: SMS Attacks; Apple Airplay Vulnerabilities</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-april-30th-sms-attacks-apple-airplay-vulnerabilities--65800451</link><description><![CDATA[<br /> More Scans for SMS Gateways and APIs<br />  Attackers are not just looking for SMS Gateways like the scans we reported on last week, but they are also actively scanning for other ways to use APIs and add on tools to send messages using other people s credentials.<br /><a href="https://isc.sans.edu/diary/More%20Scans%20for%20SMS%20Gateways%20and%20APIs/31902" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/More%20Scans%20for%20SMS%20Gateways%20and%20APIs/31902</a><br /> AirBorne: AirPlay Vulnerabilities<br />  Researchers at Oligo revealed over 20 weaknesses they found in Apple s implementation of the AirPlay protocol. These vulnerabilities can be abused to execute code or launch denial-of-service attacks against affected devices. Apple patched the vulnerabilities in recent updates.<br /><a href="https://www.oligo.security/blog/airborne" target="_blank" rel="noreferrer noopener">https://www.oligo.security/blog/airborne</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9430.mp3</guid><pubDate>Wed, 30 Apr 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65800451/9430.mp3" length="7440736" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9430" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 More Scans for SMS Gateways and APIs
  Attackers are not just looking for SMS Gateways like the scans we reported on last week, but they are also actively scanning for other ways to use APIs and add on tools to send messages using other people s...</itunes:subtitle><itunes:summary><![CDATA[<br /> More Scans for SMS Gateways and APIs<br />  Attackers are not just looking for SMS Gateways like the scans we reported on last week, but they are also actively scanning for other ways to use APIs and add on tools to send messages using other people s credentials.<br /><a href="https://isc.sans.edu/diary/More%20Scans%20for%20SMS%20Gateways%20and%20APIs/31902" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/More%20Scans%20for%20SMS%20Gateways%20and%20APIs/31902</a><br /> AirBorne: AirPlay Vulnerabilities<br />  Researchers at Oligo revealed over 20 weaknesses they found in Apple s implementation of the AirPlay protocol. These vulnerabilities can be abused to execute code or launch denial-of-service attacks against affected devices. Apple patched the vulnerabilities in recent updates.<br /><a href="https://www.oligo.security/blog/airborne" target="_blank" rel="noreferrer noopener">https://www.oligo.security/blog/airborne</a><br />]]></itunes:summary><itunes:duration>532</itunes:duration><itunes:keywords>airplay,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,sms</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9430</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, April 29th: SRUM-DUMP 3; Policy Puppetry; Choice Jacking; @sansinstitute at #RSAC</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-april-29th-srum-dump-3-policy-puppetry-choice-jacking-sansinstitute-at-rsac--65788253</link><description><![CDATA[<br /> SRUM-DUMP Version 3: Uncovering Malware Activity in Forensics<br />   Mark Baggett released SRUM-DUMP Version 3. The tool simplifies data extraction from Widnows  System Resource Usage Monitor (SRUM). This database logs how much resources software used for 30 days, and is invaluable to find out what software was executed when and if it sent or received network data.<br /><a href="https://isc.sans.edu/diary/SRUM-DUMP%20Version%203%3A%20Uncovering%20Malware%20Activity%20in%20Forensics/31896" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SRUM-DUMP%20Version%203%3A%20Uncovering%20Malware%20Activity%20in%20Forensics/31896</a><br /> Novel Universal Bypass For All Major LLMS<br />   Hidden Layer discovered a new prompt injection technique that bypasses security constraints in large language models.<br /> The technique uses an XML formatted prequel for a prompt, which appears to the LLM as a policy file. This  Policy Puppetry  can be used to rewrite some of the security policies configured for LLMs. Unlike other techniques, this technique works across multiple LLMs without changing the policy.<br /><a href="https://hiddenlayer.com/innovation-hub/novel-universal-bypass-for-all-major-llms/" target="_blank" rel="noreferrer noopener">https://hiddenlayer.com/innovation-hub/novel-universal-bypass-for-all-major-llms/</a><br /> CHOICEJACKING: Compromising Mobile Devices through Malicious Chargers like a Decade ago<br />  The old  Juice Jacking  is back, at least if you do not run the latest version of Android or iOS. This issue may allow a malicious USB device, particularly a USB charger, to take control of a device connected to it.<br /><a href="https://pure.tugraz.at/ws/portalfiles/portal/89650227/Final_Paper_Usenix.pdf" target="_blank" rel="noreferrer noopener">https://pure.tugraz.at/ws/portalfiles/portal/89650227/Final_Paper_Usenix.pdf</a><br /> SANS @RSA: <a href="https://www.sans.org/mlp/rsac/" target="_blank" rel="noreferrer noopener">https://www.sans.org/mlp/rsac/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9428.mp3</guid><pubDate>Tue, 29 Apr 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65788253/9428.mp3" length="6405917" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9428" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 SRUM-DUMP Version 3: Uncovering Malware Activity in Forensics
   Mark Baggett released SRUM-DUMP Version 3. The tool simplifies data extraction from Widnows  System Resource Usage Monitor (SRUM). This database logs how much resources software used...</itunes:subtitle><itunes:summary><![CDATA[<br /> SRUM-DUMP Version 3: Uncovering Malware Activity in Forensics<br />   Mark Baggett released SRUM-DUMP Version 3. The tool simplifies data extraction from Widnows  System Resource Usage Monitor (SRUM). This database logs how much resources software used for 30 days, and is invaluable to find out what software was executed when and if it sent or received network data.<br /><a href="https://isc.sans.edu/diary/SRUM-DUMP%20Version%203%3A%20Uncovering%20Malware%20Activity%20in%20Forensics/31896" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SRUM-DUMP%20Version%203%3A%20Uncovering%20Malware%20Activity%20in%20Forensics/31896</a><br /> Novel Universal Bypass For All Major LLMS<br />   Hidden Layer discovered a new prompt injection technique that bypasses security constraints in large language models.<br /> The technique uses an XML formatted prequel for a prompt, which appears to the LLM as a policy file. This  Policy Puppetry  can be used to rewrite some of the security policies configured for LLMs. Unlike other techniques, this technique works across multiple LLMs without changing the policy.<br /><a href="https://hiddenlayer.com/innovation-hub/novel-universal-bypass-for-all-major-llms/" target="_blank" rel="noreferrer noopener">https://hiddenlayer.com/innovation-hub/novel-universal-bypass-for-all-major-llms/</a><br /> CHOICEJACKING: Compromising Mobile Devices through Malicious Chargers like a Decade ago<br />  The old  Juice Jacking  is back, at least if you do not run the latest version of Android or iOS. This issue may allow a malicious USB device, particularly a USB charger, to take control of a device connected to it.<br /><a href="https://pure.tugraz.at/ws/portalfiles/portal/89650227/Final_Paper_Usenix.pdf" target="_blank" rel="noreferrer noopener">https://pure.tugraz.at/ws/portalfiles/portal/89650227/Final_Paper_Usenix.pdf</a><br /> SANS @RSA: <a href="https://www.sans.org/mlp/rsac/" target="_blank" rel="noreferrer noopener">https://www.sans.org/mlp/rsac/</a><br />]]></itunes:summary><itunes:duration>457</itunes:duration><itunes:keywords>business,chargers,choice jacking,cyber,cybersecurity,daily,forensics,hacking,infosec,it,llms,network,news,policy,puppetry,rsac,security,srum,usb,windows</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9428</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, April 28th: Image Steganography; SAP Netweaver Exploited</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-april-28th-image-steganography-sap-netweaver-exploited--65774782</link><description><![CDATA[<br /> Example of a Payload Delivered Through Steganography<br />  Xavier and Didier published two diaries this weekend, building on each other. First, Xavier showed an example of an image being used to smuggle an executable past network defenses, and second, Didier showed how to use his tools to extract the binary.<br /><a href="https://isc.sans.edu/diary/Example%20of%20a%20Payload%20Delivered%20Through%20Steganography/31892" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Example%20of%20a%20Payload%20Delivered%20Through%20Steganography/31892</a><br /> SAP Netweaver Exploited CVE-2025-31324 <br />   An arbitrary file upload vulnerability in SAP s Netweaver product is actively exploited to upload webshells. Reliaquest discovered the issue. Reliaquest reports that they saw it being abused to upload the Brute Ratel C2 framework. Users of Netweaver must turn off the developmentserver alias and disable visual composer, and the application was deprecated for about 10 years. SAP has released an emergency update for the issue.<br /><a href="https://reliaquest.com/blog/threat-spotlight-reliaquest-uncovers-vulnerability-behind-sap-netweaver-compromise/" target="_blank" rel="noreferrer noopener">https://reliaquest.com/blog/threat-spotlight-reliaquest-uncovers-vulnerability-behind-sap-netweaver-compromise/</a><br /><a href="https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/" target="_blank" rel="noreferrer noopener">https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/</a><br /> Any.Run Reports False Positive Uploads<br />  Due to false positives caused by MS Defender XDR flagging Adobe Acrobat Cloud links as malicious, many users of Any.Run s free tier uploaded confidential documents to Any.Run. Anyrun blocked these uploads for now but reminded users to be cautious about what documents are being uploaded.<br /><a href="https://x.com/anyrun_app/status/1915429758516560190" target="_blank" rel="noreferrer noopener">https://x.com/anyrun_app/status/1915429758516560190</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9426.mp3</guid><pubDate>Mon, 28 Apr 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65774782/9426.mp3" length="6658743" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9426" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Example of a Payload Delivered Through Steganography
  Xavier and Didier published two diaries this weekend, building on each other. First, Xavier showed an example of an image being used to smuggle an executable past network defenses, and second,...</itunes:subtitle><itunes:summary><![CDATA[<br /> Example of a Payload Delivered Through Steganography<br />  Xavier and Didier published two diaries this weekend, building on each other. First, Xavier showed an example of an image being used to smuggle an executable past network defenses, and second, Didier showed how to use his tools to extract the binary.<br /><a href="https://isc.sans.edu/diary/Example%20of%20a%20Payload%20Delivered%20Through%20Steganography/31892" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Example%20of%20a%20Payload%20Delivered%20Through%20Steganography/31892</a><br /> SAP Netweaver Exploited CVE-2025-31324 <br />   An arbitrary file upload vulnerability in SAP s Netweaver product is actively exploited to upload webshells. Reliaquest discovered the issue. Reliaquest reports that they saw it being abused to upload the Brute Ratel C2 framework. Users of Netweaver must turn off the developmentserver alias and disable visual composer, and the application was deprecated for about 10 years. SAP has released an emergency update for the issue.<br /><a href="https://reliaquest.com/blog/threat-spotlight-reliaquest-uncovers-vulnerability-behind-sap-netweaver-compromise/" target="_blank" rel="noreferrer noopener">https://reliaquest.com/blog/threat-spotlight-reliaquest-uncovers-vulnerability-behind-sap-netweaver-compromise/</a><br /><a href="https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/" target="_blank" rel="noreferrer noopener">https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/</a><br /> Any.Run Reports False Positive Uploads<br />  Due to false positives caused by MS Defender XDR flagging Adobe Acrobat Cloud links as malicious, many users of Any.Run s free tier uploaded confidential documents to Any.Run. Anyrun blocked these uploads for now but reminded users to be cautious about what documents are being uploaded.<br /><a href="https://x.com/anyrun_app/status/1915429758516560190" target="_blank" rel="noreferrer noopener">https://x.com/anyrun_app/status/1915429758516560190</a><br />]]></itunes:summary><itunes:duration>476</itunes:duration><itunes:keywords>adobe,any.run,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microsoft,netweaver,network,news,sap,security,steganography,xdr</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9426</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, April 25th: SMS Gateway Scans; Comvault Exploit; Patch Window Shrinkage; More inetpub issues;</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-april-25th-sms-gateway-scans-comvault-exploit-patch-window-shrinkage-more-inetpub-issues--65717004</link><description><![CDATA[<br /> Attacks against Teltonika Networks SMS Gateways<br />   Attackers are actively scanning for SMS Gateways. These attacks take advantage of default passwords and other commonly used passwords. <br /><a href="https://isc.sans.edu/diary/Attacks%20against%20Teltonika%20Networks%20SMS%20Gateways/31888" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Attacks%20against%20Teltonika%20Networks%20SMS%20Gateways/31888</a><br /> Commvault Vulnerability CVE-2205-34028<br />  Commvault, about a week ago, published an advisory and a fix for a vulnerability in its backup software. watchTowr now released a detailed writeup and exploit for the vulnerability<br /><a href="https://labs.watchtowr.com/fire-in-the-hole-were-breaching-the-vault-commvault-remote-code-execution-cve-2025-34028/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/fire-in-the-hole-were-breaching-the-vault-commvault-remote-code-execution-cve-2025-34028/</a><br /> Exploitation Trends Q1 2025<br />  Vulncheck published a summary of exploitation trends, pointing out that about a quarter of vulnerabilities are exploited a day after a patch is made available.<br /><a href="https://vulncheck.com/blog/exploitation-trends-q1-2025" target="_blank" rel="noreferrer noopener">https://vulncheck.com/blog/exploitation-trends-q1-2025</a><br /> inetpub directory issues<br />  The inetpub directory introduced by Microsoft in its April patch may lead to a denial of service against applying patches on Windows if an attacker can create a junction for that location pointing to an existing system binary like Notepad.<br /><a href="https://doublepulsar.com/microsofts-patch-for-cve-2025-21204-symlink-vulnerability-introduces-another-symlink-vulnerability-9ea085537741" target="_blank" rel="noreferrer noopener">https://doublepulsar.com/microsofts-patch-for-cve-2025-21204-symlink-vulnerability-introduces-another-symlink-vulnerability-9ea085537741</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9424.mp3</guid><pubDate>Fri, 25 Apr 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65717004/9424.mp3" length="5579068" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9424" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Attacks against Teltonika Networks SMS Gateways
   Attackers are actively scanning for SMS Gateways. These attacks take advantage of default passwords and other commonly used passwords....</itunes:subtitle><itunes:summary><![CDATA[<br /> Attacks against Teltonika Networks SMS Gateways<br />   Attackers are actively scanning for SMS Gateways. These attacks take advantage of default passwords and other commonly used passwords. <br /><a href="https://isc.sans.edu/diary/Attacks%20against%20Teltonika%20Networks%20SMS%20Gateways/31888" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Attacks%20against%20Teltonika%20Networks%20SMS%20Gateways/31888</a><br /> Commvault Vulnerability CVE-2205-34028<br />  Commvault, about a week ago, published an advisory and a fix for a vulnerability in its backup software. watchTowr now released a detailed writeup and exploit for the vulnerability<br /><a href="https://labs.watchtowr.com/fire-in-the-hole-were-breaching-the-vault-commvault-remote-code-execution-cve-2025-34028/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/fire-in-the-hole-were-breaching-the-vault-commvault-remote-code-execution-cve-2025-34028/</a><br /> Exploitation Trends Q1 2025<br />  Vulncheck published a summary of exploitation trends, pointing out that about a quarter of vulnerabilities are exploited a day after a patch is made available.<br /><a href="https://vulncheck.com/blog/exploitation-trends-q1-2025" target="_blank" rel="noreferrer noopener">https://vulncheck.com/blog/exploitation-trends-q1-2025</a><br /> inetpub directory issues<br />  The inetpub directory introduced by Microsoft in its April patch may lead to a denial of service against applying patches on Windows if an attacker can create a junction for that location pointing to an existing system binary like Notepad.<br /><a href="https://doublepulsar.com/microsofts-patch-for-cve-2025-21204-symlink-vulnerability-introduces-another-symlink-vulnerability-9ea085537741" target="_blank" rel="noreferrer noopener">https://doublepulsar.com/microsofts-patch-for-cve-2025-21204-symlink-vulnerability-introduces-another-symlink-vulnerability-9ea085537741</a><br />]]></itunes:summary><itunes:duration>398</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,inetpub,infosec,internet,it,network,news,patches,security,sms,teltonika,vulncheck,watchtowr</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9424</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday, April 24th: Honeypot iptables Maintenance; XRPL.js Compromise; Erlang/OTP SSH Vuln affecting Cisco</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-april-24th-honeypot-iptables-maintenance-xrpl-js-compromise-erlang-otp-ssh-vuln-affecting-cisco--65694358</link><description><![CDATA[<br /> Honeypot Iptables Maintenance and DShield-SIEM Logging<br />  In this diary, Jesse is talking about some of the tasks to maintain a honeypot, like keeping filebeats up to date and adjusting configurations in case your dynamic IP address changes<br /><a href="https://isc.sans.edu/diary/Honeypot%20Iptables%20Maintenance%20and%20DShield-SIEM%20Logging/31876" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Honeypot%20Iptables%20Maintenance%20and%20DShield-SIEM%20Logging/31876</a><br /> XRPL.js Compromised<br />  An unknown actor was able to push malicious updates of the XRPL.js library to NPM. The library is officially recommended for writing Riple (RPL) cryptocurrency code. The malicious library exfiltrated secret keys to the attacker<br /><a href="https://www.aikido.dev/blog/xrp-supplychain-attack-official-npm-package-infected-with-crypto-stealing-backdoor" target="_blank" rel="noreferrer noopener">https://www.aikido.dev/blog/xrp-supplychain-attack-official-npm-package-infected-with-crypto-stealing-backdoor</a><br /><a href="https://github.com/XRPLF/xrpl.js/security/advisories/GHSA-33qr-m49q-rxfx" target="_blank" rel="noreferrer noopener">https://github.com/XRPLF/xrpl.js/security/advisories/GHSA-33qr-m49q-rxfx</a><br /> Cisco Equipment Affected by Erlang/OTP SSH Vulnerability<br />  Cisco published an advisory explaining which of its products are affected by the critical Erlang/OTP SSH library vulnerability<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-erlang-otp-ssh-xyZZy" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-erlang-otp-ssh-xyZZy</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9422.mp3</guid><pubDate>Thu, 24 Apr 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65694358/9422.mp3" length="4823630" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9422" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Honeypot Iptables Maintenance and DShield-SIEM Logging
  In this diary, Jesse is talking about some of the tasks to maintain a honeypot, like keeping filebeats up to date and adjusting configurations in case your dynamic IP address changes...</itunes:subtitle><itunes:summary><![CDATA[<br /> Honeypot Iptables Maintenance and DShield-SIEM Logging<br />  In this diary, Jesse is talking about some of the tasks to maintain a honeypot, like keeping filebeats up to date and adjusting configurations in case your dynamic IP address changes<br /><a href="https://isc.sans.edu/diary/Honeypot%20Iptables%20Maintenance%20and%20DShield-SIEM%20Logging/31876" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Honeypot%20Iptables%20Maintenance%20and%20DShield-SIEM%20Logging/31876</a><br /> XRPL.js Compromised<br />  An unknown actor was able to push malicious updates of the XRPL.js library to NPM. The library is officially recommended for writing Riple (RPL) cryptocurrency code. The malicious library exfiltrated secret keys to the attacker<br /><a href="https://www.aikido.dev/blog/xrp-supplychain-attack-official-npm-package-infected-with-crypto-stealing-backdoor" target="_blank" rel="noreferrer noopener">https://www.aikido.dev/blog/xrp-supplychain-attack-official-npm-package-infected-with-crypto-stealing-backdoor</a><br /><a href="https://github.com/XRPLF/xrpl.js/security/advisories/GHSA-33qr-m49q-rxfx" target="_blank" rel="noreferrer noopener">https://github.com/XRPLF/xrpl.js/security/advisories/GHSA-33qr-m49q-rxfx</a><br /> Cisco Equipment Affected by Erlang/OTP SSH Vulnerability<br />  Cisco published an advisory explaining which of its products are affected by the critical Erlang/OTP SSH library vulnerability<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-erlang-otp-ssh-xyZZy" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-erlang-otp-ssh-xyZZy</a><br />]]></itunes:summary><itunes:duration>345</itunes:duration><itunes:keywords>business,cyber,cybersecurity,daily,erlang,erlang/otp,filebeats,hacking,honeypot,infosec,iptables,it,network,news,npm,ripl,siem,ssh,supply chain,xrp</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9422</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday, April 23rd: More xorsearch Updates; DKIM Replay Attack; SSL.com Vulnerability Fixed</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-april-23rd-more-xorsearch-updates-dkim-replay-attack-ssl-com-vulnerability-fixed--65673564</link><description><![CDATA[<br /> xorsearch.py: Ad Hoc YARA Rules<br />   Adhoc YARA rules allow for easy searches using command line arguments without having to write complete YARA rules for simple use cases like string and regex searches<br /><a href="https://isc.sans.edu/diary/xorsearch.py%3A%20%22Ad%20Hoc%20YARA%20Rules%22/31856" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/xorsearch.py%3A%20%22Ad%20Hoc%20YARA%20Rules%22/31856</a><br /> Google Spoofed via DKIM Replay Attack<br />  DKIM replay attacks are a known issue where the attacker re-uses a prior DKIM signature. This will work as long as the headers signed by the signature are unchanged. Recently, this attack has been successful against Google.<br /><a href="https://easydmarc.com/blog/google-spoofed-via-dkim-replay-attack-a-technical-breakdown/" target="_blank" rel="noreferrer noopener">https://easydmarc.com/blog/google-spoofed-via-dkim-replay-attack-a-technical-breakdown/</a><br /> SSL.com E-Mail Validation Bug<br />  SSL.com did not properly verify which domain a particular email address is authorized to receive certificates for. This could have been exploited against webmail providers.<br /><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1961406" target="_blank" rel="noreferrer noopener">https://bugzilla.mozilla.org/show_bug.cgi?id=1961406</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9420.mp3</guid><pubDate>Wed, 23 Apr 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65673564/9420.mp3" length="5291512" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9420" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 xorsearch.py: Ad Hoc YARA Rules
   Adhoc YARA rules allow for easy searches using command line arguments without having to write complete YARA rules for simple use cases like string and regex searches...</itunes:subtitle><itunes:summary><![CDATA[<br /> xorsearch.py: Ad Hoc YARA Rules<br />   Adhoc YARA rules allow for easy searches using command line arguments without having to write complete YARA rules for simple use cases like string and regex searches<br /><a href="https://isc.sans.edu/diary/xorsearch.py%3A%20%22Ad%20Hoc%20YARA%20Rules%22/31856" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/xorsearch.py%3A%20%22Ad%20Hoc%20YARA%20Rules%22/31856</a><br /> Google Spoofed via DKIM Replay Attack<br />  DKIM replay attacks are a known issue where the attacker re-uses a prior DKIM signature. This will work as long as the headers signed by the signature are unchanged. Recently, this attack has been successful against Google.<br /><a href="https://easydmarc.com/blog/google-spoofed-via-dkim-replay-attack-a-technical-breakdown/" target="_blank" rel="noreferrer noopener">https://easydmarc.com/blog/google-spoofed-via-dkim-replay-attack-a-technical-breakdown/</a><br /> SSL.com E-Mail Validation Bug<br />  SSL.com did not properly verify which domain a particular email address is authorized to receive certificates for. This could have been exploited against webmail providers.<br /><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1961406" target="_blank" rel="noreferrer noopener">https://bugzilla.mozilla.org/show_bug.cgi?id=1961406</a><br />]]></itunes:summary><itunes:duration>378</itunes:duration><itunes:keywords>ad-hoc,business,computer,cyber,cybersecurity,daily,dkim,dmarc,google,hacking,infosec,internet,it,network,news,replay,security,xorsearch,yara</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9420</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, April 22nd: Phishing via Google; ChatGPT Fingerprint; Asus AI Cloud Vuln; PyTorch RCE</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-april-22nd-phishing-via-google-chatgpt-fingerprint-asus-ai-cloud-vuln-pytorch-rce--65659859</link><description><![CDATA[<br /> It's 2025, so why are malicious advertising URLs still going strong?<br />   Phishing attacks continue to take advantage of Google s advertising services. Sadly, this is still the case for obviously malicious links, even after various anti-phishing services flag the URL.<br /><a href="https://isc.sans.edu/diary/It%27s%202025...%20so%20why%20are%20obviously%20malicious%20advertising%20URLs%20still%20going%20strong%3F/31880" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/It%27s%202025...%20so%20why%20are%20obviously%20malicious%20advertising%20URLs%20still%20going%20strong%3F/31880</a><br /> ChatGPT Fingerprinting Documents via Unicode<br />  ChatGPT apparently started leaving fingerprints in texts, which it creates by adding invisible Unicode characters like non-breaking spaces.<br /><a href="https://www.rumidocs.com/newsroom/new-chatgpt-models-seem-to-leave-watermarks-on-text" target="_blank" rel="noreferrer noopener">https://www.rumidocs.com/newsroom/new-chatgpt-models-seem-to-leave-watermarks-on-text</a><br /> Asus AI Cloud Security Advisory<br />  Asus warns of a remote code execution vulnerability in its routers. The vulnerability is related to the AI Cloud feature. If your router is EoL, disabling the feature will mitigate the vulnerability<br /><a href="https://www.asus.com/content/asus-product-security-advisory/" target="_blank" rel="noreferrer noopener">https://www.asus.com/content/asus-product-security-advisory/</a><br /> PyTorch Vulnerability<br />  PyTorch fixed a remote code execution vulnerability exploitable if a malicious model was loaded. This issue was exploitable even with the  weight_only=True" setting selected<br /><a href="https://github.com/pytorch/pytorch/security/advisories/GHSA-53q9-r3pm-6pq6" target="_blank" rel="noreferrer noopener">https://github.com/pytorch/pytorch/security/advisories/GHSA-53q9-r3pm-6pq6</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9418.mp3</guid><pubDate>Tue, 22 Apr 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65659859/9418.mp3" length="4695314" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9418" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 It's 2025, so why are malicious advertising URLs still going strong?
   Phishing attacks continue to take advantage of Google s advertising services. Sadly, this is still the case for obviously malicious links, even after various anti-phishing...</itunes:subtitle><itunes:summary><![CDATA[<br /> It's 2025, so why are malicious advertising URLs still going strong?<br />   Phishing attacks continue to take advantage of Google s advertising services. Sadly, this is still the case for obviously malicious links, even after various anti-phishing services flag the URL.<br /><a href="https://isc.sans.edu/diary/It%27s%202025...%20so%20why%20are%20obviously%20malicious%20advertising%20URLs%20still%20going%20strong%3F/31880" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/It%27s%202025...%20so%20why%20are%20obviously%20malicious%20advertising%20URLs%20still%20going%20strong%3F/31880</a><br /> ChatGPT Fingerprinting Documents via Unicode<br />  ChatGPT apparently started leaving fingerprints in texts, which it creates by adding invisible Unicode characters like non-breaking spaces.<br /><a href="https://www.rumidocs.com/newsroom/new-chatgpt-models-seem-to-leave-watermarks-on-text" target="_blank" rel="noreferrer noopener">https://www.rumidocs.com/newsroom/new-chatgpt-models-seem-to-leave-watermarks-on-text</a><br /> Asus AI Cloud Security Advisory<br />  Asus warns of a remote code execution vulnerability in its routers. The vulnerability is related to the AI Cloud feature. If your router is EoL, disabling the feature will mitigate the vulnerability<br /><a href="https://www.asus.com/content/asus-product-security-advisory/" target="_blank" rel="noreferrer noopener">https://www.asus.com/content/asus-product-security-advisory/</a><br /> PyTorch Vulnerability<br />  PyTorch fixed a remote code execution vulnerability exploitable if a malicious model was loaded. This issue was exploitable even with the  weight_only=True" setting selected<br /><a href="https://github.com/pytorch/pytorch/security/advisories/GHSA-53q9-r3pm-6pq6" target="_blank" rel="noreferrer noopener">https://github.com/pytorch/pytorch/security/advisories/GHSA-53q9-r3pm-6pq6</a><br />]]></itunes:summary><itunes:duration>335</itunes:duration><itunes:keywords>ai cloud,asus,business,computer,cyber,cybersecurity,daily,google,hacking,infosec,internet,it,network,news,phishing,pytorch,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9418</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ANS Stormcast Monday, April 21st: MSFT Entra Lockouts; Erlang/OTP SSH Exploit; Sonicwall Exploit; bubble.io bug</title><link>https://www.spreaker.com/episode/ans-stormcast-monday-april-21st-msft-entra-lockouts-erlang-otp-ssh-exploit-sonicwall-exploit-bubble-io-bug--65646663</link><description><![CDATA[<br /> Microsoft Entra User Lockout<br />  Multiple organizations reported widespread alerts and account lockouts this weekend from Microsoft Entra. The issue is caused by a new feature Microsoft enabled. This feature will lock accounts if Microsoft believes that the password for the account was compromised.<br /><a href="https://www.bleepingcomputer.com/news/microsoft/widespread-microsoft-entra-lockouts-tied-to-new-security-feature-rollout/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/microsoft/widespread-microsoft-entra-lockouts-tied-to-new-security-feature-rollout/</a><br /><a href="https://learn.microsoft.com/en-us/entra/identity/authentication/feature-availability" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/entra/identity/authentication/feature-availability</a><br /> Erlang/OTP SSH Exploit<br />  An exploit was published for the Erlang/OTP SSH vulnerability. The vulnerability is easy to exploit, and the exploit and a Metasploit module allow for easy remote code execution.<br /><a href="https://github.com/exa-offsec/ssh_erlangotp_rce/blob/main/ssh_erlangotp_rce.rb" target="_blank" rel="noreferrer noopener">https://github.com/exa-offsec/ssh_erlangotp_rce/blob/main/ssh_erlangotp_rce.rb</a><br /> Sonicwall Exploited<br />  An older command injection vulnerability is now exploited on Sonicwall devices after initially gaining access by brute-forcing credentials.<br /><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0022" target="_blank" rel="noreferrer noopener">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0022</a><br /> Unpatched Vulnerability in Bubble.io<br />  An unpatched vulnerability in the no-code platform bubble.io can be used to access any project hosted on the site.<br /><a href="https://github.com/demon-i386/pop_n_bubble" target="_blank" rel="noreferrer noopener">https://github.com/demon-i386/pop_n_bubble</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9416.mp3</guid><pubDate>Mon, 21 Apr 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65646663/9416.mp3" length="6319436" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9416" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Microsoft Entra User Lockout
  Multiple organizations reported widespread alerts and account lockouts this weekend from Microsoft Entra. The issue is caused by a new feature Microsoft enabled. This feature will lock accounts if Microsoft believes...</itunes:subtitle><itunes:summary><![CDATA[<br /> Microsoft Entra User Lockout<br />  Multiple organizations reported widespread alerts and account lockouts this weekend from Microsoft Entra. The issue is caused by a new feature Microsoft enabled. This feature will lock accounts if Microsoft believes that the password for the account was compromised.<br /><a href="https://www.bleepingcomputer.com/news/microsoft/widespread-microsoft-entra-lockouts-tied-to-new-security-feature-rollout/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/microsoft/widespread-microsoft-entra-lockouts-tied-to-new-security-feature-rollout/</a><br /><a href="https://learn.microsoft.com/en-us/entra/identity/authentication/feature-availability" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/entra/identity/authentication/feature-availability</a><br /> Erlang/OTP SSH Exploit<br />  An exploit was published for the Erlang/OTP SSH vulnerability. The vulnerability is easy to exploit, and the exploit and a Metasploit module allow for easy remote code execution.<br /><a href="https://github.com/exa-offsec/ssh_erlangotp_rce/blob/main/ssh_erlangotp_rce.rb" target="_blank" rel="noreferrer noopener">https://github.com/exa-offsec/ssh_erlangotp_rce/blob/main/ssh_erlangotp_rce.rb</a><br /> Sonicwall Exploited<br />  An older command injection vulnerability is now exploited on Sonicwall devices after initially gaining access by brute-forcing credentials.<br /><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0022" target="_blank" rel="noreferrer noopener">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0022</a><br /> Unpatched Vulnerability in Bubble.io<br />  An unpatched vulnerability in the no-code platform bubble.io can be used to access any project hosted on the site.<br /><a href="https://github.com/demon-i386/pop_n_bubble" target="_blank" rel="noreferrer noopener">https://github.com/demon-i386/pop_n_bubble</a><br />]]></itunes:summary><itunes:duration>451</itunes:duration><itunes:keywords>bubble,bubble.io,business,computer,cyber,cybersecurity,daily,entra,erlang,hacking,infosec,internet,it,microsoft,network,news,no-code,security,sonicwall,ssh</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9416</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, April 18th: Remnux Cloud Environment; Erlang/OTP SSH Vuln; Brickstorm Backdoor Analysis; GPT 4.1 Safety Controversy</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-april-18th-remnux-cloud-environment-erlang-otp-ssh-vuln-brickstorm-backdoor-analysis-gpt-4-1-safety-controversy--65619461</link><description><![CDATA[<br /> RedTail: Remnux and Malware Management<br />  A description showing how to set up a malware analysis in the cloud with Remnux and Kasm. RedTail is a sample to illustrate how the environment can be used.<br /><a href="https://isc.sans.edu/diary/RedTail%2C%20Remnux%20and%20Malware%20Management%20%5BGuest%20Diary%5D/31868" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/RedTail%2C%20Remnux%20and%20Malware%20Management%20%5BGuest%20Diary%5D/31868</a><br /> Critical Erlang/OTP SSH Vulnerability<br />  Researchers identified a critical vulnerability in the Erlang/OTP SSH library. Due to this vulnerability, SSH servers written in Erlang/OTP allow arbitrary remote code execution without prior authentication<br /><a href="https://www.openwall.com/lists/oss-security/2025/04/16/2" target="_blank" rel="noreferrer noopener">https://www.openwall.com/lists/oss-security/2025/04/16/2</a><br /> Brickstorm Analysis<br />  An analysis of a recent instance of the Brickstorm backdoor. This backdoor used to be more known for infecting Linux systems, but now it also infects Windows.<br /><a href="https://www.nviso.eu/blog/nviso-analyzes-brickstorm-espionage-backdoor" target="_blank" rel="noreferrer noopener">https://www.nviso.eu/blog/nviso-analyzes-brickstorm-espionage-backdoor</a><br /><a href="https://blog.nviso.eu/wp-content/uploads/2025/04/NVISO-BRICKSTORM-Report.pdf" target="_blank" rel="noreferrer noopener">https://blog.nviso.eu/wp-content/uploads/2025/04/NVISO-BRICKSTORM-Report.pdf</a><br /> OpenAI GPT 4.1 Controversy<br />  OpenAI released its latest model, GPT 4.1, without a safety report and guardrails to prevent malware creation.<br /><a href="https://opentools.ai/news/openai-stirs-controversy-with-gpt-41-release-lacking-safety-report" target="_blank" rel="noreferrer noopener">https://opentools.ai/news/openai-stirs-controversy-with-gpt-41-release-lacking-safety-report</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9414.mp3</guid><pubDate>Fri, 18 Apr 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65619461/9414.mp3" length="5302894" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9414" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 RedTail: Remnux and Malware Management
  A description showing how to set up a malware analysis in the cloud with Remnux and Kasm. RedTail is a sample to illustrate how the environment can be used....</itunes:subtitle><itunes:summary><![CDATA[<br /> RedTail: Remnux and Malware Management<br />  A description showing how to set up a malware analysis in the cloud with Remnux and Kasm. RedTail is a sample to illustrate how the environment can be used.<br /><a href="https://isc.sans.edu/diary/RedTail%2C%20Remnux%20and%20Malware%20Management%20%5BGuest%20Diary%5D/31868" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/RedTail%2C%20Remnux%20and%20Malware%20Management%20%5BGuest%20Diary%5D/31868</a><br /> Critical Erlang/OTP SSH Vulnerability<br />  Researchers identified a critical vulnerability in the Erlang/OTP SSH library. Due to this vulnerability, SSH servers written in Erlang/OTP allow arbitrary remote code execution without prior authentication<br /><a href="https://www.openwall.com/lists/oss-security/2025/04/16/2" target="_blank" rel="noreferrer noopener">https://www.openwall.com/lists/oss-security/2025/04/16/2</a><br /> Brickstorm Analysis<br />  An analysis of a recent instance of the Brickstorm backdoor. This backdoor used to be more known for infecting Linux systems, but now it also infects Windows.<br /><a href="https://www.nviso.eu/blog/nviso-analyzes-brickstorm-espionage-backdoor" target="_blank" rel="noreferrer noopener">https://www.nviso.eu/blog/nviso-analyzes-brickstorm-espionage-backdoor</a><br /><a href="https://blog.nviso.eu/wp-content/uploads/2025/04/NVISO-BRICKSTORM-Report.pdf" target="_blank" rel="noreferrer noopener">https://blog.nviso.eu/wp-content/uploads/2025/04/NVISO-BRICKSTORM-Report.pdf</a><br /> OpenAI GPT 4.1 Controversy<br />  OpenAI released its latest model, GPT 4.1, without a safety report and guardrails to prevent malware creation.<br /><a href="https://opentools.ai/news/openai-stirs-controversy-with-gpt-41-release-lacking-safety-report" target="_blank" rel="noreferrer noopener">https://opentools.ai/news/openai-stirs-controversy-with-gpt-41-release-lacking-safety-report</a><br />]]></itunes:summary><itunes:duration>379</itunes:duration><itunes:keywords>aws,brickstorm,business,container,cyber,cybersecurity,daily,docker,erlang,hacking,infosec,it,kasm,malware,news,openai,redtail,remnux,safety,ssh</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9414</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday April 17th: Apple Updates; Oracle Updates; Google Chrome Updates; CVE News;</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-april-17th-apple-updates-oracle-updates-google-chrome-updates-cve-news--65602014</link><description><![CDATA[<br /> Apple Updates<br />  Apple released updates for iOS, iPadOS, macOS, and VisionOS. The updates fix two vulnerabilities which had already been exploited against iOS.<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Vulnerability/31866" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Vulnerability/31866</a><br /> Oracle Updates<br />  Oracle released it quarterly critical patch update. The update addresses 378 security vulnerabilities. Many of the critical updates are already known vulnerabilities in open-source software like Apache and Nginx ingress.<br /><a href="https://www.oracle.com/security-alerts/cpuapr2025.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpuapr2025.html</a><br /> Oracle Breach Guidance<br />  CISA released guidance for users affected by the recent Oracle cloud breach. The guidance focuses on the likely loss of passwords.<br /><a href="https://www.cisa.gov/news-events/alerts/2025/04/16/cisa-releases-guidance-credential-risks-associated-potential-legacy-oracle-cloud-compromise" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2025/04/16/cisa-releases-guidance-credential-risks-associated-potential-legacy-oracle-cloud-compromise</a><br /> Google Chrome Update<br />  A Google Chrome update released today fixes two security vulnerabilities. One of the vulnerabilities is rated as critical.<br /><a href="https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop_15.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop_15.html</a><br /> CVE Updates<br />  CISA extended MITRE s funding to operate the CVE numbering scheme. However, a number of other organizations announced that they may start alternative vulnerability registers.<br /><a href="https://euvd.enisa.europa.eu/" target="_blank" rel="noreferrer noopener">https://euvd.enisa.europa.eu/</a><br /><a href="https://gcve.eu/" target="_blank" rel="noreferrer noopener">https://gcve.eu/</a><br /><a href="https://www.thecvefoundation.org/" target="_blank" rel="noreferrer noopener">https://www.thecvefoundation.org/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9412.mp3</guid><pubDate>Thu, 17 Apr 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65602014/9412.mp3" length="5105560" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9412" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Apple Updates
  Apple released updates for iOS, iPadOS, macOS, and VisionOS. The updates fix two vulnerabilities which had already been exploited against iOS.
https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Vulnerability/31866
 Oracle...</itunes:subtitle><itunes:summary><![CDATA[<br /> Apple Updates<br />  Apple released updates for iOS, iPadOS, macOS, and VisionOS. The updates fix two vulnerabilities which had already been exploited against iOS.<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Vulnerability/31866" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Vulnerability/31866</a><br /> Oracle Updates<br />  Oracle released it quarterly critical patch update. The update addresses 378 security vulnerabilities. Many of the critical updates are already known vulnerabilities in open-source software like Apache and Nginx ingress.<br /><a href="https://www.oracle.com/security-alerts/cpuapr2025.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpuapr2025.html</a><br /> Oracle Breach Guidance<br />  CISA released guidance for users affected by the recent Oracle cloud breach. The guidance focuses on the likely loss of passwords.<br /><a href="https://www.cisa.gov/news-events/alerts/2025/04/16/cisa-releases-guidance-credential-risks-associated-potential-legacy-oracle-cloud-compromise" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2025/04/16/cisa-releases-guidance-credential-risks-associated-potential-legacy-oracle-cloud-compromise</a><br /> Google Chrome Update<br />  A Google Chrome update released today fixes two security vulnerabilities. One of the vulnerabilities is rated as critical.<br /><a href="https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop_15.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop_15.html</a><br /> CVE Updates<br />  CISA extended MITRE s funding to operate the CVE numbering scheme. However, a number of other organizations announced that they may start alternative vulnerability registers.<br /><a href="https://euvd.enisa.europa.eu/" target="_blank" rel="noreferrer noopener">https://euvd.enisa.europa.eu/</a><br /><a href="https://gcve.eu/" target="_blank" rel="noreferrer noopener">https://gcve.eu/</a><br /><a href="https://www.thecvefoundation.org/" target="_blank" rel="noreferrer noopener">https://www.thecvefoundation.org/</a><br />]]></itunes:summary><itunes:duration>365</itunes:duration><itunes:keywords>apple,business,chrome,cisa,computer,cve,cyber,cybersecurity,daily,google,hacking,infosec,internet,it,mitre,network,news,oracle,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9412</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday Apr 16th: File Upload Service Abuse; OpenSSH 10.0 Released; Apache Roller Vuln; Possible CVE Changes</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-apr-16th-file-upload-service-abuse-openssh-10-0-released-apache-roller-vuln-possible-cve-changes--65587827</link><description><![CDATA[<br /> Online Services Again Abused to Exfiltrate Data<br />  Attackers like to abuse free online services that can be used to exfiltrate data. From the  originals , like pastebin,<br /> to past favorites like anonfiles.com. The latest example is gofile.io. As a defender, it is important to track these services to detect exfiltration early<br /><a href="https://isc.sans.edu/diary/Online%20Services%20Again%20Abused%20to%20Exfiltrate%20Data/31862" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Online%20Services%20Again%20Abused%20to%20Exfiltrate%20Data/31862</a><br /> OpenSSH 10.0 Released<br />  OpenSSH 10.0 was released. This release adds quantum-safe ciphers and the separation of authentication services into a separate binary to reduce the authentication attack surface.<br /><a href="https://www.openssh.com/releasenotes.html#10.0p1" target="_blank" rel="noreferrer noopener">https://www.openssh.com/releasenotes.html#10.0p1</a><br /> Apache Roller Vulnerability<br />  Apache Roller addressed a vulnerability. Its CVSS score of 10.0 appears inflated, but it is still a vulnerability you probably want to address.<br /><a href="https://lists.apache.org/thread/4j906k16v21kdx8hk87gl7663sw7lg7f" target="_blank" rel="noreferrer noopener">https://lists.apache.org/thread/4j906k16v21kdx8hk87gl7663sw7lg7f</a><br /> CVE Funding Changes<br />  Mitre s government contract to operate the CVE system may run out tomorrow. This could lead to a temporary disruption of services, but the system is backed by a diverse board of directors representing many large companies. It is possible that non-government funding sources may keep the system afloat for now.<br /><a href="https://www.cve.org/" target="_blank" rel="noreferrer noopener">https://www.cve.org/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9410.mp3</guid><pubDate>Wed, 16 Apr 2025 00:48:11 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65587827/9410.mp3" length="4963285" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9410" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Online Services Again Abused to Exfiltrate Data
  Attackers like to abuse free online services that can be used to exfiltrate data. From the  originals , like pastebin,
 to past favorites like anonfiles.com. The latest example is gofile.io. As a...</itunes:subtitle><itunes:summary><![CDATA[<br /> Online Services Again Abused to Exfiltrate Data<br />  Attackers like to abuse free online services that can be used to exfiltrate data. From the  originals , like pastebin,<br /> to past favorites like anonfiles.com. The latest example is gofile.io. As a defender, it is important to track these services to detect exfiltration early<br /><a href="https://isc.sans.edu/diary/Online%20Services%20Again%20Abused%20to%20Exfiltrate%20Data/31862" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Online%20Services%20Again%20Abused%20to%20Exfiltrate%20Data/31862</a><br /> OpenSSH 10.0 Released<br />  OpenSSH 10.0 was released. This release adds quantum-safe ciphers and the separation of authentication services into a separate binary to reduce the authentication attack surface.<br /><a href="https://www.openssh.com/releasenotes.html#10.0p1" target="_blank" rel="noreferrer noopener">https://www.openssh.com/releasenotes.html#10.0p1</a><br /> Apache Roller Vulnerability<br />  Apache Roller addressed a vulnerability. Its CVSS score of 10.0 appears inflated, but it is still a vulnerability you probably want to address.<br /><a href="https://lists.apache.org/thread/4j906k16v21kdx8hk87gl7663sw7lg7f" target="_blank" rel="noreferrer noopener">https://lists.apache.org/thread/4j906k16v21kdx8hk87gl7663sw7lg7f</a><br /> CVE Funding Changes<br />  Mitre s government contract to operate the CVE system may run out tomorrow. This could lead to a temporary disruption of services, but the system is backed by a diverse board of directors representing many large companies. It is possible that non-government funding sources may keep the system afloat for now.<br /><a href="https://www.cve.org/" target="_blank" rel="noreferrer noopener">https://www.cve.org/</a><br />]]></itunes:summary><itunes:duration>354</itunes:duration><itunes:keywords>apache,business,computer,cve,cyber,cybersecurity,daily,gofile,hacking,infosec,internet,it,mitre,network,news,openssh,roller,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9410</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday April 15th: xorsearch Update; Short Lived Certificates; New USB Malware</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-april-15th-xorsearch-update-short-lived-certificates-new-usb-malware--65575610</link><description><![CDATA[<br /> xorsearch Update<br />  Diedier updated his "xorsearch" tool. It is now a python script, not a compiled binary, and supports Yara signatures. With Yara support also comes support for regular expressions.<br /><a href="https://isc.sans.edu/diary/xorsearch.py%3A%20Searching%20With%20Regexes/31854" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/xorsearch.py%3A%20Searching%20With%20Regexes/31854</a><br /> Shorter Lived Certificates<br />  The CA/Brower Forum passed an update to reduce the maximum livetime of<br /> certificates. The reduction will be implemented over the next four years. EFF also released an update to certbot introducing  profiles that can be used to request shorter lived certificates.<br /><a href="https://www.eff.org/deeplinks/2025/04/certbot-40-long-live-short-lived-certs" target="_blank" rel="noreferrer noopener">https://www.eff.org/deeplinks/2025/04/certbot-40-long-live-short-lived-certs</a><br /><a href="https://groups.google.com/a/groups.cabforum.org/g/servercert-wg/c/bvWh5RN6tYI" target="_blank" rel="noreferrer noopener">https://groups.google.com/a/groups.cabforum.org/g/servercert-wg/c/bvWh5RN6tYI</a><br /> New Malware Harvesting Data from USB drives and infecting them.<br />  Kaspersky is reporting that they identified new malware that not only harvests data from USB drives, but also spread via USB drives by replacing existing documents with malicious files.<br /><a href="https://securelist.com/goffee-apt-new-attacks/116139/" target="_blank" rel="noreferrer noopener">https://securelist.com/goffee-apt-new-attacks/116139/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9408.mp3</guid><pubDate>Tue, 15 Apr 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65575610/9408.mp3" length="4695226" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9408" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 xorsearch Update
  Diedier updated his "xorsearch" tool. It is now a python script, not a compiled binary, and supports Yara signatures. With Yara support also comes support for regular expressions....</itunes:subtitle><itunes:summary><![CDATA[<br /> xorsearch Update<br />  Diedier updated his "xorsearch" tool. It is now a python script, not a compiled binary, and supports Yara signatures. With Yara support also comes support for regular expressions.<br /><a href="https://isc.sans.edu/diary/xorsearch.py%3A%20Searching%20With%20Regexes/31854" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/xorsearch.py%3A%20Searching%20With%20Regexes/31854</a><br /> Shorter Lived Certificates<br />  The CA/Brower Forum passed an update to reduce the maximum livetime of<br /> certificates. The reduction will be implemented over the next four years. EFF also released an update to certbot introducing  profiles that can be used to request shorter lived certificates.<br /><a href="https://www.eff.org/deeplinks/2025/04/certbot-40-long-live-short-lived-certs" target="_blank" rel="noreferrer noopener">https://www.eff.org/deeplinks/2025/04/certbot-40-long-live-short-lived-certs</a><br /><a href="https://groups.google.com/a/groups.cabforum.org/g/servercert-wg/c/bvWh5RN6tYI" target="_blank" rel="noreferrer noopener">https://groups.google.com/a/groups.cabforum.org/g/servercert-wg/c/bvWh5RN6tYI</a><br /> New Malware Harvesting Data from USB drives and infecting them.<br />  Kaspersky is reporting that they identified new malware that not only harvests data from USB drives, but also spread via USB drives by replacing existing documents with malicious files.<br /><a href="https://securelist.com/goffee-apt-new-attacks/116139/" target="_blank" rel="noreferrer noopener">https://securelist.com/goffee-apt-new-attacks/116139/</a><br />]]></itunes:summary><itunes:duration>335</itunes:duration><itunes:keywords>business,certbot,certificates,cyber,cybersecurity,daily,eff,goffee,hacking,infosec,it,kaspersky,malware,network,news,russia,security,usb,xorsearch,yara</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9408</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday April 14th: Langlow AI Attacks; Fortinet Attack Cleanup; MSFT Inetpub;</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-april-14th-langlow-ai-attacks-fortinet-attack-cleanup-msft-inetpub--65562276</link><description><![CDATA[<br /> Exploit Attempts for Recent Langflow AI Vulnerability (CVE-2025-3248)<br />  After spotting individaul attempts to exploit the recent Langflow vulnerability late last weeks, we now see more systematic internet wide scans attempting to verify the vulnerability.<br /><a href="https://isc.sans.edu/forums/diary/Exploit+Attempts+for+Recent+Langflow+AI+Vulnerability+CVE20253248/31850/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Exploit+Attempts+for+Recent+Langflow+AI+Vulnerability+CVE20253248/31850/</a><br /> Fortinet Analysis of Threat Actor Activity<br />  Fortinet oberved recent vulnerablities in its devices being used to add a symlink to ease future compromise. The symlink is not removed by prior patches, and Fortinet released additional updates to detect and remove this attack artifact.<br /><a href="https://www.fortinet.com/blog/psirt-blogs/analysis-of-threat-actor-activity" target="_blank" rel="noreferrer noopener">https://www.fortinet.com/blog/psirt-blogs/analysis-of-threat-actor-activity</a><br /> MSFT Inetpub<br />  Microsoft clarrified that its April patches created the inetpub directory on purpose. Users should not remove it.<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21204#exploitability" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21204#exploitability</a><br /> SANSFIRE<br /><a href="https://isc.sans.edu/j/sansfire" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/j/sansfire</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9406.mp3</guid><pubDate>Mon, 14 Apr 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65562276/9406.mp3" length="5985428" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9406" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Exploit Attempts for Recent Langflow AI Vulnerability (CVE-2025-3248)
  After spotting individaul attempts to exploit the recent Langflow vulnerability late last weeks, we now see more systematic internet wide scans attempting to verify the...</itunes:subtitle><itunes:summary><![CDATA[<br /> Exploit Attempts for Recent Langflow AI Vulnerability (CVE-2025-3248)<br />  After spotting individaul attempts to exploit the recent Langflow vulnerability late last weeks, we now see more systematic internet wide scans attempting to verify the vulnerability.<br /><a href="https://isc.sans.edu/forums/diary/Exploit+Attempts+for+Recent+Langflow+AI+Vulnerability+CVE20253248/31850/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Exploit+Attempts+for+Recent+Langflow+AI+Vulnerability+CVE20253248/31850/</a><br /> Fortinet Analysis of Threat Actor Activity<br />  Fortinet oberved recent vulnerablities in its devices being used to add a symlink to ease future compromise. The symlink is not removed by prior patches, and Fortinet released additional updates to detect and remove this attack artifact.<br /><a href="https://www.fortinet.com/blog/psirt-blogs/analysis-of-threat-actor-activity" target="_blank" rel="noreferrer noopener">https://www.fortinet.com/blog/psirt-blogs/analysis-of-threat-actor-activity</a><br /> MSFT Inetpub<br />  Microsoft clarrified that its April patches created the inetpub directory on purpose. Users should not remove it.<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21204#exploitability" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21204#exploitability</a><br /> SANSFIRE<br /><a href="https://isc.sans.edu/j/sansfire" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/j/sansfire</a><br />]]></itunes:summary><itunes:duration>428</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,fortinet,hacking,inetpub,infosec,internet,it,langflow,network,news,sansfire,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9406</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday April 11th: Network Infraxploit; Windows Hello Broken; Dell Update; Langflow Exploit</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-april-11th-network-infraxploit-windows-hello-broken-dell-update-langflow-exploit--65538261</link><description><![CDATA[<br /> Network Infraxploit<br />  Our undergraduate intern, Matthew Gorman, wrote up a walk through of<br />  CVE-2018-0171, an older Cisco vulnerability, that is still actively being<br />  exploited. For example, VOLT TYPHOON recently exploited this problem.<br /><a href="https://isc.sans.edu/diary/Network+Infraxploit+Guest+Diary/31844" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Network+Infraxploit+Guest+Diary/31844</a><br /> Windows Update Issues / Windows 10 Update<br />  Microsoft updated its "Release Health" notes with details regarding issues<br />  users experiences with Windows Hello, Citrix, and Roblox. Microsoft also released an emergency update for Office 2016 which has stability problems after applying the most recent update.<br /><a href="https://support.microsoft.com/en-us/topic/april-8-2025-kb5055523-os-build-26100-3775-277a9d11-6ebf-410c-99f7-8c61957461eb" target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-us/topic/april-8-2025-kb5055523-os-build-26100-3775-277a9d11-6ebf-410c-99f7-8c61957461eb</a><br /><a href="https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#3521" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#3521</a><br /><a href="https://support.microsoft.com/en-us/topic/april-10-2025-update-for-office-2016-kb5002623-d60c1f31-bb7c-4426-b8f4-69186d7fc1e5" target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-us/topic/april-10-2025-update-for-office-2016-kb5002623-d60c1f31-bb7c-4426-b8f4-69186d7fc1e5</a><br /> Dell Updates<br />  Dell releases critical updates for it's Powerscale One FS product. In particular, it fixes a default password problem.<br /><a href="https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" target="_blank" rel="noreferrer noopener">https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities</a><br /> Langflow Vulnerablity (possible exploit scans sighted) CVE-2025-3248<br />  Langflow addressed a critical vulnerability end of March. This writeup by Horizon3 demonstrates how the issue is possibly exploited. We have so far seen one "hit" in our honeypot logs for the vulnerable API endpoint URL.<br /><a href="https://www.horizon3.ai/attack-research/disclosures/unsafe-at-any-speed-abusing-python-exec-for-unauth-rce-in-langflow-ai/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/disclosures/unsafe-at-any-speed-abusing-python-exec-for-unauth-rce-in-langflow-ai/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9404.mp3</guid><pubDate>Fri, 11 Apr 2025 09:48:22 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65538261/9404.mp3" length="4688121" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9404" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Network Infraxploit
  Our undergraduate intern, Matthew Gorman, wrote up a walk through of
  CVE-2018-0171, an older Cisco vulnerability, that is still actively being
  exploited. For example, VOLT TYPHOON recently exploited this problem....</itunes:subtitle><itunes:summary><![CDATA[<br /> Network Infraxploit<br />  Our undergraduate intern, Matthew Gorman, wrote up a walk through of<br />  CVE-2018-0171, an older Cisco vulnerability, that is still actively being<br />  exploited. For example, VOLT TYPHOON recently exploited this problem.<br /><a href="https://isc.sans.edu/diary/Network+Infraxploit+Guest+Diary/31844" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Network+Infraxploit+Guest+Diary/31844</a><br /> Windows Update Issues / Windows 10 Update<br />  Microsoft updated its "Release Health" notes with details regarding issues<br />  users experiences with Windows Hello, Citrix, and Roblox. Microsoft also released an emergency update for Office 2016 which has stability problems after applying the most recent update.<br /><a href="https://support.microsoft.com/en-us/topic/april-8-2025-kb5055523-os-build-26100-3775-277a9d11-6ebf-410c-99f7-8c61957461eb" target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-us/topic/april-8-2025-kb5055523-os-build-26100-3775-277a9d11-6ebf-410c-99f7-8c61957461eb</a><br /><a href="https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#3521" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#3521</a><br /><a href="https://support.microsoft.com/en-us/topic/april-10-2025-update-for-office-2016-kb5002623-d60c1f31-bb7c-4426-b8f4-69186d7fc1e5" target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-us/topic/april-10-2025-update-for-office-2016-kb5002623-d60c1f31-bb7c-4426-b8f4-69186d7fc1e5</a><br /> Dell Updates<br />  Dell releases critical updates for it's Powerscale One FS product. In particular, it fixes a default password problem.<br /><a href="https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" target="_blank" rel="noreferrer noopener">https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities</a><br /> Langflow Vulnerablity (possible exploit scans sighted) CVE-2025-3248<br />  Langflow addressed a critical vulnerability end of March. This writeup by Horizon3 demonstrates how the issue is possibly exploited. We have so far seen one "hit" in our honeypot logs for the vulnerable API endpoint URL.<br /><a href="https://www.horizon3.ai/attack-research/disclosures/unsafe-at-any-speed-abusing-python-exec-for-unauth-rce-in-langflow-ai/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/disclosures/unsafe-at-any-speed-abusing-python-exec-for-unauth-rce-in-langflow-ai/</a><br />]]></itunes:summary><itunes:duration>335</itunes:duration><itunes:keywords>business,cisco,computer,cyber,cybersecurity,daily,dell,hacking,infosec,infraxploit,internet,it,langfow,network,news,security,updates,windows</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9404</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast ThursdayApril 10th: Getting Past PyArmor; CenterStack RCE; Android 0-Day Patch; VMware Tanzu Patches; Odd Win11 Directory; Wh</title><link>https://www.spreaker.com/episode/sans-stormcast-thursdayapril-10th-getting-past-pyarmor-centerstack-rce-android-0-day-patch-vmware-tanzu-patches-odd-win11-directory-wh--65509760</link><description><![CDATA[<br /> Getting Past PyArmor<br />   PyArmor is a python obfuscation tool used for malicious and non-malicious software. Xavier is taking a look at a sample to show what can be learned from these obfuscated samples with not too much work. <br /><a href="https://isc.sans.edu/diary/Obfuscated%20Malicious%20Python%20Scripts%20with%20PyArmor/31840" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Obfuscated%20Malicious%20Python%20Scripts%20with%20PyArmor/31840</a><br /> CenterStack RCE CVE-2025-30406<br />  Gladinet s CenterStack secure file-sharing software suffers from an inadequately protected machine key vulnerability that can be used to modify ViewState data. This vulnerability may lead to remote code execution, which is already exploited.<br /><a href="https://gladinetsupport.s3.us-east-1.amazonaws.com/gladinet/securityadvisory-cve-2005.pdf" target="_blank" rel="noreferrer noopener">https://gladinetsupport.s3.us-east-1.amazonaws.com/gladinet/securityadvisory-cve-2005.pdf</a><br /> Google Patches two zero-day vulnerabilities CVE-2024-53150 CVE-2024-53197<br />  Google released its monthly patches for Android. Two of the patched vulnerabilities are already exploited. One of them was used by Serbian law enforcement.<br /><a href="https://www.malwarebytes.com/blog/news/2025/04/google-fixes-two-actively-exploited-zero-day-vulnerabilities-in-android" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/news/2025/04/google-fixes-two-actively-exploited-zero-day-vulnerabilities-in-android</a><br /> Broadcom VMWare Tenzu Updates<br />  Broadcom released updates for VMWare Tenzu. Many vulnerabilities affect the backup component and allow for arbitrary command execution.<br /><a href="https://support.broadcom.com/web/ecx/security-advisory?" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/security-advisory?</a><br /> Windows 11 April Update ads inetpub directory<br />  The April Windows 11 update appears to create a new /inetpub directory. It is unclear why, and removing it appears to have no bad effects.<br /><a href="https://www.bleepingcomputer.com/news/microsoft/windows-11-april-update-unexpectedly-creates-new-inetpub-folder/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/microsoft/windows-11-april-update-unexpectedly-creates-new-inetpub-folder/</a><br /> WhatsApp File Type Confusion/Spoofing<br />  WhatsApp patched a file type confusion vulnerability. A victim may be tricked into downloading n<br /><a href="https://www.whatsapp.com/security/advisories/2025/" target="_blank" rel="noreferrer noopener">https://www.whatsapp.com/security/advisories/2025/</a><br /> SANS Critical AI Security Guidelines<br /><a href="https://www.sans.org/mlp/critical-ai-security-guidelines" target="_blank" rel="noreferrer noopener">https://www.sans.org/mlp/critical-ai-security-guidelines</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9402.mp3</guid><pubDate>Thu, 10 Apr 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65509760/9402.mp3" length="5542925" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9402" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Getting Past PyArmor
   PyArmor is a python obfuscation tool used for malicious and non-malicious software. Xavier is taking a look at a sample to show what can be learned from these obfuscated samples with not too much work....</itunes:subtitle><itunes:summary><![CDATA[<br /> Getting Past PyArmor<br />   PyArmor is a python obfuscation tool used for malicious and non-malicious software. Xavier is taking a look at a sample to show what can be learned from these obfuscated samples with not too much work. <br /><a href="https://isc.sans.edu/diary/Obfuscated%20Malicious%20Python%20Scripts%20with%20PyArmor/31840" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Obfuscated%20Malicious%20Python%20Scripts%20with%20PyArmor/31840</a><br /> CenterStack RCE CVE-2025-30406<br />  Gladinet s CenterStack secure file-sharing software suffers from an inadequately protected machine key vulnerability that can be used to modify ViewState data. This vulnerability may lead to remote code execution, which is already exploited.<br /><a href="https://gladinetsupport.s3.us-east-1.amazonaws.com/gladinet/securityadvisory-cve-2005.pdf" target="_blank" rel="noreferrer noopener">https://gladinetsupport.s3.us-east-1.amazonaws.com/gladinet/securityadvisory-cve-2005.pdf</a><br /> Google Patches two zero-day vulnerabilities CVE-2024-53150 CVE-2024-53197<br />  Google released its monthly patches for Android. Two of the patched vulnerabilities are already exploited. One of them was used by Serbian law enforcement.<br /><a href="https://www.malwarebytes.com/blog/news/2025/04/google-fixes-two-actively-exploited-zero-day-vulnerabilities-in-android" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/news/2025/04/google-fixes-two-actively-exploited-zero-day-vulnerabilities-in-android</a><br /> Broadcom VMWare Tenzu Updates<br />  Broadcom released updates for VMWare Tenzu. Many vulnerabilities affect the backup component and allow for arbitrary command execution.<br /><a href="https://support.broadcom.com/web/ecx/security-advisory?" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/security-advisory?</a><br /> Windows 11 April Update ads inetpub directory<br />  The April Windows 11 update appears to create a new /inetpub directory. It is unclear why, and removing it appears to have no bad effects.<br /><a href="https://www.bleepingcomputer.com/news/microsoft/windows-11-april-update-unexpectedly-creates-new-inetpub-folder/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/microsoft/windows-11-april-update-unexpectedly-creates-new-inetpub-folder/</a><br /> WhatsApp File Type Confusion/Spoofing<br />  WhatsApp patched a file type confusion vulnerability. A victim may be tricked into downloading n<br /><a href="https://www.whatsapp.com/security/advisories/2025/" target="_blank" rel="noreferrer noopener">https://www.whatsapp.com/security/advisories/2025/</a><br /> SANS Critical AI Security Guidelines<br /><a href="https://www.sans.org/mlp/critical-ai-security-guidelines" target="_blank" rel="noreferrer noopener">https://www.sans.org/mlp/critical-ai-security-guidelines</a><br />]]></itunes:summary><itunes:duration>396</itunes:duration><itunes:keywords>0-day,ai,android,business,centerstrack,cyber,cybersecurity,daily,google,guidelines,hacking,inetpub,infosec,it,news,pyarmor,sans,tenzu,vmware,whatsapp</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9402</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, April 8th: Microsoft Patch Tuesday; Adobe Patches; OpenSSL 3.5 with PQC; Fortinet</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-april-8th-microsoft-patch-tuesday-adobe-patches-openssl-3-5-with-pqc-fortinet--65460308</link><description><![CDATA[<br /> Microsoft Patch Tuesday<br />   Microsoft patched over 120 vulnerabilities this month.  11 of these were rated critical, and one vulnerability is already being exploited.<br /><a href="https://isc.sans.edu/diary/Microsoft%20April%202025%20Patch%20Tuesday/31838" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20April%202025%20Patch%20Tuesday/31838</a><br /> Adobe Updates<br />  Adobe released patches for 12 different products. In particular important are patches for Coldfusion addressing several remote code execution vulnerabilities. Adobe Commercse got patches as well, but none of the vulnerabilities are rated critical.<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> OpenSSL 3.5 Released<br />   OpenSSL 3.5 was released with support to post quantum ciphers. This is a long term support release.<br /><a href="https://groups.google.com/a/openssl.org/g/openssl-project/c/9ZYdIaExmIA" target="_blank" rel="noreferrer noopener">https://groups.google.com/a/openssl.org/g/openssl-project/c/9ZYdIaExmIA</a><br /> Fortiswitch Update<br />  Fortinet released an update for Fortiswitch addressing a vulnerability that may be used to reset a password without verification.<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-24-435" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-24-435</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9400.mp3</guid><pubDate>Wed, 09 Apr 2025 10:11:11 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65460308/9400.mp3" length="6149448" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9400" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Microsoft Patch Tuesday
   Microsoft patched over 120 vulnerabilities this month.  11 of these were rated critical, and one vulnerability is already being exploited.
https://isc.sans.edu/diary/Microsoft%20April%202025%20Patch%20Tuesday/31838
 Adobe...</itunes:subtitle><itunes:summary><![CDATA[<br /> Microsoft Patch Tuesday<br />   Microsoft patched over 120 vulnerabilities this month.  11 of these were rated critical, and one vulnerability is already being exploited.<br /><a href="https://isc.sans.edu/diary/Microsoft%20April%202025%20Patch%20Tuesday/31838" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20April%202025%20Patch%20Tuesday/31838</a><br /> Adobe Updates<br />  Adobe released patches for 12 different products. In particular important are patches for Coldfusion addressing several remote code execution vulnerabilities. Adobe Commercse got patches as well, but none of the vulnerabilities are rated critical.<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> OpenSSL 3.5 Released<br />   OpenSSL 3.5 was released with support to post quantum ciphers. This is a long term support release.<br /><a href="https://groups.google.com/a/openssl.org/g/openssl-project/c/9ZYdIaExmIA" target="_blank" rel="noreferrer noopener">https://groups.google.com/a/openssl.org/g/openssl-project/c/9ZYdIaExmIA</a><br /> Fortiswitch Update<br />  Fortinet released an update for Fortiswitch addressing a vulnerability that may be used to reset a password without verification.<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-24-435" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-24-435</a><br />]]></itunes:summary><itunes:duration>439</itunes:duration><itunes:keywords>adobe,business,coldfusion,commerce,computer,cyber,cybersecurity,daily,fortinet,fortiswitch,hacking,infosec,internet,it,microsoft,network,news,patches,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9400</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday, April 8th:</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-april-8th--65414836</link><description><![CDATA[<br /> XORsearch: Searching With Regexes<br />  Didier explains a workaround to use his tool XORsearch to search for regular expressions instead of simple strings.<br /><a href="https://isc.sans.edu/diary/XORsearch%3A%20Searching%20With%20Regexes/31834" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/XORsearch%3A%20Searching%20With%20Regexes/31834</a><br /> MCP Security Notification: Tool Poisoning Attacks<br /> Invariant labs summarized a critical weakness in the Model Context Protocol (MCP) that allows for "Tool Poisoning Attacks." Many major providers such as Anthropic and OpenAI, workflow automation systems like Zapier, and MCP clients like Cursor are susceptible to this attack<br /><a href="https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks" target="_blank" rel="noreferrer noopener">https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks</a><br /> Making :visited more private<br />  Google Chrome changed how links are marked as  visited . This new  partitioning  scheme was introduced to improve privacy. Instead of marking a link as  visited  on any page where it is displayed, it is only marked as visited if the user clicks on the link while visiting the particular site where the link is displayed.<br /><a href="https://developer.chrome.com/blog/visited-links" target="_blank" rel="noreferrer noopener">https://developer.chrome.com/blog/visited-links</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9398.mp3</guid><pubDate>Tue, 08 Apr 2025 02:40:16 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65414836/9398.mp3" length="5300445" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9398" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 XORsearch: Searching With Regexes
  Didier explains a workaround to use his tool XORsearch to search for regular expressions instead of simple strings.
https://isc.sans.edu/diary/XORsearch%3A%20Searching%20With%20Regexes/31834
 MCP Security...</itunes:subtitle><itunes:summary><![CDATA[<br /> XORsearch: Searching With Regexes<br />  Didier explains a workaround to use his tool XORsearch to search for regular expressions instead of simple strings.<br /><a href="https://isc.sans.edu/diary/XORsearch%3A%20Searching%20With%20Regexes/31834" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/XORsearch%3A%20Searching%20With%20Regexes/31834</a><br /> MCP Security Notification: Tool Poisoning Attacks<br /> Invariant labs summarized a critical weakness in the Model Context Protocol (MCP) that allows for "Tool Poisoning Attacks." Many major providers such as Anthropic and OpenAI, workflow automation systems like Zapier, and MCP clients like Cursor are susceptible to this attack<br /><a href="https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks" target="_blank" rel="noreferrer noopener">https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks</a><br /> Making :visited more private<br />  Google Chrome changed how links are marked as  visited . This new  partitioning  scheme was introduced to improve privacy. Instead of marking a link as  visited  on any page where it is displayed, it is only marked as visited if the user clicks on the link while visiting the particular site where the link is displayed.<br /><a href="https://developer.chrome.com/blog/visited-links" target="_blank" rel="noreferrer noopener">https://developer.chrome.com/blog/visited-links</a><br />]]></itunes:summary><itunes:duration>379</itunes:duration><itunes:keywords>agentic,business,chrome,computer,cyber,cybersecurity,daily,hacking,infosec,it,mcp,model context protocol,network,news,privacy,regex,regular expression,security,vistied,xorsearch</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9398</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday April 7th 2025: New Username Report; Quickshell Vulnerability; Apache Traffic Director Request Smuggeling</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-april-7th-2025-new-username-report-quickshell-vulnerability-apache-traffic-director-request-smuggeling--65385841</link><description><![CDATA[<br /> New SSH Username Report<br />   A new ssh/telnet username reports makes it easier to identify new usernames attackers are using against our telnet and ssh honeypots<br /><a href="https://isc.sans.edu/diary/New%20SSH%20Username%20Report/31830" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/New%20SSH%20Username%20Report/31830</a><br /> Quickshell Sharing is Caring: About an RCE Attack Chain on Quick Share<br />  The Google Quick Share protocol is susceptible to several vulnerabilities that have not yet been fully patched, allowing for some file overwrite issues that could lead to the accidental execution of malicious code.<br /><a href="https://www.blackhat.com/asia-25/briefings/schedule/index.html#quickshell-sharing-is-caring-about-an-rce-attack-chain-on-quick-share-43874" target="_blank" rel="noreferrer noopener">https://www.blackhat.com/asia-25/briefings/schedule/index.html#quickshell-sharing-is-caring-about-an-rce-attack-chain-on-quick-share-43874</a><br /> Apache Traffic Director Request Smuggling Vulnerability<br /><a href="https://www.openwall.com/lists/oss-security/2025/04/02/4" target="_blank" rel="noreferrer noopener">https://www.openwall.com/lists/oss-security/2025/04/02/4</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9396.mp3</guid><pubDate>Mon, 07 Apr 2025 01:20:47 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65385841/9396.mp3" length="5242218" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9396" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 New SSH Username Report
   A new ssh/telnet username reports makes it easier to identify new usernames attackers are using against our telnet and ssh honeypots
https://isc.sans.edu/diary/New%20SSH%20Username%20Report/31830
 Quickshell Sharing is...</itunes:subtitle><itunes:summary><![CDATA[<br /> New SSH Username Report<br />   A new ssh/telnet username reports makes it easier to identify new usernames attackers are using against our telnet and ssh honeypots<br /><a href="https://isc.sans.edu/diary/New%20SSH%20Username%20Report/31830" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/New%20SSH%20Username%20Report/31830</a><br /> Quickshell Sharing is Caring: About an RCE Attack Chain on Quick Share<br />  The Google Quick Share protocol is susceptible to several vulnerabilities that have not yet been fully patched, allowing for some file overwrite issues that could lead to the accidental execution of malicious code.<br /><a href="https://www.blackhat.com/asia-25/briefings/schedule/index.html#quickshell-sharing-is-caring-about-an-rce-attack-chain-on-quick-share-43874" target="_blank" rel="noreferrer noopener">https://www.blackhat.com/asia-25/briefings/schedule/index.html#quickshell-sharing-is-caring-about-an-rce-attack-chain-on-quick-share-43874</a><br /> Apache Traffic Director Request Smuggling Vulnerability<br /><a href="https://www.openwall.com/lists/oss-security/2025/04/02/4" target="_blank" rel="noreferrer noopener">https://www.openwall.com/lists/oss-security/2025/04/02/4</a><br />]]></itunes:summary><itunes:duration>375</itunes:duration><itunes:keywords>apache,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,quick share,quickshell,request smuggling,security,ssh,usernames</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9396</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, Apr 4th: URL Frequency Analysis; Ivanti Flaw Exploited; WinRAR MotW Vuln; Tax filing scams; Oracle Breach Update</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-apr-4th-url-frequency-analysis-ivanti-flaw-exploited-winrar-motw-vuln-tax-filing-scams-oracle-breach-update--65343164</link><description><![CDATA[<br /> Exploring Statistical Measures to Predict URLs as Legitimate or Intrusive<br />   Using frequency analysis, and training the model with honeypot data as well as log data from legitimate websites allows for a fairly simple and reliable triage of web server logs to identify possible malicious activity.<br /><a href="https://isc.sans.edu/diary/Exploring%20Statistical%20Measures%20to%20Predict%20URLs%20as%20Legitimate%20or%20Intrusive%20%5BGuest%20Diary%5D/31822" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploring%20Statistical%20Measures%20to%20Predict%20URLs%20as%20Legitimate%20or%20Intrusive%20%5BGuest%20Diary%5D/31822</a><br /> Critical Unexploitable Ivanti Vulnerability Exploited CVE-2025-22457<br />  In February, Ivanti patched  CVE-2025-22457. At the time, the vulnerability was not considered to be exploitable. Mandiant now published a blog disclosing that the vulnerability was exploited as soon as mid-march<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-exploiting-critical-ivanti-vulnerability/" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-exploiting-critical-ivanti-vulnerability/</a><br /> WinRAR MotW Vulnerability CVE-2025-31334<br />  WinRAR patched a vulnerability that would not apply the  Mark of the Web  correctly if a compressed file included symlinks. This may make it easier to trick a victim into executing code downloaded from a website.<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31334" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2025-31334</a><br /> Microsoft Warns of Tax-Related Scam<br />  With the US personal income tax filing deadline only about a week out, Microsoft warns of commonly deployed scams that they are observing related to income tax filings<br /><a href="https://www.microsoft.com/en-us/security/blog/2025/04/03/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2025/04/03/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns/</a><br /> Oracle Breach Update<br /><a href="https://www.bloomberg.com/news/articles/2025-04-02/oracle-tells-clients-of-second-recent-hack-log-in-data-stolen" target="_blank" rel="noreferrer noopener">https://www.bloomberg.com/news/articles/2025-04-02/oracle-tells-clients-of-second-recent-hack-log-in-data-stolen</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9394.mp3</guid><pubDate>Fri, 04 Apr 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65343164/9394.mp3" length="5278250" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9394" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Exploring Statistical Measures to Predict URLs as Legitimate or Intrusive
   Using frequency analysis, and training the model with honeypot data as well as log data from legitimate websites allows for a fairly simple and reliable triage of web...</itunes:subtitle><itunes:summary><![CDATA[<br /> Exploring Statistical Measures to Predict URLs as Legitimate or Intrusive<br />   Using frequency analysis, and training the model with honeypot data as well as log data from legitimate websites allows for a fairly simple and reliable triage of web server logs to identify possible malicious activity.<br /><a href="https://isc.sans.edu/diary/Exploring%20Statistical%20Measures%20to%20Predict%20URLs%20as%20Legitimate%20or%20Intrusive%20%5BGuest%20Diary%5D/31822" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploring%20Statistical%20Measures%20to%20Predict%20URLs%20as%20Legitimate%20or%20Intrusive%20%5BGuest%20Diary%5D/31822</a><br /> Critical Unexploitable Ivanti Vulnerability Exploited CVE-2025-22457<br />  In February, Ivanti patched  CVE-2025-22457. At the time, the vulnerability was not considered to be exploitable. Mandiant now published a blog disclosing that the vulnerability was exploited as soon as mid-march<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-exploiting-critical-ivanti-vulnerability/" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-exploiting-critical-ivanti-vulnerability/</a><br /> WinRAR MotW Vulnerability CVE-2025-31334<br />  WinRAR patched a vulnerability that would not apply the  Mark of the Web  correctly if a compressed file included symlinks. This may make it easier to trick a victim into executing code downloaded from a website.<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31334" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2025-31334</a><br /> Microsoft Warns of Tax-Related Scam<br />  With the US personal income tax filing deadline only about a week out, Microsoft warns of commonly deployed scams that they are observing related to income tax filings<br /><a href="https://www.microsoft.com/en-us/security/blog/2025/04/03/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2025/04/03/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns/</a><br /> Oracle Breach Update<br /><a href="https://www.bloomberg.com/news/articles/2025-04-02/oracle-tells-clients-of-second-recent-hack-log-in-data-stolen" target="_blank" rel="noreferrer noopener">https://www.bloomberg.com/news/articles/2025-04-02/oracle-tells-clients-of-second-recent-hack-log-in-data-stolen</a><br />]]></itunes:summary><itunes:duration>377</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,frequency analysis,hacking,infosec,internet,irs,it,ivanti,microsoft,motw,network,news,oracle,security,tax,winrar</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9394</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday Apr 3rd: Juniper Password Scans; Hacking Call Records; End to End Encrypted GMail</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-apr-3rd-juniper-password-scans-hacking-call-records-end-to-end-encrypted-gmail--65328033</link><description><![CDATA[<br /> Surge in Scans for Juniper  t128  Default User<br />  Lasst week, we dedtect a significant surge in ssh scans for the username  t128 . This user is used by Juniper s Session Smart Routing, a product they acquired from  128 Technologies  which is the reason for the somewhat unusual username. <br /><a href="https://isc.sans.edu/diary/Surge%20in%20Scans%20for%20Juniper%20%22t128%22%20Default%20User/31824" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Surge%20in%20Scans%20for%20Juniper%20%22t128%22%20Default%20User/31824</a><br /> Vulnerable Verizon API Allowed for Access to Call Logs<br />  An API Verizon offered to users of its call filtering application suffered from an authentication bypass vulnerability allowing users to access any Verizon user s call history. While using a JWT to authenticate the user, the phone number used to retrieve the call history logs was passed in a not-authenticated header.<br /><a href="https://evanconnelly.github.io/post/hacking-call-records/" target="_blank" rel="noreferrer noopener">https://evanconnelly.github.io/post/hacking-call-records/</a><br /> Google Offering End-to-End Encryption to G-Mail Business Users<br />   Google will add an end-to-end encryption feature to commercial GMail users. However, for non GMail users to read the emails they first must click on a link and log in to Google.<br /><a href="https://workspace.google.com/blog/identity-and-security/gmail-easy-end-to-end-encryption-all-businesses" target="_blank" rel="noreferrer noopener">https://workspace.google.com/blog/identity-and-security/gmail-easy-end-to-end-encryption-all-businesses</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9392.mp3</guid><pubDate>Thu, 03 Apr 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65328033/9392.mp3" length="7884345" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9392" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Surge in Scans for Juniper  t128  Default User
  Lasst week, we dedtect a significant surge in ssh scans for the username  t128 . This user is used by Juniper s Session Smart Routing, a product they acquired from  128 Technologies  which is the...</itunes:subtitle><itunes:summary><![CDATA[<br /> Surge in Scans for Juniper  t128  Default User<br />  Lasst week, we dedtect a significant surge in ssh scans for the username  t128 . This user is used by Juniper s Session Smart Routing, a product they acquired from  128 Technologies  which is the reason for the somewhat unusual username. <br /><a href="https://isc.sans.edu/diary/Surge%20in%20Scans%20for%20Juniper%20%22t128%22%20Default%20User/31824" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Surge%20in%20Scans%20for%20Juniper%20%22t128%22%20Default%20User/31824</a><br /> Vulnerable Verizon API Allowed for Access to Call Logs<br />  An API Verizon offered to users of its call filtering application suffered from an authentication bypass vulnerability allowing users to access any Verizon user s call history. While using a JWT to authenticate the user, the phone number used to retrieve the call history logs was passed in a not-authenticated header.<br /><a href="https://evanconnelly.github.io/post/hacking-call-records/" target="_blank" rel="noreferrer noopener">https://evanconnelly.github.io/post/hacking-call-records/</a><br /> Google Offering End-to-End Encryption to G-Mail Business Users<br />   Google will add an end-to-end encryption feature to commercial GMail users. However, for non GMail users to read the emails they first must click on a link and log in to Google.<br /><a href="https://workspace.google.com/blog/identity-and-security/gmail-easy-end-to-end-encryption-all-businesses" target="_blank" rel="noreferrer noopener">https://workspace.google.com/blog/identity-and-security/gmail-easy-end-to-end-encryption-all-businesses</a><br />]]></itunes:summary><itunes:duration>563</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,gmail,google,hacking,infosec,internet,it,juniper,network,news,security,t128,verizon</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9392</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday Apr 2nd: Apple Updates Everything;</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-apr-2nd-apple-updates-everything--65298026</link><description><![CDATA[<br /> Apple Patches Everything<br />  Apple released updates for all of its operating systems. Most were released on Monday with WatchOS patches released today on Tuesday. Two already exploited vulnerabilities, which were already patched in the latest iOS and macOS versions, are now patched for older operating systems as well. A total of 145 vulnerabilities were patched.<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20March%2031st%202025%20Edition/31816" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20March%2031st%202025%20Edition/31816</a><br /> VMWare Workstation and Fusion update check broken<br />  VMWare s automatic update check in its Workstation and Fusion products is currently broken due to a redirect added as part of the Broadcom transition<br /><a href="https://community.broadcom.com/vmware-cloud-foundation/question/certificate-error-is-occured-during-connecting-update-server" target="_blank" rel="noreferrer noopener">https://community.broadcom.com/vmware-cloud-foundation/question/certificate-error-is-occured-during-connecting-update-server</a><br /> NIM Postgres Vulnerability<br />  NIM Developers using prepared statements to send SQL queries to Postgres may expose themselves to a SQL injection vulnerability. NIM s Postgres library does not appear to use actual prepared statements; instead, it assembles the code and the user data as a string and passes them on to the database. This may lead to a SQL injection vulnerability<br /><a href="https://blog.nns.ee/2025/03/28/nim-postgres-vulnerability/" target="_blank" rel="noreferrer noopener">https://blog.nns.ee/2025/03/28/nim-postgres-vulnerability/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9390.mp3</guid><pubDate>Wed, 02 Apr 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65298026/9390.mp3" length="6112689" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9390" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Apple Patches Everything
  Apple released updates for all of its operating systems. Most were released on Monday with WatchOS patches released today on Tuesday. Two already exploited vulnerabilities, which were already patched in the latest iOS and...</itunes:subtitle><itunes:summary><![CDATA[<br /> Apple Patches Everything<br />  Apple released updates for all of its operating systems. Most were released on Monday with WatchOS patches released today on Tuesday. Two already exploited vulnerabilities, which were already patched in the latest iOS and macOS versions, are now patched for older operating systems as well. A total of 145 vulnerabilities were patched.<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20March%2031st%202025%20Edition/31816" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20March%2031st%202025%20Edition/31816</a><br /> VMWare Workstation and Fusion update check broken<br />  VMWare s automatic update check in its Workstation and Fusion products is currently broken due to a redirect added as part of the Broadcom transition<br /><a href="https://community.broadcom.com/vmware-cloud-foundation/question/certificate-error-is-occured-during-connecting-update-server" target="_blank" rel="noreferrer noopener">https://community.broadcom.com/vmware-cloud-foundation/question/certificate-error-is-occured-during-connecting-update-server</a><br /> NIM Postgres Vulnerability<br />  NIM Developers using prepared statements to send SQL queries to Postgres may expose themselves to a SQL injection vulnerability. NIM s Postgres library does not appear to use actual prepared statements; instead, it assembles the code and the user data as a string and passes them on to the database. This may lead to a SQL injection vulnerability<br /><a href="https://blog.nns.ee/2025/03/28/nim-postgres-vulnerability/" target="_blank" rel="noreferrer noopener">https://blog.nns.ee/2025/03/28/nim-postgres-vulnerability/</a><br />]]></itunes:summary><itunes:duration>437</itunes:duration><itunes:keywords>apple,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,ios,it,macos,network,news,nim,postres,security,vmware</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9390</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday Apr 1st: Apache Camel Exploits; New Cert Authorities Requirements; Possible Oracle Breach</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-apr-1st-apache-camel-exploits-new-cert-authorities-requirements-possible-oracle-breach--65265600</link><description><![CDATA[<br /> Apache Camel Exploit Attempt by Vulnerability Scans<br />  A recently patched vulnerability in Apache Camel has been integrated into some vulnerability scanners, like for example OpenVAS. We do see some exploit attempts in our honeypots, but they appear to be part of internal vulnerablity scans<br /><a href="https://isc.sans.edu/diary/Apache%20Camel%20Exploit%20Attempt%20by%20Vulnerability%20Scan%20%28CVE-2025-27636%2C%20CVE-2025-29891%29/31814" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apache%20Camel%20Exploit%20Attempt%20by%20Vulnerability%20Scan%20%28CVE-2025-27636%2C%20CVE-2025-29891%29/31814</a><br /> New Security Requirements for Certificate Authorities<br />  Starting in July, certificate authorities need to verify domain ownership data from multiple viewpoints around the internet. They will also have to use linters to verify certificate requests.<br /><a href="https://security.googleblog.com/2025/03/new-security-requirements-adopted-by.html" target="_blank" rel="noreferrer noopener">https://security.googleblog.com/2025/03/new-security-requirements-adopted-by.html</a><br /> Possible Oracle Breach<br />  Oracle still denies being the victim of a data berach as leaked data may show different.<br /><a href="https://doublepulsar.com/oracle-attempt-to-hide-serious-cybersecurity-incident-from-customers-in-oracle-saas-service-9231c8daff4a" target="_blank" rel="noreferrer noopener">https://doublepulsar.com/oracle-attempt-to-hide-serious-cybersecurity-incident-from-customers-in-oracle-saas-service-9231c8daff4a</a><br /><a href="https://www.theregister.com/2025/03/30/infosec_news_in_brief/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2025/03/30/infosec_news_in_brief/</a><br /><a href="https://www.darkreading.com/cyberattacks-data-breaches/oracle-still-denies-breach-researchers-persist" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/cyberattacks-data-breaches/oracle-still-denies-breach-researchers-persist</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9388.mp3</guid><pubDate>Tue, 01 Apr 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65265600/9388.mp3" length="6662912" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9388" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Apache Camel Exploit Attempt by Vulnerability Scans
  A recently patched vulnerability in Apache Camel has been integrated into some vulnerability scanners, like for example OpenVAS. We do see some exploit attempts in our honeypots, but they appear...</itunes:subtitle><itunes:summary><![CDATA[<br /> Apache Camel Exploit Attempt by Vulnerability Scans<br />  A recently patched vulnerability in Apache Camel has been integrated into some vulnerability scanners, like for example OpenVAS. We do see some exploit attempts in our honeypots, but they appear to be part of internal vulnerablity scans<br /><a href="https://isc.sans.edu/diary/Apache%20Camel%20Exploit%20Attempt%20by%20Vulnerability%20Scan%20%28CVE-2025-27636%2C%20CVE-2025-29891%29/31814" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apache%20Camel%20Exploit%20Attempt%20by%20Vulnerability%20Scan%20%28CVE-2025-27636%2C%20CVE-2025-29891%29/31814</a><br /> New Security Requirements for Certificate Authorities<br />  Starting in July, certificate authorities need to verify domain ownership data from multiple viewpoints around the internet. They will also have to use linters to verify certificate requests.<br /><a href="https://security.googleblog.com/2025/03/new-security-requirements-adopted-by.html" target="_blank" rel="noreferrer noopener">https://security.googleblog.com/2025/03/new-security-requirements-adopted-by.html</a><br /> Possible Oracle Breach<br />  Oracle still denies being the victim of a data berach as leaked data may show different.<br /><a href="https://doublepulsar.com/oracle-attempt-to-hide-serious-cybersecurity-incident-from-customers-in-oracle-saas-service-9231c8daff4a" target="_blank" rel="noreferrer noopener">https://doublepulsar.com/oracle-attempt-to-hide-serious-cybersecurity-incident-from-customers-in-oracle-saas-service-9231c8daff4a</a><br /><a href="https://www.theregister.com/2025/03/30/infosec_news_in_brief/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2025/03/30/infosec_news_in_brief/</a><br /><a href="https://www.darkreading.com/cyberattacks-data-breaches/oracle-still-denies-breach-researchers-persist" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/cyberattacks-data-breaches/oracle-still-denies-breach-researchers-persist</a><br />]]></itunes:summary><itunes:duration>457</itunes:duration><itunes:keywords>breach,business,camel,certificates,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,oracle,security,tls</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9388</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday, March 31st: Comparing Phishing Sites; DOH and MX Abuse Phishing; opkssh</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-march-31st-comparing-phishing-sites-doh-and-mx-abuse-phishing-opkssh--65245240</link><description><![CDATA[<br /> A Tale of Two Phishing Sties<br />  Two phishing sites may use very different backends, even if the site itself appears to be visually very similar. Phishing kits are often copied and modified, leading to sites using similar visual tricks on the user facing site, but very different backends to host the sites and reporting data to the miscreant.<br /><a href="https://isc.sans.edu/diary/A%20Tale%20of%20Two%20Phishing%20Sites/31810" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20Tale%20of%20Two%20Phishing%20Sites/31810</a><br /> A Phihsing Tale of DOH and DNS MX Abuse<br />  Infoblox discovered a new variant of the Meerkat phishing kit that uses DoH in Javascript to discover MX records, and generate better customized phishing pages.<br /><a href="https://blogs.infoblox.com/threat-intelligence/a-phishing-tale-of-doh-and-dns-mx-abuse/" target="_blank" rel="noreferrer noopener">https://blogs.infoblox.com/threat-intelligence/a-phishing-tale-of-doh-and-dns-mx-abuse/</a><br /> Using OpenID Connect for SSH<br />  Cloudflare opensourced it's OPKSSH too. It integrates SSO systems supporting OpenID connect with SSH.<br /><a href="https://github.com/openpubkey/opkssh/" target="_blank" rel="noreferrer noopener">https://github.com/openpubkey/opkssh/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9386.mp3</guid><pubDate>Mon, 31 Mar 2025 01:18:33 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65245240/9386.mp3" length="6365443" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9386" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 A Tale of Two Phishing Sties
  Two phishing sites may use very different backends, even if the site itself appears to be visually very similar. Phishing kits are often copied and modified, leading to sites using similar visual tricks on the user...</itunes:subtitle><itunes:summary><![CDATA[<br /> A Tale of Two Phishing Sties<br />  Two phishing sites may use very different backends, even if the site itself appears to be visually very similar. Phishing kits are often copied and modified, leading to sites using similar visual tricks on the user facing site, but very different backends to host the sites and reporting data to the miscreant.<br /><a href="https://isc.sans.edu/diary/A%20Tale%20of%20Two%20Phishing%20Sites/31810" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20Tale%20of%20Two%20Phishing%20Sites/31810</a><br /> A Phihsing Tale of DOH and DNS MX Abuse<br />  Infoblox discovered a new variant of the Meerkat phishing kit that uses DoH in Javascript to discover MX records, and generate better customized phishing pages.<br /><a href="https://blogs.infoblox.com/threat-intelligence/a-phishing-tale-of-doh-and-dns-mx-abuse/" target="_blank" rel="noreferrer noopener">https://blogs.infoblox.com/threat-intelligence/a-phishing-tale-of-doh-and-dns-mx-abuse/</a><br /> Using OpenID Connect for SSH<br />  Cloudflare opensourced it's OPKSSH too. It integrates SSO systems supporting OpenID connect with SSH.<br /><a href="https://github.com/openpubkey/opkssh/" target="_blank" rel="noreferrer noopener">https://github.com/openpubkey/opkssh/</a><br />]]></itunes:summary><itunes:duration>436</itunes:duration><itunes:keywords>business,cloudflare,computer,cyber,cybersecurity,daily,dns,doh,hacking,infosec,internet,it,network,news,openid,phishing,phishing kits,security,ssh</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9386</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday, March 27th: Sitecore Exploited; Blasting Past Webp; Splunk and Firefox Vulnerabilities</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-march-27th-sitecore-exploited-blasting-past-webp-splunk-and-firefox-vulnerabilities--65174613</link><description><![CDATA[<br /> Sitecore "thumbnailsaccesstoken" Deserialization Scans (and some new reports) CVE-2025-27218<br />  Our honeypots detected a deserialization attack against the CMS Sitecore using a  thumnailaccesstoken  header. The underlying vulnerability was patched in January, and security firm Searchlight Cyber revealed details about this vulnerability a couple of weeks ago. <br /><a href="https://isc.sans.edu/diary/Sitecore%20%22thumbnailsaccesstoken%22%20Deserialization%20Scans%20%28and%20some%20new%20reports%29%20CVE-2025-27218/31806" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Sitecore%20%22thumbnailsaccesstoken%22%20Deserialization%20Scans%20%28and%20some%20new%20reports%29%20CVE-2025-27218/31806</a><br /> Blasting Past Webp<br />  Google s Project Zero revealed details how the NSO BLASTPASS exploit took advantage of a Webp image parsing vulnerability in iOS. This zero-click attack was employed in targeted attack back in 2023 and Apple patched the underlying vulnerability in September 2023. But this is the first  byte by byte  description showing how the attack worked.<br /><a href="https://googleprojectzero.blogspot.com/2025/03/blasting-past-webp.html" target="_blank" rel="noreferrer noopener">https://googleprojectzero.blogspot.com/2025/03/blasting-past-webp.html</a><br /> Splunk Vulnerabilities<br />  Splunk patched about a dozen of vulnerabilities. None of them are rated critical, but a vulnerability rated  High  allows authenticated users to execute arbitrary code.<br /><a href="https://advisory.splunk.com/" target="_blank" rel="noreferrer noopener">https://advisory.splunk.com/</a><br /> Firefox 0-day Patched<br />  Mozilla patched a sandbox escape vulnerability that is already being exploited.<br /><a href="https://www.mozilla.org/en-US/security/advisories/mfsa2025-19/" target="_blank" rel="noreferrer noopener">https://www.mozilla.org/en-US/security/advisories/mfsa2025-19/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9384.mp3</guid><pubDate>Fri, 28 Mar 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65174613/9384.mp3" length="5521880" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9384" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Sitecore "thumbnailsaccesstoken" Deserialization Scans (and some new reports) CVE-2025-27218
  Our honeypots detected a deserialization attack against the CMS Sitecore using a  thumnailaccesstoken  header. The underlying vulnerability was patched in...</itunes:subtitle><itunes:summary><![CDATA[<br /> Sitecore "thumbnailsaccesstoken" Deserialization Scans (and some new reports) CVE-2025-27218<br />  Our honeypots detected a deserialization attack against the CMS Sitecore using a  thumnailaccesstoken  header. The underlying vulnerability was patched in January, and security firm Searchlight Cyber revealed details about this vulnerability a couple of weeks ago. <br /><a href="https://isc.sans.edu/diary/Sitecore%20%22thumbnailsaccesstoken%22%20Deserialization%20Scans%20%28and%20some%20new%20reports%29%20CVE-2025-27218/31806" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Sitecore%20%22thumbnailsaccesstoken%22%20Deserialization%20Scans%20%28and%20some%20new%20reports%29%20CVE-2025-27218/31806</a><br /> Blasting Past Webp<br />  Google s Project Zero revealed details how the NSO BLASTPASS exploit took advantage of a Webp image parsing vulnerability in iOS. This zero-click attack was employed in targeted attack back in 2023 and Apple patched the underlying vulnerability in September 2023. But this is the first  byte by byte  description showing how the attack worked.<br /><a href="https://googleprojectzero.blogspot.com/2025/03/blasting-past-webp.html" target="_blank" rel="noreferrer noopener">https://googleprojectzero.blogspot.com/2025/03/blasting-past-webp.html</a><br /> Splunk Vulnerabilities<br />  Splunk patched about a dozen of vulnerabilities. None of them are rated critical, but a vulnerability rated  High  allows authenticated users to execute arbitrary code.<br /><a href="https://advisory.splunk.com/" target="_blank" rel="noreferrer noopener">https://advisory.splunk.com/</a><br /> Firefox 0-day Patched<br />  Mozilla patched a sandbox escape vulnerability that is already being exploited.<br /><a href="https://www.mozilla.org/en-US/security/advisories/mfsa2025-19/" target="_blank" rel="noreferrer noopener">https://www.mozilla.org/en-US/security/advisories/mfsa2025-19/</a><br />]]></itunes:summary><itunes:duration>375</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,deserialization,firefox,hacking,infosec,internet,it,mozilla,network,news,security,sitecore,splunk,webp</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9384</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday Mar 27th: Classifying Malware with ML; Malicious NPM Packages; Google Chrome 0-day</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-mar-27th-classifying-malware-with-ml-malicious-npm-packages-google-chrome-0-day--65150801</link><description><![CDATA[<br /> Leveraging CNNs and Entropy-Based Feature Selection to Identify Potential Malware Artifacts of Interest<br />     This diary explores a novel methodology for classifying malware by integrating entropy-driven feature selection with a specialized Convolutional Neural Network (CNN). Motivated by the increasing obfuscation tactics used by modern malware authors, we will focus on capturing high-entropy segments within files, regions most likely to harbor malicious functionality, and feeding these distinct byte patterns into our model.<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Leveraging%20CNNs%20and%20Entropy-Based%20Feature%20Selection%20to%20Identify%20Potential%20Malware%20Artifacts%20of%20Interest/31790" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Leveraging%20CNNs%20and%20Entropy-Based%20Feature%20Selection%20to%20Identify%20Potential%20Malware%20Artifacts%20of%20Interest/31790</a><br /><br /> Malware found on npm infecting local package with reverse shell<br />  Researchers at Reversinglabs found two malicious NPM packages, ethers-provider2, and ethers-providerz that patch the well known (and not malicious) ethers package to add a reverse shell and downloader.<br /><a href="https://www.reversinglabs.com/blog/malicious-npm-patch-delivers-reverse-shell" target="_blank" rel="noreferrer noopener">https://www.reversinglabs.com/blog/malicious-npm-patch-delivers-reverse-shell</a><br /> Google Patched Google Chrome 0-day<br />   Google patched a vulnerability in Chrome that was already exploited in attacks against media and educational organizations in Russia<br /><a href="https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop_25.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop_25.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9382.mp3</guid><pubDate>Thu, 27 Mar 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65150801/9382.mp3" length="6309798" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9382" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Leveraging CNNs and Entropy-Based Feature Selection to Identify Potential Malware Artifacts of Interest
     This diary explores a novel methodology for classifying malware by integrating entropy-driven feature selection with a specialized...</itunes:subtitle><itunes:summary><![CDATA[<br /> Leveraging CNNs and Entropy-Based Feature Selection to Identify Potential Malware Artifacts of Interest<br />     This diary explores a novel methodology for classifying malware by integrating entropy-driven feature selection with a specialized Convolutional Neural Network (CNN). Motivated by the increasing obfuscation tactics used by modern malware authors, we will focus on capturing high-entropy segments within files, regions most likely to harbor malicious functionality, and feeding these distinct byte patterns into our model.<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Leveraging%20CNNs%20and%20Entropy-Based%20Feature%20Selection%20to%20Identify%20Potential%20Malware%20Artifacts%20of%20Interest/31790" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Leveraging%20CNNs%20and%20Entropy-Based%20Feature%20Selection%20to%20Identify%20Potential%20Malware%20Artifacts%20of%20Interest/31790</a><br /><br /> Malware found on npm infecting local package with reverse shell<br />  Researchers at Reversinglabs found two malicious NPM packages, ethers-provider2, and ethers-providerz that patch the well known (and not malicious) ethers package to add a reverse shell and downloader.<br /><a href="https://www.reversinglabs.com/blog/malicious-npm-patch-delivers-reverse-shell" target="_blank" rel="noreferrer noopener">https://www.reversinglabs.com/blog/malicious-npm-patch-delivers-reverse-shell</a><br /> Google Patched Google Chrome 0-day<br />   Google patched a vulnerability in Chrome that was already exploited in attacks against media and educational organizations in Russia<br /><a href="https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop_25.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop_25.html</a><br />]]></itunes:summary><itunes:duration>431</itunes:duration><itunes:keywords>business,chrome,computer,cyber,cybersecurity,daily,ethers,google,hacking,infosec,internet,it,network,news,npm,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9382</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday Mar 26th: XWiki Exploit; File Converter Correction; VMWare Vulnerability; Draytek Router Reboots; MMC Exploit Detai</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-mar-26th-xwiki-exploit-file-converter-correction-vmware-vulnerability-draytek-router-reboots-mmc-exploit-detai--65123888</link><description><![CDATA[<br /> XWiki Search Vulnerablity Exploit Attempts (CVE-2024-3721)<br />  Our honeypot detected an increase in exploit attempts for an XWiki command injection vulnerablity. The vulnerability was patched last April, but appears to be exploited more these last couple days. The vulnerability affects the search feature and allows the attacker to inject Groovy code templates.<br /><a href="https://isc.sans.edu/diary/X-Wiki%20Search%20Vulnerability%20exploit%20attempts%20%28CVE-2024-3721%29/31800" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/X-Wiki%20Search%20Vulnerability%20exploit%20attempts%20%28CVE-2024-3721%29/31800</a> <br /> Correction: FBI Image Converter Warning<br />  The FBI's Denver office warned of online file converters, not downloadable conversion tools<br /><a href="https://www.fbi.gov/contact-us/field-offices/denver/news/fbi-denver-warns-of-online-file-converter-scam" target="_blank" rel="noreferrer noopener">https://www.fbi.gov/contact-us/field-offices/denver/news/fbi-denver-warns-of-online-file-converter-scam</a><br /> VMWare Vulnerability<br />  Broadcom released a fix for a VMWare Tools vulnerability. The vulnerability allows users of a Windows virtual machine to escalate privileges within the machine.<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25518" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25518</a><br /> Draytek Reboots<br />  Over the weekend, users started reporting Draytek routers rebooting and getting stuck in a reboot loop. Draytek now published advise as to how to fix the problem.<br /><a href="https://faq.draytek.com.au/docs/draytek-routers-rebooting-how-to-solve-this-issue/" target="_blank" rel="noreferrer noopener">https://faq.draytek.com.au/docs/draytek-routers-rebooting-how-to-solve-this-issue/</a><br /> Microsoft Managemnt Console Exploit CVE-2025-26633<br />  TrendMicro released details showing how the MMC vulnerability Microsoft patched as part of its patch tuesday this month was exploited.<br /><a href="https://www.trendmicro.com/en_us/research/25/c/cve-2025-26633-water-gamayun.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_us/research/25/c/cve-2025-26633-water-gamayun.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9380.mp3</guid><pubDate>Wed, 26 Mar 2025 02:05:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65123888/9380.mp3" length="5515404" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9380" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 XWiki Search Vulnerablity Exploit Attempts (CVE-2024-3721)
  Our honeypot detected an increase in exploit attempts for an XWiki command injection vulnerablity. The vulnerability was patched last April, but appears to be exploited more these last...</itunes:subtitle><itunes:summary><![CDATA[<br /> XWiki Search Vulnerablity Exploit Attempts (CVE-2024-3721)<br />  Our honeypot detected an increase in exploit attempts for an XWiki command injection vulnerablity. The vulnerability was patched last April, but appears to be exploited more these last couple days. The vulnerability affects the search feature and allows the attacker to inject Groovy code templates.<br /><a href="https://isc.sans.edu/diary/X-Wiki%20Search%20Vulnerability%20exploit%20attempts%20%28CVE-2024-3721%29/31800" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/X-Wiki%20Search%20Vulnerability%20exploit%20attempts%20%28CVE-2024-3721%29/31800</a> <br /> Correction: FBI Image Converter Warning<br />  The FBI's Denver office warned of online file converters, not downloadable conversion tools<br /><a href="https://www.fbi.gov/contact-us/field-offices/denver/news/fbi-denver-warns-of-online-file-converter-scam" target="_blank" rel="noreferrer noopener">https://www.fbi.gov/contact-us/field-offices/denver/news/fbi-denver-warns-of-online-file-converter-scam</a><br /> VMWare Vulnerability<br />  Broadcom released a fix for a VMWare Tools vulnerability. The vulnerability allows users of a Windows virtual machine to escalate privileges within the machine.<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25518" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25518</a><br /> Draytek Reboots<br />  Over the weekend, users started reporting Draytek routers rebooting and getting stuck in a reboot loop. Draytek now published advise as to how to fix the problem.<br /><a href="https://faq.draytek.com.au/docs/draytek-routers-rebooting-how-to-solve-this-issue/" target="_blank" rel="noreferrer noopener">https://faq.draytek.com.au/docs/draytek-routers-rebooting-how-to-solve-this-issue/</a><br /> Microsoft Managemnt Console Exploit CVE-2025-26633<br />  TrendMicro released details showing how the MMC vulnerability Microsoft patched as part of its patch tuesday this month was exploited.<br /><a href="https://www.trendmicro.com/en_us/research/25/c/cve-2025-26633-water-gamayun.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_us/research/25/c/cve-2025-26633-water-gamayun.html</a><br />]]></itunes:summary><itunes:duration>375</itunes:duration><itunes:keywords>business,cyber,cybersecurity,daily,denver,draytek,fbi,groovy,hacking,image conversion,infosec,it,microsoft,mmc,network,news,security,trendmicro,vmware,xwiki</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9380</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday Mar 25th: Privacy Awware Bots; Ingress Nightmare; Malicious File Converters; VSCode Extension Leads to Ransomware</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-mar-25th-privacy-awware-bots-ingress-nightmare-malicious-file-converters-vscode-extension-leads-to-ransomware--65091426</link><description><![CDATA[<br /> Privacy Aware Bots<br />  A botnet is using privacy as well as CSRF prevention headers to better blend in with normal browsers. However, in the process they may make it actually easier to spot them.<br /><a href="https://isc.sans.edu/diary/Privacy%20Aware%20Bots/31796" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Privacy%20Aware%20Bots/31796</a><br /> Critical Ingress Nightmare Vulnerability<br />  ingress-nginx fixed four new vulnerabilities, one of which may lead to a Kubernetes cluster compromise. Note that at the time I am making this live, not all of the URLs below are available yet, but I hope they will be available shortly after publishing this podcast<br /><a href="https://www.darkreading.com/application-security/critical-ingressnightmare-vulns-kubernetes-environments" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/application-security/critical-ingressnightmare-vulns-kubernetes-environments</a><br /><a href="https://www.wiz.io/blog/ingress-nginx-kubernetes-vulnerabilities" target="_blank" rel="noreferrer noopener">https://www.wiz.io/blog/ingress-nginx-kubernetes-vulnerabilities</a><br /><a href="https://kubernetes.io/blog/" target="_blank" rel="noreferrer noopener">https://kubernetes.io/blog/</a><br /> FBI Warns of File Converter Scams<br />  File converters may include malicious ad ons. Be careful where you get your software from.<br /><a href="https://www.fbi.gov/contact-us/field-offices/denver/news/fbi-denver-warns-of-online-file-converter-scam" target="_blank" rel="noreferrer noopener">https://www.fbi.gov/contact-us/field-offices/denver/news/fbi-denver-warns-of-online-file-converter-scam</a><br /> VSCode Extension Includes Ransomware<br /><a href="https://x.com/ReversingLabs/status/1902355043065500145" target="_blank" rel="noreferrer noopener">https://x.com/ReversingLabs/status/1902355043065500145</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9378.mp3</guid><pubDate>Tue, 25 Mar 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65091426/9378.mp3" length="5238921" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9378" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Privacy Aware Bots
  A botnet is using privacy as well as CSRF prevention headers to better blend in with normal browsers. However, in the process they may make it actually easier to spot them.
https://isc.sans.edu/diary/Privacy%20Aware%20Bots/31796...</itunes:subtitle><itunes:summary><![CDATA[<br /> Privacy Aware Bots<br />  A botnet is using privacy as well as CSRF prevention headers to better blend in with normal browsers. However, in the process they may make it actually easier to spot them.<br /><a href="https://isc.sans.edu/diary/Privacy%20Aware%20Bots/31796" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Privacy%20Aware%20Bots/31796</a><br /> Critical Ingress Nightmare Vulnerability<br />  ingress-nginx fixed four new vulnerabilities, one of which may lead to a Kubernetes cluster compromise. Note that at the time I am making this live, not all of the URLs below are available yet, but I hope they will be available shortly after publishing this podcast<br /><a href="https://www.darkreading.com/application-security/critical-ingressnightmare-vulns-kubernetes-environments" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/application-security/critical-ingressnightmare-vulns-kubernetes-environments</a><br /><a href="https://www.wiz.io/blog/ingress-nginx-kubernetes-vulnerabilities" target="_blank" rel="noreferrer noopener">https://www.wiz.io/blog/ingress-nginx-kubernetes-vulnerabilities</a><br /><a href="https://kubernetes.io/blog/" target="_blank" rel="noreferrer noopener">https://kubernetes.io/blog/</a><br /> FBI Warns of File Converter Scams<br />  File converters may include malicious ad ons. Be careful where you get your software from.<br /><a href="https://www.fbi.gov/contact-us/field-offices/denver/news/fbi-denver-warns-of-online-file-converter-scam" target="_blank" rel="noreferrer noopener">https://www.fbi.gov/contact-us/field-offices/denver/news/fbi-denver-warns-of-online-file-converter-scam</a><br /> VSCode Extension Includes Ransomware<br /><a href="https://x.com/ReversingLabs/status/1902355043065500145" target="_blank" rel="noreferrer noopener">https://x.com/ReversingLabs/status/1902355043065500145</a><br />]]></itunes:summary><itunes:duration>355</itunes:duration><itunes:keywords>bots,business,cyber,cybersecurity,daily,fbi,file converter,hacking,infosec,ingress,it,kubernetes,malware,network,news,nightmare,privacy,ransomware,scam,vscode</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9378</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday Mar 24th: Critical Next.js Vulnerability; Microsoft Trust Signing Platform Abuse</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-mar-24th-critical-next-js-vulnerability-microsoft-trust-signing-platform-abuse--65058244</link><description><![CDATA[<br /> Critical Next.js Vulnerability CVE-2025-29927<br />  A critical vulnerability in how the x-middleware-subrequest header is verified may lead to bypassing authorization in Next.js applications.<br /><a href="https://zhero-web-sec.github.io/research-and-things/nextjs-and-the-corrupt-middleware" target="_blank" rel="noreferrer noopener">https://zhero-web-sec.github.io/research-and-things/nextjs-and-the-corrupt-middleware</a><br /><a href="https://github.com/vercel/next.js/security/advisories/GHSA-f82v-jwr5-mffw" target="_blank" rel="noreferrer noopener">https://github.com/vercel/next.js/security/advisories/GHSA-f82v-jwr5-mffw</a><br /><a href="https://www.runzero.com/blog/next-js/" target="_blank" rel="noreferrer noopener">https://www.runzero.com/blog/next-js/</a><br /> Microsoft Trust Signing Service Abused<br />  Attackers abut the Microsoft Trust Signing Service, a service meant to help developers create signed software, to obtain short lived signatures for malware.<br /><a href="https://www.bleepingcomputer.com/news/security/microsoft-trust-signing-service-abused-to-code-sign-malware/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/microsoft-trust-signing-service-abused-to-code-sign-malware/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9376.mp3</guid><pubDate>Mon, 24 Mar 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65058244/9376.mp3" length="6292846" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9376" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Critical Next.js Vulnerability CVE-2025-29927
  A critical vulnerability in how the x-middleware-subrequest header is verified may lead to bypassing authorization in Next.js applications....</itunes:subtitle><itunes:summary><![CDATA[<br /> Critical Next.js Vulnerability CVE-2025-29927<br />  A critical vulnerability in how the x-middleware-subrequest header is verified may lead to bypassing authorization in Next.js applications.<br /><a href="https://zhero-web-sec.github.io/research-and-things/nextjs-and-the-corrupt-middleware" target="_blank" rel="noreferrer noopener">https://zhero-web-sec.github.io/research-and-things/nextjs-and-the-corrupt-middleware</a><br /><a href="https://github.com/vercel/next.js/security/advisories/GHSA-f82v-jwr5-mffw" target="_blank" rel="noreferrer noopener">https://github.com/vercel/next.js/security/advisories/GHSA-f82v-jwr5-mffw</a><br /><a href="https://www.runzero.com/blog/next-js/" target="_blank" rel="noreferrer noopener">https://www.runzero.com/blog/next-js/</a><br /> Microsoft Trust Signing Service Abused<br />  Attackers abut the Microsoft Trust Signing Service, a service meant to help developers create signed software, to obtain short lived signatures for malware.<br /><a href="https://www.bleepingcomputer.com/news/security/microsoft-trust-signing-service-abused-to-code-sign-malware/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/microsoft-trust-signing-service-abused-to-code-sign-malware/</a><br />]]></itunes:summary><itunes:duration>430</itunes:duration><itunes:keywords>authorization,business,computer,cyber,cybersecurity,daily,digital signature,hacking,infosec,internet,it,microsoft,middleware,network,news,next.js,proxies,security,signing,trust</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9376</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday Mar 21st: New Data Feeds; SEO Spam; Veeam Deserialization; IBM AIX RCE;</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-mar-21st-new-data-feeds-seo-spam-veeam-deserialization-ibm-aix-rce--65006657</link><description><![CDATA[<br /> Some New Data Feeds and Little Incident<br />  We started offering additional data feeds, and an SEO spamer attempted to make us change a link from an old podcast episode.<br /><a href="https://isc.sans.edu/diary/Some%20new%20Data%20Feeds%2C%20and%20a%20little%20%22incident%22./31786" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Some%20new%20Data%20Feeds%2C%20and%20a%20little%20%22incident%22./31786</a><br /> Veeam Deserialization Vulnerability<br />  Veeam released details regarding the latest vulnerablity in Veeam, pointing out the insufficient patch applied to a prior deserialization vulnerability.<br /><a href="https://labs.watchtowr.com/by-executive-order-we-are-banning-blacklists-domain-level-rce-in-veeam-backup-replication-cve-2025-23120/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/by-executive-order-we-are-banning-blacklists-domain-level-rce-in-veeam-backup-replication-cve-2025-23120/</a><br /> IBM AIX Vulnerablity<br />  The AIX NIM service is vulnerable to an unauthenticated remote code execution vulnerability<br /><a href="https://www.ibm.com/support/pages/node/7186621" target="_blank" rel="noreferrer noopener">https://www.ibm.com/support/pages/node/7186621</a><br /> thanks Chris Mosby for Spotify comment<br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9374.mp3</guid><pubDate>Fri, 21 Mar 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/65006657/9374.mp3" length="7336373" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9374" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Some New Data Feeds and Little Incident
  We started offering additional data feeds, and an SEO spamer attempted to make us change a link from an old podcast episode....</itunes:subtitle><itunes:summary><![CDATA[<br /> Some New Data Feeds and Little Incident<br />  We started offering additional data feeds, and an SEO spamer attempted to make us change a link from an old podcast episode.<br /><a href="https://isc.sans.edu/diary/Some%20new%20Data%20Feeds%2C%20and%20a%20little%20%22incident%22./31786" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Some%20new%20Data%20Feeds%2C%20and%20a%20little%20%22incident%22./31786</a><br /> Veeam Deserialization Vulnerability<br />  Veeam released details regarding the latest vulnerablity in Veeam, pointing out the insufficient patch applied to a prior deserialization vulnerability.<br /><a href="https://labs.watchtowr.com/by-executive-order-we-are-banning-blacklists-domain-level-rce-in-veeam-backup-replication-cve-2025-23120/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/by-executive-order-we-are-banning-blacklists-domain-level-rce-in-veeam-backup-replication-cve-2025-23120/</a><br /> IBM AIX Vulnerablity<br />  The AIX NIM service is vulnerable to an unauthenticated remote code execution vulnerability<br /><a href="https://www.ibm.com/support/pages/node/7186621" target="_blank" rel="noreferrer noopener">https://www.ibm.com/support/pages/node/7186621</a><br /> thanks Chris Mosby for Spotify comment<br />]]></itunes:summary><itunes:duration>505</itunes:duration><itunes:keywords>aix,business,computer,cyber,cybersecurity,daily,data feeds,hacking,ibm,infosec,internet,it,network,news,security,seo spam,veeam</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9374</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday Mar 20th: Cisco Smart Licensing Attacks; Vulnerable Drivers again; Synology Advisories Updated</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-mar-20th-cisco-smart-licensing-attacks-vulnerable-drivers-again-synology-advisories-updated--64987588</link><description><![CDATA[<br /> Exploit Attempts for Cisco Smart Licensing Utility CVE-2024-20439 CVE-2024-20440<br />  Attackers added last September's Cisco Smart Licensing Utility vulnerability to their toolset. These attacks orginate most likely from botnets and the same attackers are scanning for a wide range of additional vulnerabilities. The vulnerability is a static credential issue and trivial to exploit after the credentials were published last fall.<br /><a href="https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Cisco%20Smart%20Licensing%20Utility%20CVE-2024-20439%20and%20CVE-2024-20440/31782" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Cisco%20Smart%20Licensing%20Utility%20CVE-2024-20439%20and%20CVE-2024-20440/31782</a><br /> Legacy Driver Exploitation Through Bypassing Certificate Verification<br />  Ahnlab documented a new type of "bring your own vulnerable driver" vulnerability. In this case, an old driver used by an anit-malware and anti-rootkit system can be used to shut down arbitrary processeses, including security related processeses.<br /><a href="https://asec.ahnlab.com/en/86881/" target="_blank" rel="noreferrer noopener">https://asec.ahnlab.com/en/86881/</a><br /> Synology Vulnerability Updates<br />  Synology updates some security advisories it release last year adding addition details and vulnerable systems.<br /><a href="https://www.synology.com/en-global/security/advisory/Synology_SA_24_20" target="_blank" rel="noreferrer noopener">https://www.synology.com/en-global/security/advisory/Synology_SA_24_20</a><br /><a href="https://www.synology.com/en-global/security/advisory/Synology_SA_24_24" target="_blank" rel="noreferrer noopener">https://www.synology.com/en-global/security/advisory/Synology_SA_24_24</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9372.mp3</guid><pubDate>Thu, 20 Mar 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64987588/9372.mp3" length="6278305" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9372" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Exploit Attempts for Cisco Smart Licensing Utility CVE-2024-20439 CVE-2024-20440
  Attackers added last September's Cisco Smart Licensing Utility vulnerability to their toolset. These attacks orginate most likely from botnets and the same attackers...</itunes:subtitle><itunes:summary><![CDATA[<br /> Exploit Attempts for Cisco Smart Licensing Utility CVE-2024-20439 CVE-2024-20440<br />  Attackers added last September's Cisco Smart Licensing Utility vulnerability to their toolset. These attacks orginate most likely from botnets and the same attackers are scanning for a wide range of additional vulnerabilities. The vulnerability is a static credential issue and trivial to exploit after the credentials were published last fall.<br /><a href="https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Cisco%20Smart%20Licensing%20Utility%20CVE-2024-20439%20and%20CVE-2024-20440/31782" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Cisco%20Smart%20Licensing%20Utility%20CVE-2024-20439%20and%20CVE-2024-20440/31782</a><br /> Legacy Driver Exploitation Through Bypassing Certificate Verification<br />  Ahnlab documented a new type of "bring your own vulnerable driver" vulnerability. In this case, an old driver used by an anit-malware and anti-rootkit system can be used to shut down arbitrary processeses, including security related processeses.<br /><a href="https://asec.ahnlab.com/en/86881/" target="_blank" rel="noreferrer noopener">https://asec.ahnlab.com/en/86881/</a><br /> Synology Vulnerability Updates<br />  Synology updates some security advisories it release last year adding addition details and vulnerable systems.<br /><a href="https://www.synology.com/en-global/security/advisory/Synology_SA_24_20" target="_blank" rel="noreferrer noopener">https://www.synology.com/en-global/security/advisory/Synology_SA_24_20</a><br /><a href="https://www.synology.com/en-global/security/advisory/Synology_SA_24_24" target="_blank" rel="noreferrer noopener">https://www.synology.com/en-global/security/advisory/Synology_SA_24_24</a><br />]]></itunes:summary><itunes:duration>429</itunes:duration><itunes:keywords>business,cisco,computer,cyber,cybersecurity,daily,driver,hacking,infosec,internet,it,network,news,security,synology</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9372</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday Mar 19th 2025: Python DLL Side Loading; Tomcast RCE Correction; SAML Roulette; Windows Shortcut 0-Day</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-mar-19th-2025-python-dll-side-loading-tomcast-rce-correction-saml-roulette-windows-shortcut-0-day--64965983</link><description><![CDATA[<br /> Python Bot Delivered Through DLL Side-Loading<br />  A "normal", but vulnerable to DLL side-loading PDF reader may be used to launch additional exploit code<br /><a href="https://isc.sans.edu/diary/Python%20Bot%20Delivered%20Through%20DLL%20Side-Loading/31778" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Python%20Bot%20Delivered%20Through%20DLL%20Side-Loading/31778</a><br /> Tomcat RCE Correction<br />  To exploit the Tomcat RCE I mentioned yesterday, two non-default configuration options must be selected by the victim.<br /><a href="https://x.com/dkx02668274/status/1901893656316969308" target="_blank" rel="noreferrer noopener">https://x.com/dkx02668274/status/1901893656316969308</a><br /> SAML Roulette: The Hacker Always Wins<br />  This Portswigger blog explains in detail how to exploit the ruby-saml vulnerablity against GitLab.<br /><a href="https://portswigger.net/research/saml-roulette-the-hacker-always-wins" target="_blank" rel="noreferrer noopener">https://portswigger.net/research/saml-roulette-the-hacker-always-wins</a><br /> Windows Shortcut Zero Day Exploit<br />  Attackers are currently taking advantage of an unpatched vulnerability in how Windows displays Shortcut (.lnk file) details. Trendmicro explains how the attack works and provides PoC code. Microsoft is not planning to fix this issue<br /><a href="https://www.trendmicro.com/en_us/research/25/c/windows-shortcut-zero-day-exploit.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_us/research/25/c/windows-shortcut-zero-day-exploit.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9370.mp3</guid><pubDate>Wed, 19 Mar 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64965983/9370.mp3" length="6412030" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9370" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Python Bot Delivered Through DLL Side-Loading
  A "normal", but vulnerable to DLL side-loading PDF reader may be used to launch additional exploit code
https://isc.sans.edu/diary/Python%20Bot%20Delivered%20Through%20DLL%20Side-Loading/31778
 Tomcat...</itunes:subtitle><itunes:summary><![CDATA[<br /> Python Bot Delivered Through DLL Side-Loading<br />  A "normal", but vulnerable to DLL side-loading PDF reader may be used to launch additional exploit code<br /><a href="https://isc.sans.edu/diary/Python%20Bot%20Delivered%20Through%20DLL%20Side-Loading/31778" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Python%20Bot%20Delivered%20Through%20DLL%20Side-Loading/31778</a><br /> Tomcat RCE Correction<br />  To exploit the Tomcat RCE I mentioned yesterday, two non-default configuration options must be selected by the victim.<br /><a href="https://x.com/dkx02668274/status/1901893656316969308" target="_blank" rel="noreferrer noopener">https://x.com/dkx02668274/status/1901893656316969308</a><br /> SAML Roulette: The Hacker Always Wins<br />  This Portswigger blog explains in detail how to exploit the ruby-saml vulnerablity against GitLab.<br /><a href="https://portswigger.net/research/saml-roulette-the-hacker-always-wins" target="_blank" rel="noreferrer noopener">https://portswigger.net/research/saml-roulette-the-hacker-always-wins</a><br /> Windows Shortcut Zero Day Exploit<br />  Attackers are currently taking advantage of an unpatched vulnerability in how Windows displays Shortcut (.lnk file) details. Trendmicro explains how the attack works and provides PoC code. Microsoft is not planning to fix this issue<br /><a href="https://www.trendmicro.com/en_us/research/25/c/windows-shortcut-zero-day-exploit.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_us/research/25/c/windows-shortcut-zero-day-exploit.html</a><br />]]></itunes:summary><itunes:duration>439</itunes:duration><itunes:keywords>business,cyber,cybersecurity,daily,dll,hacking,infosec,it,link,lnk,news,python,rce,ruby,saml,shortcut,sideloading,tomcat,windows,xml</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9370</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday Mar 17th 2025: Analyzing GUID Encoded Shellcode; Node.js SAML Vuln; Tomcat RCE in the Wild; CSS e-mail obfuscation</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-mar-17th-2025-analyzing-guid-encoded-shellcode-node-js-saml-vuln-tomcat-rce-in-the-wild-css-e-mail-obfuscation--64947522</link><description><![CDATA[<br /> Static Analysis of GUID Encoded Shellcode<br />  Didier explains how to decode shell code embeded as GUIDs in malware, and how to feed the result to his tool 1768.py which will extract Cobal Strike configuration information from the code.<br /><a href="https://isc.sans.edu/diary/Static%20Analysis%20of%20GUID%20Encoded%20Shellcode/31774" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Static%20Analysis%20of%20GUID%20Encoded%20Shellcode/31774</a><br /> SAMLStorm: Critical Authentication Bypass in xml-crypto and Node.js libraries<br />  xml-crypto, a library use in Node.js applications to decode XML and support SAML, has found to parse comments incorrectly leading to several SAML vulnerabilities.<br /><a href="https://workos.com/blog/samlstorm" target="_blank" rel="noreferrer noopener">https://workos.com/blog/samlstorm</a><br /> One PUT Request to Own Tomcat: CVE-2025-24813 RCE is in the Wild<br />  A just made public deserialization vulnerablity in Tomcat is already being exploited. Contributing to the rapid exploit release is the similarity of this vulnerability to other Java deserializtion vulnerabilities. <br /><a href="https://lab.wallarm.com/one-put-request-to-own-tomcat-cve-2025-24813-rce-is-in-the-wild/" target="_blank" rel="noreferrer noopener">https://lab.wallarm.com/one-put-request-to-own-tomcat-cve-2025-24813-rce-is-in-the-wild/</a>  CVE-2025-24813<br /> CSS Abuse for Evasion and Tracking<br />  Attackers are using cascading stylesheets to evade detection and enable more stealthy tracking of users<br /><a href="https://blog.talosintelligence.com/css-abuse-for-evasion-and-tracking/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/css-abuse-for-evasion-and-tracking/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9368.mp3</guid><pubDate>Tue, 18 Mar 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64947522/9368.mp3" length="6193071" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9368" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Static Analysis of GUID Encoded Shellcode
  Didier explains how to decode shell code embeded as GUIDs in malware, and how to feed the result to his tool 1768.py which will extract Cobal Strike configuration information from the code....</itunes:subtitle><itunes:summary><![CDATA[<br /> Static Analysis of GUID Encoded Shellcode<br />  Didier explains how to decode shell code embeded as GUIDs in malware, and how to feed the result to his tool 1768.py which will extract Cobal Strike configuration information from the code.<br /><a href="https://isc.sans.edu/diary/Static%20Analysis%20of%20GUID%20Encoded%20Shellcode/31774" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Static%20Analysis%20of%20GUID%20Encoded%20Shellcode/31774</a><br /> SAMLStorm: Critical Authentication Bypass in xml-crypto and Node.js libraries<br />  xml-crypto, a library use in Node.js applications to decode XML and support SAML, has found to parse comments incorrectly leading to several SAML vulnerabilities.<br /><a href="https://workos.com/blog/samlstorm" target="_blank" rel="noreferrer noopener">https://workos.com/blog/samlstorm</a><br /> One PUT Request to Own Tomcat: CVE-2025-24813 RCE is in the Wild<br />  A just made public deserialization vulnerablity in Tomcat is already being exploited. Contributing to the rapid exploit release is the similarity of this vulnerability to other Java deserializtion vulnerabilities. <br /><a href="https://lab.wallarm.com/one-put-request-to-own-tomcat-cve-2025-24813-rce-is-in-the-wild/" target="_blank" rel="noreferrer noopener">https://lab.wallarm.com/one-put-request-to-own-tomcat-cve-2025-24813-rce-is-in-the-wild/</a>  CVE-2025-24813<br /> CSS Abuse for Evasion and Tracking<br />  Attackers are using cascading stylesheets to evade detection and enable more stealthy tracking of users<br /><a href="https://blog.talosintelligence.com/css-abuse-for-evasion-and-tracking/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/css-abuse-for-evasion-and-tracking/</a><br />]]></itunes:summary><itunes:duration>423</itunes:duration><itunes:keywords>abuse,business,cobalt strike,css,cyber,cybersecurity,daily,guid,hacking,infosec,it,network,news,node.js,put,saml,security,tomcat,tracking,xml-crypto</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9368</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday March 17th: Mirai Makes Mistakes; Compromised Github Action; ruby-saml vulnerability; Fake GitHub Security Alert Phish</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-march-17th-mirai-makes-mistakes-compromised-github-action-ruby-saml-vulnerability-fake-github-security-alert-phish--64927020</link><description><![CDATA[<br /> Mirai Bot Now Incorporating Malformed DrayTek Vigor Router Exploits<br />  One of the many versions of the Mirai botnet added some new exploit strings attempting to take advantage of an old DrayTek Vigor Router vulnerability, but they got the URL wrong.<br /><a href="https://isc.sans.edu/diary/Mirai%20Bot%20now%20incroporating%20%28malformed%3F%29%20DrayTek%20Vigor%20Router%20Exploits/31770" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Mirai%20Bot%20now%20incroporating%20%28malformed%3F%29%20DrayTek%20Vigor%20Router%20Exploits/31770</a><br /> Compromised GitHub Action<br />  The popular GitHub action tj-actions/changed-files was compromised and leaks credentials via the action logs<br /><a href="https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised" target="_blank" rel="noreferrer noopener">https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised</a><br /> ruby-saml authentication bypass<br />  A confusion in how to parse SAML messages between two XML parsers used by Ruby leads to an authentication bypass in saml-ruby.<br /><a href="https://github.blog/security/sign-in-as-anyone-bypassing-saml-sso-authentication-with-parser-differentials/" target="_blank" rel="noreferrer noopener">https://github.blog/security/sign-in-as-anyone-bypassing-saml-sso-authentication-with-parser-differentials/</a><br /> GitHub Fake Security Alerts<br />  Fake GitHub security alerts are used to trick package maintainers into adding OAUTH privileges to malicious apps.<br /><a href="https://www.bleepingcomputer.com/news/security/fake-security-alert-issues-on-github-use-oauth-app-to-hijack-accounts/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/fake-security-alert-issues-on-github-use-oauth-app-to-hijack-accounts/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9366.mp3</guid><pubDate>Mon, 17 Mar 2025 01:35:10 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64927020/9366.mp3" length="5850177" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9366" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Mirai Bot Now Incorporating Malformed DrayTek Vigor Router Exploits
  One of the many versions of the Mirai botnet added some new exploit strings attempting to take advantage of an old DrayTek Vigor Router vulnerability, but they got the URL wrong....</itunes:subtitle><itunes:summary><![CDATA[<br /> Mirai Bot Now Incorporating Malformed DrayTek Vigor Router Exploits<br />  One of the many versions of the Mirai botnet added some new exploit strings attempting to take advantage of an old DrayTek Vigor Router vulnerability, but they got the URL wrong.<br /><a href="https://isc.sans.edu/diary/Mirai%20Bot%20now%20incroporating%20%28malformed%3F%29%20DrayTek%20Vigor%20Router%20Exploits/31770" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Mirai%20Bot%20now%20incroporating%20%28malformed%3F%29%20DrayTek%20Vigor%20Router%20Exploits/31770</a><br /> Compromised GitHub Action<br />  The popular GitHub action tj-actions/changed-files was compromised and leaks credentials via the action logs<br /><a href="https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised" target="_blank" rel="noreferrer noopener">https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised</a><br /> ruby-saml authentication bypass<br />  A confusion in how to parse SAML messages between two XML parsers used by Ruby leads to an authentication bypass in saml-ruby.<br /><a href="https://github.blog/security/sign-in-as-anyone-bypassing-saml-sso-authentication-with-parser-differentials/" target="_blank" rel="noreferrer noopener">https://github.blog/security/sign-in-as-anyone-bypassing-saml-sso-authentication-with-parser-differentials/</a><br /> GitHub Fake Security Alerts<br />  Fake GitHub security alerts are used to trick package maintainers into adding OAUTH privileges to malicious apps.<br /><a href="https://www.bleepingcomputer.com/news/security/fake-security-alert-issues-on-github-use-oauth-app-to-hijack-accounts/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/fake-security-alert-issues-on-github-use-oauth-app-to-hijack-accounts/</a><br />]]></itunes:summary><itunes:duration>399</itunes:duration><itunes:keywords>actions,business,computer,cyber,cybersecurity,daily,draytek,github,hacking,infosec,internet,it,mirai,network,news,oauth,phishing,ruby,saml,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9366</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast: File Hashes in MSFT BI; Apache Camel Vuln; Juniper Fixes Exploited Vuln; AMI Patches 10.0 Redfish BMC Vuln</title><link>https://www.spreaker.com/episode/sans-stormcast-file-hashes-in-msft-bi-apache-camel-vuln-juniper-fixes-exploited-vuln-ami-patches-10-0-redfish-bmc-vuln--64874598</link><description><![CDATA[<br /> File Hashes Analysis with Power BI<br />  Guy explains in this diary how to analyze Cowrie honeypot file hashes using Microsoft's BI tool and what you may be able to discover using this tool.<br /><a href="https://isc.sans.edu/diary/File%20Hashes%20Analysis%20with%20Power%20BI%20from%20Data%20Stored%20in%20DShield%20SIEM/31764" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/File%20Hashes%20Analysis%20with%20Power%20BI%20from%20Data%20Stored%20in%20DShield%20SIEM/31764</a><br /> Apache Camel Vulnerability<br />  Apache released two patches for Camel in close succession. Initially, the vulnerability was only addressed for headers, but as Akamai discovered, it can also be exploited via query parameters. This vulnerability is trivial to exploit and leads to arbitrary code execution.<br /><a href="https://www.akamai.com/blog/security-research/march-apache-camel-vulnerability-detections-and-mitigations" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/march-apache-camel-vulnerability-detections-and-mitigations</a><br /> Juniper Patches Junos Vulnerability<br />  Juniper patches an already exploited vulnerability in JunOS. However, to exploit the vulnerability, and attacker already needs privileged access. By exploiting the vulnerability, an attacker may completely compromised the device.<br /><a href="https://supportportal.juniper.net/s/article/2025-03-Out-of-Cycle-Security-Bulletin-Junos-OS-A-local-attacker-with-shell-access-can-execute-arbitrary-code-CVE-2025-21590?language=en_US" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/article/2025-03-Out-of-Cycle-Security-Bulletin-Junos-OS-A-local-attacker-with-shell-access-can-execute-arbitrary-code-CVE-2025-21590?language=en_US</a><br /> AMI Security Advisory<br />  AMI patched three vulnerabilities. One of the, an authentication bypass in Redfish, allows for a complete system compromise without authentication and is rated with a CVSS score of 10.0.<br /><a href="https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025003.pdf" target="_blank" rel="noreferrer noopener">https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025003.pdf</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9364.mp3</guid><pubDate>Fri, 14 Mar 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64874598/9364.mp3" length="5417198" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9364" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 File Hashes Analysis with Power BI
  Guy explains in this diary how to analyze Cowrie honeypot file hashes using Microsoft's BI tool and what you may be able to discover using this tool....</itunes:subtitle><itunes:summary><![CDATA[<br /> File Hashes Analysis with Power BI<br />  Guy explains in this diary how to analyze Cowrie honeypot file hashes using Microsoft's BI tool and what you may be able to discover using this tool.<br /><a href="https://isc.sans.edu/diary/File%20Hashes%20Analysis%20with%20Power%20BI%20from%20Data%20Stored%20in%20DShield%20SIEM/31764" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/File%20Hashes%20Analysis%20with%20Power%20BI%20from%20Data%20Stored%20in%20DShield%20SIEM/31764</a><br /> Apache Camel Vulnerability<br />  Apache released two patches for Camel in close succession. Initially, the vulnerability was only addressed for headers, but as Akamai discovered, it can also be exploited via query parameters. This vulnerability is trivial to exploit and leads to arbitrary code execution.<br /><a href="https://www.akamai.com/blog/security-research/march-apache-camel-vulnerability-detections-and-mitigations" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/march-apache-camel-vulnerability-detections-and-mitigations</a><br /> Juniper Patches Junos Vulnerability<br />  Juniper patches an already exploited vulnerability in JunOS. However, to exploit the vulnerability, and attacker already needs privileged access. By exploiting the vulnerability, an attacker may completely compromised the device.<br /><a href="https://supportportal.juniper.net/s/article/2025-03-Out-of-Cycle-Security-Bulletin-Junos-OS-A-local-attacker-with-shell-access-can-execute-arbitrary-code-CVE-2025-21590?language=en_US" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/article/2025-03-Out-of-Cycle-Security-Bulletin-Junos-OS-A-local-attacker-with-shell-access-can-execute-arbitrary-code-CVE-2025-21590?language=en_US</a><br /> AMI Security Advisory<br />  AMI patched three vulnerabilities. One of the, an authentication bypass in Redfish, allows for a complete system compromise without authentication and is rated with a CVSS score of 10.0.<br /><a href="https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025003.pdf" target="_blank" rel="noreferrer noopener">https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025003.pdf</a><br />]]></itunes:summary><itunes:duration>368</itunes:duration><itunes:keywords>ami,apache,bios,business,camel,cowrie,cyber,cybersecurity,daily,hacking,honeypot,infosec,it,juniper,junos,network,news,power bi,redfish,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9364</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday Mar 13th: Exploiting Login Pages with Log4j; Patch Tuesday Fallout; Adobe Patches; Medusa Ransomware; Zoom and Font</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-mar-13th-exploiting-login-pages-with-log4j-patch-tuesday-fallout-adobe-patches-medusa-ransomware-zoom-and-font--64854567</link><description><![CDATA[<br /> Log4J Scans for VMWare Hyhbrid Cloud Extensions<br />  An attacker is scanning various login pages, including the authentication feature in the VMWare HCX REST API for Log4j vulnerabilities. The attack submits the exploit string as username, hoping to trigger the vulnerability as Log4j logs the username<br /><a href="https://isc.sans.edu/diary/Scans%20for%20VMWare%20Hybrid%20Cloud%20Extension%20%28HCX%29%20API%20(Log4j%20-%20not%20brute%20forcing)/31762" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20VMWare%20Hybrid%20Cloud%20Extension%20%28HCX%29%20API%20(Log4j%20-%20not%20brute%20forcing)/31762</a><br /> Patch Tuesday Fallout<br />  Yesterday's Apple patch may re-activate Apple Intelligence for users who earlier disabled it. Microsoft is offering support for users whos USB printers started printing giberish after a January patch was applies.<br /><a href="https://www.macrumors.com/2025/03/11/ios-18-3-2-apple-intelligence-auto-on/" target="_blank" rel="noreferrer noopener">https://www.macrumors.com/2025/03/11/ios-18-3-2-apple-intelligence-auto-on/</a><br /><a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-22h2#usb-printers-might-print-random-text-with-the-january-2025-preview-update" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-22h2#usb-printers-might-print-random-text-with-the-january-2025-preview-update</a><br /> Adobe Updates<br />  Adobe updated seven different products, including Adobe Acrobat. The Acrobat vulnerability may lead to remote code execution and Adobe considers the vulnerablities critical.<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> Medusa Ransomware<br />  CISA and partner agencies released details about the Medusa Ransomware. The document includes many details useful to defenders.<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a</a><br /> Zoom Update<br />  Zoom released a critical update fixing a number of remote code execution vulnerabilities.<br /><a href="https://www.zoom.com/en/trust/security-bulletin/" target="_blank" rel="noreferrer noopener">https://www.zoom.com/en/trust/security-bulletin/</a><br /> FreeType Library Vulnerability<br /><a href="https://www.facebook.com/security/advisories/cve-2025-27363" target="_blank" rel="noreferrer noopener">https://www.facebook.com/security/advisories/cve-2025-27363</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9362.mp3</guid><pubDate>Thu, 13 Mar 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64854567/9362.mp3" length="5266271" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9362" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Log4J Scans for VMWare Hyhbrid Cloud Extensions
  An attacker is scanning various login pages, including the authentication feature in the VMWare HCX REST API for Log4j vulnerabilities. The attack submits the exploit string as username, hoping to...</itunes:subtitle><itunes:summary><![CDATA[<br /> Log4J Scans for VMWare Hyhbrid Cloud Extensions<br />  An attacker is scanning various login pages, including the authentication feature in the VMWare HCX REST API for Log4j vulnerabilities. The attack submits the exploit string as username, hoping to trigger the vulnerability as Log4j logs the username<br /><a href="https://isc.sans.edu/diary/Scans%20for%20VMWare%20Hybrid%20Cloud%20Extension%20%28HCX%29%20API%20(Log4j%20-%20not%20brute%20forcing)/31762" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20VMWare%20Hybrid%20Cloud%20Extension%20%28HCX%29%20API%20(Log4j%20-%20not%20brute%20forcing)/31762</a><br /> Patch Tuesday Fallout<br />  Yesterday's Apple patch may re-activate Apple Intelligence for users who earlier disabled it. Microsoft is offering support for users whos USB printers started printing giberish after a January patch was applies.<br /><a href="https://www.macrumors.com/2025/03/11/ios-18-3-2-apple-intelligence-auto-on/" target="_blank" rel="noreferrer noopener">https://www.macrumors.com/2025/03/11/ios-18-3-2-apple-intelligence-auto-on/</a><br /><a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-22h2#usb-printers-might-print-random-text-with-the-january-2025-preview-update" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-22h2#usb-printers-might-print-random-text-with-the-january-2025-preview-update</a><br /> Adobe Updates<br />  Adobe updated seven different products, including Adobe Acrobat. The Acrobat vulnerability may lead to remote code execution and Adobe considers the vulnerablities critical.<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> Medusa Ransomware<br />  CISA and partner agencies released details about the Medusa Ransomware. The document includes many details useful to defenders.<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a</a><br /> Zoom Update<br />  Zoom released a critical update fixing a number of remote code execution vulnerabilities.<br /><a href="https://www.zoom.com/en/trust/security-bulletin/" target="_blank" rel="noreferrer noopener">https://www.zoom.com/en/trust/security-bulletin/</a><br /> FreeType Library Vulnerability<br /><a href="https://www.facebook.com/security/advisories/cve-2025-27363" target="_blank" rel="noreferrer noopener">https://www.facebook.com/security/advisories/cve-2025-27363</a><br />]]></itunes:summary><itunes:duration>357</itunes:duration><itunes:keywords>adobe,business,computer,cyber,cybersecurity,daily,freetype,hacking,infosec,internet,it,medusa,network,news,patch tuesday,ransomware,security,zoom</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9362</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday Mar 12th: Microsoft Patch Tuesday; Apple Patch; Espressif ESP32 Statement</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-mar-12th-microsoft-patch-tuesday-apple-patch-espressif-esp32-statement--64826091</link><description><![CDATA[<br /> Microsoft Patch Tuesday<br />  Microsoft Patched six already exploited vulnerabilities today. In addition, the patches included a critical patch for Microsoft's DNS server and about 50 additional patches.<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%3A%20March%202025/31756" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%3A%20March%202025/31756</a><br /> Apple Updates iOS/macOS<br />  Apple released an update to address a single, already exploited, vulnerability in WebKit. This vulnerability affects iOS, macOS and VisionOS.<br /><a href="https://support.apple.com/en-us/100100" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/100100</a><br /> Expressif Response to ESP32 Debug Commands<br />  Expressif released a statement commenting on the recent release of a paper alledging "Backdoors" in ESP32 chipsets. According to Expressif, these commands are debug commands and not reachable directly via Bluetooth.<br /><a href="https://www.espressif.com/en/news/Response_ESP32_Bluetooth" target="_blank" rel="noreferrer noopener">https://www.espressif.com/en/news/Response_ESP32_Bluetooth</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9360.mp3</guid><pubDate>Wed, 12 Mar 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64826091/9360.mp3" length="6911147" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9360" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Microsoft Patch Tuesday
  Microsoft Patched six already exploited vulnerabilities today. In addition, the patches included a critical patch for Microsoft's DNS server and about 50 additional patches....</itunes:subtitle><itunes:summary><![CDATA[<br /> Microsoft Patch Tuesday<br />  Microsoft Patched six already exploited vulnerabilities today. In addition, the patches included a critical patch for Microsoft's DNS server and about 50 additional patches.<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%3A%20March%202025/31756" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%3A%20March%202025/31756</a><br /> Apple Updates iOS/macOS<br />  Apple released an update to address a single, already exploited, vulnerability in WebKit. This vulnerability affects iOS, macOS and VisionOS.<br /><a href="https://support.apple.com/en-us/100100" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/100100</a><br /> Expressif Response to ESP32 Debug Commands<br />  Expressif released a statement commenting on the recent release of a paper alledging "Backdoors" in ESP32 chipsets. According to Expressif, these commands are debug commands and not reachable directly via Bluetooth.<br /><a href="https://www.espressif.com/en/news/Response_ESP32_Bluetooth" target="_blank" rel="noreferrer noopener">https://www.espressif.com/en/news/Response_ESP32_Bluetooth</a><br />]]></itunes:summary><itunes:duration>475</itunes:duration><itunes:keywords>apple,business,computer,cyber,cybersecurity,daily,esp32,expressif,hacking,infosec,internet,it,microsoft,network,news,patches,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9360</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday Mar 11th: Shellcode as UUIDs; Moxe Switch Vuln Updates; Opentext Vuln; Livewire Volt Vuln;</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-mar-11th-shellcode-as-uuids-moxe-switch-vuln-updates-opentext-vuln-livewire-volt-vuln--64801625</link><description><![CDATA[<br /> Shellcode Encoded in UUIDs<br />  Attackers are using UUIDs to encode Shellcode. The 128 Bit (or 16 Bytes) encoded in each UUID are converted to shell code to implement a cobalt strike beacon<br /><a href="https://isc.sans.edu/diary/Shellcode%20Encoded%20in%20UUIDs/31752" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Shellcode%20Encoded%20in%20UUIDs/31752</a><br /> Moxa CVE-2024-12297 Expanded to PT Switches<br />  Moxa in January first releast an update to address a fronted authorizaation logic disclosure vulnerability. It now updated the advisory and included the PT series switches as vulenrable.<br /><a href="https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241408-cve-2024-12297-frontend-authorization-logic-disclosure-vulnerability-identified-in-pt-switches" target="_blank" rel="noreferrer noopener">https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241408-cve-2024-12297-frontend-authorization-logic-disclosure-vulnerability-identified-in-pt-switches</a><br /> Opentext Insufficently Protected Credentials<br /><a href="https://portal.microfocus.com/s/article/KM000037455?language=en_US" target="_blank" rel="noreferrer noopener">https://portal.microfocus.com/s/article/KM000037455?language=en_US</a><br /> Livewire Volt API vulnerability<br /><a href="https://github.com/livewire/volt/security/advisories/GHSA-v69f-5jxm-hwvv" target="_blank" rel="noreferrer noopener">https://github.com/livewire/volt/security/advisories/GHSA-v69f-5jxm-hwvv</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9358.mp3</guid><pubDate>Tue, 11 Mar 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64801625/9358.mp3" length="4460276" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9358" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Shellcode Encoded in UUIDs
  Attackers are using UUIDs to encode Shellcode. The 128 Bit (or 16 Bytes) encoded in each UUID are converted to shell code to implement a cobalt strike beacon...</itunes:subtitle><itunes:summary><![CDATA[<br /> Shellcode Encoded in UUIDs<br />  Attackers are using UUIDs to encode Shellcode. The 128 Bit (or 16 Bytes) encoded in each UUID are converted to shell code to implement a cobalt strike beacon<br /><a href="https://isc.sans.edu/diary/Shellcode%20Encoded%20in%20UUIDs/31752" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Shellcode%20Encoded%20in%20UUIDs/31752</a><br /> Moxa CVE-2024-12297 Expanded to PT Switches<br />  Moxa in January first releast an update to address a fronted authorizaation logic disclosure vulnerability. It now updated the advisory and included the PT series switches as vulenrable.<br /><a href="https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241408-cve-2024-12297-frontend-authorization-logic-disclosure-vulnerability-identified-in-pt-switches" target="_blank" rel="noreferrer noopener">https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241408-cve-2024-12297-frontend-authorization-logic-disclosure-vulnerability-identified-in-pt-switches</a><br /> Opentext Insufficently Protected Credentials<br /><a href="https://portal.microfocus.com/s/article/KM000037455?language=en_US" target="_blank" rel="noreferrer noopener">https://portal.microfocus.com/s/article/KM000037455?language=en_US</a><br /> Livewire Volt API vulnerability<br /><a href="https://github.com/livewire/volt/security/advisories/GHSA-v69f-5jxm-hwvv" target="_blank" rel="noreferrer noopener">https://github.com/livewire/volt/security/advisories/GHSA-v69f-5jxm-hwvv</a><br />]]></itunes:summary><itunes:duration>299</itunes:duration><itunes:keywords>api,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,livewire,moxa,network,news,opentest,pt,security,shellcode uuid,switches,volt</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9358</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast: Webshells; Undocumented ESP32 Commands; Camera Used For Ransomware Distribution</title><link>https://www.spreaker.com/episode/sans-stormcast-webshells-undocumented-esp32-commands-camera-used-for-ransomware-distribution--64782660</link><description><![CDATA[<br /> Commonly Probed Webshell URLs<br />  Many attackers deploy web shells to gain a foothold on vulnerable web servers. These webshells can also be taken over by parasitic exploits.<br /><a href="https://isc.sans.edu/diary/Commonly%20Probed%20Webshell%20URLs/31748" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Commonly%20Probed%20Webshell%20URLs/31748</a><br /> Undocumented ESP32 Commands<br />  A recent conference presentation by Tarlogic revealed several "backdoors" or undocumented features in the commonly used ESP32 Chipsets. Tarlogic also released a toolkit to make it easier to audit chipsets and find these hiddent commands.<br /><a href="https://www.tarlogic.com/news/backdoor-esp32-chip-infect-ot-devices/" target="_blank" rel="noreferrer noopener">https://www.tarlogic.com/news/backdoor-esp32-chip-infect-ot-devices/</a><br /> Camera Off: Akira deploys ransomware via Webcam<br />  The Akira ransomware group was recently observed infecting a network with Ransomware by taking advantage of a webcam.<br /><a href="https://www.s-rminform.com/latest-thinking/camera-off-akira-deploys-ransomware-via-webcam" target="_blank" rel="noreferrer noopener">https://www.s-rminform.com/latest-thinking/camera-off-akira-deploys-ransomware-via-webcam</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9356.mp3</guid><pubDate>Mon, 10 Mar 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64782660/9356.mp3" length="5940271" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9356" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Commonly Probed Webshell URLs
  Many attackers deploy web shells to gain a foothold on vulnerable web servers. These webshells can also be taken over by parasitic exploits.
https://isc.sans.edu/diary/Commonly%20Probed%20Webshell%20URLs/31748...</itunes:subtitle><itunes:summary><![CDATA[<br /> Commonly Probed Webshell URLs<br />  Many attackers deploy web shells to gain a foothold on vulnerable web servers. These webshells can also be taken over by parasitic exploits.<br /><a href="https://isc.sans.edu/diary/Commonly%20Probed%20Webshell%20URLs/31748" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Commonly%20Probed%20Webshell%20URLs/31748</a><br /> Undocumented ESP32 Commands<br />  A recent conference presentation by Tarlogic revealed several "backdoors" or undocumented features in the commonly used ESP32 Chipsets. Tarlogic also released a toolkit to make it easier to audit chipsets and find these hiddent commands.<br /><a href="https://www.tarlogic.com/news/backdoor-esp32-chip-infect-ot-devices/" target="_blank" rel="noreferrer noopener">https://www.tarlogic.com/news/backdoor-esp32-chip-infect-ot-devices/</a><br /> Camera Off: Akira deploys ransomware via Webcam<br />  The Akira ransomware group was recently observed infecting a network with Ransomware by taking advantage of a webcam.<br /><a href="https://www.s-rminform.com/latest-thinking/camera-off-akira-deploys-ransomware-via-webcam" target="_blank" rel="noreferrer noopener">https://www.s-rminform.com/latest-thinking/camera-off-akira-deploys-ransomware-via-webcam</a><br />]]></itunes:summary><itunes:duration>405</itunes:duration><itunes:keywords>akira,business,computer,cyber,cybersecurity,daily,esp32,expressif,hacking,infosec,internet,it,network,news,security,webcam,webshell</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9356</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday Mar 7th: Chrome vs Extensions; Kibana Update; PrePw0n3d Android TV Sticks; Identifying APTs (@sans_edu, Eric LeBlanc)</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-mar-7th-chrome-vs-extensions-kibana-update-prepw0n3d-android-tv-sticks-identifying-apts-sans-edu-eric-leblanc--64742390</link><description><![CDATA[<br /> Latest Google Chrome Update Encourages UBlock Origin Removal<br />  The latest update to Google Chrome not only disabled the UBlock Origin ad blocker, but also guides users to uninstall the extension instead of re-enabling it.<br /><a href="https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop.html</a><br /><a href="https://www.reddit.com/r/youtube/comments/1j2ec76/ublock_origin_is_gone/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/youtube/comments/1j2ec76/ublock_origin_is_gone/</a><br /> Critical Kibana Update<br />  Elastic published a critical Kibana update patching a prototype polution vulnerability that would allow arbitrary code execution for users with the "Viewer" role.<br /><a href="https://discuss.elastic.co/t/kibana-8-17-3-security-update-esa-2025-06/375441" target="_blank" rel="noreferrer noopener">https://discuss.elastic.co/t/kibana-8-17-3-security-update-esa-2025-06/375441</a><br /> Certified PrePw0n3d Android TV Sticks<br />  Wired is reporting of over a million Android TV sticks that were found to be pre-infected with adware<br /><a href="https://www.wired.com/story/android-tv-streaming-boxes-china-backdoor/" target="_blank" rel="noreferrer noopener">https://www.wired.com/story/android-tv-streaming-boxes-china-backdoor/</a><br /> SANS.edu Research Paper<br />  Advanced Persistent Threats (APTs) are among the most challenging to detect in enterprise environments, often mimicking authorized privileged access prior to their actions on objectives.<br /><a href="https://www.sans.edu/cyber-research/identifying-advanced-persistent-threat-activity-through-threat-informed-detection-engineering-enhancing-alert-visibility-enterprises/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/identifying-advanced-persistent-threat-activity-through-threat-informed-detection-engineering-enhancing-alert-visibility-enterprises/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9354.mp3</guid><pubDate>Fri, 07 Mar 2025 02:45:24 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64742390/9354.mp3" length="11936179" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9354" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Latest Google Chrome Update Encourages UBlock Origin Removal
  The latest update to Google Chrome not only disabled the UBlock Origin ad blocker, but also guides users to uninstall the extension instead of re-enabling it....</itunes:subtitle><itunes:summary><![CDATA[<br /> Latest Google Chrome Update Encourages UBlock Origin Removal<br />  The latest update to Google Chrome not only disabled the UBlock Origin ad blocker, but also guides users to uninstall the extension instead of re-enabling it.<br /><a href="https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop.html</a><br /><a href="https://www.reddit.com/r/youtube/comments/1j2ec76/ublock_origin_is_gone/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/youtube/comments/1j2ec76/ublock_origin_is_gone/</a><br /> Critical Kibana Update<br />  Elastic published a critical Kibana update patching a prototype polution vulnerability that would allow arbitrary code execution for users with the "Viewer" role.<br /><a href="https://discuss.elastic.co/t/kibana-8-17-3-security-update-esa-2025-06/375441" target="_blank" rel="noreferrer noopener">https://discuss.elastic.co/t/kibana-8-17-3-security-update-esa-2025-06/375441</a><br /> Certified PrePw0n3d Android TV Sticks<br />  Wired is reporting of over a million Android TV sticks that were found to be pre-infected with adware<br /><a href="https://www.wired.com/story/android-tv-streaming-boxes-china-backdoor/" target="_blank" rel="noreferrer noopener">https://www.wired.com/story/android-tv-streaming-boxes-china-backdoor/</a><br /> SANS.edu Research Paper<br />  Advanced Persistent Threats (APTs) are among the most challenging to detect in enterprise environments, often mimicking authorized privileged access prior to their actions on objectives.<br /><a href="https://www.sans.edu/cyber-research/identifying-advanced-persistent-threat-activity-through-threat-informed-detection-engineering-enhancing-alert-visibility-enterprises/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/identifying-advanced-persistent-threat-activity-through-threat-informed-detection-engineering-enhancing-alert-visibility-enterprises/</a><br />]]></itunes:summary><itunes:duration>833</itunes:duration><itunes:keywords>android,apt,business,chrome,cyber,cybersecurity,daily,elastic,extensions,hacking,infosec,it,kibana,network,news,origin,research,sans.edu,security,ublock</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9354</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday Mar 6th: DShield ELK Analysis; Jailbreaking AMD CPUs; VIM Vulnerability; Snail Mail Ransomware</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-mar-6th-dshield-elk-analysis-jailbreaking-amd-cpus-vim-vulnerability-snail-mail-ransomware--64723552</link><description><![CDATA[<br /> DShield Traffic Analysis using ELK<br />  The "DShield SIEM" includes an ELK dashboard as part of the Honeypot. Learn how to find traffic of interest with this tool.<br /><a href="https://isc.sans.edu/diary/DShield%20Traffic%20Analysis%20using%20ELK/31742" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/DShield%20Traffic%20Analysis%20using%20ELK/31742</a><br /> Zen and the Art of Microcode Hacking<br />  Google released details, including a proof of concept exploit, showing how to take advantage of the recently patched AMD microcode vulnerability<br /><a href="https://bughunters.google.com/blog/5424842357473280/zen-and-the-art-of-microcode-hacking" target="_blank" rel="noreferrer noopener">https://bughunters.google.com/blog/5424842357473280/zen-and-the-art-of-microcode-hacking</a> CVE-2024-56161<br /> VIM Vulnerability<br />  An attacker may execute arbitrary code by tricking a user to open a crafted tar file in VIM<br /><a href="https://github.com/vim/vim/security/advisories/GHSA-wfmf-8626-q3r3" target="_blank" rel="noreferrer noopener">https://github.com/vim/vim/security/advisories/GHSA-wfmf-8626-q3r3</a><br /> Snil Mail Fake Ransom Note<br />  A copy cat group is impersonating ransomware actors. The group sends snail mail to company executives claiming to have stolen company data and threatening to leak it unless a payment is made.<br /><a href="https://www.guidepointsecurity.com/blog/snail-mail-fail-fake-ransom-note-campaign-preys-on-fear/" target="_blank" rel="noreferrer noopener">https://www.guidepointsecurity.com/blog/snail-mail-fail-fake-ransom-note-campaign-preys-on-fear/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9352.mp3</guid><pubDate>Thu, 06 Mar 2025 02:45:34 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64723552/9352.mp3" length="5939797" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9352" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 DShield Traffic Analysis using ELK
  The "DShield SIEM" includes an ELK dashboard as part of the Honeypot. Learn how to find traffic of interest with this tool.
https://isc.sans.edu/diary/DShield%20Traffic%20Analysis%20using%20ELK/31742
 Zen and the...</itunes:subtitle><itunes:summary><![CDATA[<br /> DShield Traffic Analysis using ELK<br />  The "DShield SIEM" includes an ELK dashboard as part of the Honeypot. Learn how to find traffic of interest with this tool.<br /><a href="https://isc.sans.edu/diary/DShield%20Traffic%20Analysis%20using%20ELK/31742" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/DShield%20Traffic%20Analysis%20using%20ELK/31742</a><br /> Zen and the Art of Microcode Hacking<br />  Google released details, including a proof of concept exploit, showing how to take advantage of the recently patched AMD microcode vulnerability<br /><a href="https://bughunters.google.com/blog/5424842357473280/zen-and-the-art-of-microcode-hacking" target="_blank" rel="noreferrer noopener">https://bughunters.google.com/blog/5424842357473280/zen-and-the-art-of-microcode-hacking</a> CVE-2024-56161<br /> VIM Vulnerability<br />  An attacker may execute arbitrary code by tricking a user to open a crafted tar file in VIM<br /><a href="https://github.com/vim/vim/security/advisories/GHSA-wfmf-8626-q3r3" target="_blank" rel="noreferrer noopener">https://github.com/vim/vim/security/advisories/GHSA-wfmf-8626-q3r3</a><br /> Snil Mail Fake Ransom Note<br />  A copy cat group is impersonating ransomware actors. The group sends snail mail to company executives claiming to have stolen company data and threatening to leak it unless a payment is made.<br /><a href="https://www.guidepointsecurity.com/blog/snail-mail-fail-fake-ransom-note-campaign-preys-on-fear/" target="_blank" rel="noreferrer noopener">https://www.guidepointsecurity.com/blog/snail-mail-fail-fake-ransom-note-campaign-preys-on-fear/</a><br />]]></itunes:summary><itunes:duration>405</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dshield,elk,hacking,infosec,internet,it,microcode,network,news,ransomware,security,snail mail,vim,zen</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9352</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday Mar 5th: SMTP Credential Hunt; mac-robber.py update; ADSelfService Plus Account Takeover; Android Patch Day; PayPal</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-mar-5th-smtp-credential-hunt-mac-robber-py-update-adselfservice-plus-account-takeover-android-patch-day-paypal--64706252</link><description><![CDATA[<br /> Romanian Distillery Scanning for SMTP Credentials<br />  A particular attacker expanded the scope of their leaked credential file scans. In addition to the usual ".env" style files, it is not looking for specific SMTP related credential files.<br /><a href="https://isc.sans.edu/diary/Romanian%20Distillery%20Scanning%20for%20SMTP%20Credentials/31736" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Romanian%20Distillery%20Scanning%20for%20SMTP%20Credentials/31736</a><br /> Tool Updates: mac-robber.py<br />  This update of mac-robber.py fixes issues with symlinks.<br /><a href="https://isc.sans.edu/diary/Tool%20update%3A%20mac-robber.py/31738" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Tool%20update%3A%20mac-robber.py/31738</a><br /> CVE-2025-1723   Account takeover vulnerability in ADSelfService Plus<br />  CVE-2025-1723 describes a vulnerability caused by session mishandling in ADSelfService Plus that could allow unauthorized access to user enrollment data when MFA was not enabled for ADSelfService Plus login.<br /><a href="https://www.manageengine.com/products/self-service-password/advisory/CVE-2025-1723.html" target="_blank" rel="noreferrer noopener">https://www.manageengine.com/products/self-service-password/advisory/CVE-2025-1723.html</a><br /> Android March Update<br />  Google released an update for Android addressing two already exploited vulnerabilities and several critical issues.<br /><a href="https://source.android.com/docs/security/bulletin/2025-03-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2025-03-01</a><br /> PayPal's no-code-checkout Abuse<br />  Attackers are using PayPal's no-code-checkout feature is being abused by scammers to host PayPal tech support scam pages right within the PayPal.com domain.<br /><a href="https://www.malwarebytes.com/blog/scams/2025/02/paypals-no-code-checkout-abused-by-scammers" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/scams/2025/02/paypals-no-code-checkout-abused-by-scammers</a><br /> Broadcom Fixes three VMWare VCenter Vulnerabilities<br /><a href="https://github.com/vmware/vcf-security-and-compliance-guidelines/tree/main/security-advisories/vmsa-2025-0004" target="_blank" rel="noreferrer noopener">https://github.com/vmware/vcf-security-and-compliance-guidelines/tree/main/security-advisories/vmsa-2025-0004</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9350.mp3</guid><pubDate>Wed, 05 Mar 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64706252/9350.mp3" length="5473415" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9350" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Romanian Distillery Scanning for SMTP Credentials
  A particular attacker expanded the scope of their leaked credential file scans. In addition to the usual ".env" style files, it is not looking for specific SMTP related credential files....</itunes:subtitle><itunes:summary><![CDATA[<br /> Romanian Distillery Scanning for SMTP Credentials<br />  A particular attacker expanded the scope of their leaked credential file scans. In addition to the usual ".env" style files, it is not looking for specific SMTP related credential files.<br /><a href="https://isc.sans.edu/diary/Romanian%20Distillery%20Scanning%20for%20SMTP%20Credentials/31736" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Romanian%20Distillery%20Scanning%20for%20SMTP%20Credentials/31736</a><br /> Tool Updates: mac-robber.py<br />  This update of mac-robber.py fixes issues with symlinks.<br /><a href="https://isc.sans.edu/diary/Tool%20update%3A%20mac-robber.py/31738" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Tool%20update%3A%20mac-robber.py/31738</a><br /> CVE-2025-1723   Account takeover vulnerability in ADSelfService Plus<br />  CVE-2025-1723 describes a vulnerability caused by session mishandling in ADSelfService Plus that could allow unauthorized access to user enrollment data when MFA was not enabled for ADSelfService Plus login.<br /><a href="https://www.manageengine.com/products/self-service-password/advisory/CVE-2025-1723.html" target="_blank" rel="noreferrer noopener">https://www.manageengine.com/products/self-service-password/advisory/CVE-2025-1723.html</a><br /> Android March Update<br />  Google released an update for Android addressing two already exploited vulnerabilities and several critical issues.<br /><a href="https://source.android.com/docs/security/bulletin/2025-03-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2025-03-01</a><br /> PayPal's no-code-checkout Abuse<br />  Attackers are using PayPal's no-code-checkout feature is being abused by scammers to host PayPal tech support scam pages right within the PayPal.com domain.<br /><a href="https://www.malwarebytes.com/blog/scams/2025/02/paypals-no-code-checkout-abused-by-scammers" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/scams/2025/02/paypals-no-code-checkout-abused-by-scammers</a><br /> Broadcom Fixes three VMWare VCenter Vulnerabilities<br /><a href="https://github.com/vmware/vcf-security-and-compliance-guidelines/tree/main/security-advisories/vmsa-2025-0004" target="_blank" rel="noreferrer noopener">https://github.com/vmware/vcf-security-and-compliance-guidelines/tree/main/security-advisories/vmsa-2025-0004</a><br />]]></itunes:summary><itunes:duration>372</itunes:duration><itunes:keywords>adselfservice,android,broadcom,business,credentials,cyber,cybersecurity,daily,hacking,infosec,it,jennsen,json,mac-robber,network,news,paypal,smtp,vmware,zoho</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9350</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday Mar 4th: Mark of the Web Details; Sharepint and Click-Fix Phishing; Paragon Partionmanager BYOVD Exploit</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-mar-4th-mark-of-the-web-details-sharepint-and-click-fix-phishing-paragon-partionmanager-byovd-exploit--64685042</link><description><![CDATA[<br /> Mark of the Web: Some Technical Details<br />  Windows implements the "Mark of the Web" (MotW) as an alternate data stream that contains not just the "zoneid" of where the file came from, but may include other data like the exact URL and referrer. <br /><a href="https://isc.sans.edu/diary/Mark%20of%20the%20Web%3A%20Some%20Technical%20Details/31732" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Mark%20of%20the%20Web%3A%20Some%20Technical%20Details/31732</a><br /> Havoc Sharepoint with Microsoft Graph API<br />  A recent phishing attack observed by Fortinet uses a simple HTML email to trick a user into copy pasting powershell into their system to execute additional code. Most of the malware interaction uses a Sharepoint site via Microsoft's Graph API futher hiding the malicious traffic<br /><a href="https://www.fortinet.com/blog/threat-research/havoc-sharepoint-with-microsoft-graph-api-turns-into-fud-c2" target="_blank" rel="noreferrer noopener">https://www.fortinet.com/blog/threat-research/havoc-sharepoint-with-microsoft-graph-api-turns-into-fud-c2</a><br /> Paragon Partition Manager Exploit<br />  A vulnerable Paragon Partition Manager has been user recently to escalate privileges for ransomware deployment. Even if you to not have PAragon installed: An attacker may just "bring the vulnerable driver" to your system.<br /><a href="https://kb.cert.org/vuls/id/726882" target="_blank" rel="noreferrer noopener">https://kb.cert.org/vuls/id/726882</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9348.mp3</guid><pubDate>Tue, 04 Mar 2025 02:03:34 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64685042/9348.mp3" length="5548019" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9348" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Mark of the Web: Some Technical Details
  Windows implements the "Mark of the Web" (MotW) as an alternate data stream that contains not just the "zoneid" of where the file came from, but may include other data like the exact URL and referrer....</itunes:subtitle><itunes:summary><![CDATA[<br /> Mark of the Web: Some Technical Details<br />  Windows implements the "Mark of the Web" (MotW) as an alternate data stream that contains not just the "zoneid" of where the file came from, but may include other data like the exact URL and referrer. <br /><a href="https://isc.sans.edu/diary/Mark%20of%20the%20Web%3A%20Some%20Technical%20Details/31732" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Mark%20of%20the%20Web%3A%20Some%20Technical%20Details/31732</a><br /> Havoc Sharepoint with Microsoft Graph API<br />  A recent phishing attack observed by Fortinet uses a simple HTML email to trick a user into copy pasting powershell into their system to execute additional code. Most of the malware interaction uses a Sharepoint site via Microsoft's Graph API futher hiding the malicious traffic<br /><a href="https://www.fortinet.com/blog/threat-research/havoc-sharepoint-with-microsoft-graph-api-turns-into-fud-c2" target="_blank" rel="noreferrer noopener">https://www.fortinet.com/blog/threat-research/havoc-sharepoint-with-microsoft-graph-api-turns-into-fud-c2</a><br /> Paragon Partition Manager Exploit<br />  A vulnerable Paragon Partition Manager has been user recently to escalate privileges for ransomware deployment. Even if you to not have PAragon installed: An attacker may just "bring the vulnerable driver" to your system.<br /><a href="https://kb.cert.org/vuls/id/726882" target="_blank" rel="noreferrer noopener">https://kb.cert.org/vuls/id/726882</a><br />]]></itunes:summary><itunes:duration>377</itunes:duration><itunes:keywords>business,clickfix,click-fix,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,manager,motw,network,news,paragon,partition,phishing,security,sharepoint</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9348</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday Mar 3rd: AI Training Data Leaks; MITRE Caldera Vuln; modsecurity bypass</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-mar-3rd-ai-training-data-leaks-mitre-caldera-vuln-modsecurity-bypass--64666555</link><description><![CDATA[<br /> Common Crawl includes Common Leaks<br />  The "Common Crawl" dataset, a large dataset created by spidering website, contains as expected many API keys and other secrets. This data is often used to train large language models<br /><a href="https://trufflesecurity.com/blog/research-finds-12-000-live-api-keys-and-passwords-in-deepseek-s-training-data" target="_blank" rel="noreferrer noopener">https://trufflesecurity.com/blog/research-finds-12-000-live-api-keys-and-passwords-in-deepseek-s-training-data</a><br /> Github Repositories Exposed by Copilot<br />  As it is well known, Github's Copilot is using data from public GitHub repositories to train it's model. However, it appears that repositories who were briefly left open and later made private have been included as well, allowing Copilot users to retrieve files from these repositories.<br /><a href="https://www.lasso.security/blog/lasso-major-vulnerability-in-microsoft-copilot" target="_blank" rel="noreferrer noopener">https://www.lasso.security/blog/lasso-major-vulnerability-in-microsoft-copilot</a><br /> MITRE Caldera Framework Allows Unauthenticated Code Execution<br />  The MITRE Caldera adversary emulation framework allows for unauthenticted code execution by allowing attackers to specify compiler options<br /><a href="https://medium.com/@mitrecaldera/mitre-caldera-security-advisory-remote-code-execution-cve-2025-27364-5f679e2e2a0e" target="_blank" rel="noreferrer noopener">https://medium.com/@mitrecaldera/mitre-caldera-security-advisory-remote-code-execution-cve-2025-27364-5f679e2e2a0e</a><br /> modsecurity Rule Bypass<br />  Attackers may bypass the modsecurity web application firewall by prepending encoded characters with 0.<br /><a href="https://github.com/owasp-modsecurity/ModSecurity/security/advisories/GHSA-42w7-rmv5-4x2j" target="_blank" rel="noreferrer noopener">https://github.com/owasp-modsecurity/ModSecurity/security/advisories/GHSA-42w7-rmv5-4x2j</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9346.mp3</guid><pubDate>Mon, 03 Mar 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64666555/9346.mp3" length="6274486" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9346" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Common Crawl includes Common Leaks
  The "Common Crawl" dataset, a large dataset created by spidering website, contains as expected many API keys and other secrets. This data is often used to train large language models...</itunes:subtitle><itunes:summary><![CDATA[<br /> Common Crawl includes Common Leaks<br />  The "Common Crawl" dataset, a large dataset created by spidering website, contains as expected many API keys and other secrets. This data is often used to train large language models<br /><a href="https://trufflesecurity.com/blog/research-finds-12-000-live-api-keys-and-passwords-in-deepseek-s-training-data" target="_blank" rel="noreferrer noopener">https://trufflesecurity.com/blog/research-finds-12-000-live-api-keys-and-passwords-in-deepseek-s-training-data</a><br /> Github Repositories Exposed by Copilot<br />  As it is well known, Github's Copilot is using data from public GitHub repositories to train it's model. However, it appears that repositories who were briefly left open and later made private have been included as well, allowing Copilot users to retrieve files from these repositories.<br /><a href="https://www.lasso.security/blog/lasso-major-vulnerability-in-microsoft-copilot" target="_blank" rel="noreferrer noopener">https://www.lasso.security/blog/lasso-major-vulnerability-in-microsoft-copilot</a><br /> MITRE Caldera Framework Allows Unauthenticated Code Execution<br />  The MITRE Caldera adversary emulation framework allows for unauthenticted code execution by allowing attackers to specify compiler options<br /><a href="https://medium.com/@mitrecaldera/mitre-caldera-security-advisory-remote-code-execution-cve-2025-27364-5f679e2e2a0e" target="_blank" rel="noreferrer noopener">https://medium.com/@mitrecaldera/mitre-caldera-security-advisory-remote-code-execution-cve-2025-27364-5f679e2e2a0e</a><br /> modsecurity Rule Bypass<br />  Attackers may bypass the modsecurity web application firewall by prepending encoded characters with 0.<br /><a href="https://github.com/owasp-modsecurity/ModSecurity/security/advisories/GHSA-42w7-rmv5-4x2j" target="_blank" rel="noreferrer noopener">https://github.com/owasp-modsecurity/ModSecurity/security/advisories/GHSA-42w7-rmv5-4x2j</a><br />]]></itunes:summary><itunes:duration>429</itunes:duration><itunes:keywords>ai,api keys,business,caldera,common crawl,computer,copilot,cyber,cybersecurity,daily,hacking,infosec,internet,it,mitre,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9346</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday Feb 28th: Njrat devtunnels.ms; Apple FindMe Abuse; XSS Exploited; @sans_edu Ben Powell EDR vs. Ransomware</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-feb-28th-njrat-devtunnels-ms-apple-findme-abuse-xss-exploited-sans-edu-ben-powell-edr-vs-ransomware--64616358</link><description><![CDATA[<br /> Njrat Compaign Using Microsoft dev Tunnels:<br />  A recent version of the Njrat remote admin tool is taking advantage of Microsoft's developer tunnels (devtunnels.ms) as a command and control channel.<br /><a href="https://isc.sans.edu/diary/Njrat%20Campaign%20Using%20Microsoft%20Dev%20Tunnels/31724" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Njrat%20Campaign%20Using%20Microsoft%20Dev%20Tunnels/31724</a><br /> NrootTag Apple FindMy Abuse<br />  Malware could use a weakness in the keys used for Apple FindMy to abuse it to track victims. Updates were released with iOS 18.2, but to solve the issue the vast majority of Apple users must update.<br /><a href="https://nroottag.github.io/" target="_blank" rel="noreferrer noopener">https://nroottag.github.io/</a><br /> 360XSS: Mass Website Exploitation via Virtual Tour Framework<br />  The Krpano VR library which is often used to implement 3D virtual tours on real estate websites, is currently being abused to inject spam messages. The XSS vulnerabilty could allow attackers to inject even more malicious JavaScript.<br /><a href="https://olegzay.com/360xss/" target="_blank" rel="noreferrer noopener">https://olegzay.com/360xss/</a><br /> SANS.edu Research: Proof is in the Pudding: EDR Configuration Versus Ransomware. Benjamin Powell<br /><a href="https://www.sans.edu/cyber-research/proof-pudding-edr-configuration-versus-ransomware/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/proof-pudding-edr-configuration-versus-ransomware/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9344.mp3</guid><pubDate>Fri, 28 Feb 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64616358/9344.mp3" length="12414325" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9344" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Njrat Compaign Using Microsoft dev Tunnels:
  A recent version of the Njrat remote admin tool is taking advantage of Microsoft's developer tunnels (devtunnels.ms) as a command and control channel....</itunes:subtitle><itunes:summary><![CDATA[<br /> Njrat Compaign Using Microsoft dev Tunnels:<br />  A recent version of the Njrat remote admin tool is taking advantage of Microsoft's developer tunnels (devtunnels.ms) as a command and control channel.<br /><a href="https://isc.sans.edu/diary/Njrat%20Campaign%20Using%20Microsoft%20Dev%20Tunnels/31724" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Njrat%20Campaign%20Using%20Microsoft%20Dev%20Tunnels/31724</a><br /> NrootTag Apple FindMy Abuse<br />  Malware could use a weakness in the keys used for Apple FindMy to abuse it to track victims. Updates were released with iOS 18.2, but to solve the issue the vast majority of Apple users must update.<br /><a href="https://nroottag.github.io/" target="_blank" rel="noreferrer noopener">https://nroottag.github.io/</a><br /> 360XSS: Mass Website Exploitation via Virtual Tour Framework<br />  The Krpano VR library which is often used to implement 3D virtual tours on real estate websites, is currently being abused to inject spam messages. The XSS vulnerabilty could allow attackers to inject even more malicious JavaScript.<br /><a href="https://olegzay.com/360xss/" target="_blank" rel="noreferrer noopener">https://olegzay.com/360xss/</a><br /> SANS.edu Research: Proof is in the Pudding: EDR Configuration Versus Ransomware. Benjamin Powell<br /><a href="https://www.sans.edu/cyber-research/proof-pudding-edr-configuration-versus-ransomware/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/proof-pudding-edr-configuration-versus-ransomware/</a><br />]]></itunes:summary><itunes:duration>868</itunes:duration><itunes:keywords>360,ben power,business,cyber,cybersecurity,daily,devtunnels,findmy,hacking,infosec,ios,it,krpano,microsoft,network,news,njrat,sans.edu,vr,xss</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9344</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Thursday Feb 27th: High Exfil Ports; Malicious VS Code Theme; Developer Workstation Safety; NAKIVO PoC; OpenH264 and rsync vu</title><link>https://www.spreaker.com/episode/sans-stormcast-thursday-feb-27th-high-exfil-ports-malicious-vs-code-theme-developer-workstation-safety-nakivo-poc-openh264-and-rsync-vu--64596831</link><description><![CDATA[<br /> Attacker of of Ephemeral Ports<br />  Attackers often use ephermeral ports to reach out to download additional resources or exfiltrate data. This can be used, with care, to detect possible compromises.<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Malware%20Source%20Servers%3A%20The%20Threat%20of%20Attackers%20Using%20Ephemeral%20Ports%20as%20Service%20Ports%20to%20Upload%20Data/31710" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Malware%20Source%20Servers%3A%20The%20Threat%20of%20Attackers%20Using%20Ephemeral%20Ports%20as%20Service%20Ports%20to%20Upload%20Data/31710</a><br /> Compromised Visal Studio Code Extension downloaded by Millions<br />  Amit Assaraf identified a likely compromised Visual Studio Code theme that was installed by millions of potential victims. Amit did not disclose the exact malicious behaviour, but is asking for victims to contact them for details.<br /><a href="https://medium.com/@amitassaraf/a-wolf-in-dark-mode-the-malicious-vs-code-theme-that-fooled-millions-85ed92b4bd26" target="_blank" rel="noreferrer noopener">https://medium.com/@amitassaraf/a-wolf-in-dark-mode-the-malicious-vs-code-theme-that-fooled-millions-85ed92b4bd26</a> <br /> ByBit Theft Due to Compromised Developer Workstation<br />  ByBit and Safe{Wallet} disclosed that the record breaking ethereum theft was due to a compromised Safe{Wallet} developer workstation. A replaced JavaScript file targeted ByBit and altered a transaction signed by ByBit.<br /><a href="https://x.com/benbybit/status/1894768736084885929" target="_blank" rel="noreferrer noopener">https://x.com/benbybit/status/1894768736084885929</a><br /><a href="https://x.com/safe/status/1894768522720350673" target="_blank" rel="noreferrer noopener">https://x.com/safe/status/1894768522720350673</a><br /> PoC for NAKIVO Backup Replication Vulnerability<br />  This vulnerability allows the compromise of NAKIVO backup systems. The vulnerability was patched silently in November, and never disclosed by NAKIVO. Instead, WatchTowr now disloses details including a proof of concept exploit.<br /><a href="https://labs.watchtowr.com/the-best-security-is-when-we-all-agree-to-keep-everything-secret-except-the-secrets-nakivo-backup-replication-cve-2024-48248/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/the-best-security-is-when-we-all-agree-to-keep-everything-secret-except-the-secrets-nakivo-backup-replication-cve-2024-48248/</a><br /> OpenH264 Vulnerability<br /><a href="https://github.com/cisco/openh264/security/advisories/GHSA-m99q-5j7x-7m9x" target="_blank" rel="noreferrer noopener">https://github.com/cisco/openh264/security/advisories/GHSA-m99q-5j7x-7m9x</a><br /> rsync vulnerability exploited<br /><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9342.mp3</guid><pubDate>Thu, 27 Feb 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64596831/9342.mp3" length="5950045" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9342" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Attacker of of Ephemeral Ports
  Attackers often use ephermeral ports to reach out to download additional resources or exfiltrate data. This can be used, with care, to detect possible compromises....</itunes:subtitle><itunes:summary><![CDATA[<br /> Attacker of of Ephemeral Ports<br />  Attackers often use ephermeral ports to reach out to download additional resources or exfiltrate data. This can be used, with care, to detect possible compromises.<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Malware%20Source%20Servers%3A%20The%20Threat%20of%20Attackers%20Using%20Ephemeral%20Ports%20as%20Service%20Ports%20to%20Upload%20Data/31710" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Malware%20Source%20Servers%3A%20The%20Threat%20of%20Attackers%20Using%20Ephemeral%20Ports%20as%20Service%20Ports%20to%20Upload%20Data/31710</a><br /> Compromised Visal Studio Code Extension downloaded by Millions<br />  Amit Assaraf identified a likely compromised Visual Studio Code theme that was installed by millions of potential victims. Amit did not disclose the exact malicious behaviour, but is asking for victims to contact them for details.<br /><a href="https://medium.com/@amitassaraf/a-wolf-in-dark-mode-the-malicious-vs-code-theme-that-fooled-millions-85ed92b4bd26" target="_blank" rel="noreferrer noopener">https://medium.com/@amitassaraf/a-wolf-in-dark-mode-the-malicious-vs-code-theme-that-fooled-millions-85ed92b4bd26</a> <br /> ByBit Theft Due to Compromised Developer Workstation<br />  ByBit and Safe{Wallet} disclosed that the record breaking ethereum theft was due to a compromised Safe{Wallet} developer workstation. A replaced JavaScript file targeted ByBit and altered a transaction signed by ByBit.<br /><a href="https://x.com/benbybit/status/1894768736084885929" target="_blank" rel="noreferrer noopener">https://x.com/benbybit/status/1894768736084885929</a><br /><a href="https://x.com/safe/status/1894768522720350673" target="_blank" rel="noreferrer noopener">https://x.com/safe/status/1894768522720350673</a><br /> PoC for NAKIVO Backup Replication Vulnerability<br />  This vulnerability allows the compromise of NAKIVO backup systems. The vulnerability was patched silently in November, and never disclosed by NAKIVO. Instead, WatchTowr now disloses details including a proof of concept exploit.<br /><a href="https://labs.watchtowr.com/the-best-security-is-when-we-all-agree-to-keep-everything-secret-except-the-secrets-nakivo-backup-replication-cve-2024-48248/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/the-best-security-is-when-we-all-agree-to-keep-everything-secret-except-the-secrets-nakivo-backup-replication-cve-2024-48248/</a><br /> OpenH264 Vulnerability<br /><a href="https://github.com/cisco/openh264/security/advisories/GHSA-m99q-5j7x-7m9x" target="_blank" rel="noreferrer noopener">https://github.com/cisco/openh264/security/advisories/GHSA-m99q-5j7x-7m9x</a><br /> rsync vulnerability exploited<br /><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a><br />]]></itunes:summary><itunes:duration>406</itunes:duration><itunes:keywords>business,bybit,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,nakivo,network,news,openh254,rsync,safewallet,security,visual studio code</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9342</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday Feb 26th: M365 Infostealer Botnet; Mixing OpenID Keys; Malicious Medical Image Apps</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-feb-26th-m365-infostealer-botnet-mixing-openid-keys-malicious-medical-image-apps--64575833</link><description><![CDATA[<br /> Massive Botnet Targets M365 with Password Spraying<br />  A large botnet is targeting service accounts in M365 with credentials stolen by infostealer malware.<br /><a href="https://securityscorecard.com/wp-content/uploads/2025/02/MassiveBotnet-Report_022125_03.pdf" target="_blank" rel="noreferrer noopener">https://securityscorecard.com/wp-content/uploads/2025/02/MassiveBotnet-Report_022125_03.pdf</a><br /> Mixing up Public and Private Keys in OpenID<br />  The complex OpenID specificiation and the flexibility it supports enables careless administrators to publich private keys instead or in addition to public keys<br /><a href="https://blog.hboeck.de/archives/909-Mixing-up-Public-and-Private-Keys-in-OpenID-Connect-deployments.html" target="_blank" rel="noreferrer noopener">https://blog.hboeck.de/archives/909-Mixing-up-Public-and-Private-Keys-in-OpenID-Connect-deployments.html</a><br /> Healthcare Malware Hunt Part 1:<br />  Medial images are often encoded in the DICOM format, an image format unique to medical imaging. Patients looking for viewers for DICOM images are tricked into downloading malware.<br /><a href="https://www.forescout.com/blog/healthcare-malware-hunt-part-1-silver-fox-apt-targets-philips-dicom-viewers/" target="_blank" rel="noreferrer noopener">https://www.forescout.com/blog/healthcare-malware-hunt-part-1-silver-fox-apt-targets-philips-dicom-viewers/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9340.mp3</guid><pubDate>Wed, 26 Feb 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64575833/9340.mp3" length="5298015" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9340" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Massive Botnet Targets M365 with Password Spraying
  A large botnet is targeting service accounts in M365 with credentials stolen by infostealer malware.
https://securityscorecard.com/wp-content/uploads/2025/02/MassiveBotnet-Report_022125_03.pdf...</itunes:subtitle><itunes:summary><![CDATA[<br /> Massive Botnet Targets M365 with Password Spraying<br />  A large botnet is targeting service accounts in M365 with credentials stolen by infostealer malware.<br /><a href="https://securityscorecard.com/wp-content/uploads/2025/02/MassiveBotnet-Report_022125_03.pdf" target="_blank" rel="noreferrer noopener">https://securityscorecard.com/wp-content/uploads/2025/02/MassiveBotnet-Report_022125_03.pdf</a><br /> Mixing up Public and Private Keys in OpenID<br />  The complex OpenID specificiation and the flexibility it supports enables careless administrators to publich private keys instead or in addition to public keys<br /><a href="https://blog.hboeck.de/archives/909-Mixing-up-Public-and-Private-Keys-in-OpenID-Connect-deployments.html" target="_blank" rel="noreferrer noopener">https://blog.hboeck.de/archives/909-Mixing-up-Public-and-Private-Keys-in-OpenID-Connect-deployments.html</a><br /> Healthcare Malware Hunt Part 1:<br />  Medial images are often encoded in the DICOM format, an image format unique to medical imaging. Patients looking for viewers for DICOM images are tricked into downloading malware.<br /><a href="https://www.forescout.com/blog/healthcare-malware-hunt-part-1-silver-fox-apt-targets-philips-dicom-viewers/" target="_blank" rel="noreferrer noopener">https://www.forescout.com/blog/healthcare-malware-hunt-part-1-silver-fox-apt-targets-philips-dicom-viewers/</a><br />]]></itunes:summary><itunes:duration>359</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dicom,hacking,infosec,infostealer,internet,it,m365,malware,medical,network,news,openid,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9340</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday Feb 25th: Unfurl Updates; Google Ditches SMS; Paypal Phish; Exim, libXML, Parallels Vuln</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-feb-25th-unfurl-updates-google-ditches-sms-paypal-phish-exim-libxml-parallels-vuln--64553925</link><description><![CDATA[<br /> Unfurl Update Released<br />  Unfurl released an Update fixing a few bugs and adding support to decode BlueSky URLs.<br /><a href="https://isc.sans.edu/diary/Unfurl%20v2025.02%20released/31716" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Unfurl%20v2025.02%20released/31716</a><br /> Google Confirms GMail To Ditch SMS Code Authentication<br />  Google no longer considers SMS authentication save enough for GMail. Instead, it pushes users to use Passkeys, or QR code based app authentication<br /><a href="https://www.forbes.com/sites/daveywinder/2025/02/23/google-confirms-gmail-to-ditch-sms-code-authentication/" target="_blank" rel="noreferrer noopener">https://www.forbes.com/sites/daveywinder/2025/02/23/google-confirms-gmail-to-ditch-sms-code-authentication/</a><br /> Beware of Paypal New Address Feature Abuse<br />  Attackers are using "address change" e-mails to send links to phishing sites or trick users into calling fake tech support phone numbers. Attackers are just adding the malicious content as part of the address. The e-mail themselves are legitimate PayPal emails and will pass various spam and phishing filters.<br /><a href="https://www.bleepingcomputer.com/news/security/beware-paypal-new-address-feature-abused-to-send-phishing-emails/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/beware-paypal-new-address-feature-abused-to-send-phishing-emails/</a><br /> Exim SQL Injection Vulnerability<br />  Exim, with sqlite support and ETRN enabled, is vulnerable to a simple SQL injection exploit. A PoC has been released<br /><a href="https://www.exim.org/static/doc/security/CVE-2025-26794.txt" target="_blank" rel="noreferrer noopener">https://www.exim.org/static/doc/security/CVE-2025-26794.txt</a><br /><a href="https://github.com/OscarBataille/CVE-2025-26794?" target="_blank" rel="noreferrer noopener">https://github.com/OscarBataille/CVE-2025-26794?</a><br /> XMLlib patches<br /><a href="https://gitlab.gnome.org/GNOME/libxml2/-/issues/847" target="_blank" rel="noreferrer noopener">https://gitlab.gnome.org/GNOME/libxml2/-/issues/847</a><br /><a href="https://gitlab.gnome.org/GNOME/libxml2/-/issues/828" target="_blank" rel="noreferrer noopener">https://gitlab.gnome.org/GNOME/libxml2/-/issues/828</a><br /> 0-Day in Parallels<br /><a href="https://jhftss.github.io/Parallels-0-day/" target="_blank" rel="noreferrer noopener">https://jhftss.github.io/Parallels-0-day/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9338.mp3</guid><pubDate>Tue, 25 Feb 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64553925/9338.mp3" length="5456793" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9338" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Unfurl Update Released
  Unfurl released an Update fixing a few bugs and adding support to decode BlueSky URLs.
https://isc.sans.edu/diary/Unfurl%20v2025.02%20released/31716
 Google Confirms GMail To Ditch SMS Code Authentication
  Google no longer...</itunes:subtitle><itunes:summary><![CDATA[<br /> Unfurl Update Released<br />  Unfurl released an Update fixing a few bugs and adding support to decode BlueSky URLs.<br /><a href="https://isc.sans.edu/diary/Unfurl%20v2025.02%20released/31716" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Unfurl%20v2025.02%20released/31716</a><br /> Google Confirms GMail To Ditch SMS Code Authentication<br />  Google no longer considers SMS authentication save enough for GMail. Instead, it pushes users to use Passkeys, or QR code based app authentication<br /><a href="https://www.forbes.com/sites/daveywinder/2025/02/23/google-confirms-gmail-to-ditch-sms-code-authentication/" target="_blank" rel="noreferrer noopener">https://www.forbes.com/sites/daveywinder/2025/02/23/google-confirms-gmail-to-ditch-sms-code-authentication/</a><br /> Beware of Paypal New Address Feature Abuse<br />  Attackers are using "address change" e-mails to send links to phishing sites or trick users into calling fake tech support phone numbers. Attackers are just adding the malicious content as part of the address. The e-mail themselves are legitimate PayPal emails and will pass various spam and phishing filters.<br /><a href="https://www.bleepingcomputer.com/news/security/beware-paypal-new-address-feature-abused-to-send-phishing-emails/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/beware-paypal-new-address-feature-abused-to-send-phishing-emails/</a><br /> Exim SQL Injection Vulnerability<br />  Exim, with sqlite support and ETRN enabled, is vulnerable to a simple SQL injection exploit. A PoC has been released<br /><a href="https://www.exim.org/static/doc/security/CVE-2025-26794.txt" target="_blank" rel="noreferrer noopener">https://www.exim.org/static/doc/security/CVE-2025-26794.txt</a><br /><a href="https://github.com/OscarBataille/CVE-2025-26794?" target="_blank" rel="noreferrer noopener">https://github.com/OscarBataille/CVE-2025-26794?</a><br /> XMLlib patches<br /><a href="https://gitlab.gnome.org/GNOME/libxml2/-/issues/847" target="_blank" rel="noreferrer noopener">https://gitlab.gnome.org/GNOME/libxml2/-/issues/847</a><br /><a href="https://gitlab.gnome.org/GNOME/libxml2/-/issues/828" target="_blank" rel="noreferrer noopener">https://gitlab.gnome.org/GNOME/libxml2/-/issues/828</a><br /> 0-Day in Parallels<br /><a href="https://jhftss.github.io/Parallels-0-day/" target="_blank" rel="noreferrer noopener">https://jhftss.github.io/Parallels-0-day/</a><br />]]></itunes:summary><itunes:duration>370</itunes:duration><itunes:keywords>0-day,business,computer,cyber,cybersecurity,daily,exim; sql; injection; paypal; ,hacking,infosec,internet,it,network,news,parallels,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9338</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday Feb 24th: sigs.py update; Google Introdusing Quantum Safe Sigs; MSFT Update Win 11 issues; LTE/5G Vulns;</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-feb-24th-sigs-py-update-google-introdusing-quantum-safe-sigs-msft-update-win-11-issues-lte-5g-vulns--64536279</link><description><![CDATA[<br /> Tool Update: Sigs.py<br />  Jim updates sigs.py. The tool verifies hashes for files and automatically recognizes what hash is used.<br /><a href="https://isc.sans.edu/diary/Tool%20update%3A%20sigs.py%20-%20added%20check%20mode/31706" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Tool%20update%3A%20sigs.py%20-%20added%20check%20mode/31706</a><br /> Google Announcing Quantum Safe Digital Signatures in Cloud KMS<br />  Google announced the option to use quantum safe digital signatures for its<br />  cloud key management system.<br /><a href="https://cloud.google.com/blog/products/identity-security/announcing-quantum-safe-digital-signatures-in-cloud-kms" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/products/identity-security/announcing-quantum-safe-digital-signatures-in-cloud-kms</a><br /> Windows 11 Patch issues<br />  The February Patch Tuesday appears to have caused issues with a number of Windows 11 systems. In particular the usability of the file manager appears to be affected.<br /><a href="https://www.windowslatest.com/2025/02/16/windows-11-kb5051987-breaks-file-explorer-install-fails-on-windows-11-24h2/" target="_blank" rel="noreferrer noopener">https://www.windowslatest.com/2025/02/16/windows-11-kb5051987-breaks-file-explorer-install-fails-on-windows-11-24h2/</a><br /> LTE/5G Vulnerabilities<br />  Researchers at the university of Florida have identified a large number of vulnerabilities in 5G and LTE networks.<br /><a href="https://nathanielbennett.com/publications/ransacked.pdf" target="_blank" rel="noreferrer noopener">https://nathanielbennett.com/publications/ransacked.pdf</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9336.mp3</guid><pubDate>Mon, 24 Feb 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64536279/9336.mp3" length="4756867" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9336" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Tool Update: Sigs.py
  Jim updates sigs.py. The tool verifies hashes for files and automatically recognizes what hash is used.
https://isc.sans.edu/diary/Tool%20update%3A%20sigs.py%20-%20added%20check%20mode/31706
 Google Announcing Quantum Safe...</itunes:subtitle><itunes:summary><![CDATA[<br /> Tool Update: Sigs.py<br />  Jim updates sigs.py. The tool verifies hashes for files and automatically recognizes what hash is used.<br /><a href="https://isc.sans.edu/diary/Tool%20update%3A%20sigs.py%20-%20added%20check%20mode/31706" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Tool%20update%3A%20sigs.py%20-%20added%20check%20mode/31706</a><br /> Google Announcing Quantum Safe Digital Signatures in Cloud KMS<br />  Google announced the option to use quantum safe digital signatures for its<br />  cloud key management system.<br /><a href="https://cloud.google.com/blog/products/identity-security/announcing-quantum-safe-digital-signatures-in-cloud-kms" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/products/identity-security/announcing-quantum-safe-digital-signatures-in-cloud-kms</a><br /> Windows 11 Patch issues<br />  The February Patch Tuesday appears to have caused issues with a number of Windows 11 systems. In particular the usability of the file manager appears to be affected.<br /><a href="https://www.windowslatest.com/2025/02/16/windows-11-kb5051987-breaks-file-explorer-install-fails-on-windows-11-24h2/" target="_blank" rel="noreferrer noopener">https://www.windowslatest.com/2025/02/16/windows-11-kb5051987-breaks-file-explorer-install-fails-on-windows-11-24h2/</a><br /> LTE/5G Vulnerabilities<br />  Researchers at the university of Florida have identified a large number of vulnerabilities in 5G and LTE networks.<br /><a href="https://nathanielbennett.com/publications/ransacked.pdf" target="_blank" rel="noreferrer noopener">https://nathanielbennett.com/publications/ransacked.pdf</a><br />]]></itunes:summary><itunes:duration>321</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,ransacked; lte; 5g; windows 11,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9336</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Friday Feb 21st: Kibana Queries; Mongoose Injection; U-Boot Flaws; Unifi Protect Camera Vulnerabilities; Protecting Network D</title><link>https://www.spreaker.com/episode/sans-stormcast-friday-feb-21st-kibana-queries-mongoose-injection-u-boot-flaws-unifi-protect-camera-vulnerabilities-protecting-network-d--64486904</link><description><![CDATA[<br /> Using ES|QL In Kibana to Query DShield Honeypot Logs<br />  Using the "Elastic Search Piped Query Language" to query DShield honeypot logs<br /><a href="https://isc.sans.edu/diary/Using%20ES%7CQL%20in%20Kibana%20to%20Queries%20DShield%20Honeypot%20Logs/31704" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Using%20ES%7CQL%20in%20Kibana%20to%20Queries%20DShield%20Honeypot%20Logs/31704</a><br /> Mongoose Flaws Put MongoDB at risk<br />  The Object Direct Mapping library Mongoose suffers from an injection vulnerability leading to the potenitial of remote code exeuction in MongoDB<br /><a href="https://www.theregister.com/2025/02/20/mongoose_flaws_mongodb/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2025/02/20/mongoose_flaws_mongodb/</a><br /> U-Boot Vulnerabilities<br />  The open source boot loader U-Boot does suffer from a number of issues allowing the bypass of its integrity checks. This may lead to the execution of malicious code on boot.<br /><a href="https://www.openwall.com/lists/oss-security/2025/02/17/2" target="_blank" rel="noreferrer noopener">https://www.openwall.com/lists/oss-security/2025/02/17/2</a><br /> Unifi Protect Camera Update<br /><a href="https://community.ui.com/releases/Security-Advisory-Bulletin-046-046/9649ea8f-93db-4713-a875-c3fd7614943f" target="_blank" rel="noreferrer noopener">https://community.ui.com/releases/Security-Advisory-Bulletin-046-046/9649ea8f-93db-4713-a875-c3fd7614943f</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9334.mp3</guid><pubDate>Fri, 21 Feb 2025 00:50:46 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64486904/9334.mp3" length="10767483" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9334" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Using ES|QL In Kibana to Query DShield Honeypot Logs
  Using the "Elastic Search Piped Query Language" to query DShield honeypot logs
https://isc.sans.edu/diary/Using%20ES%7CQL%20in%20Kibana%20to%20Queries%20DShield%20Honeypot%20Logs/31704
 Mongoose...</itunes:subtitle><itunes:summary><![CDATA[<br /> Using ES|QL In Kibana to Query DShield Honeypot Logs<br />  Using the "Elastic Search Piped Query Language" to query DShield honeypot logs<br /><a href="https://isc.sans.edu/diary/Using%20ES%7CQL%20in%20Kibana%20to%20Queries%20DShield%20Honeypot%20Logs/31704" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Using%20ES%7CQL%20in%20Kibana%20to%20Queries%20DShield%20Honeypot%20Logs/31704</a><br /> Mongoose Flaws Put MongoDB at risk<br />  The Object Direct Mapping library Mongoose suffers from an injection vulnerability leading to the potenitial of remote code exeuction in MongoDB<br /><a href="https://www.theregister.com/2025/02/20/mongoose_flaws_mongodb/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2025/02/20/mongoose_flaws_mongodb/</a><br /> U-Boot Vulnerabilities<br />  The open source boot loader U-Boot does suffer from a number of issues allowing the bypass of its integrity checks. This may lead to the execution of malicious code on boot.<br /><a href="https://www.openwall.com/lists/oss-security/2025/02/17/2" target="_blank" rel="noreferrer noopener">https://www.openwall.com/lists/oss-security/2025/02/17/2</a><br /> Unifi Protect Camera Update<br /><a href="https://community.ui.com/releases/Security-Advisory-Bulletin-046-046/9649ea8f-93db-4713-a875-c3fd7614943f" target="_blank" rel="noreferrer noopener">https://community.ui.com/releases/Security-Advisory-Bulletin-046-046/9649ea8f-93db-4713-a875-c3fd7614943f</a><br />]]></itunes:summary><itunes:duration>750</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,unifi; protect; u-boot; honeyp</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9334</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Wednesday Feb 20th: XWorm Cocktail; Quantum Computing Breakthrough; Signal Phishing</title><link>https://www.spreaker.com/episode/sans-stormcast-wednesday-feb-20th-xworm-cocktail-quantum-computing-breakthrough-signal-phishing--64465493</link><description><![CDATA[<br /> XWorm Cocktail: A Mix of PE data with PowerShell Code<br />  Quick analysis of an interesting XWrom sample with powershell code embedded inside an executable<br /><a href="https://isc.sans.edu/diary/XWorm+Cocktail+A+Mix+of+PE+data+with+PowerShell+Code/31700" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/XWorm+Cocktail+A+Mix+of+PE+data+with+PowerShell+Code/31700</a><br /> Microsoft's Majorana 1 Chip Carves New Path for Quantum Computing<br />  Microsoft announced a breack through in Quantum computing. Its new prototype Majorana 1 chip takes advantage of exotic majorana particles to implement a scalable low error rate solution to building quantum computers<br /><a href="https://news.microsoft.com/source/features/ai/microsofts-majorana-1-chip-carves-new-path-for-quantum-computing/" target="_blank" rel="noreferrer noopener">https://news.microsoft.com/source/features/ai/microsofts-majorana-1-chip-carves-new-path-for-quantum-computing/</a><br /> Russia Targeting Signal Messenger<br />  Signal is well regarded as a secure end to end encrypted messaging platform. However, a user may be tricked into providing access to their account by scanning a QR code masquerading as a group channel invitation.<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger/" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9332.mp3</guid><pubDate>Thu, 20 Feb 2025 01:38:40 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64465493/9332.mp3" length="6175716" type="audio/mpeg"/><podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9332" type="text/plain" language="en"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 XWorm Cocktail: A Mix of PE data with PowerShell Code
  Quick analysis of an interesting XWrom sample with powershell code embedded inside an executable
https://isc.sans.edu/diary/XWorm+Cocktail+A+Mix+of+PE+data+with+PowerShell+Code/31700...</itunes:subtitle><itunes:summary><![CDATA[<br /> XWorm Cocktail: A Mix of PE data with PowerShell Code<br />  Quick analysis of an interesting XWrom sample with powershell code embedded inside an executable<br /><a href="https://isc.sans.edu/diary/XWorm+Cocktail+A+Mix+of+PE+data+with+PowerShell+Code/31700" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/XWorm+Cocktail+A+Mix+of+PE+data+with+PowerShell+Code/31700</a><br /> Microsoft's Majorana 1 Chip Carves New Path for Quantum Computing<br />  Microsoft announced a breack through in Quantum computing. Its new prototype Majorana 1 chip takes advantage of exotic majorana particles to implement a scalable low error rate solution to building quantum computers<br /><a href="https://news.microsoft.com/source/features/ai/microsofts-majorana-1-chip-carves-new-path-for-quantum-computing/" target="_blank" rel="noreferrer noopener">https://news.microsoft.com/source/features/ai/microsofts-majorana-1-chip-carves-new-path-for-quantum-computing/</a><br /> Russia Targeting Signal Messenger<br />  Signal is well regarded as a secure end to end encrypted messaging platform. However, a user may be tricked into providing access to their account by scanning a QR code masquerading as a group channel invitation.<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger/" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger/</a><br />]]></itunes:summary><itunes:duration>422</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,russia; signal; ukraine; quant,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9332</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Tuesday Feb 19th: ModelScan AI Model Security; OpenSSH Vuln; Juniper Patches; Dell BIOS Vulnerability</title><link>https://www.spreaker.com/episode/sans-stormcast-tuesday-feb-19th-modelscan-ai-model-security-openssh-vuln-juniper-patches-dell-bios-vulnerability--64443240</link><description><![CDATA[<br /> ModelScan: Protection Against Model Serialization Attacks<br />  ModelScan is a tool to inspect AI models for deserialization attacks. The tool will detect suspect commands and warn the user.<br /><a href="https://isc.sans.edu/diary/ModelScan%20-%20Protection%20Against%20Model%20Serialization%20Attacks/31692" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/ModelScan%20-%20Protection%20Against%20Model%20Serialization%20Attacks/31692</a><br /> OpenSSH MitM and DoS Vulnerabilities<br />  OpenSSH Patched two vulnerabilities discovered by Qualys. One may be used for MitM attack in specfic configurations of OpenSSH.<br /><a href="https://www.qualys.com/2025/02/18/openssh-mitm-dos.txt" target="_blank" rel="noreferrer noopener">https://www.qualys.com/2025/02/18/openssh-mitm-dos.txt</a><br /> Juniper Authentication Bypass<br />  Juniper fixed an authentication bypass vulnerability that affects several prodcuts. The patch was released outside the normal patch schedule.<br /><a href="https://supportportal.juniper.net/s/article/2025-02-Out-of-Cycle-Security-Bulletin-Session-Smart-Router-Session-Smart-Conductor-WAN-Assurance-Router-API-Authentication-Bypass-Vulnerability-CVE-2025-21589?language=en_US" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/article/2025-02-Out-of-Cycle-Security-Bulletin-Session-Smart-Router-Session-Smart-Conductor-WAN-Assurance-Router-API-Authentication-Bypass-Vulnerability-CVE-2025-21589?language=en_US</a><br /> DELL BIOS Patches<br />  DELL released BIOS updates fixing a privilege escalation issue. The update affects a large part of Dell's portfolio<br /><a href="https://www.dell.com/support/kbdoc/en-en/000258429/dsa-2025-021" target="_blank" rel="noreferrer noopener">https://www.dell.com/support/kbdoc/en-en/000258429/dsa-2025-021</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9330.mp3</guid><pubDate>Wed, 19 Feb 2025 00:31:58 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64443240/9330.mp3" length="6081218" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 ModelScan: Protection Against Model Serialization Attacks
  ModelScan is a tool to inspect AI models for deserialization attacks. The tool will detect suspect commands and warn the user....</itunes:subtitle><itunes:summary><![CDATA[<br /> ModelScan: Protection Against Model Serialization Attacks<br />  ModelScan is a tool to inspect AI models for deserialization attacks. The tool will detect suspect commands and warn the user.<br /><a href="https://isc.sans.edu/diary/ModelScan%20-%20Protection%20Against%20Model%20Serialization%20Attacks/31692" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/ModelScan%20-%20Protection%20Against%20Model%20Serialization%20Attacks/31692</a><br /> OpenSSH MitM and DoS Vulnerabilities<br />  OpenSSH Patched two vulnerabilities discovered by Qualys. One may be used for MitM attack in specfic configurations of OpenSSH.<br /><a href="https://www.qualys.com/2025/02/18/openssh-mitm-dos.txt" target="_blank" rel="noreferrer noopener">https://www.qualys.com/2025/02/18/openssh-mitm-dos.txt</a><br /> Juniper Authentication Bypass<br />  Juniper fixed an authentication bypass vulnerability that affects several prodcuts. The patch was released outside the normal patch schedule.<br /><a href="https://supportportal.juniper.net/s/article/2025-02-Out-of-Cycle-Security-Bulletin-Session-Smart-Router-Session-Smart-Conductor-WAN-Assurance-Router-API-Authentication-Bypass-Vulnerability-CVE-2025-21589?language=en_US" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/article/2025-02-Out-of-Cycle-Security-Bulletin-Session-Smart-Router-Session-Smart-Conductor-WAN-Assurance-Router-API-Authentication-Bypass-Vulnerability-CVE-2025-21589?language=en_US</a><br /> DELL BIOS Patches<br />  DELL released BIOS updates fixing a privilege escalation issue. The update affects a large part of Dell's portfolio<br /><a href="https://www.dell.com/support/kbdoc/en-en/000258429/dsa-2025-021" target="_blank" rel="noreferrer noopener">https://www.dell.com/support/kbdoc/en-en/000258429/dsa-2025-021</a><br />]]></itunes:summary><itunes:duration>415</itunes:duration><itunes:keywords>bios; juniper; openssh; models,business,computer,cyber,cybersecurity,daily,dell,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9330</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast: Securing the Edge; PostgreSQL Exploit; Ivanti Exploit; WinZip Vulnerablity; Xerox Patch</title><link>https://www.spreaker.com/episode/sans-stormcast-securing-the-edge-postgresql-exploit-ivanti-exploit-winzip-vulnerablity-xerox-patch--64427326</link><description><![CDATA[<br /> My Very Personal Guidance and Strategies to Protect Network Edge Devices<br />  A quick summary to help you secure edge devices. This may be a bit opinionated, but these are the strategies that I find work and are actionable.<br /><a href="https://isc.sans.edu/diary/My%20Very%20Personal%20Guidance%20and%20Strategies%20to%20Protect%20Network%20Edge%20Devices/31660" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/My%20Very%20Personal%20Guidance%20and%20Strategies%20to%20Protect%20Network%20Edge%20Devices/31660</a><br /> PostgreSQL SQL Injection<br />  A followup to yesterday's segment about the PostgreSQL vulnerability. Rapid7 released a Metasploit module to exploit the vulnerability.<br /><a href="https://github.com/rapid7/metasploit-framework/pull/19877" target="_blank" rel="noreferrer noopener">https://github.com/rapid7/metasploit-framework/pull/19877</a><br /> Ivanti Connect Secure Exploited<br />  The Japanese CERT observed exploitation of January's Connect Secure vulnerability<br /><a href="https://blogs.jpcert.or.jp/ja/2025/02/spawnchimera.html" target="_blank" rel="noreferrer noopener">https://blogs.jpcert.or.jp/ja/2025/02/spawnchimera.html</a><br /> WinZip Vulnerability<br />  WinZip patched a buffer overflow vulenrability that may be triggered by malicious 7Z files<br /><a href="https://www.zerodayinitiative.com/advisories/ZDI-25-047/" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/advisories/ZDI-25-047/</a><br /> Xerox Printer Patch<br />  Xerox patched two vulnerabililites in its enterprise multifunction printers that may be exploited for lateral movement.<br /><a href="https://securitydocs.business.xerox.com/wp-content/uploads/2025/02/Xerox-Security-Bulletin-XRX25-003-for-Xerox-VersaLinkPhaser-and-WorkCentre.pdf" target="_blank" rel="noreferrer noopener">https://securitydocs.business.xerox.com/wp-content/uploads/2025/02/Xerox-Security-Bulletin-XRX25-003-for-Xerox-VersaLinkPhaser-and-WorkCentre.pdf</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9328.mp3</guid><pubDate>Tue, 18 Feb 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64427326/9328.mp3" length="4178747" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 My Very Personal Guidance and Strategies to Protect Network Edge Devices
  A quick summary to help you secure edge devices. This may be a bit opinionated, but these are the strategies that I find work and are actionable....</itunes:subtitle><itunes:summary><![CDATA[<br /> My Very Personal Guidance and Strategies to Protect Network Edge Devices<br />  A quick summary to help you secure edge devices. This may be a bit opinionated, but these are the strategies that I find work and are actionable.<br /><a href="https://isc.sans.edu/diary/My%20Very%20Personal%20Guidance%20and%20Strategies%20to%20Protect%20Network%20Edge%20Devices/31660" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/My%20Very%20Personal%20Guidance%20and%20Strategies%20to%20Protect%20Network%20Edge%20Devices/31660</a><br /> PostgreSQL SQL Injection<br />  A followup to yesterday's segment about the PostgreSQL vulnerability. Rapid7 released a Metasploit module to exploit the vulnerability.<br /><a href="https://github.com/rapid7/metasploit-framework/pull/19877" target="_blank" rel="noreferrer noopener">https://github.com/rapid7/metasploit-framework/pull/19877</a><br /> Ivanti Connect Secure Exploited<br />  The Japanese CERT observed exploitation of January's Connect Secure vulnerability<br /><a href="https://blogs.jpcert.or.jp/ja/2025/02/spawnchimera.html" target="_blank" rel="noreferrer noopener">https://blogs.jpcert.or.jp/ja/2025/02/spawnchimera.html</a><br /> WinZip Vulnerability<br />  WinZip patched a buffer overflow vulenrability that may be triggered by malicious 7Z files<br /><a href="https://www.zerodayinitiative.com/advisories/ZDI-25-047/" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/advisories/ZDI-25-047/</a><br /> Xerox Printer Patch<br />  Xerox patched two vulnerabililites in its enterprise multifunction printers that may be exploited for lateral movement.<br /><a href="https://securitydocs.business.xerox.com/wp-content/uploads/2025/02/Xerox-Security-Bulletin-XRX25-003-for-Xerox-VersaLinkPhaser-and-WorkCentre.pdf" target="_blank" rel="noreferrer noopener">https://securitydocs.business.xerox.com/wp-content/uploads/2025/02/Xerox-Security-Bulletin-XRX25-003-for-Xerox-VersaLinkPhaser-and-WorkCentre.pdf</a><br />]]></itunes:summary><itunes:duration>279</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,xerox; winzip; ivanti; connect</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9328</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Monday Feb 17th: Fake BSOD; Volatile IPs; Postgresql libpq SQL Injection; OAUTH Phishing</title><link>https://www.spreaker.com/episode/sans-stormcast-monday-feb-17th-fake-bsod-volatile-ips-postgresql-libpq-sql-injection-oauth-phishing--64412335</link><description><![CDATA[<br /> Fake BSOD Delivered by Malicious Python Script<br />  Xavier found an odd malicious Python script that displays a blue screen of<br /> death to users. The purpose isn't quite clear. It could be a teach support scam<br /> tricking users into calling the 800 number displayed, or a simple<br /> anti-reversing trick<br /><a href="https://isc.sans.edu/diary/Fake%20BSOD%20Delivered%20by%20Malicious%20Python%20Script/31686" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Fake%20BSOD%20Delivered%20by%20Malicious%20Python%20Script/31686</a><br /> The Danger of IP Volatility<br />  Accounting for IP addresses is important, and if not done properly, may<br />  lead to resources being exposed after IP addresses are released.<br /><a href="https://isc.sans.edu/diary/The%20Danger%20of%20IP%20Volatility/31688" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20Danger%20of%20IP%20Volatility/31688</a><br /> PostgreSQL SQL Injection<br />  Functions in PostgreSQL's libpq do not properly escape parameters which may<br /> lead to SQL injection issues if the functions are used to create input for pqsql.<br /><a href="https://www.postgresql.org/support/security/CVE-2025-1094/" target="_blank" rel="noreferrer noopener">https://www.postgresql.org/support/security/CVE-2025-1094/</a><br /> Multiple Russian Threat Actors Targeting Microsoft Device Code Auth<br />  The OAUTH device code flow is used to attach devices with limited input capability to a user's account. However, this can be abused via phishing attacks.<br /><a href="https://www.volexity.com/blog/2025/02/13/multiple-russian-threat-actors-targeting-microsoft-device-code-authentication/" target="_blank" rel="noreferrer noopener">https://www.volexity.com/blog/2025/02/13/multiple-russian-threat-actors-targeting-microsoft-device-code-authentication/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9326.mp3</guid><pubDate>Mon, 17 Feb 2025 01:22:04 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64412335/9326.mp3" length="7450021" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Fake BSOD Delivered by Malicious Python Script
  Xavier found an odd malicious Python script that displays a blue screen of
 death to users. The purpose isn't quite clear. It could be a teach support scam
 tricking users into calling the 800 number...</itunes:subtitle><itunes:summary><![CDATA[<br /> Fake BSOD Delivered by Malicious Python Script<br />  Xavier found an odd malicious Python script that displays a blue screen of<br /> death to users. The purpose isn't quite clear. It could be a teach support scam<br /> tricking users into calling the 800 number displayed, or a simple<br /> anti-reversing trick<br /><a href="https://isc.sans.edu/diary/Fake%20BSOD%20Delivered%20by%20Malicious%20Python%20Script/31686" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Fake%20BSOD%20Delivered%20by%20Malicious%20Python%20Script/31686</a><br /> The Danger of IP Volatility<br />  Accounting for IP addresses is important, and if not done properly, may<br />  lead to resources being exposed after IP addresses are released.<br /><a href="https://isc.sans.edu/diary/The%20Danger%20of%20IP%20Volatility/31688" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20Danger%20of%20IP%20Volatility/31688</a><br /> PostgreSQL SQL Injection<br />  Functions in PostgreSQL's libpq do not properly escape parameters which may<br /> lead to SQL injection issues if the functions are used to create input for pqsql.<br /><a href="https://www.postgresql.org/support/security/CVE-2025-1094/" target="_blank" rel="noreferrer noopener">https://www.postgresql.org/support/security/CVE-2025-1094/</a><br /> Multiple Russian Threat Actors Targeting Microsoft Device Code Auth<br />  The OAUTH device code flow is used to attach devices with limited input capability to a user's account. However, this can be abused via phishing attacks.<br /><a href="https://www.volexity.com/blog/2025/02/13/multiple-russian-threat-actors-targeting-microsoft-device-code-authentication/" target="_blank" rel="noreferrer noopener">https://www.volexity.com/blog/2025/02/13/multiple-russian-threat-actors-targeting-microsoft-device-code-authentication/</a><br />]]></itunes:summary><itunes:duration>513</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,oauth; postgresql; ip; volatil,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9326</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Feb 14th 2025: DShield Honeypot SIEM; PAN OS Auth Bypass; Salt Typhone vs. Cisco; Crowdstrike Patch</title><link>https://www.spreaker.com/episode/sans-stormcast-feb-14th-2025-dshield-honeypot-siem-pan-os-auth-bypass-salt-typhone-vs-cisco-crowdstrike-patch--64370683</link><description><![CDATA[<br /> DShield SIEM Docker Updates<br />  Interested in learning more about the attacks hitting your honeypot?<br />  Guy assembled a neat SIEM to create dashboards summarizing the attacks.<br /><a href="https://isc.sans.edu/diary/DShield%20SIEM%20Docker%20Updates/31680" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/DShield%20SIEM%20Docker%20Updates/31680</a><br /> PANOS Path Confusion Auth Bypass<br />  Palo Alto Networks fixed a path confusion vulnerability introduced by the<br />  overly complex midle box chain in PANOS.<br /><a href="https://slcyber.io/blog/nginx-apache-path-confusion-to-auth-bypass-in-pan-os/" target="_blank" rel="noreferrer noopener">https://slcyber.io/blog/nginx-apache-path-confusion-to-auth-bypass-in-pan-os/</a><br /><a href="https://www.theregister.com/2025/02/13/palo_alto_firewall/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2025/02/13/palo_alto_firewall/</a><br /> China's Volt Typhoon Continues to use Cisco Vulns<br />  Recorded Future wrote up some recent attacks of the Red Mike / Volt Typhoon groups going after telecom providers by compromissing Cisco systems via an older vulnerabilty<br /><a href="https://www.wired.com/story/chinas-salt-typhoon-spies-are-still-hacking-telecoms-now-by-exploiting-cisco-routers/" target="_blank" rel="noreferrer noopener">https://www.wired.com/story/chinas-salt-typhoon-spies-are-still-hacking-telecoms-now-by-exploiting-cisco-routers/</a><br /> Crowdstrike Patches Linux Client<br /><a href="https://www.crowdstrike.com/security-advisories/cve-2025-1146/" target="_blank" rel="noreferrer noopener">https://www.crowdstrike.com/security-advisories/cve-2025-1146/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9324.mp3</guid><pubDate>Fri, 14 Feb 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64370683/9324.mp3" length="5343574" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 DShield SIEM Docker Updates
  Interested in learning more about the attacks hitting your honeypot?
  Guy assembled a neat SIEM to create dashboards summarizing the attacks.
https://isc.sans.edu/diary/DShield%20SIEM%20Docker%20Updates/31680
 PANOS...</itunes:subtitle><itunes:summary><![CDATA[<br /> DShield SIEM Docker Updates<br />  Interested in learning more about the attacks hitting your honeypot?<br />  Guy assembled a neat SIEM to create dashboards summarizing the attacks.<br /><a href="https://isc.sans.edu/diary/DShield%20SIEM%20Docker%20Updates/31680" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/DShield%20SIEM%20Docker%20Updates/31680</a><br /> PANOS Path Confusion Auth Bypass<br />  Palo Alto Networks fixed a path confusion vulnerability introduced by the<br />  overly complex midle box chain in PANOS.<br /><a href="https://slcyber.io/blog/nginx-apache-path-confusion-to-auth-bypass-in-pan-os/" target="_blank" rel="noreferrer noopener">https://slcyber.io/blog/nginx-apache-path-confusion-to-auth-bypass-in-pan-os/</a><br /><a href="https://www.theregister.com/2025/02/13/palo_alto_firewall/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2025/02/13/palo_alto_firewall/</a><br /> China's Volt Typhoon Continues to use Cisco Vulns<br />  Recorded Future wrote up some recent attacks of the Red Mike / Volt Typhoon groups going after telecom providers by compromissing Cisco systems via an older vulnerabilty<br /><a href="https://www.wired.com/story/chinas-salt-typhoon-spies-are-still-hacking-telecoms-now-by-exploiting-cisco-routers/" target="_blank" rel="noreferrer noopener">https://www.wired.com/story/chinas-salt-typhoon-spies-are-still-hacking-telecoms-now-by-exploiting-cisco-routers/</a><br /> Crowdstrike Patches Linux Client<br /><a href="https://www.crowdstrike.com/security-advisories/cve-2025-1146/" target="_blank" rel="noreferrer noopener">https://www.crowdstrike.com/security-advisories/cve-2025-1146/</a><br />]]></itunes:summary><itunes:duration>362</itunes:duration><itunes:keywords>business,computer,crowdstrike; falcon; china; vo,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9324</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Feb 13th 2025: Smart City Threats; Advanced Social Engineering Attacks; Wazuh Vulnerability; PAM Vulnerability; Ivanti Patche</title><link>https://www.spreaker.com/episode/sans-stormcast-feb-13th-2025-smart-city-threats-advanced-social-engineering-attacks-wazuh-vulnerability-pam-vulnerability-ivanti-patche--64350455</link><description><![CDATA[<br /> An Ontology for Threats: Cybercrime and Digital Forensic Investigation on Smart City Infrastructure<br />  Smart cities is a big topic for many local governments. With building these complex systems, attacks will follow. <br /><a href="https://isc.sans.edu/diary/An%20ontology%20for%20threats%2C%20cybercrime%20and%20digital%20forensic%20investigation%20on%20Smart%20City%20Infrastructure/31676" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/An%20ontology%20for%20threats%2C%20cybercrime%20and%20digital%20forensic%20investigation%20on%20Smart%20City%20Infrastructure/31676</a><br /> North Korean state actor tricking admins into executing PowerShell<br />  North Korean state actors are spending quite a bit of effort setting up relationships with South Korean system administrators, culminating in them getting tricked into executing malicious PowerShell scripts.<br /><a href="https://x.com/MsftSecIntel/status/1889407814604296490" target="_blank" rel="noreferrer noopener">https://x.com/MsftSecIntel/status/1889407814604296490</a><br /> Wazuh Vulnerability<br />  A deserialization vulnerability in Wazuh may lead to an unauthenticated remote code execution vulnerability<br /><a href="https://github.com/wazuh/wazuh/security/advisories/GHSA-hcrc-79hj-m3qh" target="_blank" rel="noreferrer noopener">https://github.com/wazuh/wazuh/security/advisories/GHSA-hcrc-79hj-m3qh</a><br /> PAM PKCS11 Vulnerablity<br />  Several vulnerabilities in the Linux PAM module processing smart card authentication can be used to bypass authentication<br /><a href="https://github.com/OpenSC/pam_pkcs11/releases/tag/pam_pkcs11-0.6.13" target="_blank" rel="noreferrer noopener">https://github.com/OpenSC/pam_pkcs11/releases/tag/pam_pkcs11-0.6.13</a><br /> Ivanti Patches<br />  Ivanti released its monhtly update, fixing a number of critical vulnerabilities in Connect Secure and other prodcuts<br /><a href="https://forums.ivanti.com/s/article/February-Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-and-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/February-Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-and-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs?language=en_US</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9322.mp3</guid><pubDate>Thu, 13 Feb 2025 01:26:50 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64350455/9322.mp3" length="5289644" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 An Ontology for Threats: Cybercrime and Digital Forensic Investigation on Smart City Infrastructure
  Smart cities is a big topic for many local governments. With building these complex systems, attacks will follow....</itunes:subtitle><itunes:summary><![CDATA[<br /> An Ontology for Threats: Cybercrime and Digital Forensic Investigation on Smart City Infrastructure<br />  Smart cities is a big topic for many local governments. With building these complex systems, attacks will follow. <br /><a href="https://isc.sans.edu/diary/An%20ontology%20for%20threats%2C%20cybercrime%20and%20digital%20forensic%20investigation%20on%20Smart%20City%20Infrastructure/31676" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/An%20ontology%20for%20threats%2C%20cybercrime%20and%20digital%20forensic%20investigation%20on%20Smart%20City%20Infrastructure/31676</a><br /> North Korean state actor tricking admins into executing PowerShell<br />  North Korean state actors are spending quite a bit of effort setting up relationships with South Korean system administrators, culminating in them getting tricked into executing malicious PowerShell scripts.<br /><a href="https://x.com/MsftSecIntel/status/1889407814604296490" target="_blank" rel="noreferrer noopener">https://x.com/MsftSecIntel/status/1889407814604296490</a><br /> Wazuh Vulnerability<br />  A deserialization vulnerability in Wazuh may lead to an unauthenticated remote code execution vulnerability<br /><a href="https://github.com/wazuh/wazuh/security/advisories/GHSA-hcrc-79hj-m3qh" target="_blank" rel="noreferrer noopener">https://github.com/wazuh/wazuh/security/advisories/GHSA-hcrc-79hj-m3qh</a><br /> PAM PKCS11 Vulnerablity<br />  Several vulnerabilities in the Linux PAM module processing smart card authentication can be used to bypass authentication<br /><a href="https://github.com/OpenSC/pam_pkcs11/releases/tag/pam_pkcs11-0.6.13" target="_blank" rel="noreferrer noopener">https://github.com/OpenSC/pam_pkcs11/releases/tag/pam_pkcs11-0.6.13</a><br /> Ivanti Patches<br />  Ivanti released its monhtly update, fixing a number of critical vulnerabilities in Connect Secure and other prodcuts<br /><a href="https://forums.ivanti.com/s/article/February-Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-and-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/February-Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-and-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs?language=en_US</a><br />]]></itunes:summary><itunes:duration>359</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,ivanti; pam; pkcs11; linux; wa,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9322</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Feb 12th 2025: MSFT Patch Tuesday; Adobe Patches; FortiNet Acknowledges Exploitation of FortiOS</title><link>https://www.spreaker.com/episode/sans-stormcast-feb-12th-2025-msft-patch-tuesday-adobe-patches-fortinet-acknowledges-exploitation-of-fortios--64333123</link><description><![CDATA[<br /> Microsoft Patch Tuesday<br />  Microsoft released patches for 55 vulnerabilities. Three of them are actagorized as critical, two are already exploited and another two have been publicly disclosed. The LDAP server vulnerability could become a huge deal, but it is not clear if an exploit will appear.<br /><a href="https://isc.sans.edu/diary/Microsoft%20February%202025%20Patch%20Tuesday/31674" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20February%202025%20Patch%20Tuesday/31674</a><br /> Adobe Patches<br />  Adobe released patches for seven products. Watch out in particular for the Adobe Commerce issues<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> Fortinet Acknowledges Exploitation of Vulnerability<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-24-535" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-24-535</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9320.mp3</guid><pubDate>Wed, 12 Feb 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64333123/9320.mp3" length="5217647" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Microsoft Patch Tuesday
  Microsoft released patches for 55 vulnerabilities. Three of them are actagorized as critical, two are already exploited and another two have been publicly disclosed. The LDAP server vulnerability could become a huge deal,...</itunes:subtitle><itunes:summary><![CDATA[<br /> Microsoft Patch Tuesday<br />  Microsoft released patches for 55 vulnerabilities. Three of them are actagorized as critical, two are already exploited and another two have been publicly disclosed. The LDAP server vulnerability could become a huge deal, but it is not clear if an exploit will appear.<br /><a href="https://isc.sans.edu/diary/Microsoft%20February%202025%20Patch%20Tuesday/31674" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20February%202025%20Patch%20Tuesday/31674</a><br /> Adobe Patches<br />  Adobe released patches for seven products. Watch out in particular for the Adobe Commerce issues<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> Fortinet Acknowledges Exploitation of Vulnerability<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-24-535" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-24-535</a><br />]]></itunes:summary><itunes:duration>354</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,fortinet; adobe; microsoft;,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9320</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Stormcast Feb 11th 2025: 7zip and MoW; Apple 0-Day Fix; AMD Microcode Overwrite; Trimble CityWorks 0-Day; MageCart Update</title><link>https://www.spreaker.com/episode/sans-stormcast-feb-11th-2025-7zip-and-mow-apple-0-day-fix-amd-microcode-overwrite-trimble-cityworks-0-day-magecart-update--64308985</link><description><![CDATA[<br /> Reminder: 7-Zip MoW<br />  The MoW must be added to any files extracted from ZIP or other compound file formats. 7-Zip does not do so by default unless you alter the default configuration.<br /><a href="https://isc.sans.edu/diary/Reminder%3A%207-Zip%20%26%20MoW/31668" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Reminder%3A%207-Zip%20%26%20MoW/31668</a><br /> Apple Fixes 0-Day<br />  Apple released updates to iOS and iPadOS fixing a bypass for USB Restricted Mode. The vulnerability is already being exploited.<br /><a href="https://support.apple.com/en-us/122174" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/122174</a><br /> AMD ZEN CPU Microcode Update<br />  An attacker is able to replace microcode on some AMD CPUs. This may alter how the CPUs function and Google released a PoC showing how it can be used to manipulate the random number generator.<br /><a href="https://github.com/google/security-research/security/advisories/GHSA-4xq7-4mgh-gp6w" target="_blank" rel="noreferrer noopener">https://github.com/google/security-research/security/advisories/GHSA-4xq7-4mgh-gp6w</a><br /> Trimble Cityworks Exploited<br />  CISA added a recent Trimble Cityworks vulnerabliity to its list of exploited vulnerabilities. <br /><a href="https://learn.assetlifecycle.trimble.com/i/1532182-cityworks-customer-communication-2025-02-06-docx/0?" target="_blank" rel="noreferrer noopener">https://learn.assetlifecycle.trimble.com/i/1532182-cityworks-customer-communication-2025-02-06-docx/0?</a><br /> Google Tag Manager Skimmer Steals Credit Card Info<br />  Sucuri released a blog post with updates to the mage cart campaign. The latest version is injecting malicious code as part of the google tag manager / analytics code.<br /><a href="https://blog.sucuri.net/2025/02/google-tag-manager-skimmer-steals-credit-card-info-from-magento-site.html" target="_blank" rel="noreferrer noopener">https://blog.sucuri.net/2025/02/google-tag-manager-skimmer-steals-credit-card-info-from-magento-site.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9318.mp3</guid><pubDate>Tue, 11 Feb 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64308985/9318.mp3" length="6371398" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Reminder: 7-Zip MoW
  The MoW must be added to any files extracted from ZIP or other compound file formats. 7-Zip does not do so by default unless you alter the default configuration.
https://isc.sans.edu/diary/Reminder%3A%207-Zip%20%26%20MoW/31668...</itunes:subtitle><itunes:summary><![CDATA[<br /> Reminder: 7-Zip MoW<br />  The MoW must be added to any files extracted from ZIP or other compound file formats. 7-Zip does not do so by default unless you alter the default configuration.<br /><a href="https://isc.sans.edu/diary/Reminder%3A%207-Zip%20%26%20MoW/31668" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Reminder%3A%207-Zip%20%26%20MoW/31668</a><br /> Apple Fixes 0-Day<br />  Apple released updates to iOS and iPadOS fixing a bypass for USB Restricted Mode. The vulnerability is already being exploited.<br /><a href="https://support.apple.com/en-us/122174" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/122174</a><br /> AMD ZEN CPU Microcode Update<br />  An attacker is able to replace microcode on some AMD CPUs. This may alter how the CPUs function and Google released a PoC showing how it can be used to manipulate the random number generator.<br /><a href="https://github.com/google/security-research/security/advisories/GHSA-4xq7-4mgh-gp6w" target="_blank" rel="noreferrer noopener">https://github.com/google/security-research/security/advisories/GHSA-4xq7-4mgh-gp6w</a><br /> Trimble Cityworks Exploited<br />  CISA added a recent Trimble Cityworks vulnerabliity to its list of exploited vulnerabilities. <br /><a href="https://learn.assetlifecycle.trimble.com/i/1532182-cityworks-customer-communication-2025-02-06-docx/0?" target="_blank" rel="noreferrer noopener">https://learn.assetlifecycle.trimble.com/i/1532182-cityworks-customer-communication-2025-02-06-docx/0?</a><br /> Google Tag Manager Skimmer Steals Credit Card Info<br />  Sucuri released a blog post with updates to the mage cart campaign. The latest version is injecting malicious code as part of the google tag manager / analytics code.<br /><a href="https://blog.sucuri.net/2025/02/google-tag-manager-skimmer-steals-credit-card-info-from-magento-site.html" target="_blank" rel="noreferrer noopener">https://blog.sucuri.net/2025/02/google-tag-manager-skimmer-steals-credit-card-info-from-magento-site.html</a><br />]]></itunes:summary><itunes:duration>436</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,google; sucuri; amd; trimble; ,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9318</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Internet Stormcast Feb 10th 2025: Podcast Anniversary; SSL 2.0; Exposed Deepseek Installs; Crypto Scam costs</title><link>https://www.spreaker.com/episode/sans-internet-stormcast-feb-10th-2025-podcast-anniversary-ssl-2-0-exposed-deepseek-installs-crypto-scam-costs--64290980</link><description><![CDATA[<br /> SSL 2.0 Turns 30 This Sunday<br />   SSL was created in February 1995. However, back in 2005, only a year later, SSL 3.0 was released, and as of 2011, SSL 2.0 was deprecated, and support was removed from many crypto libraries. However, over 400k hosts are still exposed via SSL 2.0.<br /><a href="https://isc.sans.edu/diary/SSL%202.0%20turns%2030%20this%20Sunday...%20Perhaps%20the%20time%20has%20come%20to%20let%20it%20die%3F/31664" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SSL%202.0%20turns%2030%20this%20Sunday...%20Perhaps%20the%20time%20has%20come%20to%20let%20it%20die%3F/31664</a><br /> Deepseek News<br />  Many articles cover various security shortcomings in the Chinese Deepseek AI model. Remember that some of these issues are not unique to Deepseek.<br /><a href="https://www.upguard.com/blog/deepseek-adoption" target="_blank" rel="noreferrer noopener">https://www.upguard.com/blog/deepseek-adoption</a><br /><a href="https://www.reversinglabs.com/blog/rl-identifies-malware-ml-model-hosted-on-hugging-face" target="_blank" rel="noreferrer noopener">https://www.reversinglabs.com/blog/rl-identifies-malware-ml-model-hosted-on-hugging-face</a><br /><a href="https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak" target="_blank" rel="noreferrer noopener">https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak</a><br /><a href="https://www.nowsecure.com/blog/2025/02/06/nowsecure-uncovers-multiple-security-and-privacy-flaws-in-deepseek-ios-mobile-app/" target="_blank" rel="noreferrer noopener">https://www.nowsecure.com/blog/2025/02/06/nowsecure-uncovers-multiple-security-and-privacy-flaws-in-deepseek-ios-mobile-app/</a><br /> Crypto Wallet Scam Not For Free<br />   Didier looked closer at the recent dual signature crypto scams. These wallets are not free; attackers must spend money to set them up.<br /><a href="https://isc.sans.edu/diary/Crypto+Wallet+Scam+Not+For+Free/31666" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Crypto+Wallet+Scam+Not+For+Free/31666</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9316.mp3</guid><pubDate>Mon, 10 Feb 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64290980/9316.mp3" length="6038550" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 SSL 2.0 Turns 30 This Sunday
   SSL was created in February 1995. However, back in 2005, only a year later, SSL 3.0 was released, and as of 2011, SSL 2.0 was deprecated, and support was removed from many crypto libraries. However, over 400k hosts...</itunes:subtitle><itunes:summary><![CDATA[<br /> SSL 2.0 Turns 30 This Sunday<br />   SSL was created in February 1995. However, back in 2005, only a year later, SSL 3.0 was released, and as of 2011, SSL 2.0 was deprecated, and support was removed from many crypto libraries. However, over 400k hosts are still exposed via SSL 2.0.<br /><a href="https://isc.sans.edu/diary/SSL%202.0%20turns%2030%20this%20Sunday...%20Perhaps%20the%20time%20has%20come%20to%20let%20it%20die%3F/31664" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SSL%202.0%20turns%2030%20this%20Sunday...%20Perhaps%20the%20time%20has%20come%20to%20let%20it%20die%3F/31664</a><br /> Deepseek News<br />  Many articles cover various security shortcomings in the Chinese Deepseek AI model. Remember that some of these issues are not unique to Deepseek.<br /><a href="https://www.upguard.com/blog/deepseek-adoption" target="_blank" rel="noreferrer noopener">https://www.upguard.com/blog/deepseek-adoption</a><br /><a href="https://www.reversinglabs.com/blog/rl-identifies-malware-ml-model-hosted-on-hugging-face" target="_blank" rel="noreferrer noopener">https://www.reversinglabs.com/blog/rl-identifies-malware-ml-model-hosted-on-hugging-face</a><br /><a href="https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak" target="_blank" rel="noreferrer noopener">https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak</a><br /><a href="https://www.nowsecure.com/blog/2025/02/06/nowsecure-uncovers-multiple-security-and-privacy-flaws-in-deepseek-ios-mobile-app/" target="_blank" rel="noreferrer noopener">https://www.nowsecure.com/blog/2025/02/06/nowsecure-uncovers-multiple-security-and-privacy-flaws-in-deepseek-ios-mobile-app/</a><br /> Crypto Wallet Scam Not For Free<br />   Didier looked closer at the recent dual signature crypto scams. These wallets are not free; attackers must spend money to set them up.<br /><a href="https://isc.sans.edu/diary/Crypto+Wallet+Scam+Not+For+Free/31666" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Crypto+Wallet+Scam+Not+For+Free/31666</a><br />]]></itunes:summary><itunes:duration>412</itunes:duration><itunes:keywords>business,computer,crypto; deepseek; ssl; anniver,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9316</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Internet Stormcast Feb 7th 2025: Unbreakable Anti-Debugging;</title><link>https://www.spreaker.com/episode/sans-internet-stormcast-feb-7th-2025-unbreakable-anti-debugging--64239618</link><description><![CDATA[<br /> The Unbreakable Multi-Layer Anti-Debugging System<br />  Xavier found a nice Python script that included what it calls the "Unbreakable Multi-Layer Anti-Debugging System". Leave it up to Xavier to tear it appart for you.<br /><a href="https://isc.sans.edu/diary/The%20Unbreakable%20Multi-Layer%20Anti-Debugging%20System/31658" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20Unbreakable%20Multi-Layer%20Anti-Debugging%20System/31658</a><br /> Take my money: OCR crypto stealers in Google Play and App Store<br />  Malware using OCR on screen shots was available not just via Google Play, but also the Apple App Store.<br /><a href="https://securelist.com/sparkcat-stealer-in-app-store-and-google-play-2/115385/" target="_blank" rel="noreferrer noopener">https://securelist.com/sparkcat-stealer-in-app-store-and-google-play-2/115385/</a><br /> Threat Actors Still Leveraging Legit RMM Tool ScreenConnect<br />  Unsurprisingly, threat actors still like to use legit remote admin tools, like ScreenConnect, as a command and control channel. Silent Push outlines the latest trends and IoCs they found<br /><a href="https://www.silentpush.com/blog/screenconnect/" target="_blank" rel="noreferrer noopener">https://www.silentpush.com/blog/screenconnect/</a><br /> Cisco Identity Services Engine Insecure Java Deserialization and Authorization Bypass Vulnerabilities<br />  Java deserializing strikes again to allow arbitrary code execution. Cisco fixed this vulnerability and a authorization bypass issue in its Identity Services Engine<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multivuls-FTW9AOXF" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multivuls-FTW9AOXF</a><br /> F5 Update<br />  F5 fixes an interesting authentication bypass problem affecting TLS client certificates<br /><a href="https://my.f5.com/manage/s/article/K000149173" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000149173</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9314.mp3</guid><pubDate>Fri, 07 Feb 2025 01:28:34 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64239618/9314.mp3" length="5630055" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 The Unbreakable Multi-Layer Anti-Debugging System
  Xavier found a nice Python script that included what it calls the "Unbreakable Multi-Layer Anti-Debugging System". Leave it up to Xavier to tear it appart for you....</itunes:subtitle><itunes:summary><![CDATA[<br /> The Unbreakable Multi-Layer Anti-Debugging System<br />  Xavier found a nice Python script that included what it calls the "Unbreakable Multi-Layer Anti-Debugging System". Leave it up to Xavier to tear it appart for you.<br /><a href="https://isc.sans.edu/diary/The%20Unbreakable%20Multi-Layer%20Anti-Debugging%20System/31658" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20Unbreakable%20Multi-Layer%20Anti-Debugging%20System/31658</a><br /> Take my money: OCR crypto stealers in Google Play and App Store<br />  Malware using OCR on screen shots was available not just via Google Play, but also the Apple App Store.<br /><a href="https://securelist.com/sparkcat-stealer-in-app-store-and-google-play-2/115385/" target="_blank" rel="noreferrer noopener">https://securelist.com/sparkcat-stealer-in-app-store-and-google-play-2/115385/</a><br /> Threat Actors Still Leveraging Legit RMM Tool ScreenConnect<br />  Unsurprisingly, threat actors still like to use legit remote admin tools, like ScreenConnect, as a command and control channel. Silent Push outlines the latest trends and IoCs they found<br /><a href="https://www.silentpush.com/blog/screenconnect/" target="_blank" rel="noreferrer noopener">https://www.silentpush.com/blog/screenconnect/</a><br /> Cisco Identity Services Engine Insecure Java Deserialization and Authorization Bypass Vulnerabilities<br />  Java deserializing strikes again to allow arbitrary code execution. Cisco fixed this vulnerability and a authorization bypass issue in its Identity Services Engine<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multivuls-FTW9AOXF" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multivuls-FTW9AOXF</a><br /> F5 Update<br />  F5 fixes an interesting authentication bypass problem affecting TLS client certificates<br /><a href="https://my.f5.com/manage/s/article/K000149173" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000149173</a><br />]]></itunes:summary><itunes:duration>383</itunes:duration><itunes:keywords>business,cisco,computer,cyber,cybersecurity,daily,f5,hacking,infosec,internet,ise; ios; android; screenshots,it,java,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9314</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS Internet Stormcast Feb 6th 2025: com- prefix domain phishing; Win 10 ESU pricing; Firewall CT Policy; Veeam and Netgear patches</title><link>https://www.spreaker.com/episode/sans-internet-stormcast-feb-6th-2025-com-prefix-domain-phishing-win-10-esu-pricing-firewall-ct-policy-veeam-and-netgear-patches--64220916</link><description><![CDATA[<br /> Phishing via com- prefix domains<br />  Every day, attackers are registering a few hunder domain names starting with com-. These are used in phishing e-mails, like for example "toll fee scams", to create more convincing phishing links.<br /><a href="https://isc.sans.edu/diary/Phishing%20via%20%22com-%22%20prefix%20domains/31654" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Phishing%20via%20%22com-%22%20prefix%20domains/31654</a><br /> Microsoft Windows 10 Extended Security Updates<br />  Microsoft released pricing and additional details for the Windows 10 extended security updates. For the first year after official free updates stopped, security updates will be available for $61 for the first year.<br /><a href="https://learn.microsoft.com/en-us/windows/whats-new/extended-security-updates" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/whats-new/extended-security-updates</a><br /> Mozilla Enforcing Certificate Transparency<br />  Mozilla is following the lead from other browsers, and will require certificates to include a certificate signature timestamp as proof of compliance with certificate transparency requirements.<br /><a href="https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/OagRKpVirsA/m/Q4c89XG-EAAJ" target="_blank" rel="noreferrer noopener">https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/OagRKpVirsA/m/Q4c89XG-EAAJ</a><br /><a href="https://wiki.mozilla.org/SecurityEngineering/Certificate_Transparency#Enterprise_Policies" target="_blank" rel="noreferrer noopener">https://wiki.mozilla.org/SecurityEngineering/Certificate_Transparency#Enterprise_Policies</a><br /> Veeam Update<br />  Veeam's internal backup process may be used to execute arbitrary code by an attacker with a machine in the middle position.<br /><a href="https://www.veeam.com/kb4712" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4712</a><br /> Netgear Unauthenticated RCE<br /><a href="https://kb.netgear.com/000066558/Security-Advisory-for-Unauthenticated-RCE-on-Some-WiFi-Routers-PSV-2023-0039" target="_blank" rel="noreferrer noopener">https://kb.netgear.com/000066558/Security-Advisory-for-Unauthenticated-RCE-on-Some-WiFi-Routers-PSV-2023-0039</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9312.mp3</guid><pubDate>Thu, 06 Feb 2025 01:30:25 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64220916/9312.mp3" length="6197561" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Phishing via com- prefix domains
  Every day, attackers are registering a few hunder domain names starting with com-. These are used in phishing e-mails, like for example "toll fee scams", to create more convincing phishing links....</itunes:subtitle><itunes:summary><![CDATA[<br /> Phishing via com- prefix domains<br />  Every day, attackers are registering a few hunder domain names starting with com-. These are used in phishing e-mails, like for example "toll fee scams", to create more convincing phishing links.<br /><a href="https://isc.sans.edu/diary/Phishing%20via%20%22com-%22%20prefix%20domains/31654" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Phishing%20via%20%22com-%22%20prefix%20domains/31654</a><br /> Microsoft Windows 10 Extended Security Updates<br />  Microsoft released pricing and additional details for the Windows 10 extended security updates. For the first year after official free updates stopped, security updates will be available for $61 for the first year.<br /><a href="https://learn.microsoft.com/en-us/windows/whats-new/extended-security-updates" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/whats-new/extended-security-updates</a><br /> Mozilla Enforcing Certificate Transparency<br />  Mozilla is following the lead from other browsers, and will require certificates to include a certificate signature timestamp as proof of compliance with certificate transparency requirements.<br /><a href="https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/OagRKpVirsA/m/Q4c89XG-EAAJ" target="_blank" rel="noreferrer noopener">https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/OagRKpVirsA/m/Q4c89XG-EAAJ</a><br /><a href="https://wiki.mozilla.org/SecurityEngineering/Certificate_Transparency#Enterprise_Policies" target="_blank" rel="noreferrer noopener">https://wiki.mozilla.org/SecurityEngineering/Certificate_Transparency#Enterprise_Policies</a><br /> Veeam Update<br />  Veeam's internal backup process may be used to execute arbitrary code by an attacker with a machine in the middle position.<br /><a href="https://www.veeam.com/kb4712" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4712</a><br /> Netgear Unauthenticated RCE<br /><a href="https://kb.netgear.com/000066558/Security-Advisory-for-Unauthenticated-RCE-on-Some-WiFi-Routers-PSV-2023-0039" target="_blank" rel="noreferrer noopener">https://kb.netgear.com/000066558/Security-Advisory-for-Unauthenticated-RCE-on-Some-WiFi-Routers-PSV-2023-0039</a><br />]]></itunes:summary><itunes:duration>423</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,netgear; veeam; firefox; certi,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9312</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS ISC Stormcast Feb 5ht 2025: Feed Updates and Rosti; Resurrecting Dead S3 Buckets; Let's Encrypt Changes; Edge Device Security</title><link>https://www.spreaker.com/episode/sans-isc-stormcast-feb-5ht-2025-feed-updates-and-rosti-resurrecting-dead-s3-buckets-let-s-encrypt-changes-edge-device-security--64197637</link><description><![CDATA[<br /> Some Updates to Our Data Feeds<br />  We made some updates to the documentation for our data feeds, and added the neat Rosti Feed to our list as well as to our ipinfo page.<br /><a href="https://isc.sans.edu/diary/Some%20updates%20to%20our%20data%20feeds/31650" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Some%20updates%20to%20our%20data%20feeds/31650</a><br /> 8 Million Request Later We Meade the Solarwindws Supply Chain Attack Look Amateur<br />  While the title is a bit of watchTowr hyperbole, the problem of resurrecting dead S3 buckets back to live is real and needs to be addressed. Boring solutions will help not becoming an exciting headline.<br /><a href="https://labs.watchtowr.com/8-million-requests-later-we-made-the-solarwinds-supply-chain-attack-look-amateur/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/8-million-requests-later-we-made-the-solarwinds-supply-chain-attack-look-amateur/</a><br /> Let's Encrypt Ending Expiration Emails<br />  Let's Encrypt will no longer send emails for expiring certificates. They suggest other free services to send these emails for you<br /><a href="https://letsencrypt.org/2025/01/22/ending-expiration-emails/" target="_blank" rel="noreferrer noopener">https://letsencrypt.org/2025/01/22/ending-expiration-emails/</a><br /> Guidance and Strategies Protect Network Edge Edvices<br />  CISA and other agencies created a guidance document outlining how to protect edge devices like firewalls, vpn concentrators and other similar devices.<br /><a href="https://www.cisa.gov/resources-tools/resources/guidance-and-strategies-protect-network-edge-devices" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/resources-tools/resources/guidance-and-strategies-protect-network-edge-devices</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9310.mp3</guid><pubDate>Wed, 05 Feb 2025 01:53:31 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64197637/9310.mp3" length="6455924" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Some Updates to Our Data Feeds
  We made some updates to the documentation for our data feeds, and added the neat Rosti Feed to our list as well as to our ipinfo page.
https://isc.sans.edu/diary/Some%20updates%20to%20our%20data%20feeds/31650
 8...</itunes:subtitle><itunes:summary><![CDATA[<br /> Some Updates to Our Data Feeds<br />  We made some updates to the documentation for our data feeds, and added the neat Rosti Feed to our list as well as to our ipinfo page.<br /><a href="https://isc.sans.edu/diary/Some%20updates%20to%20our%20data%20feeds/31650" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Some%20updates%20to%20our%20data%20feeds/31650</a><br /> 8 Million Request Later We Meade the Solarwindws Supply Chain Attack Look Amateur<br />  While the title is a bit of watchTowr hyperbole, the problem of resurrecting dead S3 buckets back to live is real and needs to be addressed. Boring solutions will help not becoming an exciting headline.<br /><a href="https://labs.watchtowr.com/8-million-requests-later-we-made-the-solarwinds-supply-chain-attack-look-amateur/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/8-million-requests-later-we-made-the-solarwinds-supply-chain-attack-look-amateur/</a><br /> Let's Encrypt Ending Expiration Emails<br />  Let's Encrypt will no longer send emails for expiring certificates. They suggest other free services to send these emails for you<br /><a href="https://letsencrypt.org/2025/01/22/ending-expiration-emails/" target="_blank" rel="noreferrer noopener">https://letsencrypt.org/2025/01/22/ending-expiration-emails/</a><br /> Guidance and Strategies Protect Network Edge Edvices<br />  CISA and other agencies created a guidance document outlining how to protect edge devices like firewalls, vpn concentrators and other similar devices.<br /><a href="https://www.cisa.gov/resources-tools/resources/guidance-and-strategies-protect-network-edge-devices" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/resources-tools/resources/guidance-and-strategies-protect-network-edge-devices</a><br />]]></itunes:summary><itunes:duration>442</itunes:duration><itunes:keywords>business,cisa; edge; devices; guidance;,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9310</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS ISC Stormcast Feb 4th 2025: Crypto Scam; Mediatek and D-Link Patches; Microsoft ends VPN Service</title><link>https://www.spreaker.com/episode/sans-isc-stormcast-feb-4th-2025-crypto-scam-mediatek-and-d-link-patches-microsoft-ends-vpn-service--64180645</link><description><![CDATA[<br /> Crypto Wallet Scam<br />  YouTube spam messages leak private keys to crypto wallets. However, these keys can not be used to withdraw funds. Victims are scammed into depositing "gas fees" which are then collected by the scammer.<br /><a href="https://isc.sans.edu/diary/Crypto%20Wallet%20Scam/31646" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Crypto%20Wallet%20Scam/31646</a><br /> Mediatek Patches<br />  Mediatek patched numerous vulnerabilities in its WLAN products. Some allow for unauthenticated arbitrary code execution<br /><a href="https://corp.mediatek.com/product-security-bulletin/February-2025" target="_blank" rel="noreferrer noopener">https://corp.mediatek.com/product-security-bulletin/February-2025</a><br /> D-Link Vulnerability<br />  D-Link disclosed a vulnerability in older routers that as of May no longer receive any updates. Your only option is to upgrade hardare.<br /><a href="https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10415" target="_blank" rel="noreferrer noopener">https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10415</a><br /> Microsoft Discontinues VPN Service<br />  Microsoft is shutting down the VPN service that was included as part of Microsoft Defender<br /><a href="https://support.microsoft.com/en-au/topic/end-of-support-privacy-protection-vpn-in-microsoft-defender-for-individuals-8b503da5-732a-4472-833a-e2ddca53036a" target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-au/topic/end-of-support-privacy-protection-vpn-in-microsoft-defender-for-individuals-8b503da5-732a-4472-833a-e2ddca53036a</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9308.mp3</guid><pubDate>Tue, 04 Feb 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64180645/9308.mp3" length="5493011" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Crypto Wallet Scam
  YouTube spam messages leak private keys to crypto wallets. However, these keys can not be used to withdraw funds. Victims are scammed into depositing "gas fees" which are then collected by the scammer....</itunes:subtitle><itunes:summary><![CDATA[<br /> Crypto Wallet Scam<br />  YouTube spam messages leak private keys to crypto wallets. However, these keys can not be used to withdraw funds. Victims are scammed into depositing "gas fees" which are then collected by the scammer.<br /><a href="https://isc.sans.edu/diary/Crypto%20Wallet%20Scam/31646" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Crypto%20Wallet%20Scam/31646</a><br /> Mediatek Patches<br />  Mediatek patched numerous vulnerabilities in its WLAN products. Some allow for unauthenticated arbitrary code execution<br /><a href="https://corp.mediatek.com/product-security-bulletin/February-2025" target="_blank" rel="noreferrer noopener">https://corp.mediatek.com/product-security-bulletin/February-2025</a><br /> D-Link Vulnerability<br />  D-Link disclosed a vulnerability in older routers that as of May no longer receive any updates. Your only option is to upgrade hardare.<br /><a href="https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10415" target="_blank" rel="noreferrer noopener">https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10415</a><br /> Microsoft Discontinues VPN Service<br />  Microsoft is shutting down the VPN service that was included as part of Microsoft Defender<br /><a href="https://support.microsoft.com/en-au/topic/end-of-support-privacy-protection-vpn-in-microsoft-defender-for-individuals-8b503da5-732a-4472-833a-e2ddca53036a" target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-au/topic/end-of-support-privacy-protection-vpn-in-microsoft-defender-for-individuals-8b503da5-732a-4472-833a-e2ddca53036a</a><br />]]></itunes:summary><itunes:duration>373</itunes:duration><itunes:keywords>business,computer,crypto,cyber,cybersecurity,daily,dlink,hacking,infosec,internet,it,mediatek,microsoft,network,news,okx,scam,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9308</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS ISC Stormcast Feb 3rd 2025: Automating Cyber Ranges; Deepseek Scams; PyPi Archived State; Medical Backdoors</title><link>https://www.spreaker.com/episode/sans-isc-stormcast-feb-3rd-2025-automating-cyber-ranges-deepseek-scams-pypi-archived-state-medical-backdoors--64153945</link><description><![CDATA[<br /> To Simulate or Replicate: Crafting Cyber Ranges<br />  Automating the creation of cyber ranges. This will be a multi part series and this part covers creating the DNS configuration in Windows<br /><a href="https://isc.sans.edu/diary/To%20Simulate%20or%20Replicate%3A%20Crafting%20Cyber%20Ranges/31642" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/To%20Simulate%20or%20Replicate%3A%20Crafting%20Cyber%20Ranges/31642</a><br /> Scammers Exploiting Deepseek Hype<br />  Scammers are using the hype around Deepseek, and some of the confusion caused by it's site not being reachable, to scam users into installing malware. I am also including a link to a "jailbreak" of Deepseek (this part was not covered in the podcast).<br /><a href="https://www.welivesecurity.com/en/cybersecurity/scammers-exploiting-deepseek-hype/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/cybersecurity/scammers-exploiting-deepseek-hype/</a><br /><a href="https://lab.wallarm.com/jailbreaking-generative-ai/" target="_blank" rel="noreferrer noopener">https://lab.wallarm.com/jailbreaking-generative-ai/</a><br /> PyPi Archived Status<br />  PyPi introduced a new feature to mark repositories as archived. This implies that the author is no longer maintaining the particular package<br /><a href="https://blog.pypi.org/posts/2025-01-30-archival/" target="_blank" rel="noreferrer noopener">https://blog.pypi.org/posts/2025-01-30-archival/</a><br /> ICS Mecial Advisory: Comtec Patient Monitor Backdoor<br />  And interested backdoor was found in a Comtech Patient Monitor.<br /><a href="https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-030-01" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-030-01</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9306.mp3</guid><pubDate>Mon, 03 Feb 2025 02:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64153945/9306.mp3" length="5638390" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 To Simulate or Replicate: Crafting Cyber Ranges
  Automating the creation of cyber ranges. This will be a multi part series and this part covers creating the DNS configuration in Windows...</itunes:subtitle><itunes:summary><![CDATA[<br /> To Simulate or Replicate: Crafting Cyber Ranges<br />  Automating the creation of cyber ranges. This will be a multi part series and this part covers creating the DNS configuration in Windows<br /><a href="https://isc.sans.edu/diary/To%20Simulate%20or%20Replicate%3A%20Crafting%20Cyber%20Ranges/31642" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/To%20Simulate%20or%20Replicate%3A%20Crafting%20Cyber%20Ranges/31642</a><br /> Scammers Exploiting Deepseek Hype<br />  Scammers are using the hype around Deepseek, and some of the confusion caused by it's site not being reachable, to scam users into installing malware. I am also including a link to a "jailbreak" of Deepseek (this part was not covered in the podcast).<br /><a href="https://www.welivesecurity.com/en/cybersecurity/scammers-exploiting-deepseek-hype/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/cybersecurity/scammers-exploiting-deepseek-hype/</a><br /><a href="https://lab.wallarm.com/jailbreaking-generative-ai/" target="_blank" rel="noreferrer noopener">https://lab.wallarm.com/jailbreaking-generative-ai/</a><br /> PyPi Archived Status<br />  PyPi introduced a new feature to mark repositories as archived. This implies that the author is no longer maintaining the particular package<br /><a href="https://blog.pypi.org/posts/2025-01-30-archival/" target="_blank" rel="noreferrer noopener">https://blog.pypi.org/posts/2025-01-30-archival/</a><br /> ICS Mecial Advisory: Comtec Patient Monitor Backdoor<br />  And interested backdoor was found in a Comtech Patient Monitor.<br /><a href="https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-030-01" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-030-01</a><br />]]></itunes:summary><itunes:duration>384</itunes:duration><itunes:keywords>business,computer,comtech; medical; backdoor; py,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9306</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS ISC Stormcast Jan 31st 2025: Old Netgear Vuln in Depth; Lightning AI RCE; Canon Printer RCE; Deepseek Leak;</title><link>https://www.spreaker.com/episode/sans-isc-stormcast-jan-31st-2025-old-netgear-vuln-in-depth-lightning-ai-rce-canon-printer-rce-deepseek-leak--64064985</link><description><![CDATA[<br /> PCAPs or It Didn't Happen: Exposing an Old Netgear Vulnerability Still Active in 2025 [Guest Diary]<br /><a href="https://isc.sans.edu/diary/PCAPs%20or%20It%20Didn%27t%20Happen%3A%20Exposing%20an%20Old%20Netgear%20Vulnerability%20Still%20Active%20in%202025%20%5BGuest%20Diary%5D/31638" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/PCAPs%20or%20It%20Didn%27t%20Happen%3A%20Exposing%20an%20Old%20Netgear%20Vulnerability%20Still%20Active%20in%202025%20%5BGuest%20Diary%5D/31638</a><br /> RCE Vulnerablity in AI Development Platform Lightning AI<br />  Noma Security discovered a neat remote code execution vulnerability in Lightning AI. This vulnerability is exploitable by tricking a logged in user into clicking a simple link.<br /><a href="https://noma.security/noma-research-discovers-rce-vulnerability-in-ai-development-platform-lightning-ai/" target="_blank" rel="noreferrer noopener">https://noma.security/noma-research-discovers-rce-vulnerability-in-ai-development-platform-lightning-ai/</a><br /> Canon Laser Printers and Small Office Multifunctional Printer Vulnerabilities<br />  Canon fixed three different vulnerablities affecting various laser and small office multifunctional printers. These vulnerabilities may lead to remote code execution, and there are some interesting exploit opportunities<br /><a href="https://www.usa.canon.com/support/canon-product-advisories/service-notice-regarding-vulnerability-measure-against-buffer-overflow-for-laser-printers-and-small-office-multifunctional-printers" target="_blank" rel="noreferrer noopener">https://www.usa.canon.com/support/canon-product-advisories/service-notice-regarding-vulnerability-measure-against-buffer-overflow-for-laser-printers-and-small-office-multifunctional-printers</a><br /> Deepseek ClickHouse Database Leak<br /><a href="https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak" target="_blank" rel="noreferrer noopener">https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9304.mp3</guid><pubDate>Fri, 31 Jan 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64064985/9304.mp3" length="5031335" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 PCAPs or It Didn't Happen: Exposing an Old Netgear Vulnerability Still Active in 2025 [Guest Diary]...</itunes:subtitle><itunes:summary><![CDATA[<br /> PCAPs or It Didn't Happen: Exposing an Old Netgear Vulnerability Still Active in 2025 [Guest Diary]<br /><a href="https://isc.sans.edu/diary/PCAPs%20or%20It%20Didn%27t%20Happen%3A%20Exposing%20an%20Old%20Netgear%20Vulnerability%20Still%20Active%20in%202025%20%5BGuest%20Diary%5D/31638" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/PCAPs%20or%20It%20Didn%27t%20Happen%3A%20Exposing%20an%20Old%20Netgear%20Vulnerability%20Still%20Active%20in%202025%20%5BGuest%20Diary%5D/31638</a><br /> RCE Vulnerablity in AI Development Platform Lightning AI<br />  Noma Security discovered a neat remote code execution vulnerability in Lightning AI. This vulnerability is exploitable by tricking a logged in user into clicking a simple link.<br /><a href="https://noma.security/noma-research-discovers-rce-vulnerability-in-ai-development-platform-lightning-ai/" target="_blank" rel="noreferrer noopener">https://noma.security/noma-research-discovers-rce-vulnerability-in-ai-development-platform-lightning-ai/</a><br /> Canon Laser Printers and Small Office Multifunctional Printer Vulnerabilities<br />  Canon fixed three different vulnerablities affecting various laser and small office multifunctional printers. These vulnerabilities may lead to remote code execution, and there are some interesting exploit opportunities<br /><a href="https://www.usa.canon.com/support/canon-product-advisories/service-notice-regarding-vulnerability-measure-against-buffer-overflow-for-laser-printers-and-small-office-multifunctional-printers" target="_blank" rel="noreferrer noopener">https://www.usa.canon.com/support/canon-product-advisories/service-notice-regarding-vulnerability-measure-against-buffer-overflow-for-laser-printers-and-small-office-multifunctional-printers</a><br /> Deepseek ClickHouse Database Leak<br /><a href="https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak" target="_blank" rel="noreferrer noopener">https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak</a><br />]]></itunes:summary><itunes:duration>340</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,deepseek; clickhouse; canon; a,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9304</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS ISC Stormcast, Jan 30th 2025: Python vs. Powershell; Fortinet Exploits and Patch Policy; Voyager PHP Framework Vuln; Zyxel Targeted; VM</title><link>https://www.spreaker.com/episode/sans-isc-stormcast-jan-30th-2025-python-vs-powershell-fortinet-exploits-and-patch-policy-voyager-php-framework-vuln-zyxel-targeted-vm--64026176</link><description><![CDATA[<br /> From PowerShell to a Python Obfuscation Race!<br />  This information stealer not only emulates a PDF document convincingly, but also includes its own Python environment for Windows<br /><a href="https://isc.sans.edu/diary/From%20PowerShell%20to%20a%20Python%20Obfuscation%20Race!/31634" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/From%20PowerShell%20to%20a%20Python%20Obfuscation%20Race!/31634</a><br /> Alleged Active Exploit Sale of CVE-2024-55591 on Fortinet Devices<br />  An exploit for this week's Fortinet vulnerability is for sale on russian forums. Fortinet also requires patching of devices without cloud license within seven days of patch release<br /><a href="https://x.com/MonThreat/status/1884577840185643345" target="_blank" rel="noreferrer noopener">https://x.com/MonThreat/status/1884577840185643345</a><br /><a href="https://community.fortinet.com/t5/Support-Forum/Firmware-upgrade-policy/td-p/373376" target="_blank" rel="noreferrer noopener">https://community.fortinet.com/t5/Support-Forum/Firmware-upgrade-policy/td-p/373376</a><br /> The Tainted Voyage: Uncovering Voyager's Vulnerabilities<br />  Sonarcube identified vulnerabilities in the popular PHP package Voyager. One of them allows arbitrary file uploads.<br /><a href="https://www.sonarsource.com/blog/the-tainted-voyage-uncovering-voyagers-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://www.sonarsource.com/blog/the-tainted-voyage-uncovering-voyagers-vulnerabilities/</a><br /> Hackers exploit critical unpatched flaw in Zyxel CPE devices<br />  A currently unpatches vulnerablity in Zyxel devices is actively exploited.<br /><a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-unpatched-flaw-in-zyxel-cpe-devices/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-unpatched-flaw-in-zyxel-cpe-devices/</a><br /> VMSA-2025-0002: VMware Avi Load Balancer addresses an unauthenticated blind SQL Injection vulnerability (CVE-2025-22217)<br />  VMWare released a patch for the AVI Load Balancer addressing an unauthenticated blink SQL injection vulnerability.<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25346" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25346</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9302.mp3</guid><pubDate>Thu, 30 Jan 2025 02:00:12 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/64026176/9302.mp3" length="4936546" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 From PowerShell to a Python Obfuscation Race!
  This information stealer not only emulates a PDF document convincingly, but also includes its own Python environment for Windows...</itunes:subtitle><itunes:summary><![CDATA[<br /> From PowerShell to a Python Obfuscation Race!<br />  This information stealer not only emulates a PDF document convincingly, but also includes its own Python environment for Windows<br /><a href="https://isc.sans.edu/diary/From%20PowerShell%20to%20a%20Python%20Obfuscation%20Race!/31634" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/From%20PowerShell%20to%20a%20Python%20Obfuscation%20Race!/31634</a><br /> Alleged Active Exploit Sale of CVE-2024-55591 on Fortinet Devices<br />  An exploit for this week's Fortinet vulnerability is for sale on russian forums. Fortinet also requires patching of devices without cloud license within seven days of patch release<br /><a href="https://x.com/MonThreat/status/1884577840185643345" target="_blank" rel="noreferrer noopener">https://x.com/MonThreat/status/1884577840185643345</a><br /><a href="https://community.fortinet.com/t5/Support-Forum/Firmware-upgrade-policy/td-p/373376" target="_blank" rel="noreferrer noopener">https://community.fortinet.com/t5/Support-Forum/Firmware-upgrade-policy/td-p/373376</a><br /> The Tainted Voyage: Uncovering Voyager's Vulnerabilities<br />  Sonarcube identified vulnerabilities in the popular PHP package Voyager. One of them allows arbitrary file uploads.<br /><a href="https://www.sonarsource.com/blog/the-tainted-voyage-uncovering-voyagers-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://www.sonarsource.com/blog/the-tainted-voyage-uncovering-voyagers-vulnerabilities/</a><br /> Hackers exploit critical unpatched flaw in Zyxel CPE devices<br />  A currently unpatches vulnerablity in Zyxel devices is actively exploited.<br /><a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-unpatched-flaw-in-zyxel-cpe-devices/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-unpatched-flaw-in-zyxel-cpe-devices/</a><br /> VMSA-2025-0002: VMware Avi Load Balancer addresses an unauthenticated blind SQL Injection vulnerability (CVE-2025-22217)<br />  VMWare released a patch for the AVI Load Balancer addressing an unauthenticated blink SQL injection vulnerability.<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25346" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25346</a><br />]]></itunes:summary><itunes:duration>333</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,vmware; avi load balancer; sql</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9302</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS ISC Stormcast, Jan 29th 2025: Python Crypto Stealer; SimpleHelp Exploited; Apple Silicon Vuln; Teamviewer Vuln; Odd QR Code</title><link>https://www.spreaker.com/episode/sans-isc-stormcast-jan-29th-2025-python-crypto-stealer-simplehelp-exploited-apple-silicon-vuln-teamviewer-vuln-odd-qr-code--63985703</link><description><![CDATA[<br /> Learn about fileless crypto stealers written in Python, the ongoing exploitation of recent SimpleHelp vulnerablities, new Apple Silicon Sidechannel attacks a Team Viewer Vulnerablity and an odd QR Code<br /> Fileless Python InfoStealer Targeting Exodus<br />  This Python script targets Exodus crypto wallet and password managers to steal crypto currencies. It does not save exfiltrated data in files, but keeps it in memory for exfiltration<br /><a href="https://isc.sans.edu/diary/Fileless%20Python%20InfoStealer%20Targeting%20Exodus/31630" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Fileless%20Python%20InfoStealer%20Targeting%20Exodus/31630</a><br /> Campaign Exploiting SimpleHelp Vulnerablity<br />  Arcticwolf observed attacks exploiting SimpleHelp for initial access to networks. It has not been verified, but is assumed that vulnerabilities made public about a week ago are being exploited.<br /><a href="https://arcticwolf.com/resources/blog-uk/arctic-wolf-observes-campaign-exploiting-simplehelp-rmm-software-initial-access/" target="_blank" rel="noreferrer noopener">https://arcticwolf.com/resources/blog-uk/arctic-wolf-observes-campaign-exploiting-simplehelp-rmm-software-initial-access/</a><br /> Two new Side Channel Vulnerabilities in Apple Silicon<br />  SLAP (Data Speculation Attacks via Load Address Prediction): This attack exploits the Load Address Predictor in Apple CPUs starting with the M2/A15, allowing unauthorized access to sensitive data by mispredicting memory addresses. FLOP (Breaking the Apple M3 CPU via False Load Output Predictions): This attack targets the Load Value Predictor in Apple's M3/A17 CPUs, enabling attackers to execute arbitrary computations on incorrect data, potentially leaking sensitive information.<br /><a href="https://predictors.fail/" target="_blank" rel="noreferrer noopener">https://predictors.fail/</a><br /> Teamviewer Security Bulletin<br />  Teamviewer patched a privilege escalation vulnerability CVE-2025-0065 <br /><a href="https://www.teamviewer.com/en-us/resources/trust-center/security-bulletins/tv-2025-1001/" target="_blank" rel="noreferrer noopener">https://www.teamviewer.com/en-us/resources/trust-center/security-bulletins/tv-2025-1001/</a><br /> Odd QR Code<br />  A QR code may resolve to a different URL if looked at at an angle.<br /><a href="https://mstdn.social/@isziaui/113874436953157913" target="_blank" rel="noreferrer noopener">https://mstdn.social/@isziaui/113874436953157913</a><br /> Limited Discount for SANS Baltimore<br /><a href="https://sans.org/u/1zQd" target="_blank" rel="noreferrer noopener">https://sans.org/u/1zQd</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9300.mp3</guid><pubDate>Wed, 29 Jan 2025 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63985703/9300.mp3" length="5421254" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Learn about fileless crypto stealers written in Python, the ongoing exploitation of recent SimpleHelp vulnerablities, new Apple Silicon Sidechannel attacks a Team Viewer Vulnerablity and an odd QR Code
 Fileless Python InfoStealer Targeting Exodus...</itunes:subtitle><itunes:summary><![CDATA[<br /> Learn about fileless crypto stealers written in Python, the ongoing exploitation of recent SimpleHelp vulnerablities, new Apple Silicon Sidechannel attacks a Team Viewer Vulnerablity and an odd QR Code<br /> Fileless Python InfoStealer Targeting Exodus<br />  This Python script targets Exodus crypto wallet and password managers to steal crypto currencies. It does not save exfiltrated data in files, but keeps it in memory for exfiltration<br /><a href="https://isc.sans.edu/diary/Fileless%20Python%20InfoStealer%20Targeting%20Exodus/31630" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Fileless%20Python%20InfoStealer%20Targeting%20Exodus/31630</a><br /> Campaign Exploiting SimpleHelp Vulnerablity<br />  Arcticwolf observed attacks exploiting SimpleHelp for initial access to networks. It has not been verified, but is assumed that vulnerabilities made public about a week ago are being exploited.<br /><a href="https://arcticwolf.com/resources/blog-uk/arctic-wolf-observes-campaign-exploiting-simplehelp-rmm-software-initial-access/" target="_blank" rel="noreferrer noopener">https://arcticwolf.com/resources/blog-uk/arctic-wolf-observes-campaign-exploiting-simplehelp-rmm-software-initial-access/</a><br /> Two new Side Channel Vulnerabilities in Apple Silicon<br />  SLAP (Data Speculation Attacks via Load Address Prediction): This attack exploits the Load Address Predictor in Apple CPUs starting with the M2/A15, allowing unauthorized access to sensitive data by mispredicting memory addresses. FLOP (Breaking the Apple M3 CPU via False Load Output Predictions): This attack targets the Load Value Predictor in Apple's M3/A17 CPUs, enabling attackers to execute arbitrary computations on incorrect data, potentially leaking sensitive information.<br /><a href="https://predictors.fail/" target="_blank" rel="noreferrer noopener">https://predictors.fail/</a><br /> Teamviewer Security Bulletin<br />  Teamviewer patched a privilege escalation vulnerability CVE-2025-0065 <br /><a href="https://www.teamviewer.com/en-us/resources/trust-center/security-bulletins/tv-2025-1001/" target="_blank" rel="noreferrer noopener">https://www.teamviewer.com/en-us/resources/trust-center/security-bulletins/tv-2025-1001/</a><br /> Odd QR Code<br />  A QR code may resolve to a different URL if looked at at an angle.<br /><a href="https://mstdn.social/@isziaui/113874436953157913" target="_blank" rel="noreferrer noopener">https://mstdn.social/@isziaui/113874436953157913</a><br /> Limited Discount for SANS Baltimore<br /><a href="https://sans.org/u/1zQd" target="_blank" rel="noreferrer noopener">https://sans.org/u/1zQd</a><br />]]></itunes:summary><itunes:duration>368</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,qr code; teamviewer; apple sil,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9300</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS ISC Stormcast, Jan 28th 2025: Z-Shy Phishing; Apple Patches 0-Day; Fortinet Exploit Details; Github and Apache Solr Patches</title><link>https://www.spreaker.com/episode/sans-isc-stormcast-jan-28th-2025-z-shy-phishing-apple-patches-0-day-fortinet-exploit-details-github-and-apache-solr-patches--63947581</link><description><![CDATA[<br /> This episode shows how attackers are bypassing phishing filter by abusing the "shy" softhyphen HTML entitiy. We got an update from Apple fixing a 0-day vulnerability in addition to a number of other issues. watchTowr show how to exploit an interesting FortiOS vulnerability and we have patches for Github Desktop and Apache Solr<br /> An unusal shy z-wasp phish<br /><a href="https://isc.sans.edu/diary/An%20unusual%20%22shy%20z-wasp%22%20phishing/31626" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/An%20unusual%20%22shy%20z-wasp%22%20phishing/31626</a><br />  How the soft hyphen "shy" HTML entity can be abused to bypass e-mail filters<br /> Apple Patches<br /><a href="https://support.apple.com/en-us/100100" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/100100</a><br />  Apple released patches for all of its operating systems, fixing a 0-day vulnerability among many others issues<br /> Get Fortirekt I am the Super_admin now<br /><a href="https://labs.watchtowr.com/get-fortirekt-i-am-the-super_admin-now-fortios-authentication-bypass-cve-2024-55591/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/get-fortirekt-i-am-the-super_admin-now-fortios-authentication-bypass-cve-2024-55591/</a><br />  Details about a recent FortiOS Vulnerability<br /> GitHub Desktop Vulnerability<br /><a href="https://thehackernews.com/2025/01/github-desktop-vulnerability-risks.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2025/01/github-desktop-vulnerability-risks.html</a><br /> Apache Solr Vulnerability<br /><a href="https://solr.apache.org/security.html#cve-2024-52012-apache-solr-configset-upload-on-windows-allows-arbitrary-path-write-access" target="_blank" rel="noreferrer noopener">https://solr.apache.org/security.html#cve-2024-52012-apache-solr-configset-upload-on-windows-allows-arbitrary-path-write-access</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9298.mp3</guid><pubDate>Tue, 28 Jan 2025 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63947581/9298.mp3" length="5509203" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 This episode shows how attackers are bypassing phishing filter by abusing the "shy" softhyphen HTML entitiy. We got an update from Apple fixing a 0-day vulnerability in addition to a number of other issues. watchTowr show how to exploit an...</itunes:subtitle><itunes:summary><![CDATA[<br /> This episode shows how attackers are bypassing phishing filter by abusing the "shy" softhyphen HTML entitiy. We got an update from Apple fixing a 0-day vulnerability in addition to a number of other issues. watchTowr show how to exploit an interesting FortiOS vulnerability and we have patches for Github Desktop and Apache Solr<br /> An unusal shy z-wasp phish<br /><a href="https://isc.sans.edu/diary/An%20unusual%20%22shy%20z-wasp%22%20phishing/31626" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/An%20unusual%20%22shy%20z-wasp%22%20phishing/31626</a><br />  How the soft hyphen "shy" HTML entity can be abused to bypass e-mail filters<br /> Apple Patches<br /><a href="https://support.apple.com/en-us/100100" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/100100</a><br />  Apple released patches for all of its operating systems, fixing a 0-day vulnerability among many others issues<br /> Get Fortirekt I am the Super_admin now<br /><a href="https://labs.watchtowr.com/get-fortirekt-i-am-the-super_admin-now-fortios-authentication-bypass-cve-2024-55591/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/get-fortirekt-i-am-the-super_admin-now-fortios-authentication-bypass-cve-2024-55591/</a><br />  Details about a recent FortiOS Vulnerability<br /> GitHub Desktop Vulnerability<br /><a href="https://thehackernews.com/2025/01/github-desktop-vulnerability-risks.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2025/01/github-desktop-vulnerability-risks.html</a><br /> Apache Solr Vulnerability<br /><a href="https://solr.apache.org/security.html#cve-2024-52012-apache-solr-configset-upload-on-windows-allows-arbitrary-path-write-access" target="_blank" rel="noreferrer noopener">https://solr.apache.org/security.html#cve-2024-52012-apache-solr-configset-upload-on-windows-allows-arbitrary-path-write-access</a><br />]]></itunes:summary><itunes:duration>374</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,solr; github; desktop; fortine</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9298</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS ISC Stormcast, Jan 27, 2025: Access Brokers; Llama Stack Vuln; ESXi SSH Tunnels; Zyxel Boot Loops; Subary StarLeak</title><link>https://www.spreaker.com/episode/sans-isc-stormcast-jan-27-2025-access-brokers-llama-stack-vuln-esxi-ssh-tunnels-zyxel-boot-loops-subary-starleak--63923347</link><description><![CDATA[<br /> Guest Diary: How Access Brokers Maintain Persistence<br />  Explore how cybercriminals utilize access brokers to persist within networks and the impact this has on organizational security.<br /><a href="https://isc.sans.edu/forums/diary/Guest+Diary+How+Access+Brokers+Maintain+Persistence/31600/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Guest+Diary+How+Access+Brokers+Maintain+Persistence/31600/</a><br /> Critical Vulnerability in Meta's Llama Stack (CVE-2024-50050)<br />  A deep dive into CVE-2024-50050, a critical vulnerability affecting Meta's Llama Stack, with exploitation details and mitigation strategies.<br /><a href="https://www.oligo.security/blog/cve-2024-50050-critical-vulnerability-in-meta-llama-llama-stack" target="_blank" rel="noreferrer noopener">https://www.oligo.security/blog/cve-2024-50050-critical-vulnerability-in-meta-llama-llama-stack</a><br /> ESXi Ransomware and SSH Tunneling Defense Strategies<br />  Learn how to fortify your infrastructure against ransomware targeting ESXi environments, focusing on SSH tunneling and proactive measures.<br /><a href="https://www.sygnia.co/blog/esxi-ransomware-ssh-tunneling-defense-strategies/" target="_blank" rel="noreferrer noopener">https://www.sygnia.co/blog/esxi-ransomware-ssh-tunneling-defense-strategies/</a><br /> Zyxel USG FLEX/ATP Series Application Signature Recovery Steps<br />  Addressing issues with Zyxel s USG FLEX/ATP Series application signatures as of January 24, 2025, with a detailed recovery guide.<br /><a href="https://support.zyxel.eu/hc/en-us/articles/24159250192658-USG-FLEX-ATP-Series-Recovery-Steps-for-Application-Signature-Issue-on-January-24th-2025" target="_blank" rel="noreferrer noopener">https://support.zyxel.eu/hc/en-us/articles/24159250192658-USG-FLEX-ATP-Series-Recovery-Steps-for-Application-Signature-Issue-on-January-24th-2025</a><br /> Subaru Starlink Vulnerability Exposed Cars to Remote Hacking<br />  Discussing how a vulnerability in Subaru s Starlink system left vehicles susceptible to remote exploitation and the steps taken to resolve it.<br /><a href="https://www.securityweek.com/subaru-starlink-vulnerability-exposed-cars-to-remote-hacking/" target="_blank" rel="noreferrer noopener">https://www.securityweek.com/subaru-starlink-vulnerability-exposed-cars-to-remote-hacking/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9296.mp3</guid><pubDate>Mon, 27 Jan 2025 00:20:09 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63923347/9296.mp3" length="5712795" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 Guest Diary: How Access Brokers Maintain Persistence
  Explore how cybercriminals utilize access brokers to persist within networks and the impact this has on organizational security....</itunes:subtitle><itunes:summary><![CDATA[<br /> Guest Diary: How Access Brokers Maintain Persistence<br />  Explore how cybercriminals utilize access brokers to persist within networks and the impact this has on organizational security.<br /><a href="https://isc.sans.edu/forums/diary/Guest+Diary+How+Access+Brokers+Maintain+Persistence/31600/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Guest+Diary+How+Access+Brokers+Maintain+Persistence/31600/</a><br /> Critical Vulnerability in Meta's Llama Stack (CVE-2024-50050)<br />  A deep dive into CVE-2024-50050, a critical vulnerability affecting Meta's Llama Stack, with exploitation details and mitigation strategies.<br /><a href="https://www.oligo.security/blog/cve-2024-50050-critical-vulnerability-in-meta-llama-llama-stack" target="_blank" rel="noreferrer noopener">https://www.oligo.security/blog/cve-2024-50050-critical-vulnerability-in-meta-llama-llama-stack</a><br /> ESXi Ransomware and SSH Tunneling Defense Strategies<br />  Learn how to fortify your infrastructure against ransomware targeting ESXi environments, focusing on SSH tunneling and proactive measures.<br /><a href="https://www.sygnia.co/blog/esxi-ransomware-ssh-tunneling-defense-strategies/" target="_blank" rel="noreferrer noopener">https://www.sygnia.co/blog/esxi-ransomware-ssh-tunneling-defense-strategies/</a><br /> Zyxel USG FLEX/ATP Series Application Signature Recovery Steps<br />  Addressing issues with Zyxel s USG FLEX/ATP Series application signatures as of January 24, 2025, with a detailed recovery guide.<br /><a href="https://support.zyxel.eu/hc/en-us/articles/24159250192658-USG-FLEX-ATP-Series-Recovery-Steps-for-Application-Signature-Issue-on-January-24th-2025" target="_blank" rel="noreferrer noopener">https://support.zyxel.eu/hc/en-us/articles/24159250192658-USG-FLEX-ATP-Series-Recovery-Steps-for-Application-Signature-Issue-on-January-24th-2025</a><br /> Subaru Starlink Vulnerability Exposed Cars to Remote Hacking<br />  Discussing how a vulnerability in Subaru s Starlink system left vehicles susceptible to remote exploitation and the steps taken to resolve it.<br /><a href="https://www.securityweek.com/subaru-starlink-vulnerability-exposed-cars-to-remote-hacking/" target="_blank" rel="noreferrer noopener">https://www.securityweek.com/subaru-starlink-vulnerability-exposed-cars-to-remote-hacking/</a><br />]]></itunes:summary><itunes:duration>389</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,subaru; starlink; zyxel; usg f</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9296</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS ISC Stormcast, Jan 24, 2025: XSS in Email, SonicWall Exploited; Cisco Vulnerablities; AI and SOAR (@sans_edu research paper by Anthony</title><link>https://www.spreaker.com/episode/sans-isc-stormcast-jan-24-2025-xss-in-email-sonicwall-exploited-cisco-vulnerablities-ai-and-soar-sans-edu-research-paper-by-anthony--63864420</link><description><![CDATA[<br /> In today's episode, learn how an attacker attempted to exploit webmail XSS vulnerablities against us. Sonicwall released a critical patch fixing an already exploited vulnerability in its SMA 1000 appliance. Cisco fixed vulnerabilities in ClamAV and its Meeting Manager REST API. Learn from SANS.edu student Anthony Russo how to take advantage of AI for SOAR.<br /> XSS Attempts via E-Mail<br /><a href="https://isc.sans.edu/diary/XSS%20Attempts%20via%20E-Mail/31620" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/XSS%20Attempts%20via%20E-Mail/31620</a><br />  An analysis of a recent surge in email-based XSS attack attempts targeting users and organizations. Learn the implications and mitigation techniques.<br /> SonicWall PSIRT Advisory: CVE-2025-23006<br /><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0002" target="_blank" rel="noreferrer noopener">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0002</a> CVE-2025-23006<br />  Details of a critical vulnerability in SonicWall appliances (SNWLID-2025-0002) and what you need to do to secure your systems.<br /> Cisco ClamAV Advisory: OLE2 Parsing Vulnerability<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-ole2-H549rphA" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-ole2-H549rphA</a><br />  A DoS vulnerability in the popular open source anti virus engine ClamAV<br /> Cisco CMM Privilege Escalation Vulnerability<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cmm-privesc-uy2Vf8pc" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cmm-privesc-uy2Vf8pc</a><br />  A patch of a privilege escalation flaw in Cisco s CMM module.<br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9294.mp3</guid><pubDate>Fri, 24 Jan 2025 00:13:40 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63864420/9294.mp3" length="12664452" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>
 In today's episode, learn how an attacker attempted to exploit webmail XSS vulnerablities against us. Sonicwall released a critical patch fixing an already exploited vulnerability in its SMA 1000 appliance. Cisco fixed vulnerabilities in ClamAV and...</itunes:subtitle><itunes:summary><![CDATA[<br /> In today's episode, learn how an attacker attempted to exploit webmail XSS vulnerablities against us. Sonicwall released a critical patch fixing an already exploited vulnerability in its SMA 1000 appliance. Cisco fixed vulnerabilities in ClamAV and its Meeting Manager REST API. Learn from SANS.edu student Anthony Russo how to take advantage of AI for SOAR.<br /> XSS Attempts via E-Mail<br /><a href="https://isc.sans.edu/diary/XSS%20Attempts%20via%20E-Mail/31620" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/XSS%20Attempts%20via%20E-Mail/31620</a><br />  An analysis of a recent surge in email-based XSS attack attempts targeting users and organizations. Learn the implications and mitigation techniques.<br /> SonicWall PSIRT Advisory: CVE-2025-23006<br /><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0002" target="_blank" rel="noreferrer noopener">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0002</a> CVE-2025-23006<br />  Details of a critical vulnerability in SonicWall appliances (SNWLID-2025-0002) and what you need to do to secure your systems.<br /> Cisco ClamAV Advisory: OLE2 Parsing Vulnerability<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-ole2-H549rphA" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-ole2-H549rphA</a><br />  A DoS vulnerability in the popular open source anti virus engine ClamAV<br /> Cisco CMM Privilege Escalation Vulnerability<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cmm-privesc-uy2Vf8pc" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cmm-privesc-uy2Vf8pc</a><br />  A patch of a privilege escalation flaw in Cisco s CMM module.<br />]]></itunes:summary><itunes:duration>885</itunes:duration><itunes:keywords>business,cisco; cmm; clamav; ole2; soni,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9294</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS ISC Stormcast, Jan 23, 2025: PFSync Protocol; Oracle CPU; Korean VPN Supply Chain Attack; Ivanti Guidance</title><link>https://www.spreaker.com/episode/sans-isc-stormcast-jan-23-2025-pfsync-protocol-oracle-cpu-korean-vpn-supply-chain-attack-ivanti-guidance--63833700</link><description><![CDATA[In today's episode, we start by talking about the PFSYNC protocol used to synchronize firewall states to support failover. Oracle released it's quarterly critical patch update. ESET is reporting about a critical VPN supply chain attack and CISA released guidance for victims of recent Ivanti related attacks.<br /> Catching CARP: Fishing for Firewall States in PFSync Traffic<br /><a href="https://isc.sans.edu/diary/Catching%20CARP%3A%20Fishing%20for%20Firewall%20Stat%20es%20in%20PFSync%20Traffic/31616)**" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Catching%20CARP%3A%20Fishing%20for%20Firewall%20Stat%20es%20in%20PFSync%20Traffic/31616)**</a>  <br />   Discover how attackers exploit PFSync traffic to manipulate firewall states. This deep dive explores vulnerabilities and mitigation strategies in network defense.<br /> Oracle Critical Patch Update   January 2025<br /><a href="https://www.oracle.com/security-alerts/cpujan2025.html)**" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpujan2025.html)**</a>  <br />   Oracle's January 2025 patch release addresses numerous critical vulnerabilities across their product suite. Learn about key updates and how to secure your systems.<br /> PlushDaemon: Compromising the Supply Chain of a Korean VPN Service<br /><a href="https://www.welivesecurity.com/en/eset-research/plushdaemon-compromises-supply-chain-korean-vpn-service/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/plushdaemon-compromises-supply-chain-korean-vpn-service/</a><br />   ESET Research uncovers PlushDaemon, a sophisticated supply chain attack targeting a Korean VPN provider. Understand the implications for supply chain security.<br /> CISA Cybersecurity Advisory: AA25-022A<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-022a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-022a</a><br />   The latest advisory highlights active threats and mitigation strategies for critical infrastructure. Stay ahead with CISA s guidance on emerging cyber risks.<br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9292.mp3</guid><pubDate>Wed, 22 Jan 2025 23:45:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63833700/9292.mp3" length="6844299" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>In today's episode, we start by talking about the PFSYNC protocol used to synchronize firewall states to support failover. Oracle released it's quarterly critical patch update. ESET is reporting about a critical VPN supply chain attack and CISA...</itunes:subtitle><itunes:summary><![CDATA[In today's episode, we start by talking about the PFSYNC protocol used to synchronize firewall states to support failover. Oracle released it's quarterly critical patch update. ESET is reporting about a critical VPN supply chain attack and CISA released guidance for victims of recent Ivanti related attacks.<br /> Catching CARP: Fishing for Firewall States in PFSync Traffic<br /><a href="https://isc.sans.edu/diary/Catching%20CARP%3A%20Fishing%20for%20Firewall%20Stat%20es%20in%20PFSync%20Traffic/31616)**" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Catching%20CARP%3A%20Fishing%20for%20Firewall%20Stat%20es%20in%20PFSync%20Traffic/31616)**</a>  <br />   Discover how attackers exploit PFSync traffic to manipulate firewall states. This deep dive explores vulnerabilities and mitigation strategies in network defense.<br /> Oracle Critical Patch Update   January 2025<br /><a href="https://www.oracle.com/security-alerts/cpujan2025.html)**" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpujan2025.html)**</a>  <br />   Oracle's January 2025 patch release addresses numerous critical vulnerabilities across their product suite. Learn about key updates and how to secure your systems.<br /> PlushDaemon: Compromising the Supply Chain of a Korean VPN Service<br /><a href="https://www.welivesecurity.com/en/eset-research/plushdaemon-compromises-supply-chain-korean-vpn-service/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/plushdaemon-compromises-supply-chain-korean-vpn-service/</a><br />   ESET Research uncovers PlushDaemon, a sophisticated supply chain attack targeting a Korean VPN provider. Understand the implications for supply chain security.<br /> CISA Cybersecurity Advisory: AA25-022A<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-022a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-022a</a><br />   The latest advisory highlights active threats and mitigation strategies for critical infrastructure. Stay ahead with CISA s guidance on emerging cyber risks.<br />]]></itunes:summary><itunes:duration>470</itunes:duration><itunes:keywords>business,cisa; ivanti; vpn; korea; orac,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9292</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, January 22nd, 2025</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-january-22nd-2025--63806667</link><description><![CDATA[This episodes covers how Starlink users can be geolocated and how Cloudflare may help deanonymize users. The increased use of AI helpers leads to leaking data via careless prompts.<br /> Geolocation and Starlink<br /><a href="https://isc.sans.edu/diary/Geolocation%20and%20Starlink/31612" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Geolocation%20and%20Starlink/31612</a><br />  Discover the potential geolocation risks associated with Starlink and how they might be exploited. This diary entry dives into new concerns for satellite internet users.<br /> Deanonymizing Users via Cloudflare<br /><a href="https://gist.github.com/hackermondev/45a3cdfa52246f1d1201c1e8cdef6117" target="_blank" rel="noreferrer noopener">https://gist.github.com/hackermondev/45a3cdfa52246f1d1201c1e8cdef6117</a><br />  Deanonymizing users by identifying which cloudflare server cashed particular content<br /> Sage's AI Assistant and Customer Data Concerns<br /><a href="https://www.theregister.com/2025/01/20/sage_copilot_data_issue/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2025/01/20/sage_copilot_data_issue/</a><br />  Examine how a Sage AI tool inadvertently exposed sensitive customer data, raising questions about AI governance and trust in business applications.<br /> The Threat of Sensitive Data in Generative AI Prompts<br /><a href="https://www.darkreading.com/threat-intelligence/employees-sensitive-data-genai-prompts" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/threat-intelligence/employees-sensitive-data-genai-prompts</a><br />  Analyze how employees  careless prompts to generative AI tools can lead to sensitive data breaches and the importance of awareness training.<br /> Homebrew Phishing<br /><a href="https://x.com/ryanchenkie/status/1880730173634699393" target="_blank" rel="noreferrer noopener">https://x.com/ryanchenkie/status/1880730173634699393</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9290.mp3</guid><pubDate>Wed, 22 Jan 2025 02:15:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63806667/9290.mp3" length="8053444" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>This episodes covers how Starlink users can be geolocated and how Cloudflare may help deanonymize users. The increased use of AI helpers leads to leaking data via careless prompts.
 Geolocation and Starlink...</itunes:subtitle><itunes:summary><![CDATA[This episodes covers how Starlink users can be geolocated and how Cloudflare may help deanonymize users. The increased use of AI helpers leads to leaking data via careless prompts.<br /> Geolocation and Starlink<br /><a href="https://isc.sans.edu/diary/Geolocation%20and%20Starlink/31612" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Geolocation%20and%20Starlink/31612</a><br />  Discover the potential geolocation risks associated with Starlink and how they might be exploited. This diary entry dives into new concerns for satellite internet users.<br /> Deanonymizing Users via Cloudflare<br /><a href="https://gist.github.com/hackermondev/45a3cdfa52246f1d1201c1e8cdef6117" target="_blank" rel="noreferrer noopener">https://gist.github.com/hackermondev/45a3cdfa52246f1d1201c1e8cdef6117</a><br />  Deanonymizing users by identifying which cloudflare server cashed particular content<br /> Sage's AI Assistant and Customer Data Concerns<br /><a href="https://www.theregister.com/2025/01/20/sage_copilot_data_issue/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2025/01/20/sage_copilot_data_issue/</a><br />  Examine how a Sage AI tool inadvertently exposed sensitive customer data, raising questions about AI governance and trust in business applications.<br /> The Threat of Sensitive Data in Generative AI Prompts<br /><a href="https://www.darkreading.com/threat-intelligence/employees-sensitive-data-genai-prompts" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/threat-intelligence/employees-sensitive-data-genai-prompts</a><br />  Analyze how employees  careless prompts to generative AI tools can lead to sensitive data breaches and the importance of awareness training.<br /> Homebrew Phishing<br /><a href="https://x.com/ryanchenkie/status/1880730173634699393" target="_blank" rel="noreferrer noopener">https://x.com/ryanchenkie/status/1880730173634699393</a><br />]]></itunes:summary><itunes:duration>556</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,phishing; homebrew; ai; prompt,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9290</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, January 21st, 2025</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-january-21st-2025--63772621</link><description><![CDATA[In this episode, we talk about downloading and analyzing partial ZIP files, how legitimate remote access tools are used in recent compromises and how a research found an SSRF vulnerability in Azure DevOps<br /> Partial ZIP File Downloads<br />  A closer look at how attackers are leveraging partial ZIP file downloads to bypass file verification systems and plant malicious content.<br /><a href="https://isc.sans.edu/diary/Partial%20ZIP%20File%20Downloads/31608" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Partial%20ZIP%20File%20Downloads/31608</a><br /> Ukrainian CERT Advisory on AnyDesk Threat<br />  The Ukrainian CERT provides detailed guidance on identifying and mitigating recent cyber threats exploiting AnyDesk for unauthorized access.<br /><a href="https://cert.gov.ua/article/6282069" target="_blank" rel="noreferrer noopener">https://cert.gov.ua/article/6282069</a><br /> Finding SSRFs in Azure DevOps<br />  An in-depth analysis of how server-side request forgery (SSRF) vulnerabilities are discovered and exploited in Azure DevOps pipelines.<br /><a href="https://binarysecurity.no/posts/2025/01/finding-ssrfs-in-devops" target="_blank" rel="noreferrer noopener">https://binarysecurity.no/posts/2025/01/finding-ssrfs-in-devops</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9288.mp3</guid><pubDate>Tue, 21 Jan 2025 01:47:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63772621/9288.mp3" length="5596880" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>In this episode, we talk about downloading and analyzing partial ZIP files, how legitimate remote access tools are used in recent compromises and how a research found an SSRF vulnerability in Azure DevOps
 Partial ZIP File Downloads
  A closer look at...</itunes:subtitle><itunes:summary><![CDATA[In this episode, we talk about downloading and analyzing partial ZIP files, how legitimate remote access tools are used in recent compromises and how a research found an SSRF vulnerability in Azure DevOps<br /> Partial ZIP File Downloads<br />  A closer look at how attackers are leveraging partial ZIP file downloads to bypass file verification systems and plant malicious content.<br /><a href="https://isc.sans.edu/diary/Partial%20ZIP%20File%20Downloads/31608" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Partial%20ZIP%20File%20Downloads/31608</a><br /> Ukrainian CERT Advisory on AnyDesk Threat<br />  The Ukrainian CERT provides detailed guidance on identifying and mitigating recent cyber threats exploiting AnyDesk for unauthorized access.<br /><a href="https://cert.gov.ua/article/6282069" target="_blank" rel="noreferrer noopener">https://cert.gov.ua/article/6282069</a><br /> Finding SSRFs in Azure DevOps<br />  An in-depth analysis of how server-side request forgery (SSRF) vulnerabilities are discovered and exploited in Azure DevOps pipelines.<br /><a href="https://binarysecurity.no/posts/2025/01/finding-ssrfs-in-devops" target="_blank" rel="noreferrer noopener">https://binarysecurity.no/posts/2025/01/finding-ssrfs-in-devops</a><br />]]></itunes:summary><itunes:duration>381</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,devops; azure; ssrf; ukraine; ,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9288</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, January 20th, 2025</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-january-20th-2025--63756450</link><description><![CDATA[In this episode, we cover how to use honeypot data to keep your offensive infrastructure alive longer, three critical vulnerabilities in SimpleHelp that must be patched now, and an interesting vulnerability affecting many systems allowing UEFI Secure Boot bypass.<br /> Leveraging Honeypot Data for Offensive Security Operations [Guest Diary] A recent guest diary on the SANS Internet Storm Center discusses how offensive security professionals can utilize honeypot data to enhance their operations. The diary highlights the detection of scans from multiple IP addresses, emphasizing the importance of monitoring non-standard user-agent strings in web requests.<br /><a href="https://isc.sans.edu/diary/Leveraging%20Honeypot%20Data%20for%20Offensive%20Security%20Operations%20%5BGuest%20Diary%5D/31596" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Leveraging%20Honeypot%20Data%20for%20Offensive%20Security%20Operations%20%5BGuest%20Diary%5D/31596</a><br /> Security Vulnerabilities in SimpleHelp 5.5.7 and Earlier SimpleHelp has released version 5.5.8 to address critical security vulnerabilities present in versions 5.5.7 and earlier. Users are strongly advised to upgrade to the latest version to prevent potential exploits. Detailed information and upgrade instructions are available on SimpleHelp's official website. <br /><a href="https://simple-help.com/kb---security-vulnerabilities-01-2025#send-us-your-questions" target="_blank" rel="noreferrer noopener">https://simple-help.com/kb---security-vulnerabilities-01-2025#send-us-your-questions</a><br /> Under the Cloak of UEFI Secure Boot: Introducing CVE-2024-7344 ESET researchers have identified a new vulnerability, CVE-2024-7344, that allows attackers to bypass UEFI Secure Boot on most UEFI-based systems. This flaw enables the execution of untrusted code during system boot, potentially leading to the deployment of malicious UEFI bootkits. Affected users should apply available patches to mitigate this risk. <br /><a href="https://www.welivesecurity.com/en/eset-research/under-cloak-uefi-secure-boot-introducing-cve-2024-7344/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/under-cloak-uefi-secure-boot-introducing-cve-2024-7344/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9286.mp3</guid><pubDate>Mon, 20 Jan 2025 00:48:15 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63756450/9286.mp3" length="3134530" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>In this episode, we cover how to use honeypot data to keep your offensive infrastructure alive longer, three critical vulnerabilities in SimpleHelp that must be patched now, and an interesting vulnerability affecting many systems allowing UEFI Secure...</itunes:subtitle><itunes:summary><![CDATA[In this episode, we cover how to use honeypot data to keep your offensive infrastructure alive longer, three critical vulnerabilities in SimpleHelp that must be patched now, and an interesting vulnerability affecting many systems allowing UEFI Secure Boot bypass.<br /> Leveraging Honeypot Data for Offensive Security Operations [Guest Diary] A recent guest diary on the SANS Internet Storm Center discusses how offensive security professionals can utilize honeypot data to enhance their operations. The diary highlights the detection of scans from multiple IP addresses, emphasizing the importance of monitoring non-standard user-agent strings in web requests.<br /><a href="https://isc.sans.edu/diary/Leveraging%20Honeypot%20Data%20for%20Offensive%20Security%20Operations%20%5BGuest%20Diary%5D/31596" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Leveraging%20Honeypot%20Data%20for%20Offensive%20Security%20Operations%20%5BGuest%20Diary%5D/31596</a><br /> Security Vulnerabilities in SimpleHelp 5.5.7 and Earlier SimpleHelp has released version 5.5.8 to address critical security vulnerabilities present in versions 5.5.7 and earlier. Users are strongly advised to upgrade to the latest version to prevent potential exploits. Detailed information and upgrade instructions are available on SimpleHelp's official website. <br /><a href="https://simple-help.com/kb---security-vulnerabilities-01-2025#send-us-your-questions" target="_blank" rel="noreferrer noopener">https://simple-help.com/kb---security-vulnerabilities-01-2025#send-us-your-questions</a><br /> Under the Cloak of UEFI Secure Boot: Introducing CVE-2024-7344 ESET researchers have identified a new vulnerability, CVE-2024-7344, that allows attackers to bypass UEFI Secure Boot on most UEFI-based systems. This flaw enables the execution of untrusted code during system boot, potentially leading to the deployment of malicious UEFI bootkits. Affected users should apply available patches to mitigate this risk. <br /><a href="https://www.welivesecurity.com/en/eset-research/under-cloak-uefi-secure-boot-introducing-cve-2024-7344/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/under-cloak-uefi-secure-boot-introducing-cve-2024-7344/</a><br />]]></itunes:summary><itunes:duration>205</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,uefi; simplehelp; honeypots</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9286</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, January 17th, 2025</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-january-17th-2025--63720842</link><description><![CDATA[In this episode, we explore the efficient storage of honeypot logs in databases, issues with Citrix's Session Recording Agent and Windows Update. Ivanti is having another interesting security event and our SANS.edu graduate student Rich Green talks about his research on Passkeys.<br /> Extracting Practical Observations from Impractical Datasets: A SANS Internet Storm Center diary entry discusses strategies for analyzing complex datasets to derive actionable insights.<br /><a href="https://isc.sans.edu/diary/Extracting%20Practical%20Observations%20from%20Impractical%20Datasets/31582" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Extracting%20Practical%20Observations%20from%20Impractical%20Datasets/31582</a><br /> Citrix Session Recording Agent Update Issue: Citrix reports that Microsoft's January security update fails or reverts on machines with the 2411 Session Recording Agent installed, providing guidance on addressing this issue.<br /><a href="https://support.citrix.com/s/article/CTX692505-microsofts-january-security-update-failsreverts-on-a-machine-with-2411-session-recording-agent?language=en_US" target="_blank" rel="noreferrer noopener">https://support.citrix.com/s/article/CTX692505-microsofts-january-security-update-failsreverts-on-a-machine-with-2411-session-recording-agent?language=en_US</a><br /> Ivanti Endpoint Manager Security Advisory: Ivanti releases a security advisory for Endpoint Manager versions 2024 and 2022 SU6, detailing vulnerabilities and recommended actions.<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6?language=en_US</a><br /> Revolutionizing Enterprise Security: The Exciting Future of Passkeys Beyond Passwords: A SANS.edu research paper explores the shift from traditional passwords to passkeys, highlighting the benefits and challenges of adopting passwordless authentication methods.<br /><a href="https://www.sans.edu/cyber-research/revolutionizing-enterprise-security-exciting-future-passkeys-beyond-passwords/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/revolutionizing-enterprise-security-exciting-future-passkeys-beyond-passwords/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9284.mp3</guid><pubDate>Fri, 17 Jan 2025 00:39:29 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63720842/9284.mp3" length="11053957" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>In this episode, we explore the efficient storage of honeypot logs in databases, issues with Citrix's Session Recording Agent and Windows Update. Ivanti is having another interesting security event and our SANS.edu graduate student Rich Green talks...</itunes:subtitle><itunes:summary><![CDATA[In this episode, we explore the efficient storage of honeypot logs in databases, issues with Citrix's Session Recording Agent and Windows Update. Ivanti is having another interesting security event and our SANS.edu graduate student Rich Green talks about his research on Passkeys.<br /> Extracting Practical Observations from Impractical Datasets: A SANS Internet Storm Center diary entry discusses strategies for analyzing complex datasets to derive actionable insights.<br /><a href="https://isc.sans.edu/diary/Extracting%20Practical%20Observations%20from%20Impractical%20Datasets/31582" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Extracting%20Practical%20Observations%20from%20Impractical%20Datasets/31582</a><br /> Citrix Session Recording Agent Update Issue: Citrix reports that Microsoft's January security update fails or reverts on machines with the 2411 Session Recording Agent installed, providing guidance on addressing this issue.<br /><a href="https://support.citrix.com/s/article/CTX692505-microsofts-january-security-update-failsreverts-on-a-machine-with-2411-session-recording-agent?language=en_US" target="_blank" rel="noreferrer noopener">https://support.citrix.com/s/article/CTX692505-microsofts-january-security-update-failsreverts-on-a-machine-with-2411-session-recording-agent?language=en_US</a><br /> Ivanti Endpoint Manager Security Advisory: Ivanti releases a security advisory for Endpoint Manager versions 2024 and 2022 SU6, detailing vulnerabilities and recommended actions.<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6?language=en_US</a><br /> Revolutionizing Enterprise Security: The Exciting Future of Passkeys Beyond Passwords: A SANS.edu research paper explores the shift from traditional passwords to passkeys, highlighting the benefits and challenges of adopting passwordless authentication methods.<br /><a href="https://www.sans.edu/cyber-research/revolutionizing-enterprise-security-exciting-future-passkeys-beyond-passwords/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/revolutionizing-enterprise-security-exciting-future-passkeys-beyond-passwords/</a><br />]]></itunes:summary><itunes:duration>770</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,passkeys; citrix; ivanti; hone,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9284</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, January 16th, 2025</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-january-16th-2025--63709597</link><description><![CDATA[Today's episode covers an odd 12 year old Netgear vulnerability that only received a proper CVE number last year. Learn about how to properly identify OpenID connect users and avoid domain name resue. Good old rsync turns out to be in need of patching and Fortinet: Not sure if it needs patching. Probably it does. Go ahead and patch it.<br /> The Curious Case of a 12-Year-Old Netgear Router Vulnerability<br /> Outdated Netgear routers remain a security risk, with attackers actively exploiting a 2013 vulnerability to deploy crypto miners. Learn how to protect your network by updating or replacing legacy hardware.<br /> URL: <a href="https://isc.sans.edu/diary/The%20Curious%20Case%20of%20a%2012-Year-Old%20Netgear%20Router%20Vulnerability/31592" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20Curious%20Case%20of%20a%2012-Year-Old%20Netgear%20Router%20Vulnerability/31592</a><br /> Millions at Risk Due to Google s OAuth Flaw<br /> A flaw in Google s OAuth implementation enables attackers to exploit defunct domain accounts, exposing sensitive data. Tips on implementing MFA and domain monitoring to reduce risks.<br /> URL: <a href="https://trufflesecurity.com/blog/millions-at-risk-due-to-google-s-oauth-flaw" target="_blank" rel="noreferrer noopener">https://trufflesecurity.com/blog/millions-at-risk-due-to-google-s-oauth-flaw</a><br /> Rsync 3.4.0 Security Release<br /> The latest rsync update fixes critical vulnerabilities, including buffer overflows and symbolic link issues. Upgrade immediately to protect your file synchronization processes.<br /> URL: <a href="https://download.samba.org/pub/rsync/NEWS#3.4.0" target="_blank" rel="noreferrer noopener">https://download.samba.org/pub/rsync/NEWS#3.4.0</a><br /> Fortinet PSIRT Advisories: Stay Secure<br /> Fortinet's latest advisories address vulnerabilities in FortiOS, FortiProxy, and more. Review and apply patches promptly to secure your perimeter defenses.<br /> URL: <a href="https://www.fortiguard.com/psirt" target="_blank" rel="noreferrer noopener">https://www.fortiguard.com/psirt</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9282.mp3</guid><pubDate>Thu, 16 Jan 2025 00:48:36 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63709597/9282.mp3" length="7860214" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Today's episode covers an odd 12 year old Netgear vulnerability that only received a proper CVE number last year. Learn about how to properly identify OpenID connect users and avoid domain name resue. Good old rsync turns out to be in need of patching...</itunes:subtitle><itunes:summary><![CDATA[Today's episode covers an odd 12 year old Netgear vulnerability that only received a proper CVE number last year. Learn about how to properly identify OpenID connect users and avoid domain name resue. Good old rsync turns out to be in need of patching and Fortinet: Not sure if it needs patching. Probably it does. Go ahead and patch it.<br /> The Curious Case of a 12-Year-Old Netgear Router Vulnerability<br /> Outdated Netgear routers remain a security risk, with attackers actively exploiting a 2013 vulnerability to deploy crypto miners. Learn how to protect your network by updating or replacing legacy hardware.<br /> URL: <a href="https://isc.sans.edu/diary/The%20Curious%20Case%20of%20a%2012-Year-Old%20Netgear%20Router%20Vulnerability/31592" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20Curious%20Case%20of%20a%2012-Year-Old%20Netgear%20Router%20Vulnerability/31592</a><br /> Millions at Risk Due to Google s OAuth Flaw<br /> A flaw in Google s OAuth implementation enables attackers to exploit defunct domain accounts, exposing sensitive data. Tips on implementing MFA and domain monitoring to reduce risks.<br /> URL: <a href="https://trufflesecurity.com/blog/millions-at-risk-due-to-google-s-oauth-flaw" target="_blank" rel="noreferrer noopener">https://trufflesecurity.com/blog/millions-at-risk-due-to-google-s-oauth-flaw</a><br /> Rsync 3.4.0 Security Release<br /> The latest rsync update fixes critical vulnerabilities, including buffer overflows and symbolic link issues. Upgrade immediately to protect your file synchronization processes.<br /> URL: <a href="https://download.samba.org/pub/rsync/NEWS#3.4.0" target="_blank" rel="noreferrer noopener">https://download.samba.org/pub/rsync/NEWS#3.4.0</a><br /> Fortinet PSIRT Advisories: Stay Secure<br /> Fortinet's latest advisories address vulnerabilities in FortiOS, FortiProxy, and more. Review and apply patches promptly to secure your perimeter defenses.<br /> URL: <a href="https://www.fortiguard.com/psirt" target="_blank" rel="noreferrer noopener">https://www.fortiguard.com/psirt</a><br />]]></itunes:summary><itunes:duration>542</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,fortinet; rsync; google; oauth,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9282</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, January 15th, 2025</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-january-15th-2025--63695446</link><description><![CDATA[Today, Microsoft Patch Tuesday headlines our news with Microsoft patching 209 vulnerabilities, some<br /> of which have already been exploited. Fortinet suspects a so far unpatched Node.js authentication<br /> bypass to be behind some recent exploits of FortiOS and FortiProxy devices.<br /> Microsoft January 2025 Patch Tuesday<br />  This month's Microsoft patch update addresses a total of 209 vulnerabilities, including 12 classified as critical. Among these, 3 vulnerabilities have been actively exploited in the wild, and 5 have been disclosed prior to the patch release, marking them as zero-days.<br /><a href="https://isc.sans.edu/diary/rss/31590" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/rss/31590</a><br /> Fortinet Security Advisory FG-IR-24-535 CVE-2024-55591<br />  An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS and FortiProxy may allow a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-24-535" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-24-535</a><br /> PRTG Network Monitor Update:<br />   Update for an already exploited XSS vulnerability in Paesler PRTG Network Monitor CVE-2024-12833<br /><a href="https://www.paessler.com/prtg/history/stable" target="_blank" rel="noreferrer noopener">https://www.paessler.com/prtg/history/stable</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9280.mp3</guid><pubDate>Wed, 15 Jan 2025 00:33:59 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63695446/9280.mp3" length="6830373" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Today, Microsoft Patch Tuesday headlines our news with Microsoft patching 209 vulnerabilities, some
 of which have already been exploited. Fortinet suspects a so far unpatched Node.js authentication
 bypass to be behind some recent exploits of FortiOS...</itunes:subtitle><itunes:summary><![CDATA[Today, Microsoft Patch Tuesday headlines our news with Microsoft patching 209 vulnerabilities, some<br /> of which have already been exploited. Fortinet suspects a so far unpatched Node.js authentication<br /> bypass to be behind some recent exploits of FortiOS and FortiProxy devices.<br /> Microsoft January 2025 Patch Tuesday<br />  This month's Microsoft patch update addresses a total of 209 vulnerabilities, including 12 classified as critical. Among these, 3 vulnerabilities have been actively exploited in the wild, and 5 have been disclosed prior to the patch release, marking them as zero-days.<br /><a href="https://isc.sans.edu/diary/rss/31590" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/rss/31590</a><br /> Fortinet Security Advisory FG-IR-24-535 CVE-2024-55591<br />  An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS and FortiProxy may allow a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-24-535" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-24-535</a><br /> PRTG Network Monitor Update:<br />   Update for an already exploited XSS vulnerability in Paesler PRTG Network Monitor CVE-2024-12833<br /><a href="https://www.paessler.com/prtg/history/stable" target="_blank" rel="noreferrer noopener">https://www.paessler.com/prtg/history/stable</a><br />]]></itunes:summary><itunes:duration>469</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,prtg; fortinet; network monito,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9280</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, January 14th, 2025</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-january-14th-2025--63681651</link><description><![CDATA[Episode Summary:<br /> This episode covers brute-force attacks on the password reset functionality of Hikvision devices, a macOS SIP bypass vulnerability, Linux rootkit malware, and a novel ransomware campaign targeting AWS S3 buckets.<br /> Topics Covered:<br /> Hikvision Password Reset Brute Forcing<br /> URL: <a href="https://isc.sans.edu/diary/Hikvision%20Password%20Reset%20Brute%20Forcing/31586" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Hikvision%20Password%20Reset%20Brute%20Forcing/31586</a><br /> Hikvision devices are being targeted using old brute-force attacks exploiting predictable password reset codes. <br /> Analyzing CVE-2024-44243: A macOS System Integrity Protection Bypass<br /> URL: <a href="https://www.microsoft.com/en-us/security/blog/2025/01/13/analyzing-cve-2024-44243-a-macos-system-integrity-protection-bypass-through-kernel-extensions/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2025/01/13/analyzing-cve-2024-44243-a-macos-system-integrity-protection-bypass-through-kernel-extensions/</a><br /> Microsoft details a macOS vulnerability allowing attackers to bypass SIP using kernel extensions. <br /> Rootkit Malware Controls Linux Systems Remotely<br /> URL: <a href="https://cybersecuritynews.com/rootkit-malware-controls-linux-systems-remotely/" target="_blank" rel="noreferrer noopener">https://cybersecuritynews.com/rootkit-malware-controls-linux-systems-remotely/</a><br /> A sophisticated rootkit targeting Linux systems uses zero-day vulnerabilities for remote control. <br /> Abusing AWS Native Services: Ransomware Encrypting S3 Buckets with SSE-C<br /> URL: <a href="https://www.halcyon.ai/blog/abusing-aws-native-services-ransomware-encrypting-s3-buckets-with-sse-c" target="_blank" rel="noreferrer noopener">https://www.halcyon.ai/blog/abusing-aws-native-services-ransomware-encrypting-s3-buckets-with-sse-c</a><br /> Attackers are using AWS s SSE-C encryption to lock S3 buckets during ransomware campaigns. We cover how the attack works and how to protect your AWS environment.<br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9278.mp3</guid><pubDate>Mon, 13 Jan 2025 22:59:28 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63681651/9278.mp3" length="6868245" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Episode Summary:
 This episode covers brute-force attacks on the password reset functionality of Hikvision devices, a macOS SIP bypass vulnerability, Linux rootkit malware, and a novel ransomware campaign targeting AWS S3 buckets.
 Topics Covered:...</itunes:subtitle><itunes:summary><![CDATA[Episode Summary:<br /> This episode covers brute-force attacks on the password reset functionality of Hikvision devices, a macOS SIP bypass vulnerability, Linux rootkit malware, and a novel ransomware campaign targeting AWS S3 buckets.<br /> Topics Covered:<br /> Hikvision Password Reset Brute Forcing<br /> URL: <a href="https://isc.sans.edu/diary/Hikvision%20Password%20Reset%20Brute%20Forcing/31586" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Hikvision%20Password%20Reset%20Brute%20Forcing/31586</a><br /> Hikvision devices are being targeted using old brute-force attacks exploiting predictable password reset codes. <br /> Analyzing CVE-2024-44243: A macOS System Integrity Protection Bypass<br /> URL: <a href="https://www.microsoft.com/en-us/security/blog/2025/01/13/analyzing-cve-2024-44243-a-macos-system-integrity-protection-bypass-through-kernel-extensions/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2025/01/13/analyzing-cve-2024-44243-a-macos-system-integrity-protection-bypass-through-kernel-extensions/</a><br /> Microsoft details a macOS vulnerability allowing attackers to bypass SIP using kernel extensions. <br /> Rootkit Malware Controls Linux Systems Remotely<br /> URL: <a href="https://cybersecuritynews.com/rootkit-malware-controls-linux-systems-remotely/" target="_blank" rel="noreferrer noopener">https://cybersecuritynews.com/rootkit-malware-controls-linux-systems-remotely/</a><br /> A sophisticated rootkit targeting Linux systems uses zero-day vulnerabilities for remote control. <br /> Abusing AWS Native Services: Ransomware Encrypting S3 Buckets with SSE-C<br /> URL: <a href="https://www.halcyon.ai/blog/abusing-aws-native-services-ransomware-encrypting-s3-buckets-with-sse-c" target="_blank" rel="noreferrer noopener">https://www.halcyon.ai/blog/abusing-aws-native-services-ransomware-encrypting-s3-buckets-with-sse-c</a><br /> Attackers are using AWS s SSE-C encryption to lock S3 buckets during ransomware campaigns. We cover how the attack works and how to protect your AWS environment.<br />]]></itunes:summary><itunes:duration>471</itunes:duration><itunes:keywords>aws; sse-c; rootkit; malware; ,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9278</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, January 13th, 2025</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-january-13th-2025--63670533</link><description><![CDATA[In today's episode, we cover the latest updates in cybersecurity:<br /> Windows Defender Enhances Chrome Extension Detection<br /> Microsoft's Defender now catalogs Chrome extensions to identify malicious ones. Learn how this improves enterprise security.<br /><a href="https://isc.sans.edu/diary/Windows%20Defender%20Chrome%20Extension%20Detection/31574" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Windows%20Defender%20Chrome%20Extension%20Detection/31574</a><br /> Multi-OLE Analysis in Malicious Documents<br /> A look at how attackers embed OLE files in Office documents to evade detection and the tools to combat it.<br /><a href="https://isc.sans.edu/diary/Multi-OLE/31580" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Multi-OLE/31580</a><br /> Ivanti Connect Secure RCE Vulnerability (CVE-2025-0282)<br /> Details of a critical vulnerability affecting Ivanti products and the patching timelines.<br /><a href="https://labs.watchtowr.com/exploitation-walkthrough-and-techniques-ivanti-connect-secure-rce-cve-2025-0282/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/exploitation-walkthrough-and-techniques-ivanti-connect-secure-rce-cve-2025-0282/</a><br /> Apple USB-C Controller Compromised<br /> Researchers hacked Apple s ACE3 USB-C controller, highlighting hardware security challenges.<br /><a href="https://cybersecuritynews.com/apples-new-usb-c-controller-hacked/" target="_blank" rel="noreferrer noopener">https://cybersecuritynews.com/apples-new-usb-c-controller-hacked/</a><br /> IRS Pushes for IP PIN Enrollment<br /> Protect yourself from tax-related identity theft by securing your IP PIN for the 2025 tax season.<br /><a href="https://www.irs.gov/newsroom/irs-encourages-all-taxpayers-to-sign-up-for-an-ip-pin-for-the-2025-tax-season" target="_blank" rel="noreferrer noopener">https://www.irs.gov/newsroom/irs-encourages-all-taxpayers-to-sign-up-for-an-ip-pin-for-the-2025-tax-season</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9276.mp3</guid><pubDate>Mon, 13 Jan 2025 01:42:35 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63670533/9276.mp3" length="5917754" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>In today's episode, we cover the latest updates in cybersecurity:
 Windows Defender Enhances Chrome Extension Detection
 Microsoft's Defender now catalogs Chrome extensions to identify malicious ones. Learn how this improves enterprise security....</itunes:subtitle><itunes:summary><![CDATA[In today's episode, we cover the latest updates in cybersecurity:<br /> Windows Defender Enhances Chrome Extension Detection<br /> Microsoft's Defender now catalogs Chrome extensions to identify malicious ones. Learn how this improves enterprise security.<br /><a href="https://isc.sans.edu/diary/Windows%20Defender%20Chrome%20Extension%20Detection/31574" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Windows%20Defender%20Chrome%20Extension%20Detection/31574</a><br /> Multi-OLE Analysis in Malicious Documents<br /> A look at how attackers embed OLE files in Office documents to evade detection and the tools to combat it.<br /><a href="https://isc.sans.edu/diary/Multi-OLE/31580" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Multi-OLE/31580</a><br /> Ivanti Connect Secure RCE Vulnerability (CVE-2025-0282)<br /> Details of a critical vulnerability affecting Ivanti products and the patching timelines.<br /><a href="https://labs.watchtowr.com/exploitation-walkthrough-and-techniques-ivanti-connect-secure-rce-cve-2025-0282/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/exploitation-walkthrough-and-techniques-ivanti-connect-secure-rce-cve-2025-0282/</a><br /> Apple USB-C Controller Compromised<br /> Researchers hacked Apple s ACE3 USB-C controller, highlighting hardware security challenges.<br /><a href="https://cybersecuritynews.com/apples-new-usb-c-controller-hacked/" target="_blank" rel="noreferrer noopener">https://cybersecuritynews.com/apples-new-usb-c-controller-hacked/</a><br /> IRS Pushes for IP PIN Enrollment<br /> Protect yourself from tax-related identity theft by securing your IP PIN for the 2025 tax season.<br /><a href="https://www.irs.gov/newsroom/irs-encourages-all-taxpayers-to-sign-up-for-an-ip-pin-for-the-2025-tax-season" target="_blank" rel="noreferrer noopener">https://www.irs.gov/newsroom/irs-encourages-all-taxpayers-to-sign-up-for-an-ip-pin-for-the-2025-tax-season</a><br />]]></itunes:summary><itunes:duration>403</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,irs; ip; pin; apple; usb-c; iv,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9276</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>SANS ISC Stormcast: Cryptomining Malware, Fake PoC Exploit, Malicious Browser Extensions, and Palo Alto Vulnerabilities. Jan 9th 2024</title><link>https://www.spreaker.com/episode/sans-isc-stormcast-cryptomining-malware-fake-poc-exploit-malicious-browser-extensions-and-palo-alto-vulnerabilities-jan-9th-2024--63632901</link><description><![CDATA[In this episode, we explore the following stories:<br /> "Examining Redtail: Analyzing a Sophisticated Cryptomining Malware and its Advanced Tactics"<br /> Overview of Redtail's multi-architecture cryptomining malware exploiting vulnerabilities and deploying persistence techniques.<br /> URL: Examining Redtail: Analyzing a Sophisticated Cryptomining Malware and its Advanced Tactics<br /> "Information Stealer Masquerades as LDAPNightmare PoC Exploit"<br /> A malware disguised as a PoC exploit targets users seeking to test vulnerabilities like LDAPNightmare.<br /> URL: Information Stealer Masquerades as LDAPNightmare PoC Exploit<br /> "How Extensions Trick CWS Search"<br /> Research reveals how malicious browser extensions manipulate Chrome Web Store search to appear legitimate.<br /> URL: How Extensions Trick CWS Search<br /> "Palo Alto Networks' Expedition Vulnerabilities (PAN-SA-2025-0001)"<br /> Multiple vulnerabilities in the deprecated Expedition tool can expose credentials and lead to unauthorized file and command execution.<br /> URL: Palo Alto Networks' Expedition Vulnerabilities (PAN-SA-2025-0001)<br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9274.mp3</guid><pubDate>Fri, 10 Jan 2025 01:26:17 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63632901/9274.mp3" length="6418303" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>In this episode, we explore the following stories:
 "Examining Redtail: Analyzing a Sophisticated Cryptomining Malware and its Advanced Tactics"
 Overview of Redtail's multi-architecture cryptomining malware exploiting vulnerabilities and deploying...</itunes:subtitle><itunes:summary><![CDATA[In this episode, we explore the following stories:<br /> "Examining Redtail: Analyzing a Sophisticated Cryptomining Malware and its Advanced Tactics"<br /> Overview of Redtail's multi-architecture cryptomining malware exploiting vulnerabilities and deploying persistence techniques.<br /> URL: Examining Redtail: Analyzing a Sophisticated Cryptomining Malware and its Advanced Tactics<br /> "Information Stealer Masquerades as LDAPNightmare PoC Exploit"<br /> A malware disguised as a PoC exploit targets users seeking to test vulnerabilities like LDAPNightmare.<br /> URL: Information Stealer Masquerades as LDAPNightmare PoC Exploit<br /> "How Extensions Trick CWS Search"<br /> Research reveals how malicious browser extensions manipulate Chrome Web Store search to appear legitimate.<br /> URL: How Extensions Trick CWS Search<br /> "Palo Alto Networks' Expedition Vulnerabilities (PAN-SA-2025-0001)"<br /> Multiple vulnerabilities in the deprecated Expedition tool can expose credentials and lead to unauthorized file and command execution.<br /> URL: Palo Alto Networks' Expedition Vulnerabilities (PAN-SA-2025-0001)<br />]]></itunes:summary><itunes:duration>439</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,palo alto; chrome web store; e,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9274</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, January 9th, 2025</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-january-9th-2025--63620923</link><description><![CDATA[In this episode, we discuss critical vulnerabilities in Ivanti Connect Secure and Policy Secure, command injection risks in Aviatrix Network Controllers, and the risks posed by hijacked abandoned backdoors.<br /> Episode Links and Topics:<br /> More Governments Backdoors in Your Backdoors<br /><a href="https://labs.watchtowr.com/more-governments-backdoors-in-your-backdoors/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/more-governments-backdoors-in-your-backdoors/</a><br /> Researchers reveal how expired domains linked to abandoned backdoors can be hijacked, exposing systems to further compromise.<br /> Security Update: Ivanti Connect Secure, Policy Secure, and Neurons for ZTA Gateways<br /><a href="https://www.ivanti.com/blog/security-update-ivanti-connect-secure-policy-secure-and-neurons-for-zta-gateways" target="_blank" rel="noreferrer noopener">https://www.ivanti.com/blog/security-update-ivanti-connect-secure-policy-secure-and-neurons-for-zta-gateways</a><br /> Ivanti addresses critical vulnerabilities (CVE-2025-0282, CVE-2025-0283) in their secure gateway products, with active exploitation in the wild.<br /> CVE-2024-50603: Aviatrix Network Controller Command Injection Vulnerability<br /><a href="https://www.securing.pl/en/cve-2024-50603-aviatrix-network-controller-command-injection-vulnerability/" target="_blank" rel="noreferrer noopener">https://www.securing.pl/en/cve-2024-50603-aviatrix-network-controller-command-injection-vulnerability/</a><br /> A command injection vulnerability in Aviatrix Network Controllers allows unauthenticated code execution, posing severe risks to network environments.<br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9272.mp3</guid><pubDate>Thu, 09 Jan 2025 01:32:18 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63620923/9272.mp3" length="5365523" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>In this episode, we discuss critical vulnerabilities in Ivanti Connect Secure and Policy Secure, command injection risks in Aviatrix Network Controllers, and the risks posed by hijacked abandoned backdoors.
 Episode Links and Topics:
 More Governments...</itunes:subtitle><itunes:summary><![CDATA[In this episode, we discuss critical vulnerabilities in Ivanti Connect Secure and Policy Secure, command injection risks in Aviatrix Network Controllers, and the risks posed by hijacked abandoned backdoors.<br /> Episode Links and Topics:<br /> More Governments Backdoors in Your Backdoors<br /><a href="https://labs.watchtowr.com/more-governments-backdoors-in-your-backdoors/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/more-governments-backdoors-in-your-backdoors/</a><br /> Researchers reveal how expired domains linked to abandoned backdoors can be hijacked, exposing systems to further compromise.<br /> Security Update: Ivanti Connect Secure, Policy Secure, and Neurons for ZTA Gateways<br /><a href="https://www.ivanti.com/blog/security-update-ivanti-connect-secure-policy-secure-and-neurons-for-zta-gateways" target="_blank" rel="noreferrer noopener">https://www.ivanti.com/blog/security-update-ivanti-connect-secure-policy-secure-and-neurons-for-zta-gateways</a><br /> Ivanti addresses critical vulnerabilities (CVE-2025-0282, CVE-2025-0283) in their secure gateway products, with active exploitation in the wild.<br /> CVE-2024-50603: Aviatrix Network Controller Command Injection Vulnerability<br /><a href="https://www.securing.pl/en/cve-2024-50603-aviatrix-network-controller-command-injection-vulnerability/" target="_blank" rel="noreferrer noopener">https://www.securing.pl/en/cve-2024-50603-aviatrix-network-controller-command-injection-vulnerability/</a><br /> A command injection vulnerability in Aviatrix Network Controllers allows unauthenticated code execution, posing severe risks to network environments.<br />]]></itunes:summary><itunes:duration>364</itunes:duration><itunes:keywords>aviatrix; ivanti; backdoors; d,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9272</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, January 8th, 2025</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-january-8th-2025--63608471</link><description><![CDATA[In this episode, we dive into active exploitation of a zero-day in SonicWall SSL-VPN, privilege escalation vulnerabilities in Moxa devices, and a BitLocker bypass in Windows 11. We also cover cryptocurrency mining malware hitting PHP servers and the White House's launch of the U.S. Cyber Trust Mark to secure connected devices.<br /> Episode Links and Topics:<br /> PacketCrypt Classic Cryptocurrency Miner on PHP Servers<br /><a href="https://isc.sans.edu/diary/PacketCrypt%20Classic%20Cryptocurrency%20Miner%20on%20PHP%20Servers/31564" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/PacketCrypt%20Classic%20Cryptocurrency%20Miner%20on%20PHP%20Servers/31564</a><br /> Malware exploiting PHP servers to mine PacketCrypt Classic cryptocurrency.<br /> SonicOS Affected By Multiple Vulnerabilities<br /><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0003" target="_blank" rel="noreferrer noopener">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0003</a><br /> A zero-day vulnerability in SonicWall SSL-VPN devices is under active attack.<br /> Privilege Escalation and OS Command Injection Vulnerabilities in Moxa Devices<br /><a href="https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241155-privilege-escalation-and-os-command-injection-vulnerabilities-in-cellular-routers,-secure-routers,-and-netwo" target="_blank" rel="noreferrer noopener">https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241155-privilege-escalation-and-os-command-injection-vulnerabilities-in-cellular-routers,-secure-routers,-and-netwo</a><br /> Critical vulnerabilities in Moxa routers and security appliances allow privilege escalation and OS command injection.<br /> White House Launches U.S. Cyber Trust Mark<br /><a href="https://www.whitehouse.gov/briefing-room/statements-releases/2025/01/07/white-house-launches-u-s-cyber-trust-mark-providing-american-consumers-an-easy-label-to-see-if-connected-devices-are-cybersecure/" target="_blank" rel="noreferrer noopener">https://www.whitehouse.gov/briefing-room/statements-releases/2025/01/07/white-house-launches-u-s-cyber-trust-mark-providing-american-consumers-an-easy-label-to-see-if-connected-devices-are-cybersecure/</a><br /> A new cybersecurity labeling program for connected devices aims to help consumers choose secure products.<br /> Windows BitLocker: Screwed without a Screwdriver<br /><a href="https://media.ccc.de/v/38c3-windows-bitlocker-screwed-without-a-screwdriver#t=761" target="_blank" rel="noreferrer noopener">https://media.ccc.de/v/38c3-windows-bitlocker-screwed-without-a-screwdriver#t=761</a><br /> (video in English)<br /> A two-year-old vulnerability in Windows 11 allows bypassing BitLocker encryption.<br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9270.mp3</guid><pubDate>Wed, 08 Jan 2025 01:31:58 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63608471/9270.mp3" length="5860069" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>In this episode, we dive into active exploitation of a zero-day in SonicWall SSL-VPN, privilege escalation vulnerabilities in Moxa devices, and a BitLocker bypass in Windows 11. We also cover cryptocurrency mining malware hitting PHP servers and the...</itunes:subtitle><itunes:summary><![CDATA[In this episode, we dive into active exploitation of a zero-day in SonicWall SSL-VPN, privilege escalation vulnerabilities in Moxa devices, and a BitLocker bypass in Windows 11. We also cover cryptocurrency mining malware hitting PHP servers and the White House's launch of the U.S. Cyber Trust Mark to secure connected devices.<br /> Episode Links and Topics:<br /> PacketCrypt Classic Cryptocurrency Miner on PHP Servers<br /><a href="https://isc.sans.edu/diary/PacketCrypt%20Classic%20Cryptocurrency%20Miner%20on%20PHP%20Servers/31564" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/PacketCrypt%20Classic%20Cryptocurrency%20Miner%20on%20PHP%20Servers/31564</a><br /> Malware exploiting PHP servers to mine PacketCrypt Classic cryptocurrency.<br /> SonicOS Affected By Multiple Vulnerabilities<br /><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0003" target="_blank" rel="noreferrer noopener">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0003</a><br /> A zero-day vulnerability in SonicWall SSL-VPN devices is under active attack.<br /> Privilege Escalation and OS Command Injection Vulnerabilities in Moxa Devices<br /><a href="https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241155-privilege-escalation-and-os-command-injection-vulnerabilities-in-cellular-routers,-secure-routers,-and-netwo" target="_blank" rel="noreferrer noopener">https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241155-privilege-escalation-and-os-command-injection-vulnerabilities-in-cellular-routers,-secure-routers,-and-netwo</a><br /> Critical vulnerabilities in Moxa routers and security appliances allow privilege escalation and OS command injection.<br /> White House Launches U.S. Cyber Trust Mark<br /><a href="https://www.whitehouse.gov/briefing-room/statements-releases/2025/01/07/white-house-launches-u-s-cyber-trust-mark-providing-american-consumers-an-easy-label-to-see-if-connected-devices-are-cybersecure/" target="_blank" rel="noreferrer noopener">https://www.whitehouse.gov/briefing-room/statements-releases/2025/01/07/white-house-launches-u-s-cyber-trust-mark-providing-american-consumers-an-easy-label-to-see-if-connected-devices-are-cybersecure/</a><br /> A new cybersecurity labeling program for connected devices aims to help consumers choose secure products.<br /> Windows BitLocker: Screwed without a Screwdriver<br /><a href="https://media.ccc.de/v/38c3-windows-bitlocker-screwed-without-a-screwdriver#t=761" target="_blank" rel="noreferrer noopener">https://media.ccc.de/v/38c3-windows-bitlocker-screwed-without-a-screwdriver#t=761</a><br /> (video in English)<br /> A two-year-old vulnerability in Windows 11 allows bypassing BitLocker encryption.<br />]]></itunes:summary><itunes:duration>399</itunes:duration><itunes:keywords>bitlocker; windows; cyber trus,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9270</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, January 7th, 2025</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-january-7th-2025--63596271</link><description><![CDATA[In this episode of the SANS Internet Storm Center's Stormcast, we cover critical vulnerabilities affecting OpenSSH, BeyondTrust, and Nuclei, including the newly discovered "RegreSSHion" flaw and a bypass vulnerability in Nuclei. We also discuss how malware evasion techniques can impact analysis environments and highlight the dangers of fake exploits targeting researchers. Tune in for insights on patching, mitigation strategies, and staying ahead of emerging threats.<br /> Topics Covered:<br /> Make Malware Happy<br /><a href="https://isc.sans.edu/diary/Make%20Malware%20Happy/31560" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Make%20Malware%20Happy/31560</a><br /> A look at how malware adapts and detects analysis environments, and why replicating operational settings is critical during malware analysis.<br /> Nuclei Signature Verification Bypass (CVE-2024-43405)<br /><a href="https://www.wiz.io/blog/nuclei-signature-verification-bypass" target="_blank" rel="noreferrer noopener">https://www.wiz.io/blog/nuclei-signature-verification-bypass</a><br /> A critical vulnerability in Nuclei allows malicious templates to bypass signature verification, risking arbitrary code execution.<br /> Critical Vulnerability in BeyondTrust (CVE-2024-12356)<br /><a href="https://censys.com/cve-2024-12356/" target="_blank" rel="noreferrer noopener">https://censys.com/cve-2024-12356/</a><br /> A high-risk flaw in BeyondTrust products allows unauthenticated OS command execution, posing a significant threat to privileged access systems.<br /> RegreSSHion Code Execution Vulnerability (CVE-2024-6387)<br /><a href="https://cybersecuritynews.com/regresshion-code-execution-vulnerability/" target="_blank" rel="noreferrer noopener">https://cybersecuritynews.com/regresshion-code-execution-vulnerability/</a><br /> OpenSSH vulnerability "RegreSSHion" enables remote code execution, and fake exploits targeting security researchers are in circulation.<br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9268.mp3</guid><pubDate>Tue, 07 Jan 2025 01:26:19 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63596271/9268.mp3" length="4359513" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>In this episode of the SANS Internet Storm Center's Stormcast, we cover critical vulnerabilities affecting OpenSSH, BeyondTrust, and Nuclei, including the newly discovered "RegreSSHion" flaw and a bypass vulnerability in Nuclei. We also discuss how...</itunes:subtitle><itunes:summary><![CDATA[In this episode of the SANS Internet Storm Center's Stormcast, we cover critical vulnerabilities affecting OpenSSH, BeyondTrust, and Nuclei, including the newly discovered "RegreSSHion" flaw and a bypass vulnerability in Nuclei. We also discuss how malware evasion techniques can impact analysis environments and highlight the dangers of fake exploits targeting researchers. Tune in for insights on patching, mitigation strategies, and staying ahead of emerging threats.<br /> Topics Covered:<br /> Make Malware Happy<br /><a href="https://isc.sans.edu/diary/Make%20Malware%20Happy/31560" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Make%20Malware%20Happy/31560</a><br /> A look at how malware adapts and detects analysis environments, and why replicating operational settings is critical during malware analysis.<br /> Nuclei Signature Verification Bypass (CVE-2024-43405)<br /><a href="https://www.wiz.io/blog/nuclei-signature-verification-bypass" target="_blank" rel="noreferrer noopener">https://www.wiz.io/blog/nuclei-signature-verification-bypass</a><br /> A critical vulnerability in Nuclei allows malicious templates to bypass signature verification, risking arbitrary code execution.<br /> Critical Vulnerability in BeyondTrust (CVE-2024-12356)<br /><a href="https://censys.com/cve-2024-12356/" target="_blank" rel="noreferrer noopener">https://censys.com/cve-2024-12356/</a><br /> A high-risk flaw in BeyondTrust products allows unauthenticated OS command execution, posing a significant threat to privileged access systems.<br /> RegreSSHion Code Execution Vulnerability (CVE-2024-6387)<br /><a href="https://cybersecuritynews.com/regresshion-code-execution-vulnerability/" target="_blank" rel="noreferrer noopener">https://cybersecuritynews.com/regresshion-code-execution-vulnerability/</a><br /> OpenSSH vulnerability "RegreSSHion" enables remote code execution, and fake exploits targeting security researchers are in circulation.<br />]]></itunes:summary><itunes:duration>292</itunes:duration><itunes:keywords>beyondtrust,business,computer,cyber,cybersecurity,daily,evasion,hacking,infosec,internet,it,malware,network,news,nuclei,openssh,rce,regresshion,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9268</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, January 6th, 2025</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-january-6th-2025--63586015</link><description><![CDATA[In this episode of the SANS Internet Storm Center's Stormcast, we cover the latest cybersecurity threats and defenses, including Python-delivered malware, goodware hash sets, SSL/TLS protocol updates, and critical vulnerabilities in ASUS routers and Paessler PRTG. Stay informed and secure your systems!<br /> Full details and links to all stories:<br /> SwaetRAT via Python: <a href="https://isc.sans.edu/diary/SwaetRAT%20Delivery%20Through%20Python/31554" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SwaetRAT%20Delivery%20Through%20Python/31554</a><br /> Goodware Hash Sets: <a href="https://isc.sans.edu/diary/Goodware%20Hash%20Sets/31556" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Goodware%20Hash%20Sets/31556</a><br /> SSL/TLS Updates: <a href="https://isc.sans.edu/diary/Changes%20in%20SSL%20and%20TLS%20support%20in%202024/31550" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Changes%20in%20SSL%20and%20TLS%20support%20in%202024/31550</a><br /> Cyberhaven Extension Compromise: <a href="https://secureannex.com/blog/cyberhaven-extension-compromise/" target="_blank" rel="noreferrer noopener">https://secureannex.com/blog/cyberhaven-extension-compromise/</a><br /> PRTG Vulnerability: <a href="https://www.zerodayinitiative.com/advisories/ZDI-24-1736/" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/advisories/ZDI-24-1736/</a><br /> ASUS Router Vulnerabilities: <a href="https://cybersecuritynews.com/asus-router-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://cybersecuritynews.com/asus-router-vulnerabilities/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9266.mp3</guid><pubDate>Mon, 06 Jan 2025 02:37:57 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63586015/9266.mp3" length="7228051" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>In this episode of the SANS Internet Storm Center's Stormcast, we cover the latest cybersecurity threats and defenses, including Python-delivered malware, goodware hash sets, SSL/TLS protocol updates, and critical vulnerabilities in ASUS routers and...</itunes:subtitle><itunes:summary><![CDATA[In this episode of the SANS Internet Storm Center's Stormcast, we cover the latest cybersecurity threats and defenses, including Python-delivered malware, goodware hash sets, SSL/TLS protocol updates, and critical vulnerabilities in ASUS routers and Paessler PRTG. Stay informed and secure your systems!<br /> Full details and links to all stories:<br /> SwaetRAT via Python: <a href="https://isc.sans.edu/diary/SwaetRAT%20Delivery%20Through%20Python/31554" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SwaetRAT%20Delivery%20Through%20Python/31554</a><br /> Goodware Hash Sets: <a href="https://isc.sans.edu/diary/Goodware%20Hash%20Sets/31556" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Goodware%20Hash%20Sets/31556</a><br /> SSL/TLS Updates: <a href="https://isc.sans.edu/diary/Changes%20in%20SSL%20and%20TLS%20support%20in%202024/31550" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Changes%20in%20SSL%20and%20TLS%20support%20in%202024/31550</a><br /> Cyberhaven Extension Compromise: <a href="https://secureannex.com/blog/cyberhaven-extension-compromise/" target="_blank" rel="noreferrer noopener">https://secureannex.com/blog/cyberhaven-extension-compromise/</a><br /> PRTG Vulnerability: <a href="https://www.zerodayinitiative.com/advisories/ZDI-24-1736/" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/advisories/ZDI-24-1736/</a><br /> ASUS Router Vulnerabilities: <a href="https://cybersecuritynews.com/asus-router-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://cybersecuritynews.com/asus-router-vulnerabilities/</a><br />]]></itunes:summary><itunes:duration>497</itunes:duration><itunes:keywords>asus,business,chrome,computer,cyber,cyberhaven,cybersecurity,daily,extensions,goodware,hacking,infosec,internet,it,network,news,prtg,python,security,swaetrat</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9266</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, December 20th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-december-20th-2024--63407493</link><description><![CDATA[PHPUnit and Androxgh0st<br /><a href="https://isc.sans.edu/diary/Command%20Injection%20Exploit%20For%20PHPUnit%20before%204.8.28%20and%205.x%20before%205.6.3%20%5BGuest%20Diary%5D/31528" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Command%20Injection%20Exploit%20For%20PHPUnit%20before%204.8.28%20and%205.x%20before%205.6.3%20%5BGuest%20Diary%5D/31528</a><br /> Mirai Attacks Session Smart Routers<br /><a href="https://supportportal.juniper.net/s/article/2024-12-Reference-Advisory-Session-Smart-Router-Mirai-malware-found-on-systems-when-the-default-password-remains-unchanged?language=en_US" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/article/2024-12-Reference-Advisory-Session-Smart-Router-Mirai-malware-found-on-systems-when-the-default-password-remains-unchanged?language=en_US</a><br /> FortiWLM Unauthenticated limited file read vulnerability<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-23-144" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-23-144</a><br /><a href="https://securityonline.info/kaspersky-uncovers-active-exploitation-of-fortinet-vulnerability-cve-2023-48788/" target="_blank" rel="noreferrer noopener">https://securityonline.info/kaspersky-uncovers-active-exploitation-of-fortinet-vulnerability-cve-2023-48788/</a><br /> Beyond Trust Security Advisory<br /><a href="https://www.beyondtrust.com/trust-center/security-advisories/bt24-10" target="_blank" rel="noreferrer noopener">https://www.beyondtrust.com/trust-center/security-advisories/bt24-10</a><br /> BadBox Update<br /><a href="https://www.bitsight.com/blog/badbox-botnet-back" target="_blank" rel="noreferrer noopener">https://www.bitsight.com/blog/badbox-botnet-back</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9264.mp3</guid><pubDate>Fri, 20 Dec 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63407493/9264.mp3" length="5341828" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>PHPUnit and Androxgh0st
https://isc.sans.edu/diary/Command%20Injection%20Exploit%20For%20PHPUnit%20before%204.8.28%20and%205.x%20before%205.6.3%20%5BGuest%20Diary%5D/31528
 Mirai Attacks Session Smart Routers...</itunes:subtitle><itunes:summary><![CDATA[PHPUnit and Androxgh0st<br /><a href="https://isc.sans.edu/diary/Command%20Injection%20Exploit%20For%20PHPUnit%20before%204.8.28%20and%205.x%20before%205.6.3%20%5BGuest%20Diary%5D/31528" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Command%20Injection%20Exploit%20For%20PHPUnit%20before%204.8.28%20and%205.x%20before%205.6.3%20%5BGuest%20Diary%5D/31528</a><br /> Mirai Attacks Session Smart Routers<br /><a href="https://supportportal.juniper.net/s/article/2024-12-Reference-Advisory-Session-Smart-Router-Mirai-malware-found-on-systems-when-the-default-password-remains-unchanged?language=en_US" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/article/2024-12-Reference-Advisory-Session-Smart-Router-Mirai-malware-found-on-systems-when-the-default-password-remains-unchanged?language=en_US</a><br /> FortiWLM Unauthenticated limited file read vulnerability<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-23-144" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-23-144</a><br /><a href="https://securityonline.info/kaspersky-uncovers-active-exploitation-of-fortinet-vulnerability-cve-2023-48788/" target="_blank" rel="noreferrer noopener">https://securityonline.info/kaspersky-uncovers-active-exploitation-of-fortinet-vulnerability-cve-2023-48788/</a><br /> Beyond Trust Security Advisory<br /><a href="https://www.beyondtrust.com/trust-center/security-advisories/bt24-10" target="_blank" rel="noreferrer noopener">https://www.beyondtrust.com/trust-center/security-advisories/bt24-10</a><br /> BadBox Update<br /><a href="https://www.bitsight.com/blog/badbox-botnet-back" target="_blank" rel="noreferrer noopener">https://www.bitsight.com/blog/badbox-botnet-back</a><br />]]></itunes:summary><itunes:duration>360</itunes:duration><itunes:keywords>badbox; beyond trust; fortiwlm,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9264</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, December 19th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-december-19th-2024--63385851</link><description><![CDATA[A Deep Dive into TeamTNT and Spinning YARN<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20A%20Deep%20Dive%20into%20TeamTNT%20and%20Spinning%20YARN/31530" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20A%20Deep%20Dive%20into%20TeamTNT%20and%20Spinning%20YARN/31530</a><br /> Earth Koshchei Coopts Red Team Tools in Complex RDP Attacks<br /><a href="https://www.trendmicro.com/en_us/research/24/l/earth-koshchei.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_us/research/24/l/earth-koshchei.html</a><br /> Okta Social Engineering Impersonation Report<br /><a href="https://sec.okta.com/articles/2024/okta-social-engineering-report-response-and-recommendation" target="_blank" rel="noreferrer noopener">https://sec.okta.com/articles/2024/okta-social-engineering-report-response-and-recommendation</a><br /> US considers banning TP-Link routers over cybersecurity risks<br /><a href="https://www.bleepingcomputer.com/news/security/us-considers-banning-tp-link-routers-over-cybersecurity-risks/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/us-considers-banning-tp-link-routers-over-cybersecurity-risks/</a><br /> CISA Releases Best Practice Guidance for Mobile Communications<br /><a href="https://www.cisa.gov/news-events/alerts/2024/12/18/cisa-releases-best-practice-guidance-mobile-communications" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2024/12/18/cisa-releases-best-practice-guidance-mobile-communications</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9262.mp3</guid><pubDate>Thu, 19 Dec 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63385851/9262.mp3" length="6261066" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>A Deep Dive into TeamTNT and Spinning YARN
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20A%20Deep%20Dive%20into%20TeamTNT%20and%20Spinning%20YARN/31530
 Earth Koshchei Coopts Red Team Tools in Complex RDP Attacks...</itunes:subtitle><itunes:summary><![CDATA[A Deep Dive into TeamTNT and Spinning YARN<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20A%20Deep%20Dive%20into%20TeamTNT%20and%20Spinning%20YARN/31530" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20A%20Deep%20Dive%20into%20TeamTNT%20and%20Spinning%20YARN/31530</a><br /> Earth Koshchei Coopts Red Team Tools in Complex RDP Attacks<br /><a href="https://www.trendmicro.com/en_us/research/24/l/earth-koshchei.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_us/research/24/l/earth-koshchei.html</a><br /> Okta Social Engineering Impersonation Report<br /><a href="https://sec.okta.com/articles/2024/okta-social-engineering-report-response-and-recommendation" target="_blank" rel="noreferrer noopener">https://sec.okta.com/articles/2024/okta-social-engineering-report-response-and-recommendation</a><br /> US considers banning TP-Link routers over cybersecurity risks<br /><a href="https://www.bleepingcomputer.com/news/security/us-considers-banning-tp-link-routers-over-cybersecurity-risks/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/us-considers-banning-tp-link-routers-over-cybersecurity-risks/</a><br /> CISA Releases Best Practice Guidance for Mobile Communications<br /><a href="https://www.cisa.gov/news-events/alerts/2024/12/18/cisa-releases-best-practice-guidance-mobile-communications" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2024/12/18/cisa-releases-best-practice-guidance-mobile-communications</a><br />]]></itunes:summary><itunes:duration>426</itunes:duration><itunes:keywords>business,cisa; mobile; tp-link; okta; k,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9262</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, December 18th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-december-18th-2024--63366483</link><description><![CDATA[Python Delivering AnyDesk Client as RAT<br /><a href="https://isc.sans.edu/diary/Python+Delivering+AnyDesk+Client+as+RAT/31524/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Python+Delivering+AnyDesk+Client+as+RAT/31524/</a><br /> Vishing via Microsoft Teams Facilitates DarkGate Malware Intrusion<br /><a href="https://www.trendmicro.com/en_us/research/24/l/darkgate-malware.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_us/research/24/l/darkgate-malware.html</a><br /> SS7 Attacks<br /><a href="https://www.404media.co/email/ac709882-1e4b-42fc-bcca-cf7ce4793716/" target="_blank" rel="noreferrer noopener">https://www.404media.co/email/ac709882-1e4b-42fc-bcca-cf7ce4793716/</a><br /> CrushFTP Vulnerability<br /><a href="https://crushftp.com/crush11wiki/Wiki.jsp?page=Update" target="_blank" rel="noreferrer noopener">https://crushftp.com/crush11wiki/Wiki.jsp?page=Update</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9260.mp3</guid><pubDate>Wed, 18 Dec 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63366483/9260.mp3" length="4717742" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Python Delivering AnyDesk Client as RAT
https://isc.sans.edu/diary/Python+Delivering+AnyDesk+Client+as+RAT/31524/
 Vishing via Microsoft Teams Facilitates DarkGate Malware Intrusion
https://www.trendmicro.com/en_us/research/24/l/darkgate-malware.html...</itunes:subtitle><itunes:summary><![CDATA[Python Delivering AnyDesk Client as RAT<br /><a href="https://isc.sans.edu/diary/Python+Delivering+AnyDesk+Client+as+RAT/31524/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Python+Delivering+AnyDesk+Client+as+RAT/31524/</a><br /> Vishing via Microsoft Teams Facilitates DarkGate Malware Intrusion<br /><a href="https://www.trendmicro.com/en_us/research/24/l/darkgate-malware.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_us/research/24/l/darkgate-malware.html</a><br /> SS7 Attacks<br /><a href="https://www.404media.co/email/ac709882-1e4b-42fc-bcca-cf7ce4793716/" target="_blank" rel="noreferrer noopener">https://www.404media.co/email/ac709882-1e4b-42fc-bcca-cf7ce4793716/</a><br /> CrushFTP Vulnerability<br /><a href="https://crushftp.com/crush11wiki/Wiki.jsp?page=Update" target="_blank" rel="noreferrer noopener">https://crushftp.com/crush11wiki/Wiki.jsp?page=Update</a><br />]]></itunes:summary><itunes:duration>315</itunes:duration><itunes:keywords>business,computer,crushftp; ss7; vishing; teams;,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9260</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, December 17th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-december-17th-2024--63348126</link><description><![CDATA[MUT-1244 Targeting Offensive Actors<br /><a href="https://securitylabs.datadoghq.com/articles/mut-1244-targeting-offensive-actors/" target="_blank" rel="noreferrer noopener">https://securitylabs.datadoghq.com/articles/mut-1244-targeting-offensive-actors/</a><br /> Golang Crypto Vulnerability<br /><a href="https://github.com/golang/crypto/commit/b4f1988a35dee11ec3e05d6bf3e90b695fbd8909" target="_blank" rel="noreferrer noopener">https://github.com/golang/crypto/commit/b4f1988a35dee11ec3e05d6bf3e90b695fbd8909</a><br /> Meeten Malware: A Cross-Platform Threat to Crypto Wallets on macOS and Windows<br /><a href="https://www.cadosecurity.com/blog/meeten-malware-threat" target="_blank" rel="noreferrer noopener">https://www.cadosecurity.com/blog/meeten-malware-threat</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9258.mp3</guid><pubDate>Tue, 17 Dec 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63348126/9258.mp3" length="5571152" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>MUT-1244 Targeting Offensive Actors
https://securitylabs.datadoghq.com/articles/mut-1244-targeting-offensive-actors/
 Golang Crypto Vulnerability
https://github.com/golang/crypto/commit/b4f1988a35dee11ec3e05d6bf3e90b695fbd8909
 Meeten Malware: A...</itunes:subtitle><itunes:summary><![CDATA[MUT-1244 Targeting Offensive Actors<br /><a href="https://securitylabs.datadoghq.com/articles/mut-1244-targeting-offensive-actors/" target="_blank" rel="noreferrer noopener">https://securitylabs.datadoghq.com/articles/mut-1244-targeting-offensive-actors/</a><br /> Golang Crypto Vulnerability<br /><a href="https://github.com/golang/crypto/commit/b4f1988a35dee11ec3e05d6bf3e90b695fbd8909" target="_blank" rel="noreferrer noopener">https://github.com/golang/crypto/commit/b4f1988a35dee11ec3e05d6bf3e90b695fbd8909</a><br /> Meeten Malware: A Cross-Platform Threat to Crypto Wallets on macOS and Windows<br /><a href="https://www.cadosecurity.com/blog/meeten-malware-threat" target="_blank" rel="noreferrer noopener">https://www.cadosecurity.com/blog/meeten-malware-threat</a><br />]]></itunes:summary><itunes:duration>376</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,meeten; malware; voip; video c,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9258</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, December 16th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-december-16th-2024--63333680</link><description><![CDATA[Exploit Attempts Inspired by Recent Struts 2 File Upload Vulnerability<br /><a href="https://isc.sans.edu/diary/Exploit%20attempts%20inspired%20by%20recent%20Struts2%20File%20Upload%20Vulnerability%20%28CVE-2024-53677%2C%20CVE-2023-50164%29/31520" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit%20attempts%20inspired%20by%20recent%20Struts2%20File%20Upload%20Vulnerability%20%28CVE-2024-53677%2C%20CVE-2023-50164%29/31520</a><br /> Citrix Netscaler Password Spraying Mitigation<br /><a href="https://www.citrix.com/blogs/2024/12/13/password-spraying-attacks-netscaler-december-2024/" target="_blank" rel="noreferrer noopener">https://www.citrix.com/blogs/2024/12/13/password-spraying-attacks-netscaler-december-2024/</a><br /> Let's Encrypt Six Day Certifiates<br /><a href="https://letsencrypt.org/2024/12/11/eoy-letter-2024/" target="_blank" rel="noreferrer noopener">https://letsencrypt.org/2024/12/11/eoy-letter-2024/</a><br /> Devices in Germany Arrived Pre-Pw0n3d<br /><a href="https://cybersecuritynews.com/30000-devices-in-germany-discovered-with-pre-installed-malware-badbox/" target="_blank" rel="noreferrer noopener">https://cybersecuritynews.com/30000-devices-in-germany-discovered-with-pre-installed-malware-badbox/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9256.mp3</guid><pubDate>Mon, 16 Dec 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63333680/9256.mp3" length="4919585" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Exploit Attempts Inspired by Recent Struts 2 File Upload Vulnerability
https://isc.sans.edu/diary/Exploit%20attempts%20inspired%20by%20recent%20Struts2%20File%20Upload%20Vulnerability%20%28CVE-2024-53677%2C%20CVE-2023-50164%29/31520
 Citrix Netscaler...</itunes:subtitle><itunes:summary><![CDATA[Exploit Attempts Inspired by Recent Struts 2 File Upload Vulnerability<br /><a href="https://isc.sans.edu/diary/Exploit%20attempts%20inspired%20by%20recent%20Struts2%20File%20Upload%20Vulnerability%20%28CVE-2024-53677%2C%20CVE-2023-50164%29/31520" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit%20attempts%20inspired%20by%20recent%20Struts2%20File%20Upload%20Vulnerability%20%28CVE-2024-53677%2C%20CVE-2023-50164%29/31520</a><br /> Citrix Netscaler Password Spraying Mitigation<br /><a href="https://www.citrix.com/blogs/2024/12/13/password-spraying-attacks-netscaler-december-2024/" target="_blank" rel="noreferrer noopener">https://www.citrix.com/blogs/2024/12/13/password-spraying-attacks-netscaler-december-2024/</a><br /> Let's Encrypt Six Day Certifiates<br /><a href="https://letsencrypt.org/2024/12/11/eoy-letter-2024/" target="_blank" rel="noreferrer noopener">https://letsencrypt.org/2024/12/11/eoy-letter-2024/</a><br /> Devices in Germany Arrived Pre-Pw0n3d<br /><a href="https://cybersecuritynews.com/30000-devices-in-germany-discovered-with-pre-installed-malware-badbox/" target="_blank" rel="noreferrer noopener">https://cybersecuritynews.com/30000-devices-in-germany-discovered-with-pre-installed-malware-badbox/</a><br />]]></itunes:summary><itunes:duration>330</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,germany; badbox; lets encrypt;,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9256</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, December 13th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-december-13th-2024--63295052</link><description><![CDATA[Windows 11 and TPM <br /><a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/tpm-2-0-%E2%80%93-a-necessity-for-a-secure-and-future-proof-windows-11/4339066" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/blog/windows-itpro-blog/tpm-2-0-%E2%80%93-a-necessity-for-a-secure-and-future-proof-windows-11/4339066</a><br /><a href="https://www.forbes.com/sites/zakdoffman/2024/12/12/microsoft-warns-400-million-windows-users-do-not-update-your-pc/" target="_blank" rel="noreferrer noopener">https://www.forbes.com/sites/zakdoffman/2024/12/12/microsoft-warns-400-million-windows-users-do-not-update-your-pc/</a><br /> Microsoft Azure MFA Bypass<br /><a href="https://www.oasis.security/resources/blog/oasis-security-research-team-discovers-microsoft-azure-mfa-bypass" target="_blank" rel="noreferrer noopener">https://www.oasis.security/resources/blog/oasis-security-research-team-discovers-microsoft-azure-mfa-bypass</a><br /> Struts 2 Arbitrary File Upload CVE-2024-53677<br /><a href="https://cwiki.apache.org/confluence/display/WW/S2-067" target="_blank" rel="noreferrer noopener">https://cwiki.apache.org/confluence/display/WW/S2-067</a><br /> Russian actor Secret Blizzard using tools of other groups to attack Ukraine<br /><a href="https://www.microsoft.com/en-us/security/blog/2024/12/11/frequent-freeloader-part-ii-russian-actor-secret-blizzard-using-tools-of-other-groups-to-attack-ukraine/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2024/12/11/frequent-freeloader-part-ii-russian-actor-secret-blizzard-using-tools-of-other-groups-to-attack-ukraine/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9254.mp3</guid><pubDate>Fri, 13 Dec 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63295052/9254.mp3" length="5601619" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Windows 11 and TPM 
https://techcommunity.microsoft.com/blog/windows-itpro-blog/tpm-2-0-%E2%80%93-a-necessity-for-a-secure-and-future-proof-windows-11/4339066...</itunes:subtitle><itunes:summary><![CDATA[Windows 11 and TPM <br /><a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/tpm-2-0-%E2%80%93-a-necessity-for-a-secure-and-future-proof-windows-11/4339066" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/blog/windows-itpro-blog/tpm-2-0-%E2%80%93-a-necessity-for-a-secure-and-future-proof-windows-11/4339066</a><br /><a href="https://www.forbes.com/sites/zakdoffman/2024/12/12/microsoft-warns-400-million-windows-users-do-not-update-your-pc/" target="_blank" rel="noreferrer noopener">https://www.forbes.com/sites/zakdoffman/2024/12/12/microsoft-warns-400-million-windows-users-do-not-update-your-pc/</a><br /> Microsoft Azure MFA Bypass<br /><a href="https://www.oasis.security/resources/blog/oasis-security-research-team-discovers-microsoft-azure-mfa-bypass" target="_blank" rel="noreferrer noopener">https://www.oasis.security/resources/blog/oasis-security-research-team-discovers-microsoft-azure-mfa-bypass</a><br /> Struts 2 Arbitrary File Upload CVE-2024-53677<br /><a href="https://cwiki.apache.org/confluence/display/WW/S2-067" target="_blank" rel="noreferrer noopener">https://cwiki.apache.org/confluence/display/WW/S2-067</a><br /> Russian actor Secret Blizzard using tools of other groups to attack Ukraine<br /><a href="https://www.microsoft.com/en-us/security/blog/2024/12/11/frequent-freeloader-part-ii-russian-actor-secret-blizzard-using-tools-of-other-groups-to-attack-ukraine/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2024/12/11/frequent-freeloader-part-ii-russian-actor-secret-blizzard-using-tools-of-other-groups-to-attack-ukraine/</a><br />]]></itunes:summary><itunes:duration>378</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,secret blizzard; ukraine; stru,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9254</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, December 12th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-december-12th-2024--63278541</link><description><![CDATA[Vulnerability Symbiosis: vSphere's CVE-2024-38812 and CVE-2024-38813<br /><a href="https://isc.sans.edu/diary/Vulnerability%20Symbiosis%3A%20vSphere%3Fs%20CVE-2024-38812%20and%20CVE-2024-38813%20%5BGuest%20Diary%5D/31510" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Vulnerability%20Symbiosis%3A%20vSphere%3Fs%20CVE-2024-38812%20and%20CVE-2024-38813%20%5BGuest%20Diary%5D/31510</a><br /> Apple Updates Everything (iOS, iPadOS, macOS, watchOS, tvOS, visionOS)<br /><a href="https://isc.sans.edu/diary/Apple+Updates+Everything+iOS+iPadOS+macOS+watchOS+tvOS+visionOS/31514/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple+Updates+Everything+iOS+iPadOS+macOS+watchOS+tvOS+visionOS/31514/</a><br /> Widespread exploitation of Cleo file transfer software (CVE-2024-50623)<br /><a href="https://www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wild" target="_blank" rel="noreferrer noopener">https://www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wild</a><br /><a href="https://labs.watchtowr.com/cleo-cve-2024-50623/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/cleo-cve-2024-50623/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9252.mp3</guid><pubDate>Thu, 12 Dec 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63278541/9252.mp3" length="5151658" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Vulnerability Symbiosis: vSphere's CVE-2024-38812 and CVE-2024-38813
https://isc.sans.edu/diary/Vulnerability%20Symbiosis%3A%20vSphere%3Fs%20CVE-2024-38812%20and%20CVE-2024-38813%20%5BGuest%20Diary%5D/31510
 Apple Updates Everything (iOS, iPadOS,...</itunes:subtitle><itunes:summary><![CDATA[Vulnerability Symbiosis: vSphere's CVE-2024-38812 and CVE-2024-38813<br /><a href="https://isc.sans.edu/diary/Vulnerability%20Symbiosis%3A%20vSphere%3Fs%20CVE-2024-38812%20and%20CVE-2024-38813%20%5BGuest%20Diary%5D/31510" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Vulnerability%20Symbiosis%3A%20vSphere%3Fs%20CVE-2024-38812%20and%20CVE-2024-38813%20%5BGuest%20Diary%5D/31510</a><br /> Apple Updates Everything (iOS, iPadOS, macOS, watchOS, tvOS, visionOS)<br /><a href="https://isc.sans.edu/diary/Apple+Updates+Everything+iOS+iPadOS+macOS+watchOS+tvOS+visionOS/31514/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple+Updates+Everything+iOS+iPadOS+macOS+watchOS+tvOS+visionOS/31514/</a><br /> Widespread exploitation of Cleo file transfer software (CVE-2024-50623)<br /><a href="https://www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wild" target="_blank" rel="noreferrer noopener">https://www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wild</a><br /><a href="https://labs.watchtowr.com/cleo-cve-2024-50623/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/cleo-cve-2024-50623/</a><br />]]></itunes:summary><itunes:duration>346</itunes:duration><itunes:keywords>business,cleo; apple; vsphere; vmware,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9252</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, December 11th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-december-11th-2024--63261108</link><description><![CDATA[Microsoft Patch Tuesday December 2024<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%3A%20December%202024/31508" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%3A%20December%202024/31508</a><br /> Ivanty Security Advisory<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Services-Application-CSA-CVE-2024-11639-CVE-2024-11772-CVE-2024-11773?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Services-Application-CSA-CVE-2024-11639-CVE-2024-11772-CVE-2024-11773?language=en_US</a><br /> Visual Studio Code Tunnels<br /><a href="https://www.sentinelone.com/labs/operation-digital-eye-chinese-apt-compromises-critical-digital-infrastructure-via-visual-studio-code-tunnels/" target="_blank" rel="noreferrer noopener">https://www.sentinelone.com/labs/operation-digital-eye-chinese-apt-compromises-critical-digital-infrastructure-via-visual-studio-code-tunnels/</a><br /> Mitigating NTLM Relay Attacks<br /><a href="https://msrc.microsoft.com/blog/2024/12/mitigating-ntlm-relay-attacks-by-default/" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/blog/2024/12/mitigating-ntlm-relay-attacks-by-default/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9250.mp3</guid><pubDate>Wed, 11 Dec 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63261108/9250.mp3" length="4913078" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft Patch Tuesday December 2024
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%3A%20December%202024/31508
 Ivanty Security Advisory...</itunes:subtitle><itunes:summary><![CDATA[Microsoft Patch Tuesday December 2024<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%3A%20December%202024/31508" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%3A%20December%202024/31508</a><br /> Ivanty Security Advisory<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Services-Application-CSA-CVE-2024-11639-CVE-2024-11772-CVE-2024-11773?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Services-Application-CSA-CVE-2024-11639-CVE-2024-11772-CVE-2024-11773?language=en_US</a><br /> Visual Studio Code Tunnels<br /><a href="https://www.sentinelone.com/labs/operation-digital-eye-chinese-apt-compromises-critical-digital-infrastructure-via-visual-studio-code-tunnels/" target="_blank" rel="noreferrer noopener">https://www.sentinelone.com/labs/operation-digital-eye-chinese-apt-compromises-critical-digital-infrastructure-via-visual-studio-code-tunnels/</a><br /> Mitigating NTLM Relay Attacks<br /><a href="https://msrc.microsoft.com/blog/2024/12/mitigating-ntlm-relay-attacks-by-default/" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/blog/2024/12/mitigating-ntlm-relay-attacks-by-default/</a><br />]]></itunes:summary><itunes:duration>329</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,ntlm; ivanti; visual studio co,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9250</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, December 10th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-december-10th-2024--63248608</link><description><![CDATA[CURLing for Crypto on Honeypots<br /><a href="https://isc.sans.edu/diary/CURLing%20for%20Crypto%20on%20Honeypots/31502" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CURLing%20for%20Crypto%20on%20Honeypots/31502</a><br /> Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection<br /><a href="https://flatt.tech/research/posts/compromising-openwrt-supply-chain-sha256-collision/" target="_blank" rel="noreferrer noopener">https://flatt.tech/research/posts/compromising-openwrt-supply-chain-sha256-collision/</a><br /> Android Monthly Update<br /><a href="https://source.android.com/docs/security/bulletin/pixel/2024-12-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/pixel/2024-12-01</a><br /> RCS Not Always Encrypted<br /><a href="https://daringfireball.net/linked/2024/12/04/shame-on-google-messages" target="_blank" rel="noreferrer noopener">https://daringfireball.net/linked/2024/12/04/shame-on-google-messages</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9248.mp3</guid><pubDate>Tue, 10 Dec 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63248608/9248.mp3" length="5591948" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>CURLing for Crypto on Honeypots
https://isc.sans.edu/diary/CURLing%20for%20Crypto%20on%20Honeypots/31502
 Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection...</itunes:subtitle><itunes:summary><![CDATA[CURLing for Crypto on Honeypots<br /><a href="https://isc.sans.edu/diary/CURLing%20for%20Crypto%20on%20Honeypots/31502" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CURLing%20for%20Crypto%20on%20Honeypots/31502</a><br /> Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection<br /><a href="https://flatt.tech/research/posts/compromising-openwrt-supply-chain-sha256-collision/" target="_blank" rel="noreferrer noopener">https://flatt.tech/research/posts/compromising-openwrt-supply-chain-sha256-collision/</a><br /> Android Monthly Update<br /><a href="https://source.android.com/docs/security/bulletin/pixel/2024-12-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/pixel/2024-12-01</a><br /> RCS Not Always Encrypted<br /><a href="https://daringfireball.net/linked/2024/12/04/shame-on-google-messages" target="_blank" rel="noreferrer noopener">https://daringfireball.net/linked/2024/12/04/shame-on-google-messages</a><br />]]></itunes:summary><itunes:duration>378</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,rcs; android; openwrt; curl; d,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9248</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, December 9th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-december-9th-2024--63231339</link><description><![CDATA[Bypassing WAFs with the Phantom Version Cookie<br /><a href="https://portswigger.net/research/bypassing-wafs-with-the-phantom-version-cookie" target="_blank" rel="noreferrer noopener">https://portswigger.net/research/bypassing-wafs-with-the-phantom-version-cookie</a><br /> URL File NTLM Hash Disclosure<br /><a href="https://blog.0patch.com/2024/12/url-file-ntlm-hash-disclosure.html" target="_blank" rel="noreferrer noopener">https://blog.0patch.com/2024/12/url-file-ntlm-hash-disclosure.html</a><br /> Ultralytics Library Infected with Miner<br /><a href="https://github.com/ultralytics/ultralytics/issues/18027#issuecomment-2521578169" target="_blank" rel="noreferrer noopener">https://github.com/ultralytics/ultralytics/issues/18027#issuecomment-2521578169</a><br /> DaMAgeCard attack targets memory directly thru SD card reader<br /><a href="https://swarm.ptsecurity.com/new-dog-old-tricks-damagecard-attack-targets-memory-directly-thru-sd-card-reader/" target="_blank" rel="noreferrer noopener">https://swarm.ptsecurity.com/new-dog-old-tricks-damagecard-attack-targets-memory-directly-thru-sd-card-reader/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9246.mp3</guid><pubDate>Mon, 09 Dec 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63231339/9246.mp3" length="5038564" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Bypassing WAFs with the Phantom Version Cookie
https://portswigger.net/research/bypassing-wafs-with-the-phantom-version-cookie
 URL File NTLM Hash Disclosure
https://blog.0patch.com/2024/12/url-file-ntlm-hash-disclosure.html
 Ultralytics Library...</itunes:subtitle><itunes:summary><![CDATA[Bypassing WAFs with the Phantom Version Cookie<br /><a href="https://portswigger.net/research/bypassing-wafs-with-the-phantom-version-cookie" target="_blank" rel="noreferrer noopener">https://portswigger.net/research/bypassing-wafs-with-the-phantom-version-cookie</a><br /> URL File NTLM Hash Disclosure<br /><a href="https://blog.0patch.com/2024/12/url-file-ntlm-hash-disclosure.html" target="_blank" rel="noreferrer noopener">https://blog.0patch.com/2024/12/url-file-ntlm-hash-disclosure.html</a><br /> Ultralytics Library Infected with Miner<br /><a href="https://github.com/ultralytics/ultralytics/issues/18027#issuecomment-2521578169" target="_blank" rel="noreferrer noopener">https://github.com/ultralytics/ultralytics/issues/18027#issuecomment-2521578169</a><br /> DaMAgeCard attack targets memory directly thru SD card reader<br /><a href="https://swarm.ptsecurity.com/new-dog-old-tricks-damagecard-attack-targets-memory-directly-thru-sd-card-reader/" target="_blank" rel="noreferrer noopener">https://swarm.ptsecurity.com/new-dog-old-tricks-damagecard-attack-targets-memory-directly-thru-sd-card-reader/</a><br />]]></itunes:summary><itunes:duration>338</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,damagecard; ultralytics; miner,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9246</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, December 6th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-december-6th-2024--63181172</link><description><![CDATA[Business E-Mail Compromise<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Business%20Email%20Compromise/31474" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Business%20Email%20Compromise/31474</a><br /> Where There s Smoke, There s Fire - Mitel MiCollab CVE-2024-35286, CVE-2024-41713 And An 0day<br /><a href="https://labs.watchtowr.com/where-theres-smoke-theres-fire-mitel-micollab-cve-2024-35286-cve-2024-41713-and-an-0day/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/where-theres-smoke-theres-fire-mitel-micollab-cve-2024-35286-cve-2024-41713-and-an-0day/</a><br /><a href="https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029" target="_blank" rel="noreferrer noopener">https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029</a><br /> Lorex 2K Indoor Wi-Fi Security Camera<br /><a href="https://www.rapid7.com/globalassets/_pdfs/research/pwn2own-iot-2024-lorex-2k-indoor-wi-fi-security-camera-research.pdf" target="_blank" rel="noreferrer noopener">https://www.rapid7.com/globalassets/_pdfs/research/pwn2own-iot-2024-lorex-2k-indoor-wi-fi-security-camera-research.pdf</a><br /><a href="https://www.lorex.com/products/2k-indoor-wi-fi-security-camera" target="_blank" rel="noreferrer noopener">https://www.lorex.com/products/2k-indoor-wi-fi-security-camera</a><br /> HPE Aruba Vulnerabilities<br /><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04761en_us&amp;docLocale=en_US" target="_blank" rel="noreferrer noopener">https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04761en_us&amp;docLocale=en_US</a><br /> Alan Paller Inducted into the Cybersecurity Hall of Fame<br /><a href="https://cybersecurityhalloffame.org/" target="_blank" rel="noreferrer noopener">https://cybersecurityhalloffame.org/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9244.mp3</guid><pubDate>Fri, 06 Dec 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63181172/9244.mp3" length="4894302" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Business E-Mail Compromise
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Business%20Email%20Compromise/31474
 Where There s Smoke, There s Fire - Mitel MiCollab CVE-2024-35286, CVE-2024-41713 And An 0day...</itunes:subtitle><itunes:summary><![CDATA[Business E-Mail Compromise<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Business%20Email%20Compromise/31474" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Business%20Email%20Compromise/31474</a><br /> Where There s Smoke, There s Fire - Mitel MiCollab CVE-2024-35286, CVE-2024-41713 And An 0day<br /><a href="https://labs.watchtowr.com/where-theres-smoke-theres-fire-mitel-micollab-cve-2024-35286-cve-2024-41713-and-an-0day/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/where-theres-smoke-theres-fire-mitel-micollab-cve-2024-35286-cve-2024-41713-and-an-0day/</a><br /><a href="https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029" target="_blank" rel="noreferrer noopener">https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029</a><br /> Lorex 2K Indoor Wi-Fi Security Camera<br /><a href="https://www.rapid7.com/globalassets/_pdfs/research/pwn2own-iot-2024-lorex-2k-indoor-wi-fi-security-camera-research.pdf" target="_blank" rel="noreferrer noopener">https://www.rapid7.com/globalassets/_pdfs/research/pwn2own-iot-2024-lorex-2k-indoor-wi-fi-security-camera-research.pdf</a><br /><a href="https://www.lorex.com/products/2k-indoor-wi-fi-security-camera" target="_blank" rel="noreferrer noopener">https://www.lorex.com/products/2k-indoor-wi-fi-security-camera</a><br /> HPE Aruba Vulnerabilities<br /><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04761en_us&amp;docLocale=en_US" target="_blank" rel="noreferrer noopener">https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04761en_us&amp;docLocale=en_US</a><br /> Alan Paller Inducted into the Cybersecurity Hall of Fame<br /><a href="https://cybersecurityhalloffame.org/" target="_blank" rel="noreferrer noopener">https://cybersecurityhalloffame.org/</a><br />]]></itunes:summary><itunes:duration>328</itunes:duration><itunes:keywords>alan paller; lorex; hp; aruba;,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9244</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, December 5th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-december-5th-2024--63156135</link><description><![CDATA[Data Analysis: The Unsung Hero of Cybersecurity Expertise<br /><a href="https://isc.sans.edu/diary/Data%20Analysis%3A%20The%20Unsung%20Hero%20of%20Cybersecurity%20Expertise%20%5BGuest%20Diary%5D/31494" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Data%20Analysis%3A%20The%20Unsung%20Hero%20of%20Cybersecurity%20Expertise%20%5BGuest%20Diary%5D/31494</a><br /> FBI Warns iPhone and Android Users Stop Sending Texts<br /><a href="https://www.forbes.com/sites/zakdoffman/2024/12/03/fbi-warns-iphone-and-android-users-stop-sending-texts/" target="_blank" rel="noreferrer noopener">https://www.forbes.com/sites/zakdoffman/2024/12/03/fbi-warns-iphone-and-android-users-stop-sending-texts/</a><br /> IdentityIQ Improper Access Control Vulnerability   CVE-2024-10905<br /><a href="https://www.sailpoint.com/security-advisories/identityiq-improper-access-control-vulnerability-cve-2024-10905" target="_blank" rel="noreferrer noopener">https://www.sailpoint.com/security-advisories/identityiq-improper-access-control-vulnerability-cve-2024-10905</a><br /> Solana web3.js Backdoor<br /><a href="https://socket.dev/blog/supply-chain-attack-solana-web3-js-library" target="_blank" rel="noreferrer noopener">https://socket.dev/blog/supply-chain-attack-solana-web3-js-library</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9242.mp3</guid><pubDate>Thu, 05 Dec 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63156135/9242.mp3" length="4366536" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Data Analysis: The Unsung Hero of Cybersecurity Expertise
https://isc.sans.edu/diary/Data%20Analysis%3A%20The%20Unsung%20Hero%20of%20Cybersecurity%20Expertise%20%5BGuest%20Diary%5D/31494
 FBI Warns iPhone and Android Users Stop Sending Texts...</itunes:subtitle><itunes:summary><![CDATA[Data Analysis: The Unsung Hero of Cybersecurity Expertise<br /><a href="https://isc.sans.edu/diary/Data%20Analysis%3A%20The%20Unsung%20Hero%20of%20Cybersecurity%20Expertise%20%5BGuest%20Diary%5D/31494" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Data%20Analysis%3A%20The%20Unsung%20Hero%20of%20Cybersecurity%20Expertise%20%5BGuest%20Diary%5D/31494</a><br /> FBI Warns iPhone and Android Users Stop Sending Texts<br /><a href="https://www.forbes.com/sites/zakdoffman/2024/12/03/fbi-warns-iphone-and-android-users-stop-sending-texts/" target="_blank" rel="noreferrer noopener">https://www.forbes.com/sites/zakdoffman/2024/12/03/fbi-warns-iphone-and-android-users-stop-sending-texts/</a><br /> IdentityIQ Improper Access Control Vulnerability   CVE-2024-10905<br /><a href="https://www.sailpoint.com/security-advisories/identityiq-improper-access-control-vulnerability-cve-2024-10905" target="_blank" rel="noreferrer noopener">https://www.sailpoint.com/security-advisories/identityiq-improper-access-control-vulnerability-cve-2024-10905</a><br /> Solana web3.js Backdoor<br /><a href="https://socket.dev/blog/supply-chain-attack-solana-web3-js-library" target="_blank" rel="noreferrer noopener">https://socket.dev/blog/supply-chain-attack-solana-web3-js-library</a><br />]]></itunes:summary><itunes:duration>290</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,data analysis; fbi; sms; rcs; ,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9242</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, December 4th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-december-4th-2024--63136918</link><description><![CDATA[Extracting Files Embedded Inside Word Documents<br /><a href="https://isc.sans.edu/diary/Extracting%20Files%20Embedded%20Inside%20Word%20Documents/31486" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Extracting%20Files%20Embedded%20Inside%20Word%20Documents/31486</a><br /> Korea arrests CEO for adding DDoS feature to satellite receivers<br /><a href="https://www.bleepingcomputer.com/news/security/korea-arrests-ceo-for-adding-ddos-feature-to-satellite-receivers/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/korea-arrests-ceo-for-adding-ddos-feature-to-satellite-receivers/</a><br /> Veeam Vulnerabilities<br /><a href="https://www.veeam.com/kb4679" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4679</a><br /> WPTaskScheduler Presistence and CVE-2024-49039 PoC<br /><a href="https://github.com/je5442804/WPTaskScheduler_CVE-2024-49039" target="_blank" rel="noreferrer noopener">https://github.com/je5442804/WPTaskScheduler_CVE-2024-49039</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9240.mp3</guid><pubDate>Wed, 04 Dec 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63136918/9240.mp3" length="4723226" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Extracting Files Embedded Inside Word Documents
https://isc.sans.edu/diary/Extracting%20Files%20Embedded%20Inside%20Word%20Documents/31486
 Korea arrests CEO for adding DDoS feature to satellite receivers...</itunes:subtitle><itunes:summary><![CDATA[Extracting Files Embedded Inside Word Documents<br /><a href="https://isc.sans.edu/diary/Extracting%20Files%20Embedded%20Inside%20Word%20Documents/31486" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Extracting%20Files%20Embedded%20Inside%20Word%20Documents/31486</a><br /> Korea arrests CEO for adding DDoS feature to satellite receivers<br /><a href="https://www.bleepingcomputer.com/news/security/korea-arrests-ceo-for-adding-ddos-feature-to-satellite-receivers/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/korea-arrests-ceo-for-adding-ddos-feature-to-satellite-receivers/</a><br /> Veeam Vulnerabilities<br /><a href="https://www.veeam.com/kb4679" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4679</a><br /> WPTaskScheduler Presistence and CVE-2024-49039 PoC<br /><a href="https://github.com/je5442804/WPTaskScheduler_CVE-2024-49039" target="_blank" rel="noreferrer noopener">https://github.com/je5442804/WPTaskScheduler_CVE-2024-49039</a><br />]]></itunes:summary><itunes:duration>316</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,word; satteliter; korea; recei</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9240</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, December 3rd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-december-3rd-2024--63117918</link><description><![CDATA[Credential Guard and Kerberos delegation<br /><a href="https://isc.sans.edu/diary/Credential%20Guard%20and%20Kerberos%20delegation/31488" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Credential%20Guard%20and%20Kerberos%20delegation/31488</a><br /> The Day We Unveiled the Secret Rotation Illusion<br /><a href="https://www.clutch.security/blog/the-day-we-unveiled-the-secret-rotation-illusion" target="_blank" rel="noreferrer noopener">https://www.clutch.security/blog/the-day-we-unveiled-the-secret-rotation-illusion</a><br /> Corrupt Word Documents used in Phshing<br /><a href="https://x.com/anyrun_app/status/1861024182210900357" target="_blank" rel="noreferrer noopener">https://x.com/anyrun_app/status/1861024182210900357</a><br /> IBM Security Verify Access Appliance Vulnerabilities<br /><a href="https://www.ibm.com/support/pages/security-bulletin-multiple-security-vulnerabilities-were-found-ibm-security-verify-access-appliance-cve-2024-49803-cve-2024-49804-cve-2024-49805-cve-2024-49806" target="_blank" rel="noreferrer noopener">https://www.ibm.com/support/pages/security-bulletin-multiple-security-vulnerabilities-were-found-ibm-security-verify-access-appliance-cve-2024-49803-cve-2024-49804-cve-2024-49805-cve-2024-49806</a> <br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9238.mp3</guid><pubDate>Tue, 03 Dec 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63117918/9238.mp3" length="5538622" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Credential Guard and Kerberos delegation
https://isc.sans.edu/diary/Credential%20Guard%20and%20Kerberos%20delegation/31488
 The Day We Unveiled the Secret Rotation Illusion...</itunes:subtitle><itunes:summary><![CDATA[Credential Guard and Kerberos delegation<br /><a href="https://isc.sans.edu/diary/Credential%20Guard%20and%20Kerberos%20delegation/31488" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Credential%20Guard%20and%20Kerberos%20delegation/31488</a><br /> The Day We Unveiled the Secret Rotation Illusion<br /><a href="https://www.clutch.security/blog/the-day-we-unveiled-the-secret-rotation-illusion" target="_blank" rel="noreferrer noopener">https://www.clutch.security/blog/the-day-we-unveiled-the-secret-rotation-illusion</a><br /> Corrupt Word Documents used in Phshing<br /><a href="https://x.com/anyrun_app/status/1861024182210900357" target="_blank" rel="noreferrer noopener">https://x.com/anyrun_app/status/1861024182210900357</a><br /> IBM Security Verify Access Appliance Vulnerabilities<br /><a href="https://www.ibm.com/support/pages/security-bulletin-multiple-security-vulnerabilities-were-found-ibm-security-verify-access-appliance-cve-2024-49803-cve-2024-49804-cve-2024-49805-cve-2024-49806" target="_blank" rel="noreferrer noopener">https://www.ibm.com/support/pages/security-bulletin-multiple-security-vulnerabilities-were-found-ibm-security-verify-access-appliance-cve-2024-49803-cve-2024-49804-cve-2024-49805-cve-2024-49806</a> <br />]]></itunes:summary><itunes:duration>374</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,ibm; credentials; static; word,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9238</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, December 2nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-december-2nd-2024--63101264</link><description><![CDATA[AWS DShield Sensor + DShield SIEM<br /><a href="https://isc.sans.edu/diary/SANS%20ISC%20Internship%20Setup%3A%20AWS%20DShield%20Sensor%20%2B%20DShield%20SIEM%20%5BGuest%20Diary%5D/31480" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SANS%20ISC%20Internship%20Setup%3A%20AWS%20DShield%20Sensor%20%2B%20DShield%20SIEM%20%5BGuest%20Diary%5D/31480</a><br /> From a Regular Infostealer to its Obfuscated Version<br /><a href="https://isc.sans.edu/diary/From%20a%20Regular%20Infostealer%20to%20its%20Obfuscated%20Version/31484" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/From%20a%20Regular%20Infostealer%20to%20its%20Obfuscated%20Version/31484</a><br /> Credit Card Skimmer Malware Targeting Magento Checkout Pages<br /><a href="https://blog.sucuri.net/2024/11/credit-card-skimmer-malware-targeting-magento-checkout-pages.html" target="_blank" rel="noreferrer noopener">https://blog.sucuri.net/2024/11/credit-card-skimmer-malware-targeting-magento-checkout-pages.html</a><br /> LogoFAIL Exploited to Deploy Bootkitty, the first UEFI bootkit for Linux<br /><a href="https://www.binarly.io/blog/logofail-exploited-to-deploy-bootkitty-the-first-uefi-bootkit-for-linux" target="_blank" rel="noreferrer noopener">https://www.binarly.io/blog/logofail-exploited-to-deploy-bootkitty-the-first-uefi-bootkit-for-linux</a><br /> Stickers:<br /><a href="https://isc.sans.edu/stickers.html" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/stickers.html</a> (code PODCAST)<br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9236.mp3</guid><pubDate>Mon, 02 Dec 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63101264/9236.mp3" length="5163160" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>AWS DShield Sensor + DShield SIEM
https://isc.sans.edu/diary/SANS%20ISC%20Internship%20Setup%3A%20AWS%20DShield%20Sensor%20%2B%20DShield%20SIEM%20%5BGuest%20Diary%5D/31480
 From a Regular Infostealer to its Obfuscated Version...</itunes:subtitle><itunes:summary><![CDATA[AWS DShield Sensor + DShield SIEM<br /><a href="https://isc.sans.edu/diary/SANS%20ISC%20Internship%20Setup%3A%20AWS%20DShield%20Sensor%20%2B%20DShield%20SIEM%20%5BGuest%20Diary%5D/31480" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SANS%20ISC%20Internship%20Setup%3A%20AWS%20DShield%20Sensor%20%2B%20DShield%20SIEM%20%5BGuest%20Diary%5D/31480</a><br /> From a Regular Infostealer to its Obfuscated Version<br /><a href="https://isc.sans.edu/diary/From%20a%20Regular%20Infostealer%20to%20its%20Obfuscated%20Version/31484" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/From%20a%20Regular%20Infostealer%20to%20its%20Obfuscated%20Version/31484</a><br /> Credit Card Skimmer Malware Targeting Magento Checkout Pages<br /><a href="https://blog.sucuri.net/2024/11/credit-card-skimmer-malware-targeting-magento-checkout-pages.html" target="_blank" rel="noreferrer noopener">https://blog.sucuri.net/2024/11/credit-card-skimmer-malware-targeting-magento-checkout-pages.html</a><br /> LogoFAIL Exploited to Deploy Bootkitty, the first UEFI bootkit for Linux<br /><a href="https://www.binarly.io/blog/logofail-exploited-to-deploy-bootkitty-the-first-uefi-bootkit-for-linux" target="_blank" rel="noreferrer noopener">https://www.binarly.io/blog/logofail-exploited-to-deploy-bootkitty-the-first-uefi-bootkit-for-linux</a><br /> Stickers:<br /><a href="https://isc.sans.edu/stickers.html" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/stickers.html</a> (code PODCAST)<br />]]></itunes:summary><itunes:duration>347</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,stickers; logofail; bootkitty;</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9236</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, November 27th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-november-27th-2024--63022357</link><description><![CDATA[Using Zeek, Snort, and Grafana to Detect Crypto Mining Malware<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Using%20Zeek%2C%20Snort%2C%20and%20Grafana%20to%20Detect%20Crypto%20Mining%20Malware/31472" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Using%20Zeek%2C%20Snort%2C%20and%20Grafana%20to%20Detect%20Crypto%20Mining%20Malware/31472</a><br /> The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access<br /><a href="https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/" target="_blank" rel="noreferrer noopener">https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/</a><br /> Introducing NachoVPN: One VPN Server to Pwn Them All<br /><a href="https://blog.amberwolf.com/blog/2024/november/introducing-nachovpn---one-vpn-server-to-pwn-them-all/" target="_blank" rel="noreferrer noopener">https://blog.amberwolf.com/blog/2024/november/introducing-nachovpn---one-vpn-server-to-pwn-them-all/</a><br /> Keycloak Patches<br /><a href="https://github.com/keycloak/keycloak/security/advisories/GHSA-93ww-43rr-79v3" target="_blank" rel="noreferrer noopener">https://github.com/keycloak/keycloak/security/advisories/GHSA-93ww-43rr-79v3</a><br /> Palo Alto Networks Global Protect App<br /><a href="https://security.paloaltonetworks.com/CVE-2024-5921" target="_blank" rel="noreferrer noopener">https://security.paloaltonetworks.com/CVE-2024-5921</a><br /> PHP Updates<br /><a href="https://github.com/php/php-src/security/advisories/GHSA-g665-fm4p-vhff" target="_blank" rel="noreferrer noopener">https://github.com/php/php-src/security/advisories/GHSA-g665-fm4p-vhff</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9234.mp3</guid><pubDate>Wed, 27 Nov 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63022357/9234.mp3" length="5527843" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Using Zeek, Snort, and Grafana to Detect Crypto Mining Malware
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Using%20Zeek%2C%20Snort%2C%20and%20Grafana%20to%20Detect%20Crypto%20Mining%20Malware/31472
 The Nearest Neighbor Attack: How A Russian APT...</itunes:subtitle><itunes:summary><![CDATA[Using Zeek, Snort, and Grafana to Detect Crypto Mining Malware<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Using%20Zeek%2C%20Snort%2C%20and%20Grafana%20to%20Detect%20Crypto%20Mining%20Malware/31472" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Using%20Zeek%2C%20Snort%2C%20and%20Grafana%20to%20Detect%20Crypto%20Mining%20Malware/31472</a><br /> The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access<br /><a href="https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/" target="_blank" rel="noreferrer noopener">https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/</a><br /> Introducing NachoVPN: One VPN Server to Pwn Them All<br /><a href="https://blog.amberwolf.com/blog/2024/november/introducing-nachovpn---one-vpn-server-to-pwn-them-all/" target="_blank" rel="noreferrer noopener">https://blog.amberwolf.com/blog/2024/november/introducing-nachovpn---one-vpn-server-to-pwn-them-all/</a><br /> Keycloak Patches<br /><a href="https://github.com/keycloak/keycloak/security/advisories/GHSA-93ww-43rr-79v3" target="_blank" rel="noreferrer noopener">https://github.com/keycloak/keycloak/security/advisories/GHSA-93ww-43rr-79v3</a><br /> Palo Alto Networks Global Protect App<br /><a href="https://security.paloaltonetworks.com/CVE-2024-5921" target="_blank" rel="noreferrer noopener">https://security.paloaltonetworks.com/CVE-2024-5921</a><br /> PHP Updates<br /><a href="https://github.com/php/php-src/security/advisories/GHSA-g665-fm4p-vhff" target="_blank" rel="noreferrer noopener">https://github.com/php/php-src/security/advisories/GHSA-g665-fm4p-vhff</a><br />]]></itunes:summary><itunes:duration>373</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,php; pan; keycloak; nachovpn; ,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9234</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, November 26th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-november-26th-2024--63008667</link><description><![CDATA[Quick &amp; Dirty Obfuscated JavaScript Analysis<br /><a href="https://isc.sans.edu/diary/Quick%20%26%20Dirty%20Obfuscated%20JavaScript%20Analysis/31468" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Quick%20%26%20Dirty%20Obfuscated%20JavaScript%20Analysis/31468</a><br /> Decrypting a PDF With a User Password<br /><a href="https://isc.sans.edu/diary/Decrypting%20a%20PDF%20With%20a%20User%20Password/31466" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Decrypting%20a%20PDF%20With%20a%20User%20Password/31466</a><br /> The strange case of disappearing Russian servers<br /><a href="https://isc.sans.edu/diary/The%20strange%20case%20of%20disappearing%20Russian%20servers/31476" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20strange%20case%20of%20disappearing%20Russian%20servers/31476</a><br /> QNAP Buggy Firmware Update<br /><a href="https://community.qnap.com/t/firmware-qts-5-2-2-2950-build-20241114-released/254" target="_blank" rel="noreferrer noopener">https://community.qnap.com/t/firmware-qts-5-2-2-2950-build-20241114-released/254</a><br /> 7-ZIP Zstandard Decompression Integer Underflow<br /><a href="https://www.zerodayinitiative.com/advisories/ZDI-24-1532/" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/advisories/ZDI-24-1532/</a><br /><a href="https://7-zip.org/download.html" target="_blank" rel="noreferrer noopener">https://7-zip.org/download.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9232.mp3</guid><pubDate>Tue, 26 Nov 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/63008667/9232.mp3" length="3984026" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Quick &amp;amp; Dirty Obfuscated JavaScript Analysis
https://isc.sans.edu/diary/Quick%20%26%20Dirty%20Obfuscated%20JavaScript%20Analysis/31468
 Decrypting a PDF With a User Password...</itunes:subtitle><itunes:summary><![CDATA[Quick &amp; Dirty Obfuscated JavaScript Analysis<br /><a href="https://isc.sans.edu/diary/Quick%20%26%20Dirty%20Obfuscated%20JavaScript%20Analysis/31468" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Quick%20%26%20Dirty%20Obfuscated%20JavaScript%20Analysis/31468</a><br /> Decrypting a PDF With a User Password<br /><a href="https://isc.sans.edu/diary/Decrypting%20a%20PDF%20With%20a%20User%20Password/31466" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Decrypting%20a%20PDF%20With%20a%20User%20Password/31466</a><br /> The strange case of disappearing Russian servers<br /><a href="https://isc.sans.edu/diary/The%20strange%20case%20of%20disappearing%20Russian%20servers/31476" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20strange%20case%20of%20disappearing%20Russian%20servers/31476</a><br /> QNAP Buggy Firmware Update<br /><a href="https://community.qnap.com/t/firmware-qts-5-2-2-2950-build-20241114-released/254" target="_blank" rel="noreferrer noopener">https://community.qnap.com/t/firmware-qts-5-2-2-2950-build-20241114-released/254</a><br /> 7-ZIP Zstandard Decompression Integer Underflow<br /><a href="https://www.zerodayinitiative.com/advisories/ZDI-24-1532/" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/advisories/ZDI-24-1532/</a><br /><a href="https://7-zip.org/download.html" target="_blank" rel="noreferrer noopener">https://7-zip.org/download.html</a><br />]]></itunes:summary><itunes:duration>263</itunes:duration><itunes:keywords>7zip; qnap; russia; servers; s,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9232</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, November 22nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-november-22nd-2024--62962141</link><description><![CDATA[Increase In Phishing SVG Attachments<br /><a href="https://isc.sans.edu/diary/Increase%20In%20Phishing%20SVG%20Attachments/31456" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Increase%20In%20Phishing%20SVG%20Attachments/31456</a><br /> Logging blind spot revealed in FortiClient VPN<br /><a href="https://pentera.io/blog/FortiClient-VPN_logging-blind-spot-revealed/" target="_blank" rel="noreferrer noopener">https://pentera.io/blog/FortiClient-VPN_logging-blind-spot-revealed/</a><br /> Needrestart Vulnerability<br /><a href="https://www.qualys.com/2024/11/19/needrestart/needrestart.txt" target="_blank" rel="noreferrer noopener">https://www.qualys.com/2024/11/19/needrestart/needrestart.txt</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9230.mp3</guid><pubDate>Fri, 22 Nov 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62962141/9230.mp3" length="5021195" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Increase In Phishing SVG Attachments
https://isc.sans.edu/diary/Increase%20In%20Phishing%20SVG%20Attachments/31456
 Logging blind spot revealed in FortiClient VPN
https://pentera.io/blog/FortiClient-VPN_logging-blind-spot-revealed/
 Needrestart...</itunes:subtitle><itunes:summary><![CDATA[Increase In Phishing SVG Attachments<br /><a href="https://isc.sans.edu/diary/Increase%20In%20Phishing%20SVG%20Attachments/31456" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Increase%20In%20Phishing%20SVG%20Attachments/31456</a><br /> Logging blind spot revealed in FortiClient VPN<br /><a href="https://pentera.io/blog/FortiClient-VPN_logging-blind-spot-revealed/" target="_blank" rel="noreferrer noopener">https://pentera.io/blog/FortiClient-VPN_logging-blind-spot-revealed/</a><br /> Needrestart Vulnerability<br /><a href="https://www.qualys.com/2024/11/19/needrestart/needrestart.txt" target="_blank" rel="noreferrer noopener">https://www.qualys.com/2024/11/19/needrestart/needrestart.txt</a><br />]]></itunes:summary><itunes:duration>337</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,needrestart; logging; forticli,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9230</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, November 21st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-november-21st-2024--62953394</link><description><![CDATA[Apple Patches Two Exploited Vulnerabilities<br /><a href="https://isc.sans.edu/diary/Apple%20Fixes%20Two%20Exploited%20Vulnerabilities/31452" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Fixes%20Two%20Exploited%20Vulnerabilities/31452</a><br /> Oracle Patch for Agile Product Lifecycle Management CVE-2024-21287<br /><a href="https://www.oracle.com/security-alerts/alert-cve-2024-21287.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/alert-cve-2024-21287.html</a><br /> OFBiz Patches CVE-2024-47208 CVE-2024-48962<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47208" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2024-47208</a><br /><a href="https://seclists.org/oss-sec/2024/q4/95" target="_blank" rel="noreferrer noopener">https://seclists.org/oss-sec/2024/q4/95</a><br /> D-Link Warns of Vulnerability in EOL Devices<br /><a href="https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10415" target="_blank" rel="noreferrer noopener">https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10415</a><br /><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9228.mp3</guid><pubDate>Thu, 21 Nov 2024 08:50:04 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62953394/9228.mp3" length="4554596" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Apple Patches Two Exploited Vulnerabilities
https://isc.sans.edu/diary/Apple%20Fixes%20Two%20Exploited%20Vulnerabilities/31452
 Oracle Patch for Agile Product Lifecycle Management CVE-2024-21287...</itunes:subtitle><itunes:summary><![CDATA[Apple Patches Two Exploited Vulnerabilities<br /><a href="https://isc.sans.edu/diary/Apple%20Fixes%20Two%20Exploited%20Vulnerabilities/31452" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Fixes%20Two%20Exploited%20Vulnerabilities/31452</a><br /> Oracle Patch for Agile Product Lifecycle Management CVE-2024-21287<br /><a href="https://www.oracle.com/security-alerts/alert-cve-2024-21287.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/alert-cve-2024-21287.html</a><br /> OFBiz Patches CVE-2024-47208 CVE-2024-48962<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47208" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2024-47208</a><br /><a href="https://seclists.org/oss-sec/2024/q4/95" target="_blank" rel="noreferrer noopener">https://seclists.org/oss-sec/2024/q4/95</a><br /> D-Link Warns of Vulnerability in EOL Devices<br /><a href="https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10415" target="_blank" rel="noreferrer noopener">https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10415</a><br /><br />]]></itunes:summary><itunes:duration>304</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,ofbiz; d-link; oracle; apple,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9228</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, November 20th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-november-20th-2024--62832948</link><description><![CDATA[Detecting the Presence of a Debugger in Linux<br /><a href="https://isc.sans.edu/diary/Detecting%20the%20Presence%20of%20a%20Debugger%20in%20Linux/31450" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Detecting%20the%20Presence%20of%20a%20Debugger%20in%20Linux/31450</a><br /> Palo Alto Patches<br /><a href="https://security.paloaltonetworks.com/CVE-2024-0012" target="_blank" rel="noreferrer noopener">https://security.paloaltonetworks.com/CVE-2024-0012</a><br /><a href="https://security.paloaltonetworks.com/CVE-2024-9474" target="_blank" rel="noreferrer noopener">https://security.paloaltonetworks.com/CVE-2024-9474</a><br /> VMware vCenter Server Attacks<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968e" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968e</a><br /> Veritas Enterprise Vault Vulnerability<br /><a href="https://www.veritas.com/support/en_US/security/VTS24-014" target="_blank" rel="noreferrer noopener">https://www.veritas.com/support/en_US/security/VTS24-014</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9226.mp3</guid><pubDate>Wed, 20 Nov 2024 02:45:06 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62832948/9226.mp3" length="5514398" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Detecting the Presence of a Debugger in Linux
https://isc.sans.edu/diary/Detecting%20the%20Presence%20of%20a%20Debugger%20in%20Linux/31450
 Palo Alto Patches
https://security.paloaltonetworks.com/CVE-2024-0012...</itunes:subtitle><itunes:summary><![CDATA[Detecting the Presence of a Debugger in Linux<br /><a href="https://isc.sans.edu/diary/Detecting%20the%20Presence%20of%20a%20Debugger%20in%20Linux/31450" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Detecting%20the%20Presence%20of%20a%20Debugger%20in%20Linux/31450</a><br /> Palo Alto Patches<br /><a href="https://security.paloaltonetworks.com/CVE-2024-0012" target="_blank" rel="noreferrer noopener">https://security.paloaltonetworks.com/CVE-2024-0012</a><br /><a href="https://security.paloaltonetworks.com/CVE-2024-9474" target="_blank" rel="noreferrer noopener">https://security.paloaltonetworks.com/CVE-2024-9474</a><br /> VMware vCenter Server Attacks<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968e" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968e</a><br /> Veritas Enterprise Vault Vulnerability<br /><a href="https://www.veritas.com/support/en_US/security/VTS24-014" target="_blank" rel="noreferrer noopener">https://www.veritas.com/support/en_US/security/VTS24-014</a><br />]]></itunes:summary><itunes:duration>372</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,veritas; enterprise; vault; vm</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9226</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, November 19th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-november-19th-2024--62800166</link><description><![CDATA[Exploit attempts for unpatched Citrix vulnerability CVE-2024-8068/CVE-2024-8069<br /><a href="https://isc.sans.edu/diary/Exploit+attempts+for+unpatched+Citrix+vulnerability/31446" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit+attempts+for+unpatched+Citrix+vulnerability/31446</a><br /><a href="https://support.citrix.com/s/article/CTX691941-citrix-session-recording-security-bulletin-for-cve20248068-and-cve20248069?language=en_US" target="_blank" rel="noreferrer noopener">https://support.citrix.com/s/article/CTX691941-citrix-session-recording-security-bulletin-for-cve20248068-and-cve20248069?language=en_US</a><br /> Microsoft Power Pages: Data Exposure Reviewed<br /><a href="https://appomni.com/ao-labs/microsoft-power-pages-data-exposure-reviewed/" target="_blank" rel="noreferrer noopener">https://appomni.com/ao-labs/microsoft-power-pages-data-exposure-reviewed/</a><br /> Zohocorp ManageEngine ADAudit Plus Vulnerable To SQL Injection Attacks CVE-2024-49574<br /><a href="https://www.manageengine.com/products/active-directory-audit/cve-2024-49574.html" target="_blank" rel="noreferrer noopener">https://www.manageengine.com/products/active-directory-audit/cve-2024-49574.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9224.mp3</guid><pubDate>Tue, 19 Nov 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62800166/9224.mp3" length="4696672" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Exploit attempts for unpatched Citrix vulnerability CVE-2024-8068/CVE-2024-8069
https://isc.sans.edu/diary/Exploit+attempts+for+unpatched+Citrix+vulnerability/31446...</itunes:subtitle><itunes:summary><![CDATA[Exploit attempts for unpatched Citrix vulnerability CVE-2024-8068/CVE-2024-8069<br /><a href="https://isc.sans.edu/diary/Exploit+attempts+for+unpatched+Citrix+vulnerability/31446" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit+attempts+for+unpatched+Citrix+vulnerability/31446</a><br /><a href="https://support.citrix.com/s/article/CTX691941-citrix-session-recording-security-bulletin-for-cve20248068-and-cve20248069?language=en_US" target="_blank" rel="noreferrer noopener">https://support.citrix.com/s/article/CTX691941-citrix-session-recording-security-bulletin-for-cve20248068-and-cve20248069?language=en_US</a><br /> Microsoft Power Pages: Data Exposure Reviewed<br /><a href="https://appomni.com/ao-labs/microsoft-power-pages-data-exposure-reviewed/" target="_blank" rel="noreferrer noopener">https://appomni.com/ao-labs/microsoft-power-pages-data-exposure-reviewed/</a><br /> Zohocorp ManageEngine ADAudit Plus Vulnerable To SQL Injection Attacks CVE-2024-49574<br /><a href="https://www.manageengine.com/products/active-directory-audit/cve-2024-49574.html" target="_blank" rel="noreferrer noopener">https://www.manageengine.com/products/active-directory-audit/cve-2024-49574.html</a><br />]]></itunes:summary><itunes:duration>314</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,zohocorp; manageengine; adaudi</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9224</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, November 18th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-november-18th-2024--62783253</link><description><![CDATA[Ancient TP-Link Backdoor Discovered by Attackers<br /><a href="https://isc.sans.edu/diary/Ancient%20TP-Link%20Backdoor%20Discovered%20by%20Attackers/31442" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Ancient%20TP-Link%20Backdoor%20Discovered%20by%20Attackers/31442</a><br /> GitHub Projects Targeted with Malicious Commits To Frame Researchers<br /><a href="https://www.bleepingcomputer.com/news/security/github-projects-targeted-with-malicious-commits-to-frame-researcher/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/github-projects-targeted-with-malicious-commits-to-frame-researcher/</a><br /> PaloAlto and Fortinet Vulnerabilities<br /><a href="https://labs.watchtowr.com/hop-skip-fortijump-fortijumphigher-cve-2024-23113-cve-2024-47575/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/hop-skip-fortijump-fortijumphigher-cve-2024-23113-cve-2024-47575/</a><br /><a href="https://security.paloaltonetworks.com/PAN-SA-2024-0015" target="_blank" rel="noreferrer noopener">https://security.paloaltonetworks.com/PAN-SA-2024-0015</a><br /><a href="https://www.volexity.com/blog/2024/11/15/brazenbamboo-weaponizes-forticlient-vulnerability-to-steal-vpn-credentials-via-deepdata/" target="_blank" rel="noreferrer noopener">https://www.volexity.com/blog/2024/11/15/brazenbamboo-weaponizes-forticlient-vulnerability-to-steal-vpn-credentials-via-deepdata/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9222.mp3</guid><pubDate>Mon, 18 Nov 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62783253/9222.mp3" length="5545209" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Ancient TP-Link Backdoor Discovered by Attackers
https://isc.sans.edu/diary/Ancient%20TP-Link%20Backdoor%20Discovered%20by%20Attackers/31442
 GitHub Projects Targeted with Malicious Commits To Frame Researchers...</itunes:subtitle><itunes:summary><![CDATA[Ancient TP-Link Backdoor Discovered by Attackers<br /><a href="https://isc.sans.edu/diary/Ancient%20TP-Link%20Backdoor%20Discovered%20by%20Attackers/31442" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Ancient%20TP-Link%20Backdoor%20Discovered%20by%20Attackers/31442</a><br /> GitHub Projects Targeted with Malicious Commits To Frame Researchers<br /><a href="https://www.bleepingcomputer.com/news/security/github-projects-targeted-with-malicious-commits-to-frame-researcher/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/github-projects-targeted-with-malicious-commits-to-frame-researcher/</a><br /> PaloAlto and Fortinet Vulnerabilities<br /><a href="https://labs.watchtowr.com/hop-skip-fortijump-fortijumphigher-cve-2024-23113-cve-2024-47575/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/hop-skip-fortijump-fortijumphigher-cve-2024-23113-cve-2024-47575/</a><br /><a href="https://security.paloaltonetworks.com/PAN-SA-2024-0015" target="_blank" rel="noreferrer noopener">https://security.paloaltonetworks.com/PAN-SA-2024-0015</a><br /><a href="https://www.volexity.com/blog/2024/11/15/brazenbamboo-weaponizes-forticlient-vulnerability-to-steal-vpn-credentials-via-deepdata/" target="_blank" rel="noreferrer noopener">https://www.volexity.com/blog/2024/11/15/brazenbamboo-weaponizes-forticlient-vulnerability-to-steal-vpn-credentials-via-deepdata/</a><br />]]></itunes:summary><itunes:duration>374</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,paloalto; pan; fortinet; githu,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9222</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, November 13th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-november-13th-2024--62713619</link><description><![CDATA[Microsoft November 2024 Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20November%202024%20Patch%20Tuesday/31438" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20November%202024%20Patch%20Tuesday/31438</a><br /> CISA Top Routinely Exploited Vulnerabilities<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a</a><br /> APT Actors Embed Malware within macOS Flutter Applications<br /><a href="https://www.jamf.com/blog/jamf-threat-labs-apt-actors-embed-malware-within-macos-flutter-applications/" target="_blank" rel="noreferrer noopener">https://www.jamf.com/blog/jamf-threat-labs-apt-actors-embed-malware-within-macos-flutter-applications/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9220.mp3</guid><pubDate>Wed, 13 Nov 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62713619/9220.mp3" length="5210296" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft November 2024 Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20November%202024%20Patch%20Tuesday/31438
 CISA Top Routinely Exploited Vulnerabilities
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a
 APT Actors Embed...</itunes:subtitle><itunes:summary><![CDATA[Microsoft November 2024 Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20November%202024%20Patch%20Tuesday/31438" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20November%202024%20Patch%20Tuesday/31438</a><br /> CISA Top Routinely Exploited Vulnerabilities<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a</a><br /> APT Actors Embed Malware within macOS Flutter Applications<br /><a href="https://www.jamf.com/blog/jamf-threat-labs-apt-actors-embed-malware-within-macos-flutter-applications/" target="_blank" rel="noreferrer noopener">https://www.jamf.com/blog/jamf-threat-labs-apt-actors-embed-malware-within-macos-flutter-applications/</a><br />]]></itunes:summary><itunes:duration>351</itunes:duration><itunes:keywords>apt; macos; flutter; cisa; mic,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9220</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, November 12th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-november-12th-2024--62699718</link><description><![CDATA[PDF Object Streams<br /><a href="https://isc.sans.edu/diary/PDF%20Object%20Streams/31430" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/PDF%20Object%20Streams/31430</a><br /> Mazda Infotainment Vulnerabilities<br /><a href="https://www.zerodayinitiative.com/blog/2024/11/7/multiple-vulnerabilities-in-the-mazda-in-vehicle-infotainment-ivi-system" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/blog/2024/11/7/multiple-vulnerabilities-in-the-mazda-in-vehicle-infotainment-ivi-system</a><br /> Ruby SAML CVE-2024-45409: As bad as it gets and hiding in plain sight<br /><a href="https://workos.com/blog/ruby-saml-cve-2024-45409" target="_blank" rel="noreferrer noopener">https://workos.com/blog/ruby-saml-cve-2024-45409</a><br /> Veeam Backup Enterprise Manager Vulnerability<br /><a href="https://www.veeam.com/kb4682" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4682</a><br /> Security Update for Dell Enterprise SONiC Distribution Vulnerabilities<br /><a href="https://www.dell.com/support/kbdoc/en-us/000245655/dsa-2024-449-security-update-for-dell-enterprise-sonic-distribution-vulnerabilities" target="_blank" rel="noreferrer noopener">https://www.dell.com/support/kbdoc/en-us/000245655/dsa-2024-449-security-update-for-dell-enterprise-sonic-distribution-vulnerabilities</a><br /> Easy Access to Information for Conducting Fraudulent<br /> Emergency Data Requests Impacts US-Based Companies<br /> and Law Enforcement Agencies<br /><a href="https://www.ic3.gov/CSA/2024/241104.pdf" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/CSA/2024/241104.pdf</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9218.mp3</guid><pubDate>Tue, 12 Nov 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62699718/9218.mp3" length="5394543" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>PDF Object Streams
https://isc.sans.edu/diary/PDF%20Object%20Streams/31430
 Mazda Infotainment Vulnerabilities
https://www.zerodayinitiative.com/blog/2024/11/7/multiple-vulnerabilities-in-the-mazda-in-vehicle-infotainment-ivi-system
 Ruby SAML...</itunes:subtitle><itunes:summary><![CDATA[PDF Object Streams<br /><a href="https://isc.sans.edu/diary/PDF%20Object%20Streams/31430" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/PDF%20Object%20Streams/31430</a><br /> Mazda Infotainment Vulnerabilities<br /><a href="https://www.zerodayinitiative.com/blog/2024/11/7/multiple-vulnerabilities-in-the-mazda-in-vehicle-infotainment-ivi-system" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/blog/2024/11/7/multiple-vulnerabilities-in-the-mazda-in-vehicle-infotainment-ivi-system</a><br /> Ruby SAML CVE-2024-45409: As bad as it gets and hiding in plain sight<br /><a href="https://workos.com/blog/ruby-saml-cve-2024-45409" target="_blank" rel="noreferrer noopener">https://workos.com/blog/ruby-saml-cve-2024-45409</a><br /> Veeam Backup Enterprise Manager Vulnerability<br /><a href="https://www.veeam.com/kb4682" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4682</a><br /> Security Update for Dell Enterprise SONiC Distribution Vulnerabilities<br /><a href="https://www.dell.com/support/kbdoc/en-us/000245655/dsa-2024-449-security-update-for-dell-enterprise-sonic-distribution-vulnerabilities" target="_blank" rel="noreferrer noopener">https://www.dell.com/support/kbdoc/en-us/000245655/dsa-2024-449-security-update-for-dell-enterprise-sonic-distribution-vulnerabilities</a><br /> Easy Access to Information for Conducting Fraudulent<br /> Emergency Data Requests Impacts US-Based Companies<br /> and Law Enforcement Agencies<br /><a href="https://www.ic3.gov/CSA/2024/241104.pdf" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/CSA/2024/241104.pdf</a><br />]]></itunes:summary><itunes:duration>364</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,fbi; dell; sonic; veeam; worko,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9218</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, November 11th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-november-11th-2024--62687404</link><description><![CDATA[zipdump and pkzip records<br /><a href="https://isc.sans.edu/diary/zipdump%20%26%20PKZIP%20Records/31428" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/zipdump%20%26%20PKZIP%20Records/31428</a><br /> Am I Isolated<br /><a href="https://github.com/edera-dev/am-i-isolated" target="_blank" rel="noreferrer noopener">https://github.com/edera-dev/am-i-isolated</a><br /> Locked iPhones Reboot<br /><a href="https://www.404media.co/police-freak-out-at-iphones-mysteriously-rebooting-themselves-locking-cops-out/" target="_blank" rel="noreferrer noopener">https://www.404media.co/police-freak-out-at-iphones-mysteriously-rebooting-themselves-locking-cops-out/</a><br /><a href="https://x.com/naehrdine/status/1854896392797360484" target="_blank" rel="noreferrer noopener">https://x.com/naehrdine/status/1854896392797360484</a><br /> Palo Alto Networks Bulletin<br /><a href="https://security.paloaltonetworks.com/PAN-SA-2024-0015" target="_blank" rel="noreferrer noopener">https://security.paloaltonetworks.com/PAN-SA-2024-0015</a><br /> D-Link Vulnerability<br /><a href="https://netsecfish.notion.site/Command-Injection-Vulnerability-in-name-parameter-for-D-Link-NAS-12d6b683e67c80c49ffcc9214c239a07" target="_blank" rel="noreferrer noopener">https://netsecfish.notion.site/Command-Injection-Vulnerability-in-name-parameter-for-D-Link-NAS-12d6b683e67c80c49ffcc9214c239a07</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9216.mp3</guid><pubDate>Mon, 11 Nov 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62687404/9216.mp3" length="4765286" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>zipdump and pkzip records
https://isc.sans.edu/diary/zipdump%20%26%20PKZIP%20Records/31428
 Am I Isolated
https://github.com/edera-dev/am-i-isolated
 Locked iPhones Reboot...</itunes:subtitle><itunes:summary><![CDATA[zipdump and pkzip records<br /><a href="https://isc.sans.edu/diary/zipdump%20%26%20PKZIP%20Records/31428" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/zipdump%20%26%20PKZIP%20Records/31428</a><br /> Am I Isolated<br /><a href="https://github.com/edera-dev/am-i-isolated" target="_blank" rel="noreferrer noopener">https://github.com/edera-dev/am-i-isolated</a><br /> Locked iPhones Reboot<br /><a href="https://www.404media.co/police-freak-out-at-iphones-mysteriously-rebooting-themselves-locking-cops-out/" target="_blank" rel="noreferrer noopener">https://www.404media.co/police-freak-out-at-iphones-mysteriously-rebooting-themselves-locking-cops-out/</a><br /><a href="https://x.com/naehrdine/status/1854896392797360484" target="_blank" rel="noreferrer noopener">https://x.com/naehrdine/status/1854896392797360484</a><br /> Palo Alto Networks Bulletin<br /><a href="https://security.paloaltonetworks.com/PAN-SA-2024-0015" target="_blank" rel="noreferrer noopener">https://security.paloaltonetworks.com/PAN-SA-2024-0015</a><br /> D-Link Vulnerability<br /><a href="https://netsecfish.notion.site/Command-Injection-Vulnerability-in-name-parameter-for-D-Link-NAS-12d6b683e67c80c49ffcc9214c239a07" target="_blank" rel="noreferrer noopener">https://netsecfish.notion.site/Command-Injection-Vulnerability-in-name-parameter-for-D-Link-NAS-12d6b683e67c80c49ffcc9214c239a07</a><br />]]></itunes:summary><itunes:duration>319</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dlink; palo alto networks; pan,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9216</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, November 8th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-november-8th-2024--62661028</link><description><![CDATA[Steam Account Checker Poisoned with Infostealer<br /><a href="https://isc.sans.edu/diary/Steam%20Account%20Checker%20Poisoned%20with%20Infostealer/31420" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Steam%20Account%20Checker%20Poisoned%20with%20Infostealer/31420</a><br /> Cisco Ultra Reliable Wireless Backhaul Vulnerability<br /><a href="https://www.cisco.com/site/us/en/products/networking/industrial-wireless/ultra-reliable-wireless-backhaul/index.html" target="_blank" rel="noreferrer noopener">https://www.cisco.com/site/us/en/products/networking/industrial-wireless/ultra-reliable-wireless-backhaul/index.html</a><br /> Breaking Down Multipart Parsers: File upload validation bypass<br /><a href="https://blog.sicuranext.com/breaking-down-multipart-parsers-validation-bypass/" target="_blank" rel="noreferrer noopener">https://blog.sicuranext.com/breaking-down-multipart-parsers-validation-bypass/</a><br /> Evasive ZIP Concatenation: Trojan Targets Windows Users<br /><a href="https://perception-point.io/blog/evasive-concatenated-zip-trojan-targets-windows-users/" target="_blank" rel="noreferrer noopener">https://perception-point.io/blog/evasive-concatenated-zip-trojan-targets-windows-users/</a><br /> Veeam Backup Enterprise Manager Vulnerability (CVE-2024-40715)<br /><a href="https://www.veeam.com/kb4682" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4682</a><br /> SANS Holiday Hack Challenge<br /><a href="https://www.sans.org/mlp/holiday-hack-challenge-2024" target="_blank" rel="noreferrer noopener">https://www.sans.org/mlp/holiday-hack-challenge-2024</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9214.mp3</guid><pubDate>Fri, 08 Nov 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62661028/9214.mp3" length="5227066" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Steam Account Checker Poisoned with Infostealer
https://isc.sans.edu/diary/Steam%20Account%20Checker%20Poisoned%20with%20Infostealer/31420
 Cisco Ultra Reliable Wireless Backhaul Vulnerability...</itunes:subtitle><itunes:summary><![CDATA[Steam Account Checker Poisoned with Infostealer<br /><a href="https://isc.sans.edu/diary/Steam%20Account%20Checker%20Poisoned%20with%20Infostealer/31420" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Steam%20Account%20Checker%20Poisoned%20with%20Infostealer/31420</a><br /> Cisco Ultra Reliable Wireless Backhaul Vulnerability<br /><a href="https://www.cisco.com/site/us/en/products/networking/industrial-wireless/ultra-reliable-wireless-backhaul/index.html" target="_blank" rel="noreferrer noopener">https://www.cisco.com/site/us/en/products/networking/industrial-wireless/ultra-reliable-wireless-backhaul/index.html</a><br /> Breaking Down Multipart Parsers: File upload validation bypass<br /><a href="https://blog.sicuranext.com/breaking-down-multipart-parsers-validation-bypass/" target="_blank" rel="noreferrer noopener">https://blog.sicuranext.com/breaking-down-multipart-parsers-validation-bypass/</a><br /> Evasive ZIP Concatenation: Trojan Targets Windows Users<br /><a href="https://perception-point.io/blog/evasive-concatenated-zip-trojan-targets-windows-users/" target="_blank" rel="noreferrer noopener">https://perception-point.io/blog/evasive-concatenated-zip-trojan-targets-windows-users/</a><br /> Veeam Backup Enterprise Manager Vulnerability (CVE-2024-40715)<br /><a href="https://www.veeam.com/kb4682" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4682</a><br /> SANS Holiday Hack Challenge<br /><a href="https://www.sans.org/mlp/holiday-hack-challenge-2024" target="_blank" rel="noreferrer noopener">https://www.sans.org/mlp/holiday-hack-challenge-2024</a><br />]]></itunes:summary><itunes:duration>352</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,holiday; hack; challenge; sans,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9214</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, November 7th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-november-7th-2024--62647893</link><description><![CDATA[Insights from August Web Traffic Surge<br /><a href="https://isc.sans.edu/forums/diary/%5BGuest%20Diary%5D%20Insights%20from%20August%20Web%20Traffic%20Surge/31408/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/%5BGuest%20Diary%5D%20Insights%20from%20August%20Web%20Traffic%20Surge/31408/</a><br /> Talkative Air Fryer<br /><a href="https://www.which.co.uk/policy-and-insight/article/why-is-my-air-fryer-spying-on-me-which-reveals-the-smart-devices-gathering-your-data-and-where-they-send-it-a9Fa24K6gY1c" target="_blank" rel="noreferrer noopener">https://www.which.co.uk/policy-and-insight/article/why-is-my-air-fryer-spying-on-me-which-reveals-the-smart-devices-gathering-your-data-and-where-they-send-it-a9Fa24K6gY1c</a><br /> Pygmy Goat Malware Report<br /><a href="https://www.ncsc.gov.uk/section/keep-up-to-date/malware-analysis-reports" target="_blank" rel="noreferrer noopener">https://www.ncsc.gov.uk/section/keep-up-to-date/malware-analysis-reports</a><br /> Apple CVE-2024-44258 PoC Exploit<br /><a href="https://github.com/ifpdz/CVE-2024-44258" target="_blank" rel="noreferrer noopener">https://github.com/ifpdz/CVE-2024-44258</a><br /> HPE Arruba vulnerabilities<br /><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04722en_us&amp;docLocale=en_US" target="_blank" rel="noreferrer noopener">https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04722en_us&amp;docLocale=en_US</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9212.mp3</guid><pubDate>Thu, 07 Nov 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62647893/9212.mp3" length="4207024" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Insights from August Web Traffic Surge
https://isc.sans.edu/forums/diary/%5BGuest%20Diary%5D%20Insights%20from%20August%20Web%20Traffic%20Surge/31408/
 Talkative Air Fryer...</itunes:subtitle><itunes:summary><![CDATA[Insights from August Web Traffic Surge<br /><a href="https://isc.sans.edu/forums/diary/%5BGuest%20Diary%5D%20Insights%20from%20August%20Web%20Traffic%20Surge/31408/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/%5BGuest%20Diary%5D%20Insights%20from%20August%20Web%20Traffic%20Surge/31408/</a><br /> Talkative Air Fryer<br /><a href="https://www.which.co.uk/policy-and-insight/article/why-is-my-air-fryer-spying-on-me-which-reveals-the-smart-devices-gathering-your-data-and-where-they-send-it-a9Fa24K6gY1c" target="_blank" rel="noreferrer noopener">https://www.which.co.uk/policy-and-insight/article/why-is-my-air-fryer-spying-on-me-which-reveals-the-smart-devices-gathering-your-data-and-where-they-send-it-a9Fa24K6gY1c</a><br /> Pygmy Goat Malware Report<br /><a href="https://www.ncsc.gov.uk/section/keep-up-to-date/malware-analysis-reports" target="_blank" rel="noreferrer noopener">https://www.ncsc.gov.uk/section/keep-up-to-date/malware-analysis-reports</a><br /> Apple CVE-2024-44258 PoC Exploit<br /><a href="https://github.com/ifpdz/CVE-2024-44258" target="_blank" rel="noreferrer noopener">https://github.com/ifpdz/CVE-2024-44258</a><br /> HPE Arruba vulnerabilities<br /><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04722en_us&amp;docLocale=en_US" target="_blank" rel="noreferrer noopener">https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04722en_us&amp;docLocale=en_US</a><br />]]></itunes:summary><itunes:duration>279</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,hpe; arruba; apple; poc; pygmy,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9212</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, November 6th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-november-6th-2024--62633336</link><description><![CDATA[Python RAT with a Nice Screensharing Feature<br /><a href="https://isc.sans.edu/diary/Python%20RAT%20with%20a%20Nice%20Screensharing%20Feature/31414" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Python%20RAT%20with%20a%20Nice%20Screensharing%20Feature/31414</a><br /> Android Security Bulletin November 2024<br /><a href="https://source.android.com/docs/security/bulletin/2024-11-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2024-11-01</a><br /> Malware Delivered as Virtual Machine<br /><a href="https://www.securonix.com/blog/crontrap-emulated-linux-environments-as-the-latest-tactic-in-malware-staging/" target="_blank" rel="noreferrer noopener">https://www.securonix.com/blog/crontrap-emulated-linux-environments-as-the-latest-tactic-in-malware-staging/</a><br /> Fake Docusign Invoices<br /><a href="https://lab.wallarm.com/attackers-abuse-docusign-api-to-send-authentic-looking-invoices-at-scale/" target="_blank" rel="noreferrer noopener">https://lab.wallarm.com/attackers-abuse-docusign-api-to-send-authentic-looking-invoices-at-scale/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9210.mp3</guid><pubDate>Wed, 06 Nov 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62633336/9210.mp3" length="4871509" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Python RAT with a Nice Screensharing Feature
https://isc.sans.edu/diary/Python%20RAT%20with%20a%20Nice%20Screensharing%20Feature/31414
 Android Security Bulletin November 2024
https://source.android.com/docs/security/bulletin/2024-11-01
 Malware...</itunes:subtitle><itunes:summary><![CDATA[Python RAT with a Nice Screensharing Feature<br /><a href="https://isc.sans.edu/diary/Python%20RAT%20with%20a%20Nice%20Screensharing%20Feature/31414" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Python%20RAT%20with%20a%20Nice%20Screensharing%20Feature/31414</a><br /> Android Security Bulletin November 2024<br /><a href="https://source.android.com/docs/security/bulletin/2024-11-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2024-11-01</a><br /> Malware Delivered as Virtual Machine<br /><a href="https://www.securonix.com/blog/crontrap-emulated-linux-environments-as-the-latest-tactic-in-malware-staging/" target="_blank" rel="noreferrer noopener">https://www.securonix.com/blog/crontrap-emulated-linux-environments-as-the-latest-tactic-in-malware-staging/</a><br /> Fake Docusign Invoices<br /><a href="https://lab.wallarm.com/attackers-abuse-docusign-api-to-send-authentic-looking-invoices-at-scale/" target="_blank" rel="noreferrer noopener">https://lab.wallarm.com/attackers-abuse-docusign-api-to-send-authentic-looking-invoices-at-scale/</a><br />]]></itunes:summary><itunes:duration>326</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,docusign; malware; vm; android,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9210</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, November 5th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-november-5th-2024--62616605</link><description><![CDATA[Analyzing an Encrypted Phishing PDF<br /><a href="https://isc.sans.edu/diary/Analyzing%20an%20Encrypted%20Phishing%20PDF/31404" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analyzing%20an%20Encrypted%20Phishing%20PDF/31404</a><br /> Okta Verify Desktop MFA For Windows Password Less Login CVE-2024-9191<br /><a href="https://trust.okta.com/security-advisories/okta-verify-desktop-mfa-for-windows-passwordless-login-cve-2024-9191/" target="_blank" rel="noreferrer noopener">https://trust.okta.com/security-advisories/okta-verify-desktop-mfa-for-windows-passwordless-login-cve-2024-9191/</a><br /> QNAP QuRouter Vulnerability and Patch<br /><a href="https://www.qnap.com/en/security-advisory/qsa-24-45" target="_blank" rel="noreferrer noopener">https://www.qnap.com/en/security-advisory/qsa-24-45</a><br /> From Naptime to Big Sleep<br /><a href="https://googleprojectzero.blogspot.com/2024/10/from-naptime-to-big-sleep.html" target="_blank" rel="noreferrer noopener">https://googleprojectzero.blogspot.com/2024/10/from-naptime-to-big-sleep.html</a><br /> Authenticated SQL injection vulnerability - ManageEngine ADManager Plus CVE-2024-48878<br /><a href="https://www.manageengine.com/products/ad-manager/admanager-kb/cve-2024-48878.html" target="_blank" rel="noreferrer noopener">https://www.manageengine.com/products/ad-manager/admanager-kb/cve-2024-48878.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9208.mp3</guid><pubDate>Tue, 05 Nov 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62616605/9208.mp3" length="4416243" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Analyzing an Encrypted Phishing PDF
https://isc.sans.edu/diary/Analyzing%20an%20Encrypted%20Phishing%20PDF/31404
 Okta Verify Desktop MFA For Windows Password Less Login CVE-2024-9191...</itunes:subtitle><itunes:summary><![CDATA[Analyzing an Encrypted Phishing PDF<br /><a href="https://isc.sans.edu/diary/Analyzing%20an%20Encrypted%20Phishing%20PDF/31404" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analyzing%20an%20Encrypted%20Phishing%20PDF/31404</a><br /> Okta Verify Desktop MFA For Windows Password Less Login CVE-2024-9191<br /><a href="https://trust.okta.com/security-advisories/okta-verify-desktop-mfa-for-windows-passwordless-login-cve-2024-9191/" target="_blank" rel="noreferrer noopener">https://trust.okta.com/security-advisories/okta-verify-desktop-mfa-for-windows-passwordless-login-cve-2024-9191/</a><br /> QNAP QuRouter Vulnerability and Patch<br /><a href="https://www.qnap.com/en/security-advisory/qsa-24-45" target="_blank" rel="noreferrer noopener">https://www.qnap.com/en/security-advisory/qsa-24-45</a><br /> From Naptime to Big Sleep<br /><a href="https://googleprojectzero.blogspot.com/2024/10/from-naptime-to-big-sleep.html" target="_blank" rel="noreferrer noopener">https://googleprojectzero.blogspot.com/2024/10/from-naptime-to-big-sleep.html</a><br /> Authenticated SQL injection vulnerability - ManageEngine ADManager Plus CVE-2024-48878<br /><a href="https://www.manageengine.com/products/ad-manager/admanager-kb/cve-2024-48878.html" target="_blank" rel="noreferrer noopener">https://www.manageengine.com/products/ad-manager/admanager-kb/cve-2024-48878.html</a><br />]]></itunes:summary><itunes:duration>294</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,zoho; manage engine; admanager</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9208</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, November 4th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-november-4th-2024--62600717</link><description><![CDATA[October Activity with Username chenzilong<br /><a href="https://isc.sans.edu/diary/October%202024%20Activity%20with%20Username%20chenzilong/31400" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/October%202024%20Activity%20with%20Username%20chenzilong/31400</a><br /> qpdf Extracting PDF Streams<br /><a href="https://isc.sans.edu/diary/qpdf%3A%20Extracting%20PDF%20Streams/31406" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/qpdf%3A%20Extracting%20PDF%20Streams/31406</a><br /> Okta bcrypt issue<br /><a href="https://trust.okta.com/security-advisories/okta-ad-ldap-delegated-authentication-username/" target="_blank" rel="noreferrer noopener">https://trust.okta.com/security-advisories/okta-ad-ldap-delegated-authentication-username/</a><br /><a href="https://medium.com/@rajat29gupta/how-bcrypts-limitations-contributed-to-okta-s-vulnerability-a-lesson-for-developers-39425c644ed5" target="_blank" rel="noreferrer noopener">https://medium.com/@rajat29gupta/how-bcrypts-limitations-contributed-to-okta-s-vulnerability-a-lesson-for-developers-39425c644ed5</a><br /> Synology Vulnerabilities<br /><a href="https://www.synology.com/de-de/security/advisory/Synology_SA_24_19" target="_blank" rel="noreferrer noopener">https://www.synology.com/de-de/security/advisory/Synology_SA_24_19</a><br /><a href="https://www.synology.com/de-de/security/advisory/Synology_SA_24_18" target="_blank" rel="noreferrer noopener">https://www.synology.com/de-de/security/advisory/Synology_SA_24_18</a><br /> Lastpass Fake Reviews<br /><a href="https://blog.lastpass.com/posts/fake-web-store-reviews-attempting-to-steal-customer-data" target="_blank" rel="noreferrer noopener">https://blog.lastpass.com/posts/fake-web-store-reviews-attempting-to-steal-customer-data</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9206.mp3</guid><pubDate>Mon, 04 Nov 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62600717/9206.mp3" length="5174786" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>October Activity with Username chenzilong
https://isc.sans.edu/diary/October%202024%20Activity%20with%20Username%20chenzilong/31400
 qpdf Extracting PDF Streams
https://isc.sans.edu/diary/qpdf%3A%20Extracting%20PDF%20Streams/31406
 Okta bcrypt issue...</itunes:subtitle><itunes:summary><![CDATA[October Activity with Username chenzilong<br /><a href="https://isc.sans.edu/diary/October%202024%20Activity%20with%20Username%20chenzilong/31400" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/October%202024%20Activity%20with%20Username%20chenzilong/31400</a><br /> qpdf Extracting PDF Streams<br /><a href="https://isc.sans.edu/diary/qpdf%3A%20Extracting%20PDF%20Streams/31406" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/qpdf%3A%20Extracting%20PDF%20Streams/31406</a><br /> Okta bcrypt issue<br /><a href="https://trust.okta.com/security-advisories/okta-ad-ldap-delegated-authentication-username/" target="_blank" rel="noreferrer noopener">https://trust.okta.com/security-advisories/okta-ad-ldap-delegated-authentication-username/</a><br /><a href="https://medium.com/@rajat29gupta/how-bcrypts-limitations-contributed-to-okta-s-vulnerability-a-lesson-for-developers-39425c644ed5" target="_blank" rel="noreferrer noopener">https://medium.com/@rajat29gupta/how-bcrypts-limitations-contributed-to-okta-s-vulnerability-a-lesson-for-developers-39425c644ed5</a><br /> Synology Vulnerabilities<br /><a href="https://www.synology.com/de-de/security/advisory/Synology_SA_24_19" target="_blank" rel="noreferrer noopener">https://www.synology.com/de-de/security/advisory/Synology_SA_24_19</a><br /><a href="https://www.synology.com/de-de/security/advisory/Synology_SA_24_18" target="_blank" rel="noreferrer noopener">https://www.synology.com/de-de/security/advisory/Synology_SA_24_18</a><br /> Lastpass Fake Reviews<br /><a href="https://blog.lastpass.com/posts/fake-web-store-reviews-attempting-to-steal-customer-data" target="_blank" rel="noreferrer noopener">https://blog.lastpass.com/posts/fake-web-store-reviews-attempting-to-steal-customer-data</a><br />]]></itunes:summary><itunes:duration>348</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,lastpass; synology; brcrypt; o,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9206</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, October 31st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-october-31st-2024--62564947</link><description><![CDATA[Scans for RDP Gateways<br /><a href="https://isc.sans.edu/diary/Scans%20for%20RDP%20Gateways/31398" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20RDP%20Gateways/31398</a><br /> CyberPanel Exploited<br /><a href="https://www.bleepingcomputer.com/news/security/massive-psaux-ransomware-attack-targets-22-000-cyberpanel-instances/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/massive-psaux-ransomware-attack-targets-22-000-cyberpanel-instances/</a><br /> Windows Themes Files Spoofing CVE-2024-38030<br /><a href="https://blog.0patch.com/2024/10/we-patched-cve-2024-38030-found-another.html" target="_blank" rel="noreferrer noopener">https://blog.0patch.com/2024/10/we-patched-cve-2024-38030-found-another.html</a><br /> QNAP Patches CVE-2024-50388, CVE-2024-50387<br /><a href="https://www.qnap.com/en/security-advisory/qsa-24-41" target="_blank" rel="noreferrer noopener">https://www.qnap.com/en/security-advisory/qsa-24-41</a><br /> Facebook Malvertising<br /><a href="https://www.bitdefender.com/en-us/blog/labs/unmasking-the-sys01-infostealer-threat-bitdefender-labs-tracks-global-malvertising-campaign-targeting-meta-business-pages/" target="_blank" rel="noreferrer noopener">https://www.bitdefender.com/en-us/blog/labs/unmasking-the-sys01-infostealer-threat-bitdefender-labs-tracks-global-malvertising-campaign-targeting-meta-business-pages/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9204.mp3</guid><pubDate>Thu, 31 Oct 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62564947/9204.mp3" length="5246246" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Scans for RDP Gateways
https://isc.sans.edu/diary/Scans%20for%20RDP%20Gateways/31398
 CyberPanel Exploited
https://www.bleepingcomputer.com/news/security/massive-psaux-ransomware-attack-targets-22-000-cyberpanel-instances/
 Windows Themes Files...</itunes:subtitle><itunes:summary><![CDATA[Scans for RDP Gateways<br /><a href="https://isc.sans.edu/diary/Scans%20for%20RDP%20Gateways/31398" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20RDP%20Gateways/31398</a><br /> CyberPanel Exploited<br /><a href="https://www.bleepingcomputer.com/news/security/massive-psaux-ransomware-attack-targets-22-000-cyberpanel-instances/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/massive-psaux-ransomware-attack-targets-22-000-cyberpanel-instances/</a><br /> Windows Themes Files Spoofing CVE-2024-38030<br /><a href="https://blog.0patch.com/2024/10/we-patched-cve-2024-38030-found-another.html" target="_blank" rel="noreferrer noopener">https://blog.0patch.com/2024/10/we-patched-cve-2024-38030-found-another.html</a><br /> QNAP Patches CVE-2024-50388, CVE-2024-50387<br /><a href="https://www.qnap.com/en/security-advisory/qsa-24-41" target="_blank" rel="noreferrer noopener">https://www.qnap.com/en/security-advisory/qsa-24-41</a><br /> Facebook Malvertising<br /><a href="https://www.bitdefender.com/en-us/blog/labs/unmasking-the-sys01-infostealer-threat-bitdefender-labs-tracks-global-malvertising-campaign-targeting-meta-business-pages/" target="_blank" rel="noreferrer noopener">https://www.bitdefender.com/en-us/blog/labs/unmasking-the-sys01-infostealer-threat-bitdefender-labs-tracks-global-malvertising-campaign-targeting-meta-business-pages/</a><br />]]></itunes:summary><itunes:duration>353</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,facebook; malvertising; bussin,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9204</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, October 30th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-october-30th-2024--62551749</link><description><![CDATA[Critical RCE Vulnerabilty in Cyberpanel<br /><a href="https://dreyand.rs/code/review/2024/10/27/what-are-my-options-cyberpanel-v236-pre-auth-rce" target="_blank" rel="noreferrer noopener">https://dreyand.rs/code/review/2024/10/27/what-are-my-options-cyberpanel-v236-pre-auth-rce</a><br /> Spring WebFlux Vulnerability<br /><a href="https://access.redhat.com/security/cve/cve-2024-38821" target="_blank" rel="noreferrer noopener">https://access.redhat.com/security/cve/cve-2024-38821</a><br /><a href="https://spring.io/security/cve-2024-38821" target="_blank" rel="noreferrer noopener">https://spring.io/security/cve-2024-38821</a><br /> Inbound SMTP DANE with DNSSEC for Exchange Online<br /><a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/announcing-general-availability-of-inbound-smtp-dane-with-dnssec/ba-p/4281292" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/exchange-team-blog/announcing-general-availability-of-inbound-smtp-dane-with-dnssec/ba-p/4281292</a><br /> HeptaX: Unauthorized RDP Connections for Cyberespionage Operations<br /><a href="https://cyble.com/blog/heptax-unauthorized-rdp-connections-for-cyberespionage-operations/" target="_blank" rel="noreferrer noopener">https://cyble.com/blog/heptax-unauthorized-rdp-connections-for-cyberespionage-operations/</a><br /><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9202.mp3</guid><pubDate>Wed, 30 Oct 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62551749/9202.mp3" length="5501549" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Critical RCE Vulnerabilty in Cyberpanel
https://dreyand.rs/code/review/2024/10/27/what-are-my-options-cyberpanel-v236-pre-auth-rce
 Spring WebFlux Vulnerability
https://access.redhat.com/security/cve/cve-2024-38821...</itunes:subtitle><itunes:summary><![CDATA[Critical RCE Vulnerabilty in Cyberpanel<br /><a href="https://dreyand.rs/code/review/2024/10/27/what-are-my-options-cyberpanel-v236-pre-auth-rce" target="_blank" rel="noreferrer noopener">https://dreyand.rs/code/review/2024/10/27/what-are-my-options-cyberpanel-v236-pre-auth-rce</a><br /> Spring WebFlux Vulnerability<br /><a href="https://access.redhat.com/security/cve/cve-2024-38821" target="_blank" rel="noreferrer noopener">https://access.redhat.com/security/cve/cve-2024-38821</a><br /><a href="https://spring.io/security/cve-2024-38821" target="_blank" rel="noreferrer noopener">https://spring.io/security/cve-2024-38821</a><br /> Inbound SMTP DANE with DNSSEC for Exchange Online<br /><a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/announcing-general-availability-of-inbound-smtp-dane-with-dnssec/ba-p/4281292" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/exchange-team-blog/announcing-general-availability-of-inbound-smtp-dane-with-dnssec/ba-p/4281292</a><br /> HeptaX: Unauthorized RDP Connections for Cyberespionage Operations<br /><a href="https://cyble.com/blog/heptax-unauthorized-rdp-connections-for-cyberespionage-operations/" target="_blank" rel="noreferrer noopener">https://cyble.com/blog/heptax-unauthorized-rdp-connections-for-cyberespionage-operations/</a><br /><br />]]></itunes:summary><itunes:duration>371</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,heptax; dane; dnssec; rdp; spr,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9202</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, October 29th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-october-29th-2024--62537133</link><description><![CDATA[Apple Update Everything<br /><a href="https://isc.sans.edu/diary/Apple%20Updates%20Everything/31390" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Updates%20Everything/31390</a><br /> Selfcontained HTML Phishing Attachment Using Telegram to Exfiltrate Credentials<br /><a href="https://isc.sans.edu/diary/Selfcontained+HTML+phishing+attachment+using+Telegram+to+exfiltrate+stolen+credentials/31388/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Selfcontained+HTML+phishing+attachment+using+Telegram+to+exfiltrate+stolen+credentials/31388/</a><br /> ChatGPT-4o Guardrail Jailbreak: Hex Encoding for Writing CVE Exploits<br /><a href="https://0din.ai/blog/chatgpt-4o-guardrail-jailbreak-hex-encoding-for-writing-cve-exploits" target="_blank" rel="noreferrer noopener">https://0din.ai/blog/chatgpt-4o-guardrail-jailbreak-hex-encoding-for-writing-cve-exploits</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9200.mp3</guid><pubDate>Tue, 29 Oct 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62537133/9200.mp3" length="4874364" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Apple Update Everything
https://isc.sans.edu/diary/Apple%20Updates%20Everything/31390
 Selfcontained HTML Phishing Attachment Using Telegram to Exfiltrate Credentials...</itunes:subtitle><itunes:summary><![CDATA[Apple Update Everything<br /><a href="https://isc.sans.edu/diary/Apple%20Updates%20Everything/31390" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Updates%20Everything/31390</a><br /> Selfcontained HTML Phishing Attachment Using Telegram to Exfiltrate Credentials<br /><a href="https://isc.sans.edu/diary/Selfcontained+HTML+phishing+attachment+using+Telegram+to+exfiltrate+stolen+credentials/31388/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Selfcontained+HTML+phishing+attachment+using+Telegram+to+exfiltrate+stolen+credentials/31388/</a><br /> ChatGPT-4o Guardrail Jailbreak: Hex Encoding for Writing CVE Exploits<br /><a href="https://0din.ai/blog/chatgpt-4o-guardrail-jailbreak-hex-encoding-for-writing-cve-exploits" target="_blank" rel="noreferrer noopener">https://0din.ai/blog/chatgpt-4o-guardrail-jailbreak-hex-encoding-for-writing-cve-exploits</a><br />]]></itunes:summary><itunes:duration>327</itunes:duration><itunes:keywords>business,chatgpt; guardrails; apple; ht,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9200</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, October 28th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-october-28th-2024--62525343</link><description><![CDATA[Two currently (old) exploited Ivanti vulnerabilities<br /><a href="https://isc.sans.edu/diary/Two%20currently%20%28old%29%20exploited%20Ivanti%20vulnerabilities/31384" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Two%20currently%20%28old%29%20exploited%20Ivanti%20vulnerabilities/31384</a><br /> Arcadyan FMIMG51AX000J (WiFi Alliance) RCE CVE-2024-41992<br /><a href="https://ssd-disclosure.com/ssd-advisory-arcadyan-fmimg51ax000j-wifi-alliance-rce/" target="_blank" rel="noreferrer noopener">https://ssd-disclosure.com/ssd-advisory-arcadyan-fmimg51ax000j-wifi-alliance-rce/</a><br /> Okta iOS App Vulnerability CVE-2024-10327<br /><a href="https://trust.okta.com/security-advisories/okta-verify-for-ios-cve-2024-10327/" target="_blank" rel="noreferrer noopener">https://trust.okta.com/security-advisories/okta-verify-for-ios-cve-2024-10327/</a><br /> Threat Alert TeamTNT's docker gatling gun campaign<br /><a href="https://www.aquasec.com/blog/threat-alert-teamtnts-docker-gatling-gun-campaign/" target="_blank" rel="noreferrer noopener">https://www.aquasec.com/blog/threat-alert-teamtnts-docker-gatling-gun-campaign/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9198.mp3</guid><pubDate>Mon, 28 Oct 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62525343/9198.mp3" length="5035437" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Two currently (old) exploited Ivanti vulnerabilities
https://isc.sans.edu/diary/Two%20currently%20%28old%29%20exploited%20Ivanti%20vulnerabilities/31384
 Arcadyan FMIMG51AX000J (WiFi Alliance) RCE CVE-2024-41992...</itunes:subtitle><itunes:summary><![CDATA[Two currently (old) exploited Ivanti vulnerabilities<br /><a href="https://isc.sans.edu/diary/Two%20currently%20%28old%29%20exploited%20Ivanti%20vulnerabilities/31384" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Two%20currently%20%28old%29%20exploited%20Ivanti%20vulnerabilities/31384</a><br /> Arcadyan FMIMG51AX000J (WiFi Alliance) RCE CVE-2024-41992<br /><a href="https://ssd-disclosure.com/ssd-advisory-arcadyan-fmimg51ax000j-wifi-alliance-rce/" target="_blank" rel="noreferrer noopener">https://ssd-disclosure.com/ssd-advisory-arcadyan-fmimg51ax000j-wifi-alliance-rce/</a><br /> Okta iOS App Vulnerability CVE-2024-10327<br /><a href="https://trust.okta.com/security-advisories/okta-verify-for-ios-cve-2024-10327/" target="_blank" rel="noreferrer noopener">https://trust.okta.com/security-advisories/okta-verify-for-ios-cve-2024-10327/</a><br /> Threat Alert TeamTNT's docker gatling gun campaign<br /><a href="https://www.aquasec.com/blog/threat-alert-teamtnts-docker-gatling-gun-campaign/" target="_blank" rel="noreferrer noopener">https://www.aquasec.com/blog/threat-alert-teamtnts-docker-gatling-gun-campaign/</a><br />]]></itunes:summary><itunes:duration>338</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,teamtnt; docker; miner; okta; </itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9198</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, October 25th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-october-25th-2024--62497562</link><description><![CDATA[Development Features Enabled in Production<br /><a href="https://isc.sans.edu/diary/Development%20Features%20Enabled%20in%20Prodcution/31380" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Development%20Features%20Enabled%20in%20Prodcution/31380</a><br /> Large-scale brute-force activity targeting VPNs, SSH services with commonly used login credentials<br /><a href="https://blog.talosintelligence.com/large-scale-brute-force-activity-targeting-vpns-ssh-services-with-commonly-used-login-credentials/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/large-scale-brute-force-activity-targeting-vpns-ssh-services-with-commonly-used-login-credentials/</a><br /> Cisco Secure Firewall Management Center Software Command Injection Vulnerability<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-v3AWDqN7" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-v3AWDqN7</a><br /> Exposing the Danger Within: Hardcoded Cloud Credentials in Popular Mobile Apps<br /><a href="https://www.security.com/threat-intelligence/exposing-danger-within-hardcoded-cloud-credentials-popular-mobile-apps" target="_blank" rel="noreferrer noopener">https://www.security.com/threat-intelligence/exposing-danger-within-hardcoded-cloud-credentials-popular-mobile-apps</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9196.mp3</guid><pubDate>Fri, 25 Oct 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62497562/9196.mp3" length="4697537" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Development Features Enabled in Production
https://isc.sans.edu/diary/Development%20Features%20Enabled%20in%20Prodcution/31380
 Large-scale brute-force activity targeting VPNs, SSH services with commonly used login credentials...</itunes:subtitle><itunes:summary><![CDATA[Development Features Enabled in Production<br /><a href="https://isc.sans.edu/diary/Development%20Features%20Enabled%20in%20Prodcution/31380" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Development%20Features%20Enabled%20in%20Prodcution/31380</a><br /> Large-scale brute-force activity targeting VPNs, SSH services with commonly used login credentials<br /><a href="https://blog.talosintelligence.com/large-scale-brute-force-activity-targeting-vpns-ssh-services-with-commonly-used-login-credentials/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/large-scale-brute-force-activity-targeting-vpns-ssh-services-with-commonly-used-login-credentials/</a><br /> Cisco Secure Firewall Management Center Software Command Injection Vulnerability<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-v3AWDqN7" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-v3AWDqN7</a><br /> Exposing the Danger Within: Hardcoded Cloud Credentials in Popular Mobile Apps<br /><a href="https://www.security.com/threat-intelligence/exposing-danger-within-hardcoded-cloud-credentials-popular-mobile-apps" target="_blank" rel="noreferrer noopener">https://www.security.com/threat-intelligence/exposing-danger-within-hardcoded-cloud-credentials-popular-mobile-apps</a><br />]]></itunes:summary><itunes:duration>314</itunes:duration><itunes:keywords>business,cloud; mobile app; cisco; ssh;,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9196</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, October 24th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-october-24th-2024--62483733</link><description><![CDATA[Everybody Loves Bash Scripts Including Attackers<br /><a href="https://isc.sans.edu/diary/Everybody%20Loves%20Bash%20Scripts.%20Including%20Attackers./31376" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Everybody%20Loves%20Bash%20Scripts.%20Including%20Attackers./31376</a><br /> Fortimanager Exploited Vulnerability<br /><a href="https://www.fortiguard.com/psirt/FG-IR-24-423" target="_blank" rel="noreferrer noopener">https://www.fortiguard.com/psirt/FG-IR-24-423</a><br /> Sharepoint Exploit<br /><a href="https://www.cisa.gov/news-events/alerts/2024/10/22/cisa-adds-one-known-exploited-vulnerability-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2024/10/22/cisa-adds-one-known-exploited-vulnerability-catalog</a><br /><a href="https://github.com/testanull/MS-SharePoint-July-Patch-RCE-PoC" target="_blank" rel="noreferrer noopener">https://github.com/testanull/MS-SharePoint-July-Patch-RCE-PoC</a><br /> OpenSSL Vulnerability<br /><a href="https://openssl-library.org/news/secadv/20241016.txt" target="_blank" rel="noreferrer noopener">https://openssl-library.org/news/secadv/20241016.txt</a><br /> Reduced Certificate Lifetime<br /><a href="https://github.com/cabforum/servercert/pull/553" target="_blank" rel="noreferrer noopener">https://github.com/cabforum/servercert/pull/553</a><br /><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9194.mp3</guid><pubDate>Thu, 24 Oct 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62483733/9194.mp3" length="5898690" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Everybody Loves Bash Scripts Including Attackers
https://isc.sans.edu/diary/Everybody%20Loves%20Bash%20Scripts.%20Including%20Attackers./31376
 Fortimanager Exploited Vulnerability
https://www.fortiguard.com/psirt/FG-IR-24-423
 Sharepoint Exploit...</itunes:subtitle><itunes:summary><![CDATA[Everybody Loves Bash Scripts Including Attackers<br /><a href="https://isc.sans.edu/diary/Everybody%20Loves%20Bash%20Scripts.%20Including%20Attackers./31376" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Everybody%20Loves%20Bash%20Scripts.%20Including%20Attackers./31376</a><br /> Fortimanager Exploited Vulnerability<br /><a href="https://www.fortiguard.com/psirt/FG-IR-24-423" target="_blank" rel="noreferrer noopener">https://www.fortiguard.com/psirt/FG-IR-24-423</a><br /> Sharepoint Exploit<br /><a href="https://www.cisa.gov/news-events/alerts/2024/10/22/cisa-adds-one-known-exploited-vulnerability-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2024/10/22/cisa-adds-one-known-exploited-vulnerability-catalog</a><br /><a href="https://github.com/testanull/MS-SharePoint-July-Patch-RCE-PoC" target="_blank" rel="noreferrer noopener">https://github.com/testanull/MS-SharePoint-July-Patch-RCE-PoC</a><br /> OpenSSL Vulnerability<br /><a href="https://openssl-library.org/news/secadv/20241016.txt" target="_blank" rel="noreferrer noopener">https://openssl-library.org/news/secadv/20241016.txt</a><br /> Reduced Certificate Lifetime<br /><a href="https://github.com/cabforum/servercert/pull/553" target="_blank" rel="noreferrer noopener">https://github.com/cabforum/servercert/pull/553</a><br /><br />]]></itunes:summary><itunes:duration>400</itunes:duration><itunes:keywords>business,certificate; openssl; cisa; sh,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9194</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, October 23rd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-october-23rd-2024--62469340</link><description><![CDATA[How much HTTP (not HTTPS) Traffic is Traversing Your Perimeter?<br /><a href="https://isc.sans.edu/diary/How%20much%20HTTP%20%28not%20HTTPS%29%20Traffic%20is%20Traversing%20Your%20Perimeter%3F/31372" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20much%20HTTP%20%28not%20HTTPS%29%20Traffic%20is%20Traversing%20Your%20Perimeter%3F/31372</a><br /> VMSA-2024-0019:VMware vCenter Server updates address heap-overflow and privilege escalation vulnerabilities (CVE-2024-38812, CVE-2024-38813)<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968</a><br /> Unifi Security Advisory Bulletin 043<br /><a href="https://community.ui.com/releases/Security-Advisory-Bulletin-043-043/28e45c75-314e-4f07-a4f3-d17f67bd53f7" target="_blank" rel="noreferrer noopener">https://community.ui.com/releases/Security-Advisory-Bulletin-043-043/28e45c75-314e-4f07-a4f3-d17f67bd53f7</a><br /> Fake attachment. Roundcube mail server attacks exploit CVE-2024-37383 vulnerability.<br /><a href="https://global.ptsecurity.com/analytics/pt-esc-threat-intelligence/fake-attachment-roundcube-mail-server-attacks-exploit-cve-2024-37383-vulnerability" target="_blank" rel="noreferrer noopener">https://global.ptsecurity.com/analytics/pt-esc-threat-intelligence/fake-attachment-roundcube-mail-server-attacks-exploit-cve-2024-37383-vulnerability</a><br /> Atlassian Security Bulletin - October 15 2024<br /><a href="https://confluence.atlassian.com/security/security-bulletin-october-15-2024-1442910972.html" target="_blank" rel="noreferrer noopener">https://confluence.atlassian.com/security/security-bulletin-october-15-2024-1442910972.html</a><br /> OneDev Arbitrary file reading for unauthenticated user<br /><a href="https://github.com/theonedev/onedev/security/advisories/GHSA-7wg5-6864-v489" target="_blank" rel="noreferrer noopener">https://github.com/theonedev/onedev/security/advisories/GHSA-7wg5-6864-v489</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9192.mp3</guid><pubDate>Wed, 23 Oct 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62469340/9192.mp3" length="4801445" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>How much HTTP (not HTTPS) Traffic is Traversing Your Perimeter?
https://isc.sans.edu/diary/How%20much%20HTTP%20%28not%20HTTPS%29%20Traffic%20is%20Traversing%20Your%20Perimeter%3F/31372
 VMSA-2024-0019:VMware vCenter Server updates address...</itunes:subtitle><itunes:summary><![CDATA[How much HTTP (not HTTPS) Traffic is Traversing Your Perimeter?<br /><a href="https://isc.sans.edu/diary/How%20much%20HTTP%20%28not%20HTTPS%29%20Traffic%20is%20Traversing%20Your%20Perimeter%3F/31372" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20much%20HTTP%20%28not%20HTTPS%29%20Traffic%20is%20Traversing%20Your%20Perimeter%3F/31372</a><br /> VMSA-2024-0019:VMware vCenter Server updates address heap-overflow and privilege escalation vulnerabilities (CVE-2024-38812, CVE-2024-38813)<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968</a><br /> Unifi Security Advisory Bulletin 043<br /><a href="https://community.ui.com/releases/Security-Advisory-Bulletin-043-043/28e45c75-314e-4f07-a4f3-d17f67bd53f7" target="_blank" rel="noreferrer noopener">https://community.ui.com/releases/Security-Advisory-Bulletin-043-043/28e45c75-314e-4f07-a4f3-d17f67bd53f7</a><br /> Fake attachment. Roundcube mail server attacks exploit CVE-2024-37383 vulnerability.<br /><a href="https://global.ptsecurity.com/analytics/pt-esc-threat-intelligence/fake-attachment-roundcube-mail-server-attacks-exploit-cve-2024-37383-vulnerability" target="_blank" rel="noreferrer noopener">https://global.ptsecurity.com/analytics/pt-esc-threat-intelligence/fake-attachment-roundcube-mail-server-attacks-exploit-cve-2024-37383-vulnerability</a><br /> Atlassian Security Bulletin - October 15 2024<br /><a href="https://confluence.atlassian.com/security/security-bulletin-october-15-2024-1442910972.html" target="_blank" rel="noreferrer noopener">https://confluence.atlassian.com/security/security-bulletin-october-15-2024-1442910972.html</a><br /> OneDev Arbitrary file reading for unauthenticated user<br /><a href="https://github.com/theonedev/onedev/security/advisories/GHSA-7wg5-6864-v489" target="_blank" rel="noreferrer noopener">https://github.com/theonedev/onedev/security/advisories/GHSA-7wg5-6864-v489</a><br />]]></itunes:summary><itunes:duration>321</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,onedev; atlassian; roundcube; ,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9192</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, October 22nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-october-22nd-2024--62457707</link><description><![CDATA[A Network Nerd's Take on Emergency Preparedness<br /><a href="https://isc.sans.edu/diary/A%20Network%20Nerd%27s%20Take%20on%20Emergency%20Preparedness/31356" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20Network%20Nerd%27s%20Take%20on%20Emergency%20Preparedness/31356</a><br /> HM Surf Vulnerability Access to Camera Exploited CVE-2024-44133<br /><a href="https://www.microsoft.com/en-us/security/blog/2024/10/17/new-macos-vulnerability-hm-surf-could-lead-to-unauthorized-data-access/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2024/10/17/new-macos-vulnerability-hm-surf-could-lead-to-unauthorized-data-access/</a><br /> Fortinet releases patches for undisclosed critical FortiManager vulnerability<br /><a href="https://www.helpnetsecurity.com/2024/10/21/fortimanager-critical-vulnerability/" target="_blank" rel="noreferrer noopener">https://www.helpnetsecurity.com/2024/10/21/fortimanager-critical-vulnerability/</a><br /> ScienceLogic Vulnerability<br /><a href="https://rackspace.service-now.com/system_status?id=detailed_status&amp;service=4dafca5a87f41610568b206f8bbb35a6" target="_blank" rel="noreferrer noopener">https://rackspace.service-now.com/system_status?id=detailed_status&amp;service=4dafca5a87f41610568b206f8bbb35a6</a><br /><a href="https://docs.sciencelogic.com/latest/Content/Web_Admin_and_Accounts/System_Administration/sys_admin_system_upgrade.htm" target="_blank" rel="noreferrer noopener">https://docs.sciencelogic.com/latest/Content/Web_Admin_and_Accounts/System_Administration/sys_admin_system_upgrade.htm</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9190.mp3</guid><pubDate>Tue, 22 Oct 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62457707/9190.mp3" length="5712081" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>A Network Nerd's Take on Emergency Preparedness
https://isc.sans.edu/diary/A%20Network%20Nerd%27s%20Take%20on%20Emergency%20Preparedness/31356
 HM Surf Vulnerability Access to Camera Exploited CVE-2024-44133...</itunes:subtitle><itunes:summary><![CDATA[A Network Nerd's Take on Emergency Preparedness<br /><a href="https://isc.sans.edu/diary/A%20Network%20Nerd%27s%20Take%20on%20Emergency%20Preparedness/31356" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20Network%20Nerd%27s%20Take%20on%20Emergency%20Preparedness/31356</a><br /> HM Surf Vulnerability Access to Camera Exploited CVE-2024-44133<br /><a href="https://www.microsoft.com/en-us/security/blog/2024/10/17/new-macos-vulnerability-hm-surf-could-lead-to-unauthorized-data-access/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2024/10/17/new-macos-vulnerability-hm-surf-could-lead-to-unauthorized-data-access/</a><br /> Fortinet releases patches for undisclosed critical FortiManager vulnerability<br /><a href="https://www.helpnetsecurity.com/2024/10/21/fortimanager-critical-vulnerability/" target="_blank" rel="noreferrer noopener">https://www.helpnetsecurity.com/2024/10/21/fortimanager-critical-vulnerability/</a><br /> ScienceLogic Vulnerability<br /><a href="https://rackspace.service-now.com/system_status?id=detailed_status&amp;service=4dafca5a87f41610568b206f8bbb35a6" target="_blank" rel="noreferrer noopener">https://rackspace.service-now.com/system_status?id=detailed_status&amp;service=4dafca5a87f41610568b206f8bbb35a6</a><br /><a href="https://docs.sciencelogic.com/latest/Content/Web_Admin_and_Accounts/System_Administration/sys_admin_system_upgrade.htm" target="_blank" rel="noreferrer noopener">https://docs.sciencelogic.com/latest/Content/Web_Admin_and_Accounts/System_Administration/sys_admin_system_upgrade.htm</a><br />]]></itunes:summary><itunes:duration>386</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,sciencelogic; rackspace; forti,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9190</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, October 21st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-october-21st-2024--62432915</link><description><![CDATA[Microsoft 365: Partially incomplete log data due to monitoring agent issue<br /><a href="https://m365admin.handsontek.net/multiple-services-partially-incomplete-log-data-due-to-monitoring-agent-issue/" target="_blank" rel="noreferrer noopener">https://m365admin.handsontek.net/multiple-services-partially-incomplete-log-data-due-to-monitoring-agent-issue/</a><br /> End-to-End Encrytped Cloud Storage in the Wild: A Broken Ecosystem<br /><a href="https://brokencloudstorage.info/paper.pdf" target="_blank" rel="noreferrer noopener">https://brokencloudstorage.info/paper.pdf</a><br /> ESET Branded Malware<br /><a href="https://x.com/ESETresearch/status/1847192384448172387" target="_blank" rel="noreferrer noopener">https://x.com/ESETresearch/status/1847192384448172387</a><br /> Synology Update<br /><a href="https://www.synology.com/en-us/security/advisory/Synology_SA_24_17" target="_blank" rel="noreferrer noopener">https://www.synology.com/en-us/security/advisory/Synology_SA_24_17</a><br /> Spring Framework Update CVe-2024-38819 CVE-2024-38820<br /><a href="https://spring.io/blog/2024/10/17/spring-framework-cve-2024-38819-and-cve-2024-38820-published" target="_blank" rel="noreferrer noopener">https://spring.io/blog/2024/10/17/spring-framework-cve-2024-38819-and-cve-2024-38820-published</a><br /> Grafana Security Release CVE-2024-9264<br /><a href="https://grafana.com/blog/2024/10/17/grafana-security-release-critical-severity-fix-for-cve-2024-9264/" target="_blank" rel="noreferrer noopener">https://grafana.com/blog/2024/10/17/grafana-security-release-critical-severity-fix-for-cve-2024-9264/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9188.mp3</guid><pubDate>Mon, 21 Oct 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62432915/9188.mp3" length="5102745" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft 365: Partially incomplete log data due to monitoring agent issue
https://m365admin.handsontek.net/multiple-services-partially-incomplete-log-data-due-to-monitoring-agent-issue/
 End-to-End Encrytped Cloud Storage in the Wild: A Broken...</itunes:subtitle><itunes:summary><![CDATA[Microsoft 365: Partially incomplete log data due to monitoring agent issue<br /><a href="https://m365admin.handsontek.net/multiple-services-partially-incomplete-log-data-due-to-monitoring-agent-issue/" target="_blank" rel="noreferrer noopener">https://m365admin.handsontek.net/multiple-services-partially-incomplete-log-data-due-to-monitoring-agent-issue/</a><br /> End-to-End Encrytped Cloud Storage in the Wild: A Broken Ecosystem<br /><a href="https://brokencloudstorage.info/paper.pdf" target="_blank" rel="noreferrer noopener">https://brokencloudstorage.info/paper.pdf</a><br /> ESET Branded Malware<br /><a href="https://x.com/ESETresearch/status/1847192384448172387" target="_blank" rel="noreferrer noopener">https://x.com/ESETresearch/status/1847192384448172387</a><br /> Synology Update<br /><a href="https://www.synology.com/en-us/security/advisory/Synology_SA_24_17" target="_blank" rel="noreferrer noopener">https://www.synology.com/en-us/security/advisory/Synology_SA_24_17</a><br /> Spring Framework Update CVe-2024-38819 CVE-2024-38820<br /><a href="https://spring.io/blog/2024/10/17/spring-framework-cve-2024-38819-and-cve-2024-38820-published" target="_blank" rel="noreferrer noopener">https://spring.io/blog/2024/10/17/spring-framework-cve-2024-38819-and-cve-2024-38820-published</a><br /> Grafana Security Release CVE-2024-9264<br /><a href="https://grafana.com/blog/2024/10/17/grafana-security-release-critical-severity-fix-for-cve-2024-9264/" target="_blank" rel="noreferrer noopener">https://grafana.com/blog/2024/10/17/grafana-security-release-critical-severity-fix-for-cve-2024-9264/</a><br />]]></itunes:summary><itunes:duration>343</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,grafana; spring; synology; ese,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9188</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, October 18th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-october-18th-2024--62406102</link><description><![CDATA[Scanning Activity from Subnet 15.184.0.0/16.<br /><a href="https://isc.sans.edu/diary/Scanning%20Activity%20from%20Subnet%2015.184.0.0%2016/31362" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scanning%20Activity%20from%20Subnet%2015.184.0.0%2016/31362</a><br /> Gatekeeper Bypass<br />  /unit42.paloaltonetworks.com/gatekeeper-bypass-macos/<br /> Oracle Critical Patch Update<br /><a href="https://www.oracle.com/security-alerts/cpuoct2024.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpuoct2024.html</a><br /> Cisco ATA 190 Series Analog Telephone Adapter Firmware Vulnerabilities<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ata19x-multi-RDTEqRsy" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ata19x-multi-RDTEqRsy</a><br /> SAP Vulnerability<br /><a href="https://redrays.io/blog/poc-sap-note-3433192-code-injection-vulnerability-in-sap-netweaver-as-java/" target="_blank" rel="noreferrer noopener">https://redrays.io/blog/poc-sap-note-3433192-code-injection-vulnerability-in-sap-netweaver-as-java/</a><br /> Dept. of Commerce Sites Advertising Medication<br /><a href="https://x.com/tliston/status/1833542884047654984" target="_blank" rel="noreferrer noopener">https://x.com/tliston/status/1833542884047654984</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9186.mp3</guid><pubDate>Fri, 18 Oct 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62406102/9186.mp3" length="5241544" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Scanning Activity from Subnet 15.184.0.0/16.
https://isc.sans.edu/diary/Scanning%20Activity%20from%20Subnet%2015.184.0.0%2016/31362
 Gatekeeper Bypass
  /unit42.paloaltonetworks.com/gatekeeper-bypass-macos/
 Oracle Critical Patch Update...</itunes:subtitle><itunes:summary><![CDATA[Scanning Activity from Subnet 15.184.0.0/16.<br /><a href="https://isc.sans.edu/diary/Scanning%20Activity%20from%20Subnet%2015.184.0.0%2016/31362" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scanning%20Activity%20from%20Subnet%2015.184.0.0%2016/31362</a><br /> Gatekeeper Bypass<br />  /unit42.paloaltonetworks.com/gatekeeper-bypass-macos/<br /> Oracle Critical Patch Update<br /><a href="https://www.oracle.com/security-alerts/cpuoct2024.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpuoct2024.html</a><br /> Cisco ATA 190 Series Analog Telephone Adapter Firmware Vulnerabilities<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ata19x-multi-RDTEqRsy" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ata19x-multi-RDTEqRsy</a><br /> SAP Vulnerability<br /><a href="https://redrays.io/blog/poc-sap-note-3433192-code-injection-vulnerability-in-sap-netweaver-as-java/" target="_blank" rel="noreferrer noopener">https://redrays.io/blog/poc-sap-note-3433192-code-injection-vulnerability-in-sap-netweaver-as-java/</a><br /> Dept. of Commerce Sites Advertising Medication<br /><a href="https://x.com/tliston/status/1833542884047654984" target="_blank" rel="noreferrer noopener">https://x.com/tliston/status/1833542884047654984</a><br />]]></itunes:summary><itunes:duration>353</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,doc; commerce; cisco; ata; ora,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9186</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, October 17th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-october-17th-2024--62391566</link><description><![CDATA[The Top 10 Not So Common SSH Usernames and Passwords<br /><a href="https://isc.sans.edu/diary/The%20Top%2010%20Not%20So%20Common%20SSH%20Usernames%20and%20Passwords/31360" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20Top%2010%20Not%20So%20Common%20SSH%20Usernames%20and%20Passwords/31360</a><br /> CISA Product Security Bad Practices<br /><a href="https://www.cisa.gov/resources-tools/resources/product-security-bad-practices" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/resources-tools/resources/product-security-bad-practices</a><br /> Kubernetes Image Builder Vulnerability CVE-2024-9486 CVE-2024-9594<br /><a href="https://discuss.kubernetes.io/t/security-advisory-cve-2024-9486-and-cve-2024-9594-vm-images-built-with-kubernetes-image-builder-use-default-credentials/30119" target="_blank" rel="noreferrer noopener">https://discuss.kubernetes.io/t/security-advisory-cve-2024-9486-and-cve-2024-9594-vm-images-built-with-kubernetes-image-builder-use-default-credentials/30119</a><br /> Solarwinds Hardcoded Password Exploited CVE-2024-28987<br /><a href="https://www.bleepingcomputer.com/news/security/solarwinds-web-help-desk-flaw-is-now-exploited-in-attacks/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/solarwinds-web-help-desk-flaw-is-now-exploited-in-attacks/</a><br /> Bypassing noexec and executing arbitrary binaries<br /><a href="https://iq.thc.org/bypassing-noexec-and-executing-arbitrary-binaries" target="_blank" rel="noreferrer noopener">https://iq.thc.org/bypassing-noexec-and-executing-arbitrary-binaries</a><br /> Workshop Website:<br /><a href="https://www.sansapi.com/" target="_blank" rel="noreferrer noopener">https://www.sansapi.com/</a><br /><a href="https://www.sansapi.com/docs" target="_blank" rel="noreferrer noopener">https://www.sansapi.com/docs</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9184.mp3</guid><pubDate>Thu, 17 Oct 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62391566/9184.mp3" length="5040816" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>The Top 10 Not So Common SSH Usernames and Passwords
https://isc.sans.edu/diary/The%20Top%2010%20Not%20So%20Common%20SSH%20Usernames%20and%20Passwords/31360
 CISA Product Security Bad Practices...</itunes:subtitle><itunes:summary><![CDATA[The Top 10 Not So Common SSH Usernames and Passwords<br /><a href="https://isc.sans.edu/diary/The%20Top%2010%20Not%20So%20Common%20SSH%20Usernames%20and%20Passwords/31360" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20Top%2010%20Not%20So%20Common%20SSH%20Usernames%20and%20Passwords/31360</a><br /> CISA Product Security Bad Practices<br /><a href="https://www.cisa.gov/resources-tools/resources/product-security-bad-practices" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/resources-tools/resources/product-security-bad-practices</a><br /> Kubernetes Image Builder Vulnerability CVE-2024-9486 CVE-2024-9594<br /><a href="https://discuss.kubernetes.io/t/security-advisory-cve-2024-9486-and-cve-2024-9594-vm-images-built-with-kubernetes-image-builder-use-default-credentials/30119" target="_blank" rel="noreferrer noopener">https://discuss.kubernetes.io/t/security-advisory-cve-2024-9486-and-cve-2024-9594-vm-images-built-with-kubernetes-image-builder-use-default-credentials/30119</a><br /> Solarwinds Hardcoded Password Exploited CVE-2024-28987<br /><a href="https://www.bleepingcomputer.com/news/security/solarwinds-web-help-desk-flaw-is-now-exploited-in-attacks/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/solarwinds-web-help-desk-flaw-is-now-exploited-in-attacks/</a><br /> Bypassing noexec and executing arbitrary binaries<br /><a href="https://iq.thc.org/bypassing-noexec-and-executing-arbitrary-binaries" target="_blank" rel="noreferrer noopener">https://iq.thc.org/bypassing-noexec-and-executing-arbitrary-binaries</a><br /> Workshop Website:<br /><a href="https://www.sansapi.com/" target="_blank" rel="noreferrer noopener">https://www.sansapi.com/</a><br /><a href="https://www.sansapi.com/docs" target="_blank" rel="noreferrer noopener">https://www.sansapi.com/docs</a><br />]]></itunes:summary><itunes:duration>338</itunes:duration><itunes:keywords>api; workdshop; noexec; solarw,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9184</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, October 16th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-october-16th-2024--62380828</link><description><![CDATA[Angular-base64-upload Demo Script Exploited<br /><a href="https://isc.sans.edu/diary/Angular-base64-upload%20Demo%20Script%20Exploited%20%28CVE-2024-42640%29/31354" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Angular-base64-upload%20Demo%20Script%20Exploited%20%28CVE-2024-42640%29/31354</a><br /> Quantum Annealing Public Key Cryptographic Attack Algorithm Based on D-Wave Advantage <br /><a href="http://cjc.ict.ac.cn/online/onlinepaper/wc-202458160402.pdf" target="_blank" rel="noreferrer noopener">http://cjc.ict.ac.cn/online/onlinepaper/wc-202458160402.pdf</a><br /> EDRSilencer<br /><a href="https://github.com/netero1010/EDRSilencer" target="_blank" rel="noreferrer noopener">https://github.com/netero1010/EDRSilencer</a><br /> Synchronizing Passkeys<br /><a href="https://fidoalliance.org/specifications-credential-exchange-specifications/" target="_blank" rel="noreferrer noopener">https://fidoalliance.org/specifications-credential-exchange-specifications/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9182.mp3</guid><pubDate>Wed, 16 Oct 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62380828/9182.mp3" length="5970828" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Angular-base64-upload Demo Script Exploited
https://isc.sans.edu/diary/Angular-base64-upload%20Demo%20Script%20Exploited%20%28CVE-2024-42640%29/31354
 Quantum Annealing Public Key Cryptographic Attack Algorithm Based on D-Wave Advantage...</itunes:subtitle><itunes:summary><![CDATA[Angular-base64-upload Demo Script Exploited<br /><a href="https://isc.sans.edu/diary/Angular-base64-upload%20Demo%20Script%20Exploited%20%28CVE-2024-42640%29/31354" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Angular-base64-upload%20Demo%20Script%20Exploited%20%28CVE-2024-42640%29/31354</a><br /> Quantum Annealing Public Key Cryptographic Attack Algorithm Based on D-Wave Advantage <br /><a href="http://cjc.ict.ac.cn/online/onlinepaper/wc-202458160402.pdf" target="_blank" rel="noreferrer noopener">http://cjc.ict.ac.cn/online/onlinepaper/wc-202458160402.pdf</a><br /> EDRSilencer<br /><a href="https://github.com/netero1010/EDRSilencer" target="_blank" rel="noreferrer noopener">https://github.com/netero1010/EDRSilencer</a><br /> Synchronizing Passkeys<br /><a href="https://fidoalliance.org/specifications-credential-exchange-specifications/" target="_blank" rel="noreferrer noopener">https://fidoalliance.org/specifications-credential-exchange-specifications/</a><br />]]></itunes:summary><itunes:duration>405</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,passkeys; edrsilencer; quantum,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9182</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, October 15th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-october-15th-2024--62368605</link><description><![CDATA[Phishing Page Delivered Through a Blob URL<br /><a href="https://isc.sans.edu/diary/Phishing%20Page%20Delivered%20Through%20a%20%20Blob%20URL/31350" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Phishing%20Page%20Delivered%20Through%20a%20%20Blob%20URL/31350</a><br /> Fortinet Fortigate CVE 2024-23113 deep dive<br /><a href="https://labs.watchtowr.com/fortinet-fortigate-cve-2024-23113-a-super-complex-vulnerability-in-a-super-secure-appliance-in-2024/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/fortinet-fortigate-cve-2024-23113-a-super-complex-vulnerability-in-a-super-secure-appliance-in-2024/</a><br /> This New Supply Chain Attack Technique Can Trojanize All Your CLI Commands<br /><a href="https://checkmarx.com/blog/this-new-supply-chain-attack-technique-can-trojanize-all-your-cli-commands/" target="_blank" rel="noreferrer noopener">https://checkmarx.com/blog/this-new-supply-chain-attack-technique-can-trojanize-all-your-cli-commands/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9180.mp3</guid><pubDate>Tue, 15 Oct 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62368605/9180.mp3" length="5117768" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Phishing Page Delivered Through a Blob URL
https://isc.sans.edu/diary/Phishing%20Page%20Delivered%20Through%20a%20%20Blob%20URL/31350
 Fortinet Fortigate CVE 2024-23113 deep dive...</itunes:subtitle><itunes:summary><![CDATA[Phishing Page Delivered Through a Blob URL<br /><a href="https://isc.sans.edu/diary/Phishing%20Page%20Delivered%20Through%20a%20%20Blob%20URL/31350" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Phishing%20Page%20Delivered%20Through%20a%20%20Blob%20URL/31350</a><br /> Fortinet Fortigate CVE 2024-23113 deep dive<br /><a href="https://labs.watchtowr.com/fortinet-fortigate-cve-2024-23113-a-super-complex-vulnerability-in-a-super-secure-appliance-in-2024/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/fortinet-fortigate-cve-2024-23113-a-super-complex-vulnerability-in-a-super-secure-appliance-in-2024/</a><br /> This New Supply Chain Attack Technique Can Trojanize All Your CLI Commands<br /><a href="https://checkmarx.com/blog/this-new-supply-chain-attack-technique-can-trojanize-all-your-cli-commands/" target="_blank" rel="noreferrer noopener">https://checkmarx.com/blog/this-new-supply-chain-attack-technique-can-trojanize-all-your-cli-commands/</a><br />]]></itunes:summary><itunes:duration>344</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,python; npm; entrypoint; cli; ,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9180</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, October 14th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-october-14th-2024--62354668</link><description><![CDATA[Windows PPTP and L2TP Deprecation<br /><a href="https://techcommunity.microsoft.com/t5/windows-server-news-and-best/pptp-and-l2tp-deprecation-a-new-era-of-secure-connectivity/ba-p/4263956" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/windows-server-news-and-best/pptp-and-l2tp-deprecation-a-new-era-of-secure-connectivity/ba-p/4263956</a><br /> BIG-IP LTM Systems Unencrypted Cookie Exploitation<br /><a href="https://www.cisa.gov/news-events/alerts/2024/10/10/best-practices-configure-big-ip-ltm-systems-encrypt-http-persistence-cookies" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2024/10/10/best-practices-configure-big-ip-ltm-systems-encrypt-http-persistence-cookies</a><br /><a href="https://www.welivesecurity.com/en/eset-research/telekopye-hits-new-hunting-ground-hotel-booking-scams/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/telekopye-hits-new-hunting-ground-hotel-booking-scams/</a><br /><a href="https://www.welivesecurity.com/en/eset-research/telekopye-hits-new-hunting-ground-hotel-booking-scams/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/telekopye-hits-new-hunting-ground-hotel-booking-scams/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9178.mp3</guid><pubDate>Mon, 14 Oct 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62354668/9178.mp3" length="5289560" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Windows PPTP and L2TP Deprecation
https://techcommunity.microsoft.com/t5/windows-server-news-and-best/pptp-and-l2tp-deprecation-a-new-era-of-secure-connectivity/ba-p/4263956
 BIG-IP LTM Systems Unencrypted Cookie Exploitation...</itunes:subtitle><itunes:summary><![CDATA[Windows PPTP and L2TP Deprecation<br /><a href="https://techcommunity.microsoft.com/t5/windows-server-news-and-best/pptp-and-l2tp-deprecation-a-new-era-of-secure-connectivity/ba-p/4263956" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/windows-server-news-and-best/pptp-and-l2tp-deprecation-a-new-era-of-secure-connectivity/ba-p/4263956</a><br /> BIG-IP LTM Systems Unencrypted Cookie Exploitation<br /><a href="https://www.cisa.gov/news-events/alerts/2024/10/10/best-practices-configure-big-ip-ltm-systems-encrypt-http-persistence-cookies" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2024/10/10/best-practices-configure-big-ip-ltm-systems-encrypt-http-persistence-cookies</a><br /><a href="https://www.welivesecurity.com/en/eset-research/telekopye-hits-new-hunting-ground-hotel-booking-scams/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/telekopye-hits-new-hunting-ground-hotel-booking-scams/</a><br /><a href="https://www.welivesecurity.com/en/eset-research/telekopye-hits-new-hunting-ground-hotel-booking-scams/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/telekopye-hits-new-hunting-ground-hotel-booking-scams/</a><br />]]></itunes:summary><itunes:duration>356</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,pptp; l2tp; big-ip; cookies; t,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9178</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, October 11th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-october-11th-2024--62326413</link><description><![CDATA[GPTHoney: A new class of honeypot<br /><a href="https://isc.sans.edu/diary/GPTHoney%3A%20A%20new%20class%20of%20honeypot%20%5BGuest%20Diary%5D/31342" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/GPTHoney%3A%20A%20new%20class%20of%20honeypot%20%5BGuest%20Diary%5D/31342</a><br /> Palo Alto Expedition: From N-Day to Full Compromise<br /><a href="https://www.horizon3.ai/attack-research/palo-alto-expedition-from-n-day-to-full-compromise/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/palo-alto-expedition-from-n-day-to-full-compromise/</a><br /> Firefox 0-Day<br /><a href="https://www.mozilla.org/en-US/security/advisories/mfsa2024-51/" target="_blank" rel="noreferrer noopener">https://www.mozilla.org/en-US/security/advisories/mfsa2024-51/</a><br /> GitLab Vulnerabilities Patched<br /><a href="https://securityonline.info/cve-2024-9164-cvss-9-6-gitlab-users-urged-to-update-now/" target="_blank" rel="noreferrer noopener">https://securityonline.info/cve-2024-9164-cvss-9-6-gitlab-users-urged-to-update-now/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9176.mp3</guid><pubDate>Fri, 11 Oct 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62326413/9176.mp3" length="4626108" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>GPTHoney: A new class of honeypot
https://isc.sans.edu/diary/GPTHoney%3A%20A%20new%20class%20of%20honeypot%20%5BGuest%20Diary%5D/31342
 Palo Alto Expedition: From N-Day to Full Compromise...</itunes:subtitle><itunes:summary><![CDATA[GPTHoney: A new class of honeypot<br /><a href="https://isc.sans.edu/diary/GPTHoney%3A%20A%20new%20class%20of%20honeypot%20%5BGuest%20Diary%5D/31342" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/GPTHoney%3A%20A%20new%20class%20of%20honeypot%20%5BGuest%20Diary%5D/31342</a><br /> Palo Alto Expedition: From N-Day to Full Compromise<br /><a href="https://www.horizon3.ai/attack-research/palo-alto-expedition-from-n-day-to-full-compromise/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/palo-alto-expedition-from-n-day-to-full-compromise/</a><br /> Firefox 0-Day<br /><a href="https://www.mozilla.org/en-US/security/advisories/mfsa2024-51/" target="_blank" rel="noreferrer noopener">https://www.mozilla.org/en-US/security/advisories/mfsa2024-51/</a><br /> GitLab Vulnerabilities Patched<br /><a href="https://securityonline.info/cve-2024-9164-cvss-9-6-gitlab-users-urged-to-update-now/" target="_blank" rel="noreferrer noopener">https://securityonline.info/cve-2024-9164-cvss-9-6-gitlab-users-urged-to-update-now/</a><br />]]></itunes:summary><itunes:duration>309</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,gitlab; firefox; palo alto; ex,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9176</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, October 10th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-october-10th-2024--62308713</link><description><![CDATA[From Perfctl to InfoStealer<br /><a href="https://isc.sans.edu/diary/From%20Perfctl%20to%20InfoStealer/31334" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/From%20Perfctl%20to%20InfoStealer/31334</a><br /> Wazuh Abused by Miner Campaign<br /><a href="https://securelist.com/miner-campaign-misuses-open-source-siem-agent/114022/" target="_blank" rel="noreferrer noopener">https://securelist.com/miner-campaign-misuses-open-source-siem-agent/114022/</a><br /> USB Sticks Still Bridge Airgaps<br /><a href="https://www.welivesecurity.com/en/eset-research/mind-air-gap-goldenjackal-gooses-government-guardrails/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/mind-air-gap-goldenjackal-gooses-government-guardrails/</a><br /> Fortigate Vulnerability now being exploited<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23113" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2024-23113</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9174.mp3</guid><pubDate>Thu, 10 Oct 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62308713/9174.mp3" length="5061372" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>From Perfctl to InfoStealer
https://isc.sans.edu/diary/From%20Perfctl%20to%20InfoStealer/31334
 Wazuh Abused by Miner Campaign
https://securelist.com/miner-campaign-misuses-open-source-siem-agent/114022/
 USB Sticks Still Bridge Airgaps...</itunes:subtitle><itunes:summary><![CDATA[From Perfctl to InfoStealer<br /><a href="https://isc.sans.edu/diary/From%20Perfctl%20to%20InfoStealer/31334" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/From%20Perfctl%20to%20InfoStealer/31334</a><br /> Wazuh Abused by Miner Campaign<br /><a href="https://securelist.com/miner-campaign-misuses-open-source-siem-agent/114022/" target="_blank" rel="noreferrer noopener">https://securelist.com/miner-campaign-misuses-open-source-siem-agent/114022/</a><br /> USB Sticks Still Bridge Airgaps<br /><a href="https://www.welivesecurity.com/en/eset-research/mind-air-gap-goldenjackal-gooses-government-guardrails/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/mind-air-gap-goldenjackal-gooses-government-guardrails/</a><br /> Fortigate Vulnerability now being exploited<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23113" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2024-23113</a><br />]]></itunes:summary><itunes:duration>340</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,fortigate; usb; bridge; arigap,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9174</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, October 9th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-october-9th-2024--62293187</link><description><![CDATA[Microsoft Patch Tuesday - October 2024<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20October%202024/31336" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20October%202024/31336</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> The Disappearance of an Internet Domain<br /><a href="https://every.to/p/the-disappearance-of-an-internet-domain" target="_blank" rel="noreferrer noopener">https://every.to/p/the-disappearance-of-an-internet-domain</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9172.mp3</guid><pubDate>Wed, 09 Oct 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62293187/9172.mp3" length="5763503" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft Patch Tuesday - October 2024
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20October%202024/31336
 Adobe Patches
https://helpx.adobe.com/security/security-bulletin.html
 The Disappearance of an Internet Domain...</itunes:subtitle><itunes:summary><![CDATA[Microsoft Patch Tuesday - October 2024<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20October%202024/31336" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20October%202024/31336</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> The Disappearance of an Internet Domain<br /><a href="https://every.to/p/the-disappearance-of-an-internet-domain" target="_blank" rel="noreferrer noopener">https://every.to/p/the-disappearance-of-an-internet-domain</a><br />]]></itunes:summary><itunes:duration>390</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,.io; domain; adobe; patches; m,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9172</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, October 8th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-october-8th-2024--62279141</link><description><![CDATA[macOS Sequoia: System/Network Admins, Hold On!<br /><a href="https://isc.sans.edu/diary/macOS%20Sequoia%3A%20System%20Network%20Admins%2C%20Hold%20On!/31330" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/macOS%20Sequoia%3A%20System%20Network%20Admins%2C%20Hold%20On!/31330</a><br /> Cisco Vulnerabilities<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv34x-privesc-rce-qE33TCms" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv34x-privesc-rce-qE33TCms</a><br /> Apple iTunes PoC<br /><a href="https://github.com/mbog14/CVE-2024-44193" target="_blank" rel="noreferrer noopener">https://github.com/mbog14/CVE-2024-44193</a><br /> Attackers used ISP's Wiretap System to Spy on Users<br /><a href="https://www.wsj.com/politics/national-security/china-cyberattack-internet-providers-260bd835" target="_blank" rel="noreferrer noopener">https://www.wsj.com/politics/national-security/china-cyberattack-internet-providers-260bd835</a><br /><a href="https://www.bleepingcomputer.com/news/security/atandt-verizon-reportedly-hacked-to-target-us-govt-wiretapping-platform/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/atandt-verizon-reportedly-hacked-to-target-us-govt-wiretapping-platform/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9170.mp3</guid><pubDate>Tue, 08 Oct 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62279141/9170.mp3" length="5014048" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>macOS Sequoia: System/Network Admins, Hold On!
https://isc.sans.edu/diary/macOS%20Sequoia%3A%20System%20Network%20Admins%2C%20Hold%20On!/31330
 Cisco Vulnerabilities...</itunes:subtitle><itunes:summary><![CDATA[macOS Sequoia: System/Network Admins, Hold On!<br /><a href="https://isc.sans.edu/diary/macOS%20Sequoia%3A%20System%20Network%20Admins%2C%20Hold%20On!/31330" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/macOS%20Sequoia%3A%20System%20Network%20Admins%2C%20Hold%20On!/31330</a><br /> Cisco Vulnerabilities<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv34x-privesc-rce-qE33TCms" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv34x-privesc-rce-qE33TCms</a><br /> Apple iTunes PoC<br /><a href="https://github.com/mbog14/CVE-2024-44193" target="_blank" rel="noreferrer noopener">https://github.com/mbog14/CVE-2024-44193</a><br /> Attackers used ISP's Wiretap System to Spy on Users<br /><a href="https://www.wsj.com/politics/national-security/china-cyberattack-internet-providers-260bd835" target="_blank" rel="noreferrer noopener">https://www.wsj.com/politics/national-security/china-cyberattack-internet-providers-260bd835</a><br /><a href="https://www.bleepingcomputer.com/news/security/atandt-verizon-reportedly-hacked-to-target-us-govt-wiretapping-platform/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/atandt-verizon-reportedly-hacked-to-target-us-govt-wiretapping-platform/</a><br />]]></itunes:summary><itunes:duration>337</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,isp; wiretap; attackers; apple,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9170</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, October 7th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-october-7th-2024--62264344</link><description><![CDATA[Survey of CUPS exploit URLs<br /><a href="https://isc.sans.edu/diary/Survey%20of%20CUPS%20exploit%20attempts/31326" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Survey%20of%20CUPS%20exploit%20attempts/31326</a><br /> Exposed LDAP Servers<br /><a href="https://www.usenix.org/conference/usenixsecurity24/presentation/kaspereit" target="_blank" rel="noreferrer noopener">https://www.usenix.org/conference/usenixsecurity24/presentation/kaspereit</a><br /> Exploiting Visual Studio via Dump Files<br /><a href="https://ynwarcs.github.io/exploiting-vs-dump-files" target="_blank" rel="noreferrer noopener">https://ynwarcs.github.io/exploiting-vs-dump-files</a><br /> Apple Security Updates<br /><a href="https://support.apple.com/en-us/100100" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/100100</a><br /> Free API Security Workshop<br /><a href="https://www.sans.org/webcasts/aviata-solo-flight-challenge-cloud-security-workshop-chapter-7/" target="_blank" rel="noreferrer noopener">https://www.sans.org/webcasts/aviata-solo-flight-challenge-cloud-security-workshop-chapter-7/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9168.mp3</guid><pubDate>Mon, 07 Oct 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62264344/9168.mp3" length="4977973" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Survey of CUPS exploit URLs
https://isc.sans.edu/diary/Survey%20of%20CUPS%20exploit%20attempts/31326
 Exposed LDAP Servers
https://www.usenix.org/conference/usenixsecurity24/presentation/kaspereit
 Exploiting Visual Studio via Dump Files...</itunes:subtitle><itunes:summary><![CDATA[Survey of CUPS exploit URLs<br /><a href="https://isc.sans.edu/diary/Survey%20of%20CUPS%20exploit%20attempts/31326" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Survey%20of%20CUPS%20exploit%20attempts/31326</a><br /> Exposed LDAP Servers<br /><a href="https://www.usenix.org/conference/usenixsecurity24/presentation/kaspereit" target="_blank" rel="noreferrer noopener">https://www.usenix.org/conference/usenixsecurity24/presentation/kaspereit</a><br /> Exploiting Visual Studio via Dump Files<br /><a href="https://ynwarcs.github.io/exploiting-vs-dump-files" target="_blank" rel="noreferrer noopener">https://ynwarcs.github.io/exploiting-vs-dump-files</a><br /> Apple Security Updates<br /><a href="https://support.apple.com/en-us/100100" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/100100</a><br /> Free API Security Workshop<br /><a href="https://www.sans.org/webcasts/aviata-solo-flight-challenge-cloud-security-workshop-chapter-7/" target="_blank" rel="noreferrer noopener">https://www.sans.org/webcasts/aviata-solo-flight-challenge-cloud-security-workshop-chapter-7/</a><br />]]></itunes:summary><itunes:duration>334</itunes:duration><itunes:keywords>apple; ldap; visual studio; cu,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9168</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, October 4th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-october-4th-2024--62219424</link><description><![CDATA[Kickstart Your DShield Honeypot<br /><a href="https://isc.sans.edu/diary/Kickstart%20Your%20DShield%20Honeypot%20%5BGuest%20Diary%5D/31320" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Kickstart%20Your%20DShield%20Honeypot%20%5BGuest%20Diary%5D/31320</a><br /> CreanaKeeper Use of Cloud Services<br /><a href="https://www.welivesecurity.com/en/eset-research/separating-bee-panda-ceranakeeper-making-beeline-thailand/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/separating-bee-panda-ceranakeeper-making-beeline-thailand/</a><br /><br /> Pixel Addressing Vulnerabilities in Cellular Modems<br /><a href="https://security.googleblog.com/2024/10/pixel-proactive-security-cellular-modems.html" target="_blank" rel="noreferrer noopener">https://security.googleblog.com/2024/10/pixel-proactive-security-cellular-modems.html</a><br /> Optigo Spectra Vulnerabilities<br /><a href="https://claroty.com/team82/disclosure-dashboard/cve-2024-41925" target="_blank" rel="noreferrer noopener">https://claroty.com/team82/disclosure-dashboard/cve-2024-41925</a><br /><a href="https://claroty.com/team82/disclosure-dashboard/cve-2024-45367" target="_blank" rel="noreferrer noopener">https://claroty.com/team82/disclosure-dashboard/cve-2024-45367</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9166.mp3</guid><pubDate>Fri, 04 Oct 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62219424/9166.mp3" length="5249608" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Kickstart Your DShield Honeypot
https://isc.sans.edu/diary/Kickstart%20Your%20DShield%20Honeypot%20%5BGuest%20Diary%5D/31320
 CreanaKeeper Use of Cloud Services...</itunes:subtitle><itunes:summary><![CDATA[Kickstart Your DShield Honeypot<br /><a href="https://isc.sans.edu/diary/Kickstart%20Your%20DShield%20Honeypot%20%5BGuest%20Diary%5D/31320" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Kickstart%20Your%20DShield%20Honeypot%20%5BGuest%20Diary%5D/31320</a><br /> CreanaKeeper Use of Cloud Services<br /><a href="https://www.welivesecurity.com/en/eset-research/separating-bee-panda-ceranakeeper-making-beeline-thailand/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/separating-bee-panda-ceranakeeper-making-beeline-thailand/</a><br /><br /> Pixel Addressing Vulnerabilities in Cellular Modems<br /><a href="https://security.googleblog.com/2024/10/pixel-proactive-security-cellular-modems.html" target="_blank" rel="noreferrer noopener">https://security.googleblog.com/2024/10/pixel-proactive-security-cellular-modems.html</a><br /> Optigo Spectra Vulnerabilities<br /><a href="https://claroty.com/team82/disclosure-dashboard/cve-2024-41925" target="_blank" rel="noreferrer noopener">https://claroty.com/team82/disclosure-dashboard/cve-2024-41925</a><br /><a href="https://claroty.com/team82/disclosure-dashboard/cve-2024-45367" target="_blank" rel="noreferrer noopener">https://claroty.com/team82/disclosure-dashboard/cve-2024-45367</a><br />]]></itunes:summary><itunes:duration>353</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,optigo; spectra; php; pixel; m,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9166</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, October 3rd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-october-3rd-2024--62205130</link><description><![CDATA[Security Related Docker Containers<br /><a href="https://isc.sans.edu/diary/Security%20related%20Docker%20containers/31318" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Security%20related%20Docker%20containers/31318</a><br /> CUPS DDoS Attack<br /><a href="https://www.akamai.com/blog/security-research/october-cups-ddos-threat" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/october-cups-ddos-threat</a><br /> Draytek Vulnerabilities<br /><a href="https://www.forescout.com/resources/draybreak-draytek-research/" target="_blank" rel="noreferrer noopener">https://www.forescout.com/resources/draybreak-draytek-research/</a><br /> SANS Munich (free Community Night Tuesday October 15th)<br /><a href="https://www.sans.org/cyber-security-training-events/munich-october-2024/" target="_blank" rel="noreferrer noopener">https://www.sans.org/cyber-security-training-events/munich-october-2024/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9164.mp3</guid><pubDate>Thu, 03 Oct 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62205130/9164.mp3" length="5833147" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Security Related Docker Containers
https://isc.sans.edu/diary/Security%20related%20Docker%20containers/31318
 CUPS DDoS Attack
https://www.akamai.com/blog/security-research/october-cups-ddos-threat
 Draytek Vulnerabilities...</itunes:subtitle><itunes:summary><![CDATA[Security Related Docker Containers<br /><a href="https://isc.sans.edu/diary/Security%20related%20Docker%20containers/31318" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Security%20related%20Docker%20containers/31318</a><br /> CUPS DDoS Attack<br /><a href="https://www.akamai.com/blog/security-research/october-cups-ddos-threat" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/october-cups-ddos-threat</a><br /> Draytek Vulnerabilities<br /><a href="https://www.forescout.com/resources/draybreak-draytek-research/" target="_blank" rel="noreferrer noopener">https://www.forescout.com/resources/draybreak-draytek-research/</a><br /> SANS Munich (free Community Night Tuesday October 15th)<br /><a href="https://www.sans.org/cyber-security-training-events/munich-october-2024/" target="_blank" rel="noreferrer noopener">https://www.sans.org/cyber-security-training-events/munich-october-2024/</a><br />]]></itunes:summary><itunes:duration>395</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,munich; bojan; draytek; cups; ,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9164</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, October 2nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-october-2nd-2024--62189687</link><description><![CDATA[Hurricane Helene Aftermath - Cyber Security Awareness Month<br /><a href="https://isc.sans.edu/diary/Hurricane%20Helene%20Aftermath%20-%20Cyber%20Security%20Awareness%20Month/31314" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Hurricane%20Helene%20Aftermath%20-%20Cyber%20Security%20Awareness%20Month/31314</a><br /> Zimbra - Remote Command Execution (CVE-2024-45519)<br /><a href="https://blog.projectdiscovery.io/zimbra-remote-code-execution/" target="_blank" rel="noreferrer noopener">https://blog.projectdiscovery.io/zimbra-remote-code-execution/</a><br /> Enhancing the security of Microsoft Edge extensions with the new Publish API<br /><a href="https://blogs.windows.com/msedgedev/2024/09/30/enhanced-security-for-extensions-with-new-publish-api/" target="_blank" rel="noreferrer noopener">https://blogs.windows.com/msedgedev/2024/09/30/enhanced-security-for-extensions-with-new-publish-api/</a><br /> CVE-2024-36435 Deep-Dive: The Year s Most Critical BMC Security Flaw<br /><a href="https://www.binarly.io/blog/cve-2024-36435-deep-dive-the-years-most-critical-bmc-security-flaw" target="_blank" rel="noreferrer noopener">https://www.binarly.io/blog/cve-2024-36435-deep-dive-the-years-most-critical-bmc-security-flaw</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9162.mp3</guid><pubDate>Wed, 02 Oct 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62189687/9162.mp3" length="5109068" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Hurricane Helene Aftermath - Cyber Security Awareness Month
https://isc.sans.edu/diary/Hurricane%20Helene%20Aftermath%20-%20Cyber%20Security%20Awareness%20Month/31314
 Zimbra - Remote Command Execution (CVE-2024-45519)...</itunes:subtitle><itunes:summary><![CDATA[Hurricane Helene Aftermath - Cyber Security Awareness Month<br /><a href="https://isc.sans.edu/diary/Hurricane%20Helene%20Aftermath%20-%20Cyber%20Security%20Awareness%20Month/31314" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Hurricane%20Helene%20Aftermath%20-%20Cyber%20Security%20Awareness%20Month/31314</a><br /> Zimbra - Remote Command Execution (CVE-2024-45519)<br /><a href="https://blog.projectdiscovery.io/zimbra-remote-code-execution/" target="_blank" rel="noreferrer noopener">https://blog.projectdiscovery.io/zimbra-remote-code-execution/</a><br /> Enhancing the security of Microsoft Edge extensions with the new Publish API<br /><a href="https://blogs.windows.com/msedgedev/2024/09/30/enhanced-security-for-extensions-with-new-publish-api/" target="_blank" rel="noreferrer noopener">https://blogs.windows.com/msedgedev/2024/09/30/enhanced-security-for-extensions-with-new-publish-api/</a><br /> CVE-2024-36435 Deep-Dive: The Year s Most Critical BMC Security Flaw<br /><a href="https://www.binarly.io/blog/cve-2024-36435-deep-dive-the-years-most-critical-bmc-security-flaw" target="_blank" rel="noreferrer noopener">https://www.binarly.io/blog/cve-2024-36435-deep-dive-the-years-most-critical-bmc-security-flaw</a><br />]]></itunes:summary><itunes:duration>343</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,supermicro; bmc; edge; microso</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9162</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, October 1st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-october-1st-2024--62174318</link><description><![CDATA[Tool Update: mac-robber.py, le-hex-to-ip.py<br /><a href="https://isc.sans.edu/diary/Tool%20update%3A%20mac-robber.py%20and%20le-hex-to-ip.py/31310" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Tool%20update%3A%20mac-robber.py%20and%20le-hex-to-ip.py/31310</a><br /> Ransomware Attacks Expanding to Hybrid Cloud Environments<br /><a href="https://www.microsoft.com/en-us/security/blog/2024/09/26/storm-0501-ransomware-attacks-expanding-to-hybrid-cloud-environments/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2024/09/26/storm-0501-ransomware-attacks-expanding-to-hybrid-cloud-environments/</a><br /> Update on Recall Security and Privacy Architecture<br /><a href="https://blogs.windows.com/windowsexperience/2024/09/27/update-on-recall-security-and-privacy-architecture/" target="_blank" rel="noreferrer noopener">https://blogs.windows.com/windowsexperience/2024/09/27/update-on-recall-security-and-privacy-architecture/</a><br /> Detecting Ransomware in Windows Event Logs<br /><a href="https://blogs.jpcert.or.jp/en/2024/09/windows.html" target="_blank" rel="noreferrer noopener">https://blogs.jpcert.or.jp/en/2024/09/windows.html</a><br /> Progress WhatsUp Gold Update<br /><a href="https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-September-2024?popup=true&amp;overview" target="_blank" rel="noreferrer noopener">https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-September-2024?popup=true&amp;overview</a><br /> Singapore Class<br /><a href="https://jbu.me/singapore" target="_blank" rel="noreferrer noopener">https://jbu.me/singapore</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9160.mp3</guid><pubDate>Tue, 01 Oct 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62174318/9160.mp3" length="5571569" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Tool Update: mac-robber.py, le-hex-to-ip.py
https://isc.sans.edu/diary/Tool%20update%3A%20mac-robber.py%20and%20le-hex-to-ip.py/31310
 Ransomware Attacks Expanding to Hybrid Cloud Environments...</itunes:subtitle><itunes:summary><![CDATA[Tool Update: mac-robber.py, le-hex-to-ip.py<br /><a href="https://isc.sans.edu/diary/Tool%20update%3A%20mac-robber.py%20and%20le-hex-to-ip.py/31310" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Tool%20update%3A%20mac-robber.py%20and%20le-hex-to-ip.py/31310</a><br /> Ransomware Attacks Expanding to Hybrid Cloud Environments<br /><a href="https://www.microsoft.com/en-us/security/blog/2024/09/26/storm-0501-ransomware-attacks-expanding-to-hybrid-cloud-environments/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2024/09/26/storm-0501-ransomware-attacks-expanding-to-hybrid-cloud-environments/</a><br /> Update on Recall Security and Privacy Architecture<br /><a href="https://blogs.windows.com/windowsexperience/2024/09/27/update-on-recall-security-and-privacy-architecture/" target="_blank" rel="noreferrer noopener">https://blogs.windows.com/windowsexperience/2024/09/27/update-on-recall-security-and-privacy-architecture/</a><br /> Detecting Ransomware in Windows Event Logs<br /><a href="https://blogs.jpcert.or.jp/en/2024/09/windows.html" target="_blank" rel="noreferrer noopener">https://blogs.jpcert.or.jp/en/2024/09/windows.html</a><br /> Progress WhatsUp Gold Update<br /><a href="https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-September-2024?popup=true&amp;overview" target="_blank" rel="noreferrer noopener">https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-September-2024?popup=true&amp;overview</a><br /> Singapore Class<br /><a href="https://jbu.me/singapore" target="_blank" rel="noreferrer noopener">https://jbu.me/singapore</a><br />]]></itunes:summary><itunes:duration>376</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,singapore; ransomware; event l</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9160</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, September 30th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-september-30th-2024--62160353</link><description><![CDATA[CUPS Vulnerability<br /><a href="https://isc.sans.edu/diary/Patch%20for%20Critical%20CUPS%20vulnerability%3A%20Don%27t%20Panic/31302" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Patch%20for%20Critical%20CUPS%20vulnerability%3A%20Don%27t%20Panic/31302</a><br /> PHP Updates<br /><a href="https://www.php.net/ChangeLog-8.php#8.1.30" target="_blank" rel="noreferrer noopener">https://www.php.net/ChangeLog-8.php#8.1.30</a><br /> DNS And Big Chinese Firewall<br /><a href="https://www.assetnote.io/resources/research/insecurity-through-censorship-vulnerabilities-caused-by-the-great-firewall" target="_blank" rel="noreferrer noopener">https://www.assetnote.io/resources/research/insecurity-through-censorship-vulnerabilities-caused-by-the-great-firewall</a><br /><a href="https://isc.sans.edu/diary/Are+You+Piratebay+thepiratebayorg+Resolving+to+Various+Hosts/19175" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Are+You+Piratebay+thepiratebayorg+Resolving+to+Various+Hosts/19175</a><br /> HPE Aruba Networking Vulnerabilities<br /><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04712en_us&amp;docLocale=en_US" target="_blank" rel="noreferrer noopener">https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04712en_us&amp;docLocale=en_US</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9158.mp3</guid><pubDate>Mon, 30 Sep 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62160353/9158.mp3" length="6188144" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>CUPS Vulnerability
https://isc.sans.edu/diary/Patch%20for%20Critical%20CUPS%20vulnerability%3A%20Don%27t%20Panic/31302
 PHP Updates
https://www.php.net/ChangeLog-8.php#8.1.30
 DNS And Big Chinese Firewall...</itunes:subtitle><itunes:summary><![CDATA[CUPS Vulnerability<br /><a href="https://isc.sans.edu/diary/Patch%20for%20Critical%20CUPS%20vulnerability%3A%20Don%27t%20Panic/31302" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Patch%20for%20Critical%20CUPS%20vulnerability%3A%20Don%27t%20Panic/31302</a><br /> PHP Updates<br /><a href="https://www.php.net/ChangeLog-8.php#8.1.30" target="_blank" rel="noreferrer noopener">https://www.php.net/ChangeLog-8.php#8.1.30</a><br /> DNS And Big Chinese Firewall<br /><a href="https://www.assetnote.io/resources/research/insecurity-through-censorship-vulnerabilities-caused-by-the-great-firewall" target="_blank" rel="noreferrer noopener">https://www.assetnote.io/resources/research/insecurity-through-censorship-vulnerabilities-caused-by-the-great-firewall</a><br /><a href="https://isc.sans.edu/diary/Are+You+Piratebay+thepiratebayorg+Resolving+to+Various+Hosts/19175" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Are+You+Piratebay+thepiratebayorg+Resolving+to+Various+Hosts/19175</a><br /> HPE Aruba Networking Vulnerabilities<br /><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04712en_us&amp;docLocale=en_US" target="_blank" rel="noreferrer noopener">https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04712en_us&amp;docLocale=en_US</a><br />]]></itunes:summary><itunes:duration>420</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,hpe; aruba; dns; firewall; php,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9158</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, September 27th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-september-27th-2024--62129285</link><description><![CDATA[Patch for Critical CUPS vulnerability: Don't Panic<br /><a href="https://isc.sans.edu/diary/Patch%20for%20Critical%20CUPS%20vulnerability%3A%20Don%27t%20Panic/31302" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Patch%20for%20Critical%20CUPS%20vulnerability%3A%20Don%27t%20Panic/31302</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9156.mp3</guid><pubDate>Fri, 27 Sep 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129285/9156.mp3" length="6085745" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Patch for Critical CUPS vulnerability: Don't Panic
https://isc.sans.edu/diary/Patch%20for%20Critical%20CUPS%20vulnerability%3A%20Don%27t%20Panic/31302
</itunes:subtitle><itunes:summary><![CDATA[Patch for Critical CUPS vulnerability: Don't Panic<br /><a href="https://isc.sans.edu/diary/Patch%20for%20Critical%20CUPS%20vulnerability%3A%20Don%27t%20Panic/31302" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Patch%20for%20Critical%20CUPS%20vulnerability%3A%20Don%27t%20Panic/31302</a><br />]]></itunes:summary><itunes:duration>413</itunes:duration><itunes:keywords>business,computer,cups; browsed; filter; evilsoc,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9156</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, September 27th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-september-27th-2024--62123737</link><description><![CDATA[Patch for Critical CUPS vulnerability: Don't Panic<br /><a href="https://isc.sans.edu/diary/Patch%20for%20Critical%20CUPS%20vulnerability%3A%20Don%27t%20Panic/31302" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Patch%20for%20Critical%20CUPS%20vulnerability%3A%20Don%27t%20Panic/31302</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9156.mp3</guid><pubDate>Fri, 27 Sep 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62123737/9156.mp3" length="6085745" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Patch for Critical CUPS vulnerability: Don't Panic
https://isc.sans.edu/diary/Patch%20for%20Critical%20CUPS%20vulnerability%3A%20Don%27t%20Panic/31302
</itunes:subtitle><itunes:summary><![CDATA[Patch for Critical CUPS vulnerability: Don't Panic<br /><a href="https://isc.sans.edu/diary/Patch%20for%20Critical%20CUPS%20vulnerability%3A%20Don%27t%20Panic/31302" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Patch%20for%20Critical%20CUPS%20vulnerability%3A%20Don%27t%20Panic/31302</a><br />]]></itunes:summary><itunes:duration>413</itunes:duration><itunes:keywords>business,computer,cups; browsed; filter; evilsoc,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9156</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, September 26th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-september-26th-2024--62129284</link><description><![CDATA[DNS Reflection Update and Corrupted DNS Requests<br /><a href="https://isc.sans.edu/diary/DNS%20Reflection%20Update%20and%20Odd%20Corrupted%20DNS%20Requests/31296" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/DNS%20Reflection%20Update%20and%20Odd%20Corrupted%20DNS%20Requests/31296</a><br /> CVE-2024-28987 Solarwinds Web Help Desk Hardcoded Credentials Vulnerability<br /><a href="https://www.horizon3.ai/attack-research/cve-2024-28987-solarwinds-web-help-desk-hardcoded-credential-vulnerability-deep-dive/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/cve-2024-28987-solarwinds-web-help-desk-hardcoded-credential-vulnerability-deep-dive/</a> cve-2024-28987<br /> Watchguard Unauthenticated and Unencrypted SSO Protocol<br /><a href="https://www.redteam-pentesting.de/en/advisories/rt-sa-2024-006/" target="_blank" rel="noreferrer noopener">https://www.redteam-pentesting.de/en/advisories/rt-sa-2024-006/</a><br /><a href="https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00014" target="_blank" rel="noreferrer noopener">https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00014</a><br /> Infostealers Overcome Chrome's App Bound Encryption<br /><a href="https://securityonline.info/infostealers-overcome-chromes-app-bound-encryption-threatening-user-data-security/" target="_blank" rel="noreferrer noopener">https://securityonline.info/infostealers-overcome-chromes-app-bound-encryption-threatening-user-data-security/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9154.mp3</guid><pubDate>Thu, 26 Sep 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129284/9154.mp3" length="6202612" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>DNS Reflection Update and Corrupted DNS Requests
https://isc.sans.edu/diary/DNS%20Reflection%20Update%20and%20Odd%20Corrupted%20DNS%20Requests/31296
 CVE-2024-28987 Solarwinds Web Help Desk Hardcoded Credentials Vulnerability...</itunes:subtitle><itunes:summary><![CDATA[DNS Reflection Update and Corrupted DNS Requests<br /><a href="https://isc.sans.edu/diary/DNS%20Reflection%20Update%20and%20Odd%20Corrupted%20DNS%20Requests/31296" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/DNS%20Reflection%20Update%20and%20Odd%20Corrupted%20DNS%20Requests/31296</a><br /> CVE-2024-28987 Solarwinds Web Help Desk Hardcoded Credentials Vulnerability<br /><a href="https://www.horizon3.ai/attack-research/cve-2024-28987-solarwinds-web-help-desk-hardcoded-credential-vulnerability-deep-dive/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/cve-2024-28987-solarwinds-web-help-desk-hardcoded-credential-vulnerability-deep-dive/</a> cve-2024-28987<br /> Watchguard Unauthenticated and Unencrypted SSO Protocol<br /><a href="https://www.redteam-pentesting.de/en/advisories/rt-sa-2024-006/" target="_blank" rel="noreferrer noopener">https://www.redteam-pentesting.de/en/advisories/rt-sa-2024-006/</a><br /><a href="https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00014" target="_blank" rel="noreferrer noopener">https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00014</a><br /> Infostealers Overcome Chrome's App Bound Encryption<br /><a href="https://securityonline.info/infostealers-overcome-chromes-app-bound-encryption-threatening-user-data-security/" target="_blank" rel="noreferrer noopener">https://securityonline.info/infostealers-overcome-chromes-app-bound-encryption-threatening-user-data-security/</a><br />]]></itunes:summary><itunes:duration>421</itunes:duration><itunes:keywords>business,chrome; cookies; infostealer; ,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9154</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, September 26th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-september-26th-2024--62111795</link><description><![CDATA[DNS Reflection Update and Corrupted DNS Requests<br /><a href="https://isc.sans.edu/diary/DNS%20Reflection%20Update%20and%20Odd%20Corrupted%20DNS%20Requests/31296" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/DNS%20Reflection%20Update%20and%20Odd%20Corrupted%20DNS%20Requests/31296</a><br /> CVE-2024-28987 Solarwinds Web Help Desk Hardcoded Credentials Vulnerability<br /><a href="https://www.horizon3.ai/attack-research/cve-2024-28987-solarwinds-web-help-desk-hardcoded-credential-vulnerability-deep-dive/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/cve-2024-28987-solarwinds-web-help-desk-hardcoded-credential-vulnerability-deep-dive/</a> cve-2024-28987<br /> Watchguard Unauthenticated and Unencrypted SSO Protocol<br /><a href="https://www.redteam-pentesting.de/en/advisories/rt-sa-2024-006/" target="_blank" rel="noreferrer noopener">https://www.redteam-pentesting.de/en/advisories/rt-sa-2024-006/</a><br /><a href="https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00014" target="_blank" rel="noreferrer noopener">https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00014</a><br /> Infostealers Overcome Chrome's App Bound Encryption<br /><a href="https://securityonline.info/infostealers-overcome-chromes-app-bound-encryption-threatening-user-data-security/" target="_blank" rel="noreferrer noopener">https://securityonline.info/infostealers-overcome-chromes-app-bound-encryption-threatening-user-data-security/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9154.mp3</guid><pubDate>Thu, 26 Sep 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62111795/9154.mp3" length="6202612" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>DNS Reflection Update and Corrupted DNS Requests
https://isc.sans.edu/diary/DNS%20Reflection%20Update%20and%20Odd%20Corrupted%20DNS%20Requests/31296
 CVE-2024-28987 Solarwinds Web Help Desk Hardcoded Credentials Vulnerability...</itunes:subtitle><itunes:summary><![CDATA[DNS Reflection Update and Corrupted DNS Requests<br /><a href="https://isc.sans.edu/diary/DNS%20Reflection%20Update%20and%20Odd%20Corrupted%20DNS%20Requests/31296" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/DNS%20Reflection%20Update%20and%20Odd%20Corrupted%20DNS%20Requests/31296</a><br /> CVE-2024-28987 Solarwinds Web Help Desk Hardcoded Credentials Vulnerability<br /><a href="https://www.horizon3.ai/attack-research/cve-2024-28987-solarwinds-web-help-desk-hardcoded-credential-vulnerability-deep-dive/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/cve-2024-28987-solarwinds-web-help-desk-hardcoded-credential-vulnerability-deep-dive/</a> cve-2024-28987<br /> Watchguard Unauthenticated and Unencrypted SSO Protocol<br /><a href="https://www.redteam-pentesting.de/en/advisories/rt-sa-2024-006/" target="_blank" rel="noreferrer noopener">https://www.redteam-pentesting.de/en/advisories/rt-sa-2024-006/</a><br /><a href="https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00014" target="_blank" rel="noreferrer noopener">https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00014</a><br /> Infostealers Overcome Chrome's App Bound Encryption<br /><a href="https://securityonline.info/infostealers-overcome-chromes-app-bound-encryption-threatening-user-data-security/" target="_blank" rel="noreferrer noopener">https://securityonline.info/infostealers-overcome-chromes-app-bound-encryption-threatening-user-data-security/</a><br />]]></itunes:summary><itunes:duration>421</itunes:duration><itunes:keywords>business,chrome; cookies; infostealer; ,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9154</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, September 25th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-september-25th-2024--62129291</link><description><![CDATA[Exploitation of RAISECOM Gateway Devices CVE-2024-7120<br /><a href="https://isc.sans.edu/diary/Exploitation%20of%20RAISECOM%20Gateway%20Devices%20Vulnerability%20CVE-2024-7120/31292" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploitation%20of%20RAISECOM%20Gateway%20Devices%20Vulnerability%20CVE-2024-7120/31292</a><br /> Cellopoint Vulnerability CVE-2024-9043<br /><a href="https://www.twcert.org.tw/en/cp-139-8103-b0568-2.html" target="_blank" rel="noreferrer noopener">https://www.twcert.org.tw/en/cp-139-8103-b0568-2.html</a><br /> Cisco Smart Licensing Vulnerability Details<br /><a href="https://starkeblog.com/cve-wednesday/cisco/2024/09/20/cve-wednesday-cve-2024-20439.html" target="_blank" rel="noreferrer noopener">https://starkeblog.com/cve-wednesday/cisco/2024/09/20/cve-wednesday-cve-2024-20439.html</a><br /> Ivanti Virtual Traffic Manager Exploited<br /><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a><br /> GNU Linux Systems Possible Critical Vulnerability<br /><a href="https://securityonline.info/severe-unauthenticated-rce-flaw-cvss-9-9-in-gnu-linux-systems-awaiting-full-disclosure/" target="_blank" rel="noreferrer noopener">https://securityonline.info/severe-unauthenticated-rce-flaw-cvss-9-9-in-gnu-linux-systems-awaiting-full-disclosure/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9152.mp3</guid><pubDate>Wed, 25 Sep 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129291/9152.mp3" length="4881636" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Exploitation of RAISECOM Gateway Devices CVE-2024-7120
https://isc.sans.edu/diary/Exploitation%20of%20RAISECOM%20Gateway%20Devices%20Vulnerability%20CVE-2024-7120/31292
 Cellopoint Vulnerability CVE-2024-9043...</itunes:subtitle><itunes:summary><![CDATA[Exploitation of RAISECOM Gateway Devices CVE-2024-7120<br /><a href="https://isc.sans.edu/diary/Exploitation%20of%20RAISECOM%20Gateway%20Devices%20Vulnerability%20CVE-2024-7120/31292" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploitation%20of%20RAISECOM%20Gateway%20Devices%20Vulnerability%20CVE-2024-7120/31292</a><br /> Cellopoint Vulnerability CVE-2024-9043<br /><a href="https://www.twcert.org.tw/en/cp-139-8103-b0568-2.html" target="_blank" rel="noreferrer noopener">https://www.twcert.org.tw/en/cp-139-8103-b0568-2.html</a><br /> Cisco Smart Licensing Vulnerability Details<br /><a href="https://starkeblog.com/cve-wednesday/cisco/2024/09/20/cve-wednesday-cve-2024-20439.html" target="_blank" rel="noreferrer noopener">https://starkeblog.com/cve-wednesday/cisco/2024/09/20/cve-wednesday-cve-2024-20439.html</a><br /> Ivanti Virtual Traffic Manager Exploited<br /><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a><br /> GNU Linux Systems Possible Critical Vulnerability<br /><a href="https://securityonline.info/severe-unauthenticated-rce-flaw-cvss-9-9-in-gnu-linux-systems-awaiting-full-disclosure/" target="_blank" rel="noreferrer noopener">https://securityonline.info/severe-unauthenticated-rce-flaw-cvss-9-9-in-gnu-linux-systems-awaiting-full-disclosure/</a><br />]]></itunes:summary><itunes:duration>327</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,linux; gnu; vulnerability; con,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9152</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, September 25th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-september-25th-2024--62098352</link><description><![CDATA[Exploitation of RAISECOM Gateway Devices CVE-2024-7120<br /><a href="https://isc.sans.edu/diary/Exploitation%20of%20RAISECOM%20Gateway%20Devices%20Vulnerability%20CVE-2024-7120/31292" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploitation%20of%20RAISECOM%20Gateway%20Devices%20Vulnerability%20CVE-2024-7120/31292</a><br /> Cellopoint Vulnerability CVE-2024-9043<br /><a href="https://www.twcert.org.tw/en/cp-139-8103-b0568-2.html" target="_blank" rel="noreferrer noopener">https://www.twcert.org.tw/en/cp-139-8103-b0568-2.html</a><br /> Cisco Smart Licensing Vulnerability Details<br /><a href="https://starkeblog.com/cve-wednesday/cisco/2024/09/20/cve-wednesday-cve-2024-20439.html" target="_blank" rel="noreferrer noopener">https://starkeblog.com/cve-wednesday/cisco/2024/09/20/cve-wednesday-cve-2024-20439.html</a><br /> Ivanti Virtual Traffic Manager Exploited<br /><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a><br /> GNU Linux Systems Possible Critical Vulnerability<br /><a href="https://securityonline.info/severe-unauthenticated-rce-flaw-cvss-9-9-in-gnu-linux-systems-awaiting-full-disclosure/" target="_blank" rel="noreferrer noopener">https://securityonline.info/severe-unauthenticated-rce-flaw-cvss-9-9-in-gnu-linux-systems-awaiting-full-disclosure/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9152.mp3</guid><pubDate>Wed, 25 Sep 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62098352/9152.mp3" length="4881636" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Exploitation of RAISECOM Gateway Devices CVE-2024-7120
https://isc.sans.edu/diary/Exploitation%20of%20RAISECOM%20Gateway%20Devices%20Vulnerability%20CVE-2024-7120/31292
 Cellopoint Vulnerability CVE-2024-9043...</itunes:subtitle><itunes:summary><![CDATA[Exploitation of RAISECOM Gateway Devices CVE-2024-7120<br /><a href="https://isc.sans.edu/diary/Exploitation%20of%20RAISECOM%20Gateway%20Devices%20Vulnerability%20CVE-2024-7120/31292" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploitation%20of%20RAISECOM%20Gateway%20Devices%20Vulnerability%20CVE-2024-7120/31292</a><br /> Cellopoint Vulnerability CVE-2024-9043<br /><a href="https://www.twcert.org.tw/en/cp-139-8103-b0568-2.html" target="_blank" rel="noreferrer noopener">https://www.twcert.org.tw/en/cp-139-8103-b0568-2.html</a><br /> Cisco Smart Licensing Vulnerability Details<br /><a href="https://starkeblog.com/cve-wednesday/cisco/2024/09/20/cve-wednesday-cve-2024-20439.html" target="_blank" rel="noreferrer noopener">https://starkeblog.com/cve-wednesday/cisco/2024/09/20/cve-wednesday-cve-2024-20439.html</a><br /> Ivanti Virtual Traffic Manager Exploited<br /><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a><br /> GNU Linux Systems Possible Critical Vulnerability<br /><a href="https://securityonline.info/severe-unauthenticated-rce-flaw-cvss-9-9-in-gnu-linux-systems-awaiting-full-disclosure/" target="_blank" rel="noreferrer noopener">https://securityonline.info/severe-unauthenticated-rce-flaw-cvss-9-9-in-gnu-linux-systems-awaiting-full-disclosure/</a><br />]]></itunes:summary><itunes:duration>327</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,linux; gnu; vulnerability; con,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9152</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, September 24th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-september-24th-2024--62129297</link><description><![CDATA[Phishing Links With @ Sign<br /><a href="https://isc.sans.edu/diary/Phishing%20links%20with%20%40%20sign%20and%20the%20need%20for%20effective%20security%20awareness%20building/31288" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Phishing%20links%20with%20%40%20sign%20and%20the%20need%20for%20effective%20security%20awareness%20building/31288</a><br /> Kaspersky Deletes Itself Installs UltraAV Antivirus Without Warning<br /><a href="https://www.bleepingcomputer.com/news/security/kaspersky-deletes-itself-installs-ultraav-antivirus-without-warning/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/kaspersky-deletes-itself-installs-ultraav-antivirus-without-warning/</a><br /> Microchip ASF tinydhcp Vulnerability<br /><a href="https://kb.cert.org/vuls/id/138043" target="_blank" rel="noreferrer noopener">https://kb.cert.org/vuls/id/138043</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9150.mp3</guid><pubDate>Tue, 24 Sep 2024 02:00:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129297/9150.mp3" length="4966612" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Phishing Links With @ Sign
https://isc.sans.edu/diary/Phishing%20links%20with%20%40%20sign%20and%20the%20need%20for%20effective%20security%20awareness%20building/31288
 Kaspersky Deletes Itself Installs UltraAV Antivirus Without Warning...</itunes:subtitle><itunes:summary><![CDATA[Phishing Links With @ Sign<br /><a href="https://isc.sans.edu/diary/Phishing%20links%20with%20%40%20sign%20and%20the%20need%20for%20effective%20security%20awareness%20building/31288" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Phishing%20links%20with%20%40%20sign%20and%20the%20need%20for%20effective%20security%20awareness%20building/31288</a><br /> Kaspersky Deletes Itself Installs UltraAV Antivirus Without Warning<br /><a href="https://www.bleepingcomputer.com/news/security/kaspersky-deletes-itself-installs-ultraav-antivirus-without-warning/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/kaspersky-deletes-itself-installs-ultraav-antivirus-without-warning/</a><br /> Microchip ASF tinydhcp Vulnerability<br /><a href="https://kb.cert.org/vuls/id/138043" target="_blank" rel="noreferrer noopener">https://kb.cert.org/vuls/id/138043</a><br />]]></itunes:summary><itunes:duration>333</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microchip; asf; tinydhcp; kasp,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9150</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, September 24th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-september-24th-2024--62086468</link><description><![CDATA[Phishing Links With @ Sign<br /><a href="https://isc.sans.edu/diary/Phishing%20links%20with%20%40%20sign%20and%20the%20need%20for%20effective%20security%20awareness%20building/31288" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Phishing%20links%20with%20%40%20sign%20and%20the%20need%20for%20effective%20security%20awareness%20building/31288</a><br /> Kaspersky Deletes Itself Installs UltraAV Antivirus Without Warning<br /><a href="https://www.bleepingcomputer.com/news/security/kaspersky-deletes-itself-installs-ultraav-antivirus-without-warning/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/kaspersky-deletes-itself-installs-ultraav-antivirus-without-warning/</a><br /> Microchip ASF tinydhcp Vulnerability<br /><a href="https://kb.cert.org/vuls/id/138043" target="_blank" rel="noreferrer noopener">https://kb.cert.org/vuls/id/138043</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9150.mp3</guid><pubDate>Tue, 24 Sep 2024 02:00:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62086468/9150.mp3" length="4966612" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Phishing Links With @ Sign
https://isc.sans.edu/diary/Phishing%20links%20with%20%40%20sign%20and%20the%20need%20for%20effective%20security%20awareness%20building/31288
 Kaspersky Deletes Itself Installs UltraAV Antivirus Without Warning...</itunes:subtitle><itunes:summary><![CDATA[Phishing Links With @ Sign<br /><a href="https://isc.sans.edu/diary/Phishing%20links%20with%20%40%20sign%20and%20the%20need%20for%20effective%20security%20awareness%20building/31288" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Phishing%20links%20with%20%40%20sign%20and%20the%20need%20for%20effective%20security%20awareness%20building/31288</a><br /> Kaspersky Deletes Itself Installs UltraAV Antivirus Without Warning<br /><a href="https://www.bleepingcomputer.com/news/security/kaspersky-deletes-itself-installs-ultraav-antivirus-without-warning/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/kaspersky-deletes-itself-installs-ultraav-antivirus-without-warning/</a><br /> Microchip ASF tinydhcp Vulnerability<br /><a href="https://kb.cert.org/vuls/id/138043" target="_blank" rel="noreferrer noopener">https://kb.cert.org/vuls/id/138043</a><br />]]></itunes:summary><itunes:duration>333</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microchip; asf; tinydhcp; kasp,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9150</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, September 23rd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-september-23rd-2024--62129286</link><description><![CDATA[Windows Server Update Services Deprecation<br /><a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-server-update-services-wsus-deprecation/ba-p/4250436" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-server-update-services-wsus-deprecation/ba-p/4250436</a><br /> Windows Server 2025 Hotpatches<br /><a href="https://techcommunity.microsoft.com/t5/windows-server-news-and-best/now-in-preview-hotpatch-for-windows-server-2025/ba-p/4248296" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/windows-server-news-and-best/now-in-preview-hotpatch-for-windows-server-2025/ba-p/4248296</a><br /> Google Suggests Not Using WHOIS for Certificate Validation<br /><a href="https://lists.cabforum.org/pipermail/servercert-wg/2024-September/004821.html" target="_blank" rel="noreferrer noopener">https://lists.cabforum.org/pipermail/servercert-wg/2024-September/004821.html</a><br /> Versa Director Vulnerability<br /><a href="https://security-portal.versa-networks.com/emailbulletins/66e4a8ebda545d61ec2b1ab9" target="_blank" rel="noreferrer noopener">https://security-portal.versa-networks.com/emailbulletins/66e4a8ebda545d61ec2b1ab9</a><br /> Apache Hugegraph Vulnerability Exploited<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27348" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2024-27348</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9148.mp3</guid><pubDate>Mon, 23 Sep 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129286/9148.mp3" length="4695291" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Windows Server Update Services Deprecation
https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-server-update-services-wsus-deprecation/ba-p/4250436
 Windows Server 2025 Hotpatches...</itunes:subtitle><itunes:summary><![CDATA[Windows Server Update Services Deprecation<br /><a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-server-update-services-wsus-deprecation/ba-p/4250436" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-server-update-services-wsus-deprecation/ba-p/4250436</a><br /> Windows Server 2025 Hotpatches<br /><a href="https://techcommunity.microsoft.com/t5/windows-server-news-and-best/now-in-preview-hotpatch-for-windows-server-2025/ba-p/4248296" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/windows-server-news-and-best/now-in-preview-hotpatch-for-windows-server-2025/ba-p/4248296</a><br /> Google Suggests Not Using WHOIS for Certificate Validation<br /><a href="https://lists.cabforum.org/pipermail/servercert-wg/2024-September/004821.html" target="_blank" rel="noreferrer noopener">https://lists.cabforum.org/pipermail/servercert-wg/2024-September/004821.html</a><br /> Versa Director Vulnerability<br /><a href="https://security-portal.versa-networks.com/emailbulletins/66e4a8ebda545d61ec2b1ab9" target="_blank" rel="noreferrer noopener">https://security-portal.versa-networks.com/emailbulletins/66e4a8ebda545d61ec2b1ab9</a><br /> Apache Hugegraph Vulnerability Exploited<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27348" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2024-27348</a><br />]]></itunes:summary><itunes:duration>314</itunes:duration><itunes:keywords>apache; hugegraph; versa; dire,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9148</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, September 23rd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-september-23rd-2024--62072683</link><description><![CDATA[Windows Server Update Services Deprecation<br /><a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-server-update-services-wsus-deprecation/ba-p/4250436" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-server-update-services-wsus-deprecation/ba-p/4250436</a><br /> Windows Server 2025 Hotpatches<br /><a href="https://techcommunity.microsoft.com/t5/windows-server-news-and-best/now-in-preview-hotpatch-for-windows-server-2025/ba-p/4248296" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/windows-server-news-and-best/now-in-preview-hotpatch-for-windows-server-2025/ba-p/4248296</a><br /> Google Suggests Not Using WHOIS for Certificate Validation<br /><a href="https://lists.cabforum.org/pipermail/servercert-wg/2024-September/004821.html" target="_blank" rel="noreferrer noopener">https://lists.cabforum.org/pipermail/servercert-wg/2024-September/004821.html</a><br /> Versa Director Vulnerability<br /><a href="https://security-portal.versa-networks.com/emailbulletins/66e4a8ebda545d61ec2b1ab9" target="_blank" rel="noreferrer noopener">https://security-portal.versa-networks.com/emailbulletins/66e4a8ebda545d61ec2b1ab9</a><br /> Apache Hugegraph Vulnerability Exploited<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27348" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2024-27348</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9148.mp3</guid><pubDate>Mon, 23 Sep 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62072683/9148.mp3" length="4695291" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Windows Server Update Services Deprecation
https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-server-update-services-wsus-deprecation/ba-p/4250436
 Windows Server 2025 Hotpatches...</itunes:subtitle><itunes:summary><![CDATA[Windows Server Update Services Deprecation<br /><a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-server-update-services-wsus-deprecation/ba-p/4250436" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-server-update-services-wsus-deprecation/ba-p/4250436</a><br /> Windows Server 2025 Hotpatches<br /><a href="https://techcommunity.microsoft.com/t5/windows-server-news-and-best/now-in-preview-hotpatch-for-windows-server-2025/ba-p/4248296" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/windows-server-news-and-best/now-in-preview-hotpatch-for-windows-server-2025/ba-p/4248296</a><br /> Google Suggests Not Using WHOIS for Certificate Validation<br /><a href="https://lists.cabforum.org/pipermail/servercert-wg/2024-September/004821.html" target="_blank" rel="noreferrer noopener">https://lists.cabforum.org/pipermail/servercert-wg/2024-September/004821.html</a><br /> Versa Director Vulnerability<br /><a href="https://security-portal.versa-networks.com/emailbulletins/66e4a8ebda545d61ec2b1ab9" target="_blank" rel="noreferrer noopener">https://security-portal.versa-networks.com/emailbulletins/66e4a8ebda545d61ec2b1ab9</a><br /> Apache Hugegraph Vulnerability Exploited<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27348" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2024-27348</a><br />]]></itunes:summary><itunes:duration>314</itunes:duration><itunes:keywords>apache; hugegraph; versa; dire,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9148</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, September 20th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-september-20th-2024--62129292</link><description><![CDATA[Fake GitHub Site Targeting Developers<br /><a href="https://isc.sans.edu/diary/Fake%20GitHub%20Site%20Targeting%20Developers/31282" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Fake%20GitHub%20Site%20Targeting%20Developers/31282</a><br /> Ivanti CSA 4.6 Advisory<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-CSA-4-6-Cloud-Services-Appliance-CVE-2024-8963?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-CSA-4-6-Cloud-Services-Appliance-CVE-2024-8963?language=en_US</a><br /> German Police Deanonymizes Tor User<br /><a href="https://blog.torproject.org/tor-is-still-safe/" target="_blank" rel="noreferrer noopener">https://blog.torproject.org/tor-is-still-safe/</a><br /> Ever wonder how crooks get the credentials to unlock stolen phones?<br /><a href="https://arstechnica.com/security/2024/09/cops-bust-website-crooks-used-to-unlock-1-2-million-stolen-mobile-phones/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2024/09/cops-bust-website-crooks-used-to-unlock-1-2-million-stolen-mobile-phones/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9146.mp3</guid><pubDate>Fri, 20 Sep 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129292/9146.mp3" length="6680773" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Fake GitHub Site Targeting Developers
https://isc.sans.edu/diary/Fake%20GitHub%20Site%20Targeting%20Developers/31282
 Ivanti CSA 4.6 Advisory...</itunes:subtitle><itunes:summary><![CDATA[Fake GitHub Site Targeting Developers<br /><a href="https://isc.sans.edu/diary/Fake%20GitHub%20Site%20Targeting%20Developers/31282" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Fake%20GitHub%20Site%20Targeting%20Developers/31282</a><br /> Ivanti CSA 4.6 Advisory<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-CSA-4-6-Cloud-Services-Appliance-CVE-2024-8963?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-CSA-4-6-Cloud-Services-Appliance-CVE-2024-8963?language=en_US</a><br /> German Police Deanonymizes Tor User<br /><a href="https://blog.torproject.org/tor-is-still-safe/" target="_blank" rel="noreferrer noopener">https://blog.torproject.org/tor-is-still-safe/</a><br /> Ever wonder how crooks get the credentials to unlock stolen phones?<br /><a href="https://arstechnica.com/security/2024/09/cops-bust-website-crooks-used-to-unlock-1-2-million-stolen-mobile-phones/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2024/09/cops-bust-website-crooks-used-to-unlock-1-2-million-stolen-mobile-phones/</a><br />]]></itunes:summary><itunes:duration>456</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,iphone; unlocker; police; tor;,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9146</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, September 20th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-september-20th-2024--62038527</link><description><![CDATA[Fake GitHub Site Targeting Developers<br /><a href="https://isc.sans.edu/diary/Fake%20GitHub%20Site%20Targeting%20Developers/31282" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Fake%20GitHub%20Site%20Targeting%20Developers/31282</a><br /> Ivanti CSA 4.6 Advisory<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-CSA-4-6-Cloud-Services-Appliance-CVE-2024-8963?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-CSA-4-6-Cloud-Services-Appliance-CVE-2024-8963?language=en_US</a><br /> German Police Deanonymizes Tor User<br /><a href="https://blog.torproject.org/tor-is-still-safe/" target="_blank" rel="noreferrer noopener">https://blog.torproject.org/tor-is-still-safe/</a><br /> Ever wonder how crooks get the credentials to unlock stolen phones?<br /><a href="https://arstechnica.com/security/2024/09/cops-bust-website-crooks-used-to-unlock-1-2-million-stolen-mobile-phones/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2024/09/cops-bust-website-crooks-used-to-unlock-1-2-million-stolen-mobile-phones/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9146.mp3</guid><pubDate>Fri, 20 Sep 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62038527/9146.mp3" length="6680773" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Fake GitHub Site Targeting Developers
https://isc.sans.edu/diary/Fake%20GitHub%20Site%20Targeting%20Developers/31282
 Ivanti CSA 4.6 Advisory...</itunes:subtitle><itunes:summary><![CDATA[Fake GitHub Site Targeting Developers<br /><a href="https://isc.sans.edu/diary/Fake%20GitHub%20Site%20Targeting%20Developers/31282" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Fake%20GitHub%20Site%20Targeting%20Developers/31282</a><br /> Ivanti CSA 4.6 Advisory<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-CSA-4-6-Cloud-Services-Appliance-CVE-2024-8963?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-CSA-4-6-Cloud-Services-Appliance-CVE-2024-8963?language=en_US</a><br /> German Police Deanonymizes Tor User<br /><a href="https://blog.torproject.org/tor-is-still-safe/" target="_blank" rel="noreferrer noopener">https://blog.torproject.org/tor-is-still-safe/</a><br /> Ever wonder how crooks get the credentials to unlock stolen phones?<br /><a href="https://arstechnica.com/security/2024/09/cops-bust-website-crooks-used-to-unlock-1-2-million-stolen-mobile-phones/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2024/09/cops-bust-website-crooks-used-to-unlock-1-2-million-stolen-mobile-phones/</a><br />]]></itunes:summary><itunes:duration>456</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,iphone; unlocker; police; tor;,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9146</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, September 19th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-september-19th-2024--62129287</link><description><![CDATA[Python Infostealer Patching Windows Exodus App<br /><a href="https://isc.sans.edu/diary/Python%20Infostealer%20Patching%20Windows%20Exodus%20App/31276" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Python%20Infostealer%20Patching%20Windows%20Exodus%20App/31276</a><br /> Service Now Knoledge Bases Data Exposures<br /><a href="https://appomni.com/ao-labs/servicenow-knowledge-bases-data-exposures-uncovered/" target="_blank" rel="noreferrer noopener">https://appomni.com/ao-labs/servicenow-knowledge-bases-data-exposures-uncovered/</a><br /> Gitlab Patch<br /><a href="https://about.gitlab.com/releases/2024/09/17/patch-release-gitlab-17-3-3-released/" target="_blank" rel="noreferrer noopener">https://about.gitlab.com/releases/2024/09/17/patch-release-gitlab-17-3-3-released/</a><br /> Aruba Patch<br /><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04709en_us&amp;docLocale=en_US" target="_blank" rel="noreferrer noopener">https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04709en_us&amp;docLocale=en_US</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9144.mp3</guid><pubDate>Thu, 19 Sep 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129287/9144.mp3" length="3853024" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Python Infostealer Patching Windows Exodus App
https://isc.sans.edu/diary/Python%20Infostealer%20Patching%20Windows%20Exodus%20App/31276
 Service Now Knoledge Bases Data Exposures...</itunes:subtitle><itunes:summary><![CDATA[Python Infostealer Patching Windows Exodus App<br /><a href="https://isc.sans.edu/diary/Python%20Infostealer%20Patching%20Windows%20Exodus%20App/31276" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Python%20Infostealer%20Patching%20Windows%20Exodus%20App/31276</a><br /> Service Now Knoledge Bases Data Exposures<br /><a href="https://appomni.com/ao-labs/servicenow-knowledge-bases-data-exposures-uncovered/" target="_blank" rel="noreferrer noopener">https://appomni.com/ao-labs/servicenow-knowledge-bases-data-exposures-uncovered/</a><br /> Gitlab Patch<br /><a href="https://about.gitlab.com/releases/2024/09/17/patch-release-gitlab-17-3-3-released/" target="_blank" rel="noreferrer noopener">https://about.gitlab.com/releases/2024/09/17/patch-release-gitlab-17-3-3-released/</a><br /> Aruba Patch<br /><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04709en_us&amp;docLocale=en_US" target="_blank" rel="noreferrer noopener">https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04709en_us&amp;docLocale=en_US</a><br />]]></itunes:summary><itunes:duration>254</itunes:duration><itunes:keywords>aruba; gitlab; service now; py,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9144</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, September 19th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-september-19th-2024--62020957</link><description><![CDATA[Python Infostealer Patching Windows Exodus App<br /><a href="https://isc.sans.edu/diary/Python%20Infostealer%20Patching%20Windows%20Exodus%20App/31276" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Python%20Infostealer%20Patching%20Windows%20Exodus%20App/31276</a><br /> Service Now Knoledge Bases Data Exposures<br /><a href="https://appomni.com/ao-labs/servicenow-knowledge-bases-data-exposures-uncovered/" target="_blank" rel="noreferrer noopener">https://appomni.com/ao-labs/servicenow-knowledge-bases-data-exposures-uncovered/</a><br /> Gitlab Patch<br /><a href="https://about.gitlab.com/releases/2024/09/17/patch-release-gitlab-17-3-3-released/" target="_blank" rel="noreferrer noopener">https://about.gitlab.com/releases/2024/09/17/patch-release-gitlab-17-3-3-released/</a><br /> Aruba Patch<br /><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04709en_us&amp;docLocale=en_US" target="_blank" rel="noreferrer noopener">https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04709en_us&amp;docLocale=en_US</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9144.mp3</guid><pubDate>Thu, 19 Sep 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62020957/9144.mp3" length="3853024" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Python Infostealer Patching Windows Exodus App
https://isc.sans.edu/diary/Python%20Infostealer%20Patching%20Windows%20Exodus%20App/31276
 Service Now Knoledge Bases Data Exposures...</itunes:subtitle><itunes:summary><![CDATA[Python Infostealer Patching Windows Exodus App<br /><a href="https://isc.sans.edu/diary/Python%20Infostealer%20Patching%20Windows%20Exodus%20App/31276" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Python%20Infostealer%20Patching%20Windows%20Exodus%20App/31276</a><br /> Service Now Knoledge Bases Data Exposures<br /><a href="https://appomni.com/ao-labs/servicenow-knowledge-bases-data-exposures-uncovered/" target="_blank" rel="noreferrer noopener">https://appomni.com/ao-labs/servicenow-knowledge-bases-data-exposures-uncovered/</a><br /> Gitlab Patch<br /><a href="https://about.gitlab.com/releases/2024/09/17/patch-release-gitlab-17-3-3-released/" target="_blank" rel="noreferrer noopener">https://about.gitlab.com/releases/2024/09/17/patch-release-gitlab-17-3-3-released/</a><br /> Aruba Patch<br /><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04709en_us&amp;docLocale=en_US" target="_blank" rel="noreferrer noopener">https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04709en_us&amp;docLocale=en_US</a><br />]]></itunes:summary><itunes:duration>254</itunes:duration><itunes:keywords>aruba; gitlab; service now; py,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9144</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, September 18th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-september-18th-2024--62129290</link><description><![CDATA[23:59, Time to Exfiltrate!<br /><a href="https://isc.sans.edu/diary/23%3A59%2C%20Time%20to%20Exfiltrate!/31272" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/23%3A59%2C%20Time%20to%20Exfiltrate!/31272</a><br /> Critical VMWare VCenter Vulnerability<br /><a href="https://blogs.vmware.com/cloud-foundation/2024/09/17/vmsa-2024-0019-questions-answers/" target="_blank" rel="noreferrer noopener">https://blogs.vmware.com/cloud-foundation/2024/09/17/vmsa-2024-0019-questions-answers/</a><br /> Zero-Click Calendar invite - Critical zero-click vulnerability chain in macOS<br /><a href="https://mikko-kenttala.medium.com/zero-click-calendar-invite-critical-zero-click-vulnerability-chain-in-macos-a7a434fc887b" target="_blank" rel="noreferrer noopener">https://mikko-kenttala.medium.com/zero-click-calendar-invite-critical-zero-click-vulnerability-chain-in-macos-a7a434fc887b</a><br /> Google Adds Latest Post Quantum Encryption Standard to Chrome<br /><a href="https://security.googleblog.com/2024/09/a-new-path-for-kyber-on-web.html" target="_blank" rel="noreferrer noopener">https://security.googleblog.com/2024/09/a-new-path-for-kyber-on-web.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9142.mp3</guid><pubDate>Wed, 18 Sep 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129290/9142.mp3" length="4759005" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>23:59, Time to Exfiltrate!
https://isc.sans.edu/diary/23%3A59%2C%20Time%20to%20Exfiltrate!/31272
 Critical VMWare VCenter Vulnerability
https://blogs.vmware.com/cloud-foundation/2024/09/17/vmsa-2024-0019-questions-answers/
 Zero-Click Calendar invite...</itunes:subtitle><itunes:summary><![CDATA[23:59, Time to Exfiltrate!<br /><a href="https://isc.sans.edu/diary/23%3A59%2C%20Time%20to%20Exfiltrate!/31272" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/23%3A59%2C%20Time%20to%20Exfiltrate!/31272</a><br /> Critical VMWare VCenter Vulnerability<br /><a href="https://blogs.vmware.com/cloud-foundation/2024/09/17/vmsa-2024-0019-questions-answers/" target="_blank" rel="noreferrer noopener">https://blogs.vmware.com/cloud-foundation/2024/09/17/vmsa-2024-0019-questions-answers/</a><br /> Zero-Click Calendar invite - Critical zero-click vulnerability chain in macOS<br /><a href="https://mikko-kenttala.medium.com/zero-click-calendar-invite-critical-zero-click-vulnerability-chain-in-macos-a7a434fc887b" target="_blank" rel="noreferrer noopener">https://mikko-kenttala.medium.com/zero-click-calendar-invite-critical-zero-click-vulnerability-chain-in-macos-a7a434fc887b</a><br /> Google Adds Latest Post Quantum Encryption Standard to Chrome<br /><a href="https://security.googleblog.com/2024/09/a-new-path-for-kyber-on-web.html" target="_blank" rel="noreferrer noopener">https://security.googleblog.com/2024/09/a-new-path-for-kyber-on-web.html</a><br />]]></itunes:summary><itunes:duration>318</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,python; firebase; vmware; vcen,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9142</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, September 18th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-september-18th-2024--62004143</link><description><![CDATA[23:59, Time to Exfiltrate!<br /><a href="https://isc.sans.edu/diary/23%3A59%2C%20Time%20to%20Exfiltrate!/31272" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/23%3A59%2C%20Time%20to%20Exfiltrate!/31272</a><br /> Critical VMWare VCenter Vulnerability<br /><a href="https://blogs.vmware.com/cloud-foundation/2024/09/17/vmsa-2024-0019-questions-answers/" target="_blank" rel="noreferrer noopener">https://blogs.vmware.com/cloud-foundation/2024/09/17/vmsa-2024-0019-questions-answers/</a><br /> Zero-Click Calendar invite - Critical zero-click vulnerability chain in macOS<br /><a href="https://mikko-kenttala.medium.com/zero-click-calendar-invite-critical-zero-click-vulnerability-chain-in-macos-a7a434fc887b" target="_blank" rel="noreferrer noopener">https://mikko-kenttala.medium.com/zero-click-calendar-invite-critical-zero-click-vulnerability-chain-in-macos-a7a434fc887b</a><br /> Google Adds Latest Post Quantum Encryption Standard to Chrome<br /><a href="https://security.googleblog.com/2024/09/a-new-path-for-kyber-on-web.html" target="_blank" rel="noreferrer noopener">https://security.googleblog.com/2024/09/a-new-path-for-kyber-on-web.html</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9142.mp3</guid><pubDate>Wed, 18 Sep 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62004143/9142.mp3" length="4759005" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>23:59, Time to Exfiltrate!
https://isc.sans.edu/diary/23%3A59%2C%20Time%20to%20Exfiltrate!/31272
 Critical VMWare VCenter Vulnerability
https://blogs.vmware.com/cloud-foundation/2024/09/17/vmsa-2024-0019-questions-answers/
 Zero-Click Calendar invite...</itunes:subtitle><itunes:summary><![CDATA[23:59, Time to Exfiltrate!<br /><a href="https://isc.sans.edu/diary/23%3A59%2C%20Time%20to%20Exfiltrate!/31272" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/23%3A59%2C%20Time%20to%20Exfiltrate!/31272</a><br /> Critical VMWare VCenter Vulnerability<br /><a href="https://blogs.vmware.com/cloud-foundation/2024/09/17/vmsa-2024-0019-questions-answers/" target="_blank" rel="noreferrer noopener">https://blogs.vmware.com/cloud-foundation/2024/09/17/vmsa-2024-0019-questions-answers/</a><br /> Zero-Click Calendar invite - Critical zero-click vulnerability chain in macOS<br /><a href="https://mikko-kenttala.medium.com/zero-click-calendar-invite-critical-zero-click-vulnerability-chain-in-macos-a7a434fc887b" target="_blank" rel="noreferrer noopener">https://mikko-kenttala.medium.com/zero-click-calendar-invite-critical-zero-click-vulnerability-chain-in-macos-a7a434fc887b</a><br /> Google Adds Latest Post Quantum Encryption Standard to Chrome<br /><a href="https://security.googleblog.com/2024/09/a-new-path-for-kyber-on-web.html" target="_blank" rel="noreferrer noopener">https://security.googleblog.com/2024/09/a-new-path-for-kyber-on-web.html</a><br />]]></itunes:summary><itunes:duration>318</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,python; firebase; vmware; vcen,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9142</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, September 17th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-september-17th-2024--62129293</link><description><![CDATA[Managing PE Files with Overlays<br /><a href="https://isc.sans.edu/forums/diary/Managing%20PE%20Files%20With%20Overlays/31268/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Managing%20PE%20Files%20With%20Overlays/31268/</a><br /> Apple Updates<br /><a href="https://support.apple.com/en-us/100100" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/100100</a><br /> Ivanti EOL Cloud Service Appliances<br /><a href="https://www.cisa.gov/news-events/alerts/2024/09/13/ivanti-releases-security-update-cloud-services-appliance" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2024/09/13/ivanti-releases-security-update-cloud-services-appliance</a><br /> Microsoft Revises September Update<br /><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-43461" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-43461</a><br /> DLink Vulnerabilities<br /><a href="https://www.twcert.org.tw/en/cp-139-8081-3fb39-2.html" target="_blank" rel="noreferrer noopener">https://www.twcert.org.tw/en/cp-139-8081-3fb39-2.html</a><br /><a href="https://www.twcert.org.tw/en/cp-139-8091-bcd52-2.html" target="_blank" rel="noreferrer noopener">https://www.twcert.org.tw/en/cp-139-8091-bcd52-2.html</a><br /><a href="https://www.twcert.org.tw/en/cp-139-8089-32df6-2.html" target="_blank" rel="noreferrer noopener">https://www.twcert.org.tw/en/cp-139-8089-32df6-2.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9140.mp3</guid><pubDate>Tue, 17 Sep 2024 02:25:18 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129293/9140.mp3" length="4708037" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Managing PE Files with Overlays
https://isc.sans.edu/forums/diary/Managing%20PE%20Files%20With%20Overlays/31268/
 Apple Updates
https://support.apple.com/en-us/100100
 Ivanti EOL Cloud Service Appliances...</itunes:subtitle><itunes:summary><![CDATA[Managing PE Files with Overlays<br /><a href="https://isc.sans.edu/forums/diary/Managing%20PE%20Files%20With%20Overlays/31268/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Managing%20PE%20Files%20With%20Overlays/31268/</a><br /> Apple Updates<br /><a href="https://support.apple.com/en-us/100100" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/100100</a><br /> Ivanti EOL Cloud Service Appliances<br /><a href="https://www.cisa.gov/news-events/alerts/2024/09/13/ivanti-releases-security-update-cloud-services-appliance" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2024/09/13/ivanti-releases-security-update-cloud-services-appliance</a><br /> Microsoft Revises September Update<br /><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-43461" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-43461</a><br /> DLink Vulnerabilities<br /><a href="https://www.twcert.org.tw/en/cp-139-8081-3fb39-2.html" target="_blank" rel="noreferrer noopener">https://www.twcert.org.tw/en/cp-139-8081-3fb39-2.html</a><br /><a href="https://www.twcert.org.tw/en/cp-139-8091-bcd52-2.html" target="_blank" rel="noreferrer noopener">https://www.twcert.org.tw/en/cp-139-8091-bcd52-2.html</a><br /><a href="https://www.twcert.org.tw/en/cp-139-8089-32df6-2.html" target="_blank" rel="noreferrer noopener">https://www.twcert.org.tw/en/cp-139-8089-32df6-2.html</a><br />]]></itunes:summary><itunes:duration>315</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dlink; microsoft; september; m,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9140</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, September 17th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-september-17th-2024--61889871</link><description><![CDATA[Managing PE Files with Overlays<br /><a href="https://isc.sans.edu/forums/diary/Managing%20PE%20Files%20With%20Overlays/31268/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Managing%20PE%20Files%20With%20Overlays/31268/</a><br /> Apple Updates<br /><a href="https://support.apple.com/en-us/100100" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/100100</a><br /> Ivanti EOL Cloud Service Appliances<br /><a href="https://www.cisa.gov/news-events/alerts/2024/09/13/ivanti-releases-security-update-cloud-services-appliance" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2024/09/13/ivanti-releases-security-update-cloud-services-appliance</a><br /> Microsoft Revises September Update<br /><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-43461" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-43461</a><br /> DLink Vulnerabilities<br /><a href="https://www.twcert.org.tw/en/cp-139-8081-3fb39-2.html" target="_blank" rel="noreferrer noopener">https://www.twcert.org.tw/en/cp-139-8081-3fb39-2.html</a><br /><a href="https://www.twcert.org.tw/en/cp-139-8091-bcd52-2.html" target="_blank" rel="noreferrer noopener">https://www.twcert.org.tw/en/cp-139-8091-bcd52-2.html</a><br /><a href="https://www.twcert.org.tw/en/cp-139-8089-32df6-2.html" target="_blank" rel="noreferrer noopener">https://www.twcert.org.tw/en/cp-139-8089-32df6-2.html</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9140.mp3</guid><pubDate>Tue, 17 Sep 2024 02:25:18 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61889871/9140.mp3" length="4708037" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Managing PE Files with Overlays
https://isc.sans.edu/forums/diary/Managing%20PE%20Files%20With%20Overlays/31268/
 Apple Updates
https://support.apple.com/en-us/100100
 Ivanti EOL Cloud Service Appliances...</itunes:subtitle><itunes:summary><![CDATA[Managing PE Files with Overlays<br /><a href="https://isc.sans.edu/forums/diary/Managing%20PE%20Files%20With%20Overlays/31268/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Managing%20PE%20Files%20With%20Overlays/31268/</a><br /> Apple Updates<br /><a href="https://support.apple.com/en-us/100100" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/100100</a><br /> Ivanti EOL Cloud Service Appliances<br /><a href="https://www.cisa.gov/news-events/alerts/2024/09/13/ivanti-releases-security-update-cloud-services-appliance" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2024/09/13/ivanti-releases-security-update-cloud-services-appliance</a><br /> Microsoft Revises September Update<br /><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-43461" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-43461</a><br /> DLink Vulnerabilities<br /><a href="https://www.twcert.org.tw/en/cp-139-8081-3fb39-2.html" target="_blank" rel="noreferrer noopener">https://www.twcert.org.tw/en/cp-139-8081-3fb39-2.html</a><br /><a href="https://www.twcert.org.tw/en/cp-139-8091-bcd52-2.html" target="_blank" rel="noreferrer noopener">https://www.twcert.org.tw/en/cp-139-8091-bcd52-2.html</a><br /><a href="https://www.twcert.org.tw/en/cp-139-8089-32df6-2.html" target="_blank" rel="noreferrer noopener">https://www.twcert.org.tw/en/cp-139-8089-32df6-2.html</a><br />]]></itunes:summary><itunes:duration>315</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dlink; microsoft; september; m,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9140</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, September 16th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-september-16th-2024--62129289</link><description><![CDATA[Finding Honeypot Clusters Using DBSCAN<br /><a href="https://isc.sans.edu/diary/Finding%20Honeypot%20Data%20Clusters%20Using%20DBSCAN%3A%20Part%202/31194" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Finding%20Honeypot%20Data%20Clusters%20Using%20DBSCAN%3A%20Part%202/31194</a><br /> Auto IT Credential Flusher<br /><a href="https://research.openanalysis.net/credflusher/kiosk/stealer/stealc/amadey/autoit/2024/09/11/cred-flusher.html" target="_blank" rel="noreferrer noopener">https://research.openanalysis.net/credflusher/kiosk/stealer/stealc/amadey/autoit/2024/09/11/cred-flusher.html</a><br /> Ivanti Patches<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Service-Appliance-CSA-CVE-2024-8190?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Service-Appliance-CSA-CVE-2024-8190?language=en_US</a><br /><a href="https://www.horizon3.ai/attack-research/attack-blogs/cve-2024-29847-deep-dive-ivanti-endpoint-manager-agentportal-deserialization-of-untrusted-data-remote-code-execution-vulnerability/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/attack-blogs/cve-2024-29847-deep-dive-ivanti-endpoint-manager-agentportal-deserialization-of-untrusted-data-remote-code-execution-vulnerability/</a><br /> File Sender Vulnerability<br /><a href="https://filesender.org/vulnerability-in-filesender-versions-below-2-49-and-3-x-beta/" target="_blank" rel="noreferrer noopener">https://filesender.org/vulnerability-in-filesender-versions-below-2-49-and-3-x-beta/</a><br /> Docker Patches<br /><a href="https://docs.docker.com/desktop/release-notes/#4342" target="_blank" rel="noreferrer noopener">https://docs.docker.com/desktop/release-notes/#4342</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9138.mp3</guid><pubDate>Mon, 16 Sep 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129289/9138.mp3" length="5393040" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Finding Honeypot Clusters Using DBSCAN
https://isc.sans.edu/diary/Finding%20Honeypot%20Data%20Clusters%20Using%20DBSCAN%3A%20Part%202/31194
 Auto IT Credential Flusher...</itunes:subtitle><itunes:summary><![CDATA[Finding Honeypot Clusters Using DBSCAN<br /><a href="https://isc.sans.edu/diary/Finding%20Honeypot%20Data%20Clusters%20Using%20DBSCAN%3A%20Part%202/31194" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Finding%20Honeypot%20Data%20Clusters%20Using%20DBSCAN%3A%20Part%202/31194</a><br /> Auto IT Credential Flusher<br /><a href="https://research.openanalysis.net/credflusher/kiosk/stealer/stealc/amadey/autoit/2024/09/11/cred-flusher.html" target="_blank" rel="noreferrer noopener">https://research.openanalysis.net/credflusher/kiosk/stealer/stealc/amadey/autoit/2024/09/11/cred-flusher.html</a><br /> Ivanti Patches<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Service-Appliance-CSA-CVE-2024-8190?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Service-Appliance-CSA-CVE-2024-8190?language=en_US</a><br /><a href="https://www.horizon3.ai/attack-research/attack-blogs/cve-2024-29847-deep-dive-ivanti-endpoint-manager-agentportal-deserialization-of-untrusted-data-remote-code-execution-vulnerability/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/attack-blogs/cve-2024-29847-deep-dive-ivanti-endpoint-manager-agentportal-deserialization-of-untrusted-data-remote-code-execution-vulnerability/</a><br /> File Sender Vulnerability<br /><a href="https://filesender.org/vulnerability-in-filesender-versions-below-2-49-and-3-x-beta/" target="_blank" rel="noreferrer noopener">https://filesender.org/vulnerability-in-filesender-versions-below-2-49-and-3-x-beta/</a><br /> Docker Patches<br /><a href="https://docs.docker.com/desktop/release-notes/#4342" target="_blank" rel="noreferrer noopener">https://docs.docker.com/desktop/release-notes/#4342</a><br />]]></itunes:summary><itunes:duration>364</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,docker; file sender; ivanti; a,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9138</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, September 16th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-september-16th-2024--61797228</link><description><![CDATA[Finding Honeypot Clusters Using DBSCAN<br /><a href="https://isc.sans.edu/diary/Finding%20Honeypot%20Data%20Clusters%20Using%20DBSCAN%3A%20Part%202/31194" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Finding%20Honeypot%20Data%20Clusters%20Using%20DBSCAN%3A%20Part%202/31194</a><br /> Auto IT Credential Flusher<br /><a href="https://research.openanalysis.net/credflusher/kiosk/stealer/stealc/amadey/autoit/2024/09/11/cred-flusher.html" target="_blank" rel="noreferrer noopener">https://research.openanalysis.net/credflusher/kiosk/stealer/stealc/amadey/autoit/2024/09/11/cred-flusher.html</a><br /> Ivanti Patches<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Service-Appliance-CSA-CVE-2024-8190?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Service-Appliance-CSA-CVE-2024-8190?language=en_US</a><br /><a href="https://www.horizon3.ai/attack-research/attack-blogs/cve-2024-29847-deep-dive-ivanti-endpoint-manager-agentportal-deserialization-of-untrusted-data-remote-code-execution-vulnerability/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/attack-blogs/cve-2024-29847-deep-dive-ivanti-endpoint-manager-agentportal-deserialization-of-untrusted-data-remote-code-execution-vulnerability/</a><br /> File Sender Vulnerability<br /><a href="https://filesender.org/vulnerability-in-filesender-versions-below-2-49-and-3-x-beta/" target="_blank" rel="noreferrer noopener">https://filesender.org/vulnerability-in-filesender-versions-below-2-49-and-3-x-beta/</a><br /> Docker Patches<br /><a href="https://docs.docker.com/desktop/release-notes/#4342" target="_blank" rel="noreferrer noopener">https://docs.docker.com/desktop/release-notes/#4342</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9138.mp3</guid><pubDate>Mon, 16 Sep 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61797228/9138.mp3" length="5393040" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Finding Honeypot Clusters Using DBSCAN
https://isc.sans.edu/diary/Finding%20Honeypot%20Data%20Clusters%20Using%20DBSCAN%3A%20Part%202/31194
 Auto IT Credential Flusher...</itunes:subtitle><itunes:summary><![CDATA[Finding Honeypot Clusters Using DBSCAN<br /><a href="https://isc.sans.edu/diary/Finding%20Honeypot%20Data%20Clusters%20Using%20DBSCAN%3A%20Part%202/31194" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Finding%20Honeypot%20Data%20Clusters%20Using%20DBSCAN%3A%20Part%202/31194</a><br /> Auto IT Credential Flusher<br /><a href="https://research.openanalysis.net/credflusher/kiosk/stealer/stealc/amadey/autoit/2024/09/11/cred-flusher.html" target="_blank" rel="noreferrer noopener">https://research.openanalysis.net/credflusher/kiosk/stealer/stealc/amadey/autoit/2024/09/11/cred-flusher.html</a><br /> Ivanti Patches<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Service-Appliance-CSA-CVE-2024-8190?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Service-Appliance-CSA-CVE-2024-8190?language=en_US</a><br /><a href="https://www.horizon3.ai/attack-research/attack-blogs/cve-2024-29847-deep-dive-ivanti-endpoint-manager-agentportal-deserialization-of-untrusted-data-remote-code-execution-vulnerability/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/attack-blogs/cve-2024-29847-deep-dive-ivanti-endpoint-manager-agentportal-deserialization-of-untrusted-data-remote-code-execution-vulnerability/</a><br /> File Sender Vulnerability<br /><a href="https://filesender.org/vulnerability-in-filesender-versions-below-2-49-and-3-x-beta/" target="_blank" rel="noreferrer noopener">https://filesender.org/vulnerability-in-filesender-versions-below-2-49-and-3-x-beta/</a><br /> Docker Patches<br /><a href="https://docs.docker.com/desktop/release-notes/#4342" target="_blank" rel="noreferrer noopener">https://docs.docker.com/desktop/release-notes/#4342</a><br />]]></itunes:summary><itunes:duration>364</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,docker; file sender; ivanti; a,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9138</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, September 13th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-september-13th-2024--62129302</link><description><![CDATA[Compromise of old hostname .mobi whois server<br /><a href="https://labs.watchtowr.com/we-spent-20-to-achieve-rce-and-accidentally-became-the-admins-of-mobi/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/we-spent-20-to-achieve-rce-and-accidentally-became-the-admins-of-mobi/</a><br /> Microsoft Reconsidering Security Tool API<br /><a href="https://blogs.windows.com/windowsexperience/2024/09/12/taking-steps-that-drive-resiliency-and-security-for-windows-customers/" target="_blank" rel="noreferrer noopener">https://blogs.windows.com/windowsexperience/2024/09/12/taking-steps-that-drive-resiliency-and-security-for-windows-customers/</a><br /> Microsoft implents PQC in SymCrypt<br /><a href="https://techcommunity.microsoft.com/t5/security-compliance-and-identity/microsoft-s-quantum-resistant-cryptography-is-here/ba-p/4238780" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/security-compliance-and-identity/microsoft-s-quantum-resistant-cryptography-is-here/ba-p/4238780</a><br /> GitLab Patch<br /><a href="https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/#execute-environment-stop-actions-as-the-owner-of-the-stop-action-job" target="_blank" rel="noreferrer noopener">https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/#execute-environment-stop-actions-as-the-owner-of-the-stop-action-job</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9136.mp3</guid><pubDate>Fri, 13 Sep 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129302/9136.mp3" length="4685161" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Compromise of old hostname .mobi whois server
https://labs.watchtowr.com/we-spent-20-to-achieve-rce-and-accidentally-became-the-admins-of-mobi/
 Microsoft Reconsidering Security Tool API...</itunes:subtitle><itunes:summary><![CDATA[Compromise of old hostname .mobi whois server<br /><a href="https://labs.watchtowr.com/we-spent-20-to-achieve-rce-and-accidentally-became-the-admins-of-mobi/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/we-spent-20-to-achieve-rce-and-accidentally-became-the-admins-of-mobi/</a><br /> Microsoft Reconsidering Security Tool API<br /><a href="https://blogs.windows.com/windowsexperience/2024/09/12/taking-steps-that-drive-resiliency-and-security-for-windows-customers/" target="_blank" rel="noreferrer noopener">https://blogs.windows.com/windowsexperience/2024/09/12/taking-steps-that-drive-resiliency-and-security-for-windows-customers/</a><br /> Microsoft implents PQC in SymCrypt<br /><a href="https://techcommunity.microsoft.com/t5/security-compliance-and-identity/microsoft-s-quantum-resistant-cryptography-is-here/ba-p/4238780" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/security-compliance-and-identity/microsoft-s-quantum-resistant-cryptography-is-here/ba-p/4238780</a><br /> GitLab Patch<br /><a href="https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/#execute-environment-stop-actions-as-the-owner-of-the-stop-action-job" target="_blank" rel="noreferrer noopener">https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/#execute-environment-stop-actions-as-the-owner-of-the-stop-action-job</a><br />]]></itunes:summary><itunes:duration>313</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,gitlab; microsoft; pqc; symcry,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9136</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, September 13th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-september-13th-2024--61413392</link><description><![CDATA[Compromise of old hostname .mobi whois server<br /><a href="https://labs.watchtowr.com/we-spent-20-to-achieve-rce-and-accidentally-became-the-admins-of-mobi/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/we-spent-20-to-achieve-rce-and-accidentally-became-the-admins-of-mobi/</a><br /> Microsoft Reconsidering Security Tool API<br /><a href="https://blogs.windows.com/windowsexperience/2024/09/12/taking-steps-that-drive-resiliency-and-security-for-windows-customers/" target="_blank" rel="noreferrer noopener">https://blogs.windows.com/windowsexperience/2024/09/12/taking-steps-that-drive-resiliency-and-security-for-windows-customers/</a><br /> Microsoft implents PQC in SymCrypt<br /><a href="https://techcommunity.microsoft.com/t5/security-compliance-and-identity/microsoft-s-quantum-resistant-cryptography-is-here/ba-p/4238780" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/security-compliance-and-identity/microsoft-s-quantum-resistant-cryptography-is-here/ba-p/4238780</a><br /> GitLab Patch<br /><a href="https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/#execute-environment-stop-actions-as-the-owner-of-the-stop-action-job" target="_blank" rel="noreferrer noopener">https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/#execute-environment-stop-actions-as-the-owner-of-the-stop-action-job</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9136.mp3</guid><pubDate>Fri, 13 Sep 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61413392/9136.mp3" length="4685161" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Compromise of old hostname .mobi whois server
https://labs.watchtowr.com/we-spent-20-to-achieve-rce-and-accidentally-became-the-admins-of-mobi/
 Microsoft Reconsidering Security Tool API...</itunes:subtitle><itunes:summary><![CDATA[Compromise of old hostname .mobi whois server<br /><a href="https://labs.watchtowr.com/we-spent-20-to-achieve-rce-and-accidentally-became-the-admins-of-mobi/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/we-spent-20-to-achieve-rce-and-accidentally-became-the-admins-of-mobi/</a><br /> Microsoft Reconsidering Security Tool API<br /><a href="https://blogs.windows.com/windowsexperience/2024/09/12/taking-steps-that-drive-resiliency-and-security-for-windows-customers/" target="_blank" rel="noreferrer noopener">https://blogs.windows.com/windowsexperience/2024/09/12/taking-steps-that-drive-resiliency-and-security-for-windows-customers/</a><br /> Microsoft implents PQC in SymCrypt<br /><a href="https://techcommunity.microsoft.com/t5/security-compliance-and-identity/microsoft-s-quantum-resistant-cryptography-is-here/ba-p/4238780" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/security-compliance-and-identity/microsoft-s-quantum-resistant-cryptography-is-here/ba-p/4238780</a><br /> GitLab Patch<br /><a href="https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/#execute-environment-stop-actions-as-the-owner-of-the-stop-action-job" target="_blank" rel="noreferrer noopener">https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/#execute-environment-stop-actions-as-the-owner-of-the-stop-action-job</a><br />]]></itunes:summary><itunes:duration>313</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,gitlab; microsoft; pqc; symcry,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9136</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, September 11th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-september-11th-2024--62129288</link><description><![CDATA[Microsoft Patches<br /><a href="https://isc.sans.edu/diary/Microsoft%20September%202024%20Patch%20Tuesday/31254" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20September%202024%20Patch%20Tuesday/31254</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> Ivanti Patches<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-EPM-September-2024-for-EPM-2024-and-EPM-2022?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-EPM-September-2024-for-EPM-2024-and-EPM-2022?language=en_US</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9134.mp3</guid><pubDate>Wed, 11 Sep 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129288/9134.mp3" length="5350845" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft Patches
https://isc.sans.edu/diary/Microsoft%20September%202024%20Patch%20Tuesday/31254
 Adobe Patches
https://helpx.adobe.com/security/security-bulletin.html
 Ivanti Patches...</itunes:subtitle><itunes:summary><![CDATA[Microsoft Patches<br /><a href="https://isc.sans.edu/diary/Microsoft%20September%202024%20Patch%20Tuesday/31254" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20September%202024%20Patch%20Tuesday/31254</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> Ivanti Patches<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-EPM-September-2024-for-EPM-2024-and-EPM-2022?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-EPM-September-2024-for-EPM-2024-and-EPM-2022?language=en_US</a><br />]]></itunes:summary><itunes:duration>361</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,ivanti; adobe; microsoft; patc,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9134</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, September 11th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-september-11th-2024--61333044</link><description><![CDATA[Microsoft Patches<br /><a href="https://isc.sans.edu/diary/Microsoft%20September%202024%20Patch%20Tuesday/31254" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20September%202024%20Patch%20Tuesday/31254</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> Ivanti Patches<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-EPM-September-2024-for-EPM-2024-and-EPM-2022?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-EPM-September-2024-for-EPM-2024-and-EPM-2022?language=en_US</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9134.mp3</guid><pubDate>Wed, 11 Sep 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61333044/9134.mp3" length="5350845" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft Patches
https://isc.sans.edu/diary/Microsoft%20September%202024%20Patch%20Tuesday/31254
 Adobe Patches
https://helpx.adobe.com/security/security-bulletin.html
 Ivanti Patches...</itunes:subtitle><itunes:summary><![CDATA[Microsoft Patches<br /><a href="https://isc.sans.edu/diary/Microsoft%20September%202024%20Patch%20Tuesday/31254" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20September%202024%20Patch%20Tuesday/31254</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> Ivanti Patches<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-EPM-September-2024-for-EPM-2024-and-EPM-2022?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-EPM-September-2024-for-EPM-2024-and-EPM-2022?language=en_US</a><br />]]></itunes:summary><itunes:duration>361</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,ivanti; adobe; microsoft; patc,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9134</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, September 10th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-september-10th-2024--62129303</link><description><![CDATA[Critical Loadmaster Security Vulnerability<br /><a href="https://support.kemptechnologies.com/hc/en-us/articles/29196371689613-LoadMaster-Security-Vulnerability-CVE-2024-7591" target="_blank" rel="noreferrer noopener">https://support.kemptechnologies.com/hc/en-us/articles/29196371689613-LoadMaster-Security-Vulnerability-CVE-2024-7591</a><br /> HA Proxy Patch<br /><a href="https://www.mail-archive.com/haproxy%40formilux.org/msg45280.html" target="_blank" rel="noreferrer noopener">https://www.mail-archive.com/haproxy%40formilux.org/msg45280.html</a><br /> Akira Ransomware Campaign Targeting Sonicwall SSLVPN Accounts<br /><a href="https://arcticwolf.com/resources/blog/arctic-wolf-observes-akira-ransomware-campaign-targeting-sonicwall-sslvpn-accounts/" target="_blank" rel="noreferrer noopener">https://arcticwolf.com/resources/blog/arctic-wolf-observes-akira-ransomware-campaign-targeting-sonicwall-sslvpn-accounts/</a><br /> Kibana Deserializatio Vulnerability<br /><a href="https://discuss.elastic.co/t/kibana-8-15-1-security-update-esa-2024-27-esa-2024-28/366119" target="_blank" rel="noreferrer noopener">https://discuss.elastic.co/t/kibana-8-15-1-security-update-esa-2024-27-esa-2024-28/366119</a><br /> Stately Taurus Abuses VSCode<br /><a href="https://unit42.paloaltonetworks.com/stately-taurus-abuses-vscode-southeast-asian-espionage/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/stately-taurus-abuses-vscode-southeast-asian-espionage/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9132.mp3</guid><pubDate>Tue, 10 Sep 2024 03:20:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129303/9132.mp3" length="4072500" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Critical Loadmaster Security Vulnerability
https://support.kemptechnologies.com/hc/en-us/articles/29196371689613-LoadMaster-Security-Vulnerability-CVE-2024-7591
 HA Proxy Patch
https://www.mail-archive.com/haproxy%40formilux.org/msg45280.html
 Akira...</itunes:subtitle><itunes:summary><![CDATA[Critical Loadmaster Security Vulnerability<br /><a href="https://support.kemptechnologies.com/hc/en-us/articles/29196371689613-LoadMaster-Security-Vulnerability-CVE-2024-7591" target="_blank" rel="noreferrer noopener">https://support.kemptechnologies.com/hc/en-us/articles/29196371689613-LoadMaster-Security-Vulnerability-CVE-2024-7591</a><br /> HA Proxy Patch<br /><a href="https://www.mail-archive.com/haproxy%40formilux.org/msg45280.html" target="_blank" rel="noreferrer noopener">https://www.mail-archive.com/haproxy%40formilux.org/msg45280.html</a><br /> Akira Ransomware Campaign Targeting Sonicwall SSLVPN Accounts<br /><a href="https://arcticwolf.com/resources/blog/arctic-wolf-observes-akira-ransomware-campaign-targeting-sonicwall-sslvpn-accounts/" target="_blank" rel="noreferrer noopener">https://arcticwolf.com/resources/blog/arctic-wolf-observes-akira-ransomware-campaign-targeting-sonicwall-sslvpn-accounts/</a><br /> Kibana Deserializatio Vulnerability<br /><a href="https://discuss.elastic.co/t/kibana-8-15-1-security-update-esa-2024-27-esa-2024-28/366119" target="_blank" rel="noreferrer noopener">https://discuss.elastic.co/t/kibana-8-15-1-security-update-esa-2024-27-esa-2024-28/366119</a><br /> Stately Taurus Abuses VSCode<br /><a href="https://unit42.paloaltonetworks.com/stately-taurus-abuses-vscode-southeast-asian-espionage/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/stately-taurus-abuses-vscode-southeast-asian-espionage/</a><br />]]></itunes:summary><itunes:duration>269</itunes:duration><itunes:keywords>business,china; taurus; vscode; kibana;,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9132</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, September 10th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-september-10th-2024--61317872</link><description><![CDATA[Critical Loadmaster Security Vulnerability<br /><a href="https://support.kemptechnologies.com/hc/en-us/articles/29196371689613-LoadMaster-Security-Vulnerability-CVE-2024-7591" target="_blank" rel="noreferrer noopener">https://support.kemptechnologies.com/hc/en-us/articles/29196371689613-LoadMaster-Security-Vulnerability-CVE-2024-7591</a><br /> HA Proxy Patch<br /><a href="https://www.mail-archive.com/haproxy%40formilux.org/msg45280.html" target="_blank" rel="noreferrer noopener">https://www.mail-archive.com/haproxy%40formilux.org/msg45280.html</a><br /> Akira Ransomware Campaign Targeting Sonicwall SSLVPN Accounts<br /><a href="https://arcticwolf.com/resources/blog/arctic-wolf-observes-akira-ransomware-campaign-targeting-sonicwall-sslvpn-accounts/" target="_blank" rel="noreferrer noopener">https://arcticwolf.com/resources/blog/arctic-wolf-observes-akira-ransomware-campaign-targeting-sonicwall-sslvpn-accounts/</a><br /> Kibana Deserializatio Vulnerability<br /><a href="https://discuss.elastic.co/t/kibana-8-15-1-security-update-esa-2024-27-esa-2024-28/366119" target="_blank" rel="noreferrer noopener">https://discuss.elastic.co/t/kibana-8-15-1-security-update-esa-2024-27-esa-2024-28/366119</a><br /> Stately Taurus Abuses VSCode<br /><a href="https://unit42.paloaltonetworks.com/stately-taurus-abuses-vscode-southeast-asian-espionage/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/stately-taurus-abuses-vscode-southeast-asian-espionage/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9132.mp3</guid><pubDate>Tue, 10 Sep 2024 03:20:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61317872/9132.mp3" length="4072500" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Critical Loadmaster Security Vulnerability
https://support.kemptechnologies.com/hc/en-us/articles/29196371689613-LoadMaster-Security-Vulnerability-CVE-2024-7591
 HA Proxy Patch
https://www.mail-archive.com/haproxy%40formilux.org/msg45280.html
 Akira...</itunes:subtitle><itunes:summary><![CDATA[Critical Loadmaster Security Vulnerability<br /><a href="https://support.kemptechnologies.com/hc/en-us/articles/29196371689613-LoadMaster-Security-Vulnerability-CVE-2024-7591" target="_blank" rel="noreferrer noopener">https://support.kemptechnologies.com/hc/en-us/articles/29196371689613-LoadMaster-Security-Vulnerability-CVE-2024-7591</a><br /> HA Proxy Patch<br /><a href="https://www.mail-archive.com/haproxy%40formilux.org/msg45280.html" target="_blank" rel="noreferrer noopener">https://www.mail-archive.com/haproxy%40formilux.org/msg45280.html</a><br /> Akira Ransomware Campaign Targeting Sonicwall SSLVPN Accounts<br /><a href="https://arcticwolf.com/resources/blog/arctic-wolf-observes-akira-ransomware-campaign-targeting-sonicwall-sslvpn-accounts/" target="_blank" rel="noreferrer noopener">https://arcticwolf.com/resources/blog/arctic-wolf-observes-akira-ransomware-campaign-targeting-sonicwall-sslvpn-accounts/</a><br /> Kibana Deserializatio Vulnerability<br /><a href="https://discuss.elastic.co/t/kibana-8-15-1-security-update-esa-2024-27-esa-2024-28/366119" target="_blank" rel="noreferrer noopener">https://discuss.elastic.co/t/kibana-8-15-1-security-update-esa-2024-27-esa-2024-28/366119</a><br /> Stately Taurus Abuses VSCode<br /><a href="https://unit42.paloaltonetworks.com/stately-taurus-abuses-vscode-southeast-asian-espionage/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/stately-taurus-abuses-vscode-southeast-asian-espionage/</a><br />]]></itunes:summary><itunes:duration>269</itunes:duration><itunes:keywords>business,china; taurus; vscode; kibana;,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9132</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, September 9th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-september-9th-2024--62129295</link><description><![CDATA[Password Cracking Energy: More Details<br /><a href="https://isc.sans.edu/diary/Password%20Cracking%20%26%20Energy%3A%20More%20Dedails/31242" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Password%20Cracking%20%26%20Energy%3A%20More%20Dedails/31242</a><br /> Python Notpad ++<br /><a href="https://isc.sans.edu/diary/Python%20%26%20Notepad%2B%2B/31240" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Python%20%26%20Notepad%2B%2B/31240</a><br /> Fake LinkedIn Job Ads<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/examining-web3-heists/" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/examining-web3-heists/</a><br /> Android Crypto Passphrase Stealer with OCR<br /><a href="https://www.mcafee.com/blogs/other-blogs/mcafee-labs/new-android-spyagent-campaign-steals-crypto-credentials-via-image-recognition/" target="_blank" rel="noreferrer noopener">https://www.mcafee.com/blogs/other-blogs/mcafee-labs/new-android-spyagent-campaign-steals-crypto-credentials-via-image-recognition/</a><br /> Sextortion Scam Now use Your Chating Spouses Name as a Lure<br /><a href="https://www.bleepingcomputer.com/news/security/sextortion-scam-now-use-your-cheating-spouses-name-as-a-lure/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/sextortion-scam-now-use-your-cheating-spouses-name-as-a-lure/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9130.mp3</guid><pubDate>Mon, 09 Sep 2024 02:50:06 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129295/9130.mp3" length="5565193" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Password Cracking Energy: More Details
https://isc.sans.edu/diary/Password%20Cracking%20%26%20Energy%3A%20More%20Dedails/31242
 Python Notpad ++
https://isc.sans.edu/diary/Python%20%26%20Notepad%2B%2B/31240
 Fake LinkedIn Job Ads...</itunes:subtitle><itunes:summary><![CDATA[Password Cracking Energy: More Details<br /><a href="https://isc.sans.edu/diary/Password%20Cracking%20%26%20Energy%3A%20More%20Dedails/31242" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Password%20Cracking%20%26%20Energy%3A%20More%20Dedails/31242</a><br /> Python Notpad ++<br /><a href="https://isc.sans.edu/diary/Python%20%26%20Notepad%2B%2B/31240" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Python%20%26%20Notepad%2B%2B/31240</a><br /> Fake LinkedIn Job Ads<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/examining-web3-heists/" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/examining-web3-heists/</a><br /> Android Crypto Passphrase Stealer with OCR<br /><a href="https://www.mcafee.com/blogs/other-blogs/mcafee-labs/new-android-spyagent-campaign-steals-crypto-credentials-via-image-recognition/" target="_blank" rel="noreferrer noopener">https://www.mcafee.com/blogs/other-blogs/mcafee-labs/new-android-spyagent-campaign-steals-crypto-credentials-via-image-recognition/</a><br /> Sextortion Scam Now use Your Chating Spouses Name as a Lure<br /><a href="https://www.bleepingcomputer.com/news/security/sextortion-scam-now-use-your-cheating-spouses-name-as-a-lure/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/sextortion-scam-now-use-your-cheating-spouses-name-as-a-lure/</a><br />]]></itunes:summary><itunes:duration>376</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,sextortion; spouse; android; o</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9130</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, September 9th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-september-9th-2024--61306924</link><description><![CDATA[Password Cracking Energy: More Details<br /><a href="https://isc.sans.edu/diary/Password%20Cracking%20%26%20Energy%3A%20More%20Dedails/31242" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Password%20Cracking%20%26%20Energy%3A%20More%20Dedails/31242</a><br /> Python Notpad ++<br /><a href="https://isc.sans.edu/diary/Python%20%26%20Notepad%2B%2B/31240" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Python%20%26%20Notepad%2B%2B/31240</a><br /> Fake LinkedIn Job Ads<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/examining-web3-heists/" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/examining-web3-heists/</a><br /> Android Crypto Passphrase Stealer with OCR<br /><a href="https://www.mcafee.com/blogs/other-blogs/mcafee-labs/new-android-spyagent-campaign-steals-crypto-credentials-via-image-recognition/" target="_blank" rel="noreferrer noopener">https://www.mcafee.com/blogs/other-blogs/mcafee-labs/new-android-spyagent-campaign-steals-crypto-credentials-via-image-recognition/</a><br /> Sextortion Scam Now use Your Chating Spouses Name as a Lure<br /><a href="https://www.bleepingcomputer.com/news/security/sextortion-scam-now-use-your-cheating-spouses-name-as-a-lure/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/sextortion-scam-now-use-your-cheating-spouses-name-as-a-lure/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9130.mp3</guid><pubDate>Mon, 09 Sep 2024 02:50:06 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61306924/9130.mp3" length="5565193" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Password Cracking Energy: More Details
https://isc.sans.edu/diary/Password%20Cracking%20%26%20Energy%3A%20More%20Dedails/31242
 Python Notpad ++
https://isc.sans.edu/diary/Python%20%26%20Notepad%2B%2B/31240
 Fake LinkedIn Job Ads...</itunes:subtitle><itunes:summary><![CDATA[Password Cracking Energy: More Details<br /><a href="https://isc.sans.edu/diary/Password%20Cracking%20%26%20Energy%3A%20More%20Dedails/31242" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Password%20Cracking%20%26%20Energy%3A%20More%20Dedails/31242</a><br /> Python Notpad ++<br /><a href="https://isc.sans.edu/diary/Python%20%26%20Notepad%2B%2B/31240" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Python%20%26%20Notepad%2B%2B/31240</a><br /> Fake LinkedIn Job Ads<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/examining-web3-heists/" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/examining-web3-heists/</a><br /> Android Crypto Passphrase Stealer with OCR<br /><a href="https://www.mcafee.com/blogs/other-blogs/mcafee-labs/new-android-spyagent-campaign-steals-crypto-credentials-via-image-recognition/" target="_blank" rel="noreferrer noopener">https://www.mcafee.com/blogs/other-blogs/mcafee-labs/new-android-spyagent-campaign-steals-crypto-credentials-via-image-recognition/</a><br /> Sextortion Scam Now use Your Chating Spouses Name as a Lure<br /><a href="https://www.bleepingcomputer.com/news/security/sextortion-scam-now-use-your-cheating-spouses-name-as-a-lure/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/sextortion-scam-now-use-your-cheating-spouses-name-as-a-lure/</a><br />]]></itunes:summary><itunes:duration>376</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,sextortion; spouse; android; o</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9130</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, September 6th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-september-6th-2024--62129318</link><description><![CDATA[Enrichment Data: Keeping it Fresh<br /><a href="https://isc.sans.edu/diary/Enrichment%20Data%3A%20Keeping%20it%20Fresh/31236" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Enrichment%20Data%3A%20Keeping%20it%20Fresh/31236</a><br /> Veeam Update<br /><a href="https://www.veeam.com/kb4649" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4649</a><br /> New OFBiz Vulnerabilities<br /><a href="https://www.rapid7.com/blog/post/2024/09/05/cve-2024-45195-apache-ofbiz-unauthenticated-remote-code-execution-fixed/" target="_blank" rel="noreferrer noopener">https://www.rapid7.com/blog/post/2024/09/05/cve-2024-45195-apache-ofbiz-unauthenticated-remote-code-execution-fixed/</a><br /> Cisco Smart License Manager Patches<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cslu-7gHMzWmw" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cslu-7gHMzWmw</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9128.mp3</guid><pubDate>Fri, 06 Sep 2024 02:25:06 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129318/9128.mp3" length="5402384" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Enrichment Data: Keeping it Fresh
https://isc.sans.edu/diary/Enrichment%20Data%3A%20Keeping%20it%20Fresh/31236
 Veeam Update
https://www.veeam.com/kb4649
 New OFBiz Vulnerabilities...</itunes:subtitle><itunes:summary><![CDATA[Enrichment Data: Keeping it Fresh<br /><a href="https://isc.sans.edu/diary/Enrichment%20Data%3A%20Keeping%20it%20Fresh/31236" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Enrichment%20Data%3A%20Keeping%20it%20Fresh/31236</a><br /> Veeam Update<br /><a href="https://www.veeam.com/kb4649" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4649</a><br /> New OFBiz Vulnerabilities<br /><a href="https://www.rapid7.com/blog/post/2024/09/05/cve-2024-45195-apache-ofbiz-unauthenticated-remote-code-execution-fixed/" target="_blank" rel="noreferrer noopener">https://www.rapid7.com/blog/post/2024/09/05/cve-2024-45195-apache-ofbiz-unauthenticated-remote-code-execution-fixed/</a><br /> Cisco Smart License Manager Patches<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cslu-7gHMzWmw" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cslu-7gHMzWmw</a><br />]]></itunes:summary><itunes:duration>364</itunes:duration><itunes:keywords>business,cisco; ofbiz; veeam; enrichmen,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9128</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, September 6th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-september-6th-2024--61279574</link><description><![CDATA[Enrichment Data: Keeping it Fresh<br /><a href="https://isc.sans.edu/diary/Enrichment%20Data%3A%20Keeping%20it%20Fresh/31236" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Enrichment%20Data%3A%20Keeping%20it%20Fresh/31236</a><br /> Veeam Update<br /><a href="https://www.veeam.com/kb4649" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4649</a><br /> New OFBiz Vulnerabilities<br /><a href="https://www.rapid7.com/blog/post/2024/09/05/cve-2024-45195-apache-ofbiz-unauthenticated-remote-code-execution-fixed/" target="_blank" rel="noreferrer noopener">https://www.rapid7.com/blog/post/2024/09/05/cve-2024-45195-apache-ofbiz-unauthenticated-remote-code-execution-fixed/</a><br /> Cisco Smart License Manager Patches<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cslu-7gHMzWmw" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cslu-7gHMzWmw</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9128.mp3</guid><pubDate>Fri, 06 Sep 2024 02:25:06 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61279574/9128.mp3" length="5402384" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Enrichment Data: Keeping it Fresh
https://isc.sans.edu/diary/Enrichment%20Data%3A%20Keeping%20it%20Fresh/31236
 Veeam Update
https://www.veeam.com/kb4649
 New OFBiz Vulnerabilities...</itunes:subtitle><itunes:summary><![CDATA[Enrichment Data: Keeping it Fresh<br /><a href="https://isc.sans.edu/diary/Enrichment%20Data%3A%20Keeping%20it%20Fresh/31236" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Enrichment%20Data%3A%20Keeping%20it%20Fresh/31236</a><br /> Veeam Update<br /><a href="https://www.veeam.com/kb4649" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4649</a><br /> New OFBiz Vulnerabilities<br /><a href="https://www.rapid7.com/blog/post/2024/09/05/cve-2024-45195-apache-ofbiz-unauthenticated-remote-code-execution-fixed/" target="_blank" rel="noreferrer noopener">https://www.rapid7.com/blog/post/2024/09/05/cve-2024-45195-apache-ofbiz-unauthenticated-remote-code-execution-fixed/</a><br /> Cisco Smart License Manager Patches<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cslu-7gHMzWmw" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cslu-7gHMzWmw</a><br />]]></itunes:summary><itunes:duration>364</itunes:duration><itunes:keywords>business,cisco; ofbiz; veeam; enrichmen,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9128</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, September 5th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-september-5th-2024--62129300</link><description><![CDATA[Scans for Moodle Learning Platform Following Recent Update<br /><a href="https://isc.sans.edu/diary/Scans+for+Moodle+Learning+Platform+Following+Recent+Update/31230" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans+for+Moodle+Learning+Platform+Following+Recent+Update/31230</a><br /> PyPi Rivival HiJack<br /><a href="https://jfrog.com/blog/revival-hijack-pypi-hijack-technique-exploited-22k-packages-at-risk/" target="_blank" rel="noreferrer noopener">https://jfrog.com/blog/revival-hijack-pypi-hijack-technique-exploited-22k-packages-at-risk/</a><br /> Android Updates<br /><a href="https://source.android.com/docs/security/bulletin/2024-09-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2024-09-01</a><br /> Mediatec WAPPD PoC Exploit<br /><a href="https://blog.coffinsec.com/0day/2024/08/30/exploiting-CVE-2024-20017-four-different-ways.html#wrapping-up" target="_blank" rel="noreferrer noopener">https://blog.coffinsec.com/0day/2024/08/30/exploiting-CVE-2024-20017-four-different-ways.html#wrapping-up</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9126.mp3</guid><pubDate>Thu, 05 Sep 2024 03:20:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129300/9126.mp3" length="6053857" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Scans for Moodle Learning Platform Following Recent Update
https://isc.sans.edu/diary/Scans+for+Moodle+Learning+Platform+Following+Recent+Update/31230
 PyPi Rivival HiJack...</itunes:subtitle><itunes:summary><![CDATA[Scans for Moodle Learning Platform Following Recent Update<br /><a href="https://isc.sans.edu/diary/Scans+for+Moodle+Learning+Platform+Following+Recent+Update/31230" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans+for+Moodle+Learning+Platform+Following+Recent+Update/31230</a><br /> PyPi Rivival HiJack<br /><a href="https://jfrog.com/blog/revival-hijack-pypi-hijack-technique-exploited-22k-packages-at-risk/" target="_blank" rel="noreferrer noopener">https://jfrog.com/blog/revival-hijack-pypi-hijack-technique-exploited-22k-packages-at-risk/</a><br /> Android Updates<br /><a href="https://source.android.com/docs/security/bulletin/2024-09-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2024-09-01</a><br /> Mediatec WAPPD PoC Exploit<br /><a href="https://blog.coffinsec.com/0day/2024/08/30/exploiting-CVE-2024-20017-four-different-ways.html#wrapping-up" target="_blank" rel="noreferrer noopener">https://blog.coffinsec.com/0day/2024/08/30/exploiting-CVE-2024-20017-four-different-ways.html#wrapping-up</a><br />]]></itunes:summary><itunes:duration>411</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,mediatec; android; pypi; moodl,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9126</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, September 5th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-september-5th-2024--61269308</link><description><![CDATA[Scans for Moodle Learning Platform Following Recent Update<br /><a href="https://isc.sans.edu/diary/Scans+for+Moodle+Learning+Platform+Following+Recent+Update/31230" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans+for+Moodle+Learning+Platform+Following+Recent+Update/31230</a><br /> PyPi Rivival HiJack<br /><a href="https://jfrog.com/blog/revival-hijack-pypi-hijack-technique-exploited-22k-packages-at-risk/" target="_blank" rel="noreferrer noopener">https://jfrog.com/blog/revival-hijack-pypi-hijack-technique-exploited-22k-packages-at-risk/</a><br /> Android Updates<br /><a href="https://source.android.com/docs/security/bulletin/2024-09-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2024-09-01</a><br /> Mediatec WAPPD PoC Exploit<br /><a href="https://blog.coffinsec.com/0day/2024/08/30/exploiting-CVE-2024-20017-four-different-ways.html#wrapping-up" target="_blank" rel="noreferrer noopener">https://blog.coffinsec.com/0day/2024/08/30/exploiting-CVE-2024-20017-four-different-ways.html#wrapping-up</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9126.mp3</guid><pubDate>Thu, 05 Sep 2024 03:20:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61269308/9126.mp3" length="6053857" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Scans for Moodle Learning Platform Following Recent Update
https://isc.sans.edu/diary/Scans+for+Moodle+Learning+Platform+Following+Recent+Update/31230
 PyPi Rivival HiJack...</itunes:subtitle><itunes:summary><![CDATA[Scans for Moodle Learning Platform Following Recent Update<br /><a href="https://isc.sans.edu/diary/Scans+for+Moodle+Learning+Platform+Following+Recent+Update/31230" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans+for+Moodle+Learning+Platform+Following+Recent+Update/31230</a><br /> PyPi Rivival HiJack<br /><a href="https://jfrog.com/blog/revival-hijack-pypi-hijack-technique-exploited-22k-packages-at-risk/" target="_blank" rel="noreferrer noopener">https://jfrog.com/blog/revival-hijack-pypi-hijack-technique-exploited-22k-packages-at-risk/</a><br /> Android Updates<br /><a href="https://source.android.com/docs/security/bulletin/2024-09-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2024-09-01</a><br /> Mediatec WAPPD PoC Exploit<br /><a href="https://blog.coffinsec.com/0day/2024/08/30/exploiting-CVE-2024-20017-four-different-ways.html#wrapping-up" target="_blank" rel="noreferrer noopener">https://blog.coffinsec.com/0day/2024/08/30/exploiting-CVE-2024-20017-four-different-ways.html#wrapping-up</a><br />]]></itunes:summary><itunes:duration>411</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,mediatec; android; pypi; moodl,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9126</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, September 4th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-september-4th-2024--62129310</link><description><![CDATA[Protected OOXML Text Documents<br /><a href="https://isc.sans.edu/diary/Protected%20OOXML%20Text%20Documents/31078" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Protected%20OOXML%20Text%20Documents/31078</a><br /> Sextortion E-Mails with Photos<br /><a href="https://krebsonsecurity.com/2024/09/sextortion-scams-now-include-photos-of-your-home/" target="_blank" rel="noreferrer noopener">https://krebsonsecurity.com/2024/09/sextortion-scams-now-include-photos-of-your-home/</a><br /> Zyxel OS Command Injection Vulnerability<br /><a href="https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-os-command-injection-vulnerability-in-aps-and-security-router-devices-09-03-2024" target="_blank" rel="noreferrer noopener">https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-os-command-injection-vulnerability-in-aps-and-security-router-devices-09-03-2024</a><br /> D-Link DIR-846W Unpatched RCE Vulnerabilities <br /><a href="https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10411" target="_blank" rel="noreferrer noopener">https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10411</a><br /> VMWare Priviledge Escalation Vulnerability CVe-2024-38811<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24939" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24939</a><br /> YubiKey Sidechannel Attack<br /><a href="https://ninjalab.io/wp-content/uploads/2024/09/20240903_eucleak.pdf" target="_blank" rel="noreferrer noopener">https://ninjalab.io/wp-content/uploads/2024/09/20240903_eucleak.pdf</a><br /><a href="https://www.yubico.com/support/security-advisories/ysa-2024-03/" target="_blank" rel="noreferrer noopener">https://www.yubico.com/support/security-advisories/ysa-2024-03/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9124.mp3</guid><pubDate>Wed, 04 Sep 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129310/9124.mp3" length="5944953" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Protected OOXML Text Documents
https://isc.sans.edu/diary/Protected%20OOXML%20Text%20Documents/31078
 Sextortion E-Mails with Photos
https://krebsonsecurity.com/2024/09/sextortion-scams-now-include-photos-of-your-home/
 Zyxel OS Command Injection...</itunes:subtitle><itunes:summary><![CDATA[Protected OOXML Text Documents<br /><a href="https://isc.sans.edu/diary/Protected%20OOXML%20Text%20Documents/31078" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Protected%20OOXML%20Text%20Documents/31078</a><br /> Sextortion E-Mails with Photos<br /><a href="https://krebsonsecurity.com/2024/09/sextortion-scams-now-include-photos-of-your-home/" target="_blank" rel="noreferrer noopener">https://krebsonsecurity.com/2024/09/sextortion-scams-now-include-photos-of-your-home/</a><br /> Zyxel OS Command Injection Vulnerability<br /><a href="https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-os-command-injection-vulnerability-in-aps-and-security-router-devices-09-03-2024" target="_blank" rel="noreferrer noopener">https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-os-command-injection-vulnerability-in-aps-and-security-router-devices-09-03-2024</a><br /> D-Link DIR-846W Unpatched RCE Vulnerabilities <br /><a href="https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10411" target="_blank" rel="noreferrer noopener">https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10411</a><br /> VMWare Priviledge Escalation Vulnerability CVe-2024-38811<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24939" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24939</a><br /> YubiKey Sidechannel Attack<br /><a href="https://ninjalab.io/wp-content/uploads/2024/09/20240903_eucleak.pdf" target="_blank" rel="noreferrer noopener">https://ninjalab.io/wp-content/uploads/2024/09/20240903_eucleak.pdf</a><br /><a href="https://www.yubico.com/support/security-advisories/ysa-2024-03/" target="_blank" rel="noreferrer noopener">https://www.yubico.com/support/security-advisories/ysa-2024-03/</a><br />]]></itunes:summary><itunes:duration>403</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,yubikey; vmware; fusion; d-lin</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9124</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, September 4th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-september-4th-2024--61258004</link><description><![CDATA[Protected OOXML Text Documents<br /><a href="https://isc.sans.edu/diary/Protected%20OOXML%20Text%20Documents/31078" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Protected%20OOXML%20Text%20Documents/31078</a><br /> Sextortion E-Mails with Photos<br /><a href="https://krebsonsecurity.com/2024/09/sextortion-scams-now-include-photos-of-your-home/" target="_blank" rel="noreferrer noopener">https://krebsonsecurity.com/2024/09/sextortion-scams-now-include-photos-of-your-home/</a><br /> Zyxel OS Command Injection Vulnerability<br /><a href="https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-os-command-injection-vulnerability-in-aps-and-security-router-devices-09-03-2024" target="_blank" rel="noreferrer noopener">https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-os-command-injection-vulnerability-in-aps-and-security-router-devices-09-03-2024</a><br /> D-Link DIR-846W Unpatched RCE Vulnerabilities <br /><a href="https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10411" target="_blank" rel="noreferrer noopener">https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10411</a><br /> VMWare Priviledge Escalation Vulnerability CVe-2024-38811<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24939" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24939</a><br /> YubiKey Sidechannel Attack<br /><a href="https://ninjalab.io/wp-content/uploads/2024/09/20240903_eucleak.pdf" target="_blank" rel="noreferrer noopener">https://ninjalab.io/wp-content/uploads/2024/09/20240903_eucleak.pdf</a><br /><a href="https://www.yubico.com/support/security-advisories/ysa-2024-03/" target="_blank" rel="noreferrer noopener">https://www.yubico.com/support/security-advisories/ysa-2024-03/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9124.mp3</guid><pubDate>Wed, 04 Sep 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61258004/9124.mp3" length="5944953" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Protected OOXML Text Documents
https://isc.sans.edu/diary/Protected%20OOXML%20Text%20Documents/31078
 Sextortion E-Mails with Photos
https://krebsonsecurity.com/2024/09/sextortion-scams-now-include-photos-of-your-home/
 Zyxel OS Command Injection...</itunes:subtitle><itunes:summary><![CDATA[Protected OOXML Text Documents<br /><a href="https://isc.sans.edu/diary/Protected%20OOXML%20Text%20Documents/31078" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Protected%20OOXML%20Text%20Documents/31078</a><br /> Sextortion E-Mails with Photos<br /><a href="https://krebsonsecurity.com/2024/09/sextortion-scams-now-include-photos-of-your-home/" target="_blank" rel="noreferrer noopener">https://krebsonsecurity.com/2024/09/sextortion-scams-now-include-photos-of-your-home/</a><br /> Zyxel OS Command Injection Vulnerability<br /><a href="https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-os-command-injection-vulnerability-in-aps-and-security-router-devices-09-03-2024" target="_blank" rel="noreferrer noopener">https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-os-command-injection-vulnerability-in-aps-and-security-router-devices-09-03-2024</a><br /> D-Link DIR-846W Unpatched RCE Vulnerabilities <br /><a href="https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10411" target="_blank" rel="noreferrer noopener">https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10411</a><br /> VMWare Priviledge Escalation Vulnerability CVe-2024-38811<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24939" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24939</a><br /> YubiKey Sidechannel Attack<br /><a href="https://ninjalab.io/wp-content/uploads/2024/09/20240903_eucleak.pdf" target="_blank" rel="noreferrer noopener">https://ninjalab.io/wp-content/uploads/2024/09/20240903_eucleak.pdf</a><br /><a href="https://www.yubico.com/support/security-advisories/ysa-2024-03/" target="_blank" rel="noreferrer noopener">https://www.yubico.com/support/security-advisories/ysa-2024-03/</a><br />]]></itunes:summary><itunes:duration>403</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,yubikey; vmware; fusion; d-lin</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9124</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, September 3rd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-september-3rd-2024--62129324</link><description><![CDATA[Wireshark 4.4: Converting Display Filters to BPF Capture Filters<br /><a href="https://isc.sans.edu/diary/Wireshark+44+Converting+Display+Filters+to+BPF+Capture+Filters/31224" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Wireshark+44+Converting+Display+Filters+to+BPF+Capture+Filters/31224</a><br /> GitHub Comments Used to Spread Malware<br /><a href="https://www.reddit.com/r/Malware/comments/1f2n1h4/comment/lkbi5gi/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/Malware/comments/1f2n1h4/comment/lkbi5gi/</a><br /> Voldemort Malware Curses Orgs Using Global Tax Authorities<br /><a href="https://www.darkreading.com/threat-intelligence/voldemort-malware-curses-orgs-global-tax-authorities" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/threat-intelligence/voldemort-malware-curses-orgs-global-tax-authorities</a><br /> Analysis of CVE-2024-43044 From file read to RCE in Jenkins through agents<br /><a href="https://blog.convisoappsec.com/en/analysis-of-cve-2024-43044/" target="_blank" rel="noreferrer noopener">https://blog.convisoappsec.com/en/analysis-of-cve-2024-43044/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9122.mp3</guid><pubDate>Tue, 03 Sep 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129324/9122.mp3" length="5079017" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Wireshark 4.4: Converting Display Filters to BPF Capture Filters
https://isc.sans.edu/diary/Wireshark+44+Converting+Display+Filters+to+BPF+Capture+Filters/31224
 GitHub Comments Used to Spread Malware...</itunes:subtitle><itunes:summary><![CDATA[Wireshark 4.4: Converting Display Filters to BPF Capture Filters<br /><a href="https://isc.sans.edu/diary/Wireshark+44+Converting+Display+Filters+to+BPF+Capture+Filters/31224" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Wireshark+44+Converting+Display+Filters+to+BPF+Capture+Filters/31224</a><br /> GitHub Comments Used to Spread Malware<br /><a href="https://www.reddit.com/r/Malware/comments/1f2n1h4/comment/lkbi5gi/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/Malware/comments/1f2n1h4/comment/lkbi5gi/</a><br /> Voldemort Malware Curses Orgs Using Global Tax Authorities<br /><a href="https://www.darkreading.com/threat-intelligence/voldemort-malware-curses-orgs-global-tax-authorities" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/threat-intelligence/voldemort-malware-curses-orgs-global-tax-authorities</a><br /> Analysis of CVE-2024-43044 From file read to RCE in Jenkins through agents<br /><a href="https://blog.convisoappsec.com/en/analysis-of-cve-2024-43044/" target="_blank" rel="noreferrer noopener">https://blog.convisoappsec.com/en/analysis-of-cve-2024-43044/</a><br />]]></itunes:summary><itunes:duration>341</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,jenkins; volemort; google shee,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9122</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, September 3rd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-september-3rd-2024--61246943</link><description><![CDATA[Wireshark 4.4: Converting Display Filters to BPF Capture Filters<br /><a href="https://isc.sans.edu/diary/Wireshark+44+Converting+Display+Filters+to+BPF+Capture+Filters/31224" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Wireshark+44+Converting+Display+Filters+to+BPF+Capture+Filters/31224</a><br /> GitHub Comments Used to Spread Malware<br /><a href="https://www.reddit.com/r/Malware/comments/1f2n1h4/comment/lkbi5gi/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/Malware/comments/1f2n1h4/comment/lkbi5gi/</a><br /> Voldemort Malware Curses Orgs Using Global Tax Authorities<br /><a href="https://www.darkreading.com/threat-intelligence/voldemort-malware-curses-orgs-global-tax-authorities" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/threat-intelligence/voldemort-malware-curses-orgs-global-tax-authorities</a><br /> Analysis of CVE-2024-43044 From file read to RCE in Jenkins through agents<br /><a href="https://blog.convisoappsec.com/en/analysis-of-cve-2024-43044/" target="_blank" rel="noreferrer noopener">https://blog.convisoappsec.com/en/analysis-of-cve-2024-43044/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9122.mp3</guid><pubDate>Tue, 03 Sep 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61246943/9122.mp3" length="5079017" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Wireshark 4.4: Converting Display Filters to BPF Capture Filters
https://isc.sans.edu/diary/Wireshark+44+Converting+Display+Filters+to+BPF+Capture+Filters/31224
 GitHub Comments Used to Spread Malware...</itunes:subtitle><itunes:summary><![CDATA[Wireshark 4.4: Converting Display Filters to BPF Capture Filters<br /><a href="https://isc.sans.edu/diary/Wireshark+44+Converting+Display+Filters+to+BPF+Capture+Filters/31224" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Wireshark+44+Converting+Display+Filters+to+BPF+Capture+Filters/31224</a><br /> GitHub Comments Used to Spread Malware<br /><a href="https://www.reddit.com/r/Malware/comments/1f2n1h4/comment/lkbi5gi/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/Malware/comments/1f2n1h4/comment/lkbi5gi/</a><br /> Voldemort Malware Curses Orgs Using Global Tax Authorities<br /><a href="https://www.darkreading.com/threat-intelligence/voldemort-malware-curses-orgs-global-tax-authorities" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/threat-intelligence/voldemort-malware-curses-orgs-global-tax-authorities</a><br /> Analysis of CVE-2024-43044 From file read to RCE in Jenkins through agents<br /><a href="https://blog.convisoappsec.com/en/analysis-of-cve-2024-43044/" target="_blank" rel="noreferrer noopener">https://blog.convisoappsec.com/en/analysis-of-cve-2024-43044/</a><br />]]></itunes:summary><itunes:duration>341</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,jenkins; volemort; google shee,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9122</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, August 30th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-august-30th-2024--62129298</link><description><![CDATA[Live Patching DLLs with Python<br /><a href="https://isc.sans.edu/diary/Live%20Patching%20DLLs%20with%20Python/31218" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Live%20Patching%20DLLs%20with%20Python/31218</a><br /> Global Protect Phishing<br /><a href="https://www.trendmicro.com/en_us/research/24/h/threat-actors-target-middle-east-using-fake-tool.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_us/research/24/h/threat-actors-target-middle-east-using-fake-tool.html</a><br /> BlackByte Ransomware Update<br /><a href="https://blog.talosintelligence.com/blackbyte-blends-tried-and-true-tradecraft-with-newly-disclosed-vulnerabilities-to-support-ongoing-attacks/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/blackbyte-blends-tried-and-true-tradecraft-with-newly-disclosed-vulnerabilities-to-support-ongoing-attacks/</a><br /> The Risks Lurking in Publicly Exposed GenAI Development Services<br /><a href="https://www.legitsecurity.com/blog/the-risks-lurking-in-publicly-exposed-genai-development-services" target="_blank" rel="noreferrer noopener">https://www.legitsecurity.com/blog/the-risks-lurking-in-publicly-exposed-genai-development-services</a><br /> Finding Lateral Movement of Adversaries Through the Noise of Systems Administration<br /><a href="https://www.sans.edu/cyber-research/finding-lateral-movement-adversaries-through-noise-systems-administration/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/finding-lateral-movement-adversaries-through-noise-systems-administration/</a><br />  YouTube Channel: <a href="https://www.youtube.com/c/CyberAttackDefense" target="_blank" rel="noreferrer noopener">https://www.youtube.com/c/CyberAttackDefense</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9120.mp3</guid><pubDate>Fri, 30 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129298/9120.mp3" length="12085388" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Live Patching DLLs with Python
https://isc.sans.edu/diary/Live%20Patching%20DLLs%20with%20Python/31218
 Global Protect Phishing
https://www.trendmicro.com/en_us/research/24/h/threat-actors-target-middle-east-using-fake-tool.html
 BlackByte Ransomware...</itunes:subtitle><itunes:summary><![CDATA[Live Patching DLLs with Python<br /><a href="https://isc.sans.edu/diary/Live%20Patching%20DLLs%20with%20Python/31218" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Live%20Patching%20DLLs%20with%20Python/31218</a><br /> Global Protect Phishing<br /><a href="https://www.trendmicro.com/en_us/research/24/h/threat-actors-target-middle-east-using-fake-tool.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_us/research/24/h/threat-actors-target-middle-east-using-fake-tool.html</a><br /> BlackByte Ransomware Update<br /><a href="https://blog.talosintelligence.com/blackbyte-blends-tried-and-true-tradecraft-with-newly-disclosed-vulnerabilities-to-support-ongoing-attacks/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/blackbyte-blends-tried-and-true-tradecraft-with-newly-disclosed-vulnerabilities-to-support-ongoing-attacks/</a><br /> The Risks Lurking in Publicly Exposed GenAI Development Services<br /><a href="https://www.legitsecurity.com/blog/the-risks-lurking-in-publicly-exposed-genai-development-services" target="_blank" rel="noreferrer noopener">https://www.legitsecurity.com/blog/the-risks-lurking-in-publicly-exposed-genai-development-services</a><br /> Finding Lateral Movement of Adversaries Through the Noise of Systems Administration<br /><a href="https://www.sans.edu/cyber-research/finding-lateral-movement-adversaries-through-noise-systems-administration/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/finding-lateral-movement-adversaries-through-noise-systems-administration/</a><br />  YouTube Channel: <a href="https://www.youtube.com/c/CyberAttackDefense" target="_blank" rel="noreferrer noopener">https://www.youtube.com/c/CyberAttackDefense</a><br />]]></itunes:summary><itunes:duration>842</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,lateral movement; sans_edu; ge,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9120</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, August 30th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-august-30th-2024--61205021</link><description><![CDATA[Live Patching DLLs with Python<br /><a href="https://isc.sans.edu/diary/Live%20Patching%20DLLs%20with%20Python/31218" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Live%20Patching%20DLLs%20with%20Python/31218</a><br /> Global Protect Phishing<br /><a href="https://www.trendmicro.com/en_us/research/24/h/threat-actors-target-middle-east-using-fake-tool.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_us/research/24/h/threat-actors-target-middle-east-using-fake-tool.html</a><br /> BlackByte Ransomware Update<br /><a href="https://blog.talosintelligence.com/blackbyte-blends-tried-and-true-tradecraft-with-newly-disclosed-vulnerabilities-to-support-ongoing-attacks/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/blackbyte-blends-tried-and-true-tradecraft-with-newly-disclosed-vulnerabilities-to-support-ongoing-attacks/</a><br /> The Risks Lurking in Publicly Exposed GenAI Development Services<br /><a href="https://www.legitsecurity.com/blog/the-risks-lurking-in-publicly-exposed-genai-development-services" target="_blank" rel="noreferrer noopener">https://www.legitsecurity.com/blog/the-risks-lurking-in-publicly-exposed-genai-development-services</a><br /> Finding Lateral Movement of Adversaries Through the Noise of Systems Administration<br /><a href="https://www.sans.edu/cyber-research/finding-lateral-movement-adversaries-through-noise-systems-administration/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/finding-lateral-movement-adversaries-through-noise-systems-administration/</a><br />  YouTube Channel: <a href="https://www.youtube.com/c/CyberAttackDefense" target="_blank" rel="noreferrer noopener">https://www.youtube.com/c/CyberAttackDefense</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9120.mp3</guid><pubDate>Fri, 30 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61205021/9120.mp3" length="12085388" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Live Patching DLLs with Python
https://isc.sans.edu/diary/Live%20Patching%20DLLs%20with%20Python/31218
 Global Protect Phishing
https://www.trendmicro.com/en_us/research/24/h/threat-actors-target-middle-east-using-fake-tool.html
 BlackByte Ransomware...</itunes:subtitle><itunes:summary><![CDATA[Live Patching DLLs with Python<br /><a href="https://isc.sans.edu/diary/Live%20Patching%20DLLs%20with%20Python/31218" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Live%20Patching%20DLLs%20with%20Python/31218</a><br /> Global Protect Phishing<br /><a href="https://www.trendmicro.com/en_us/research/24/h/threat-actors-target-middle-east-using-fake-tool.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_us/research/24/h/threat-actors-target-middle-east-using-fake-tool.html</a><br /> BlackByte Ransomware Update<br /><a href="https://blog.talosintelligence.com/blackbyte-blends-tried-and-true-tradecraft-with-newly-disclosed-vulnerabilities-to-support-ongoing-attacks/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/blackbyte-blends-tried-and-true-tradecraft-with-newly-disclosed-vulnerabilities-to-support-ongoing-attacks/</a><br /> The Risks Lurking in Publicly Exposed GenAI Development Services<br /><a href="https://www.legitsecurity.com/blog/the-risks-lurking-in-publicly-exposed-genai-development-services" target="_blank" rel="noreferrer noopener">https://www.legitsecurity.com/blog/the-risks-lurking-in-publicly-exposed-genai-development-services</a><br /> Finding Lateral Movement of Adversaries Through the Noise of Systems Administration<br /><a href="https://www.sans.edu/cyber-research/finding-lateral-movement-adversaries-through-noise-systems-administration/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/finding-lateral-movement-adversaries-through-noise-systems-administration/</a><br />  YouTube Channel: <a href="https://www.youtube.com/c/CyberAttackDefense" target="_blank" rel="noreferrer noopener">https://www.youtube.com/c/CyberAttackDefense</a><br />]]></itunes:summary><itunes:duration>842</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,lateral movement; sans_edu; ge,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9120</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, August 29th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-august-29th-2024--62129327</link><description><![CDATA[Vega-Lite With Kibana To Parse and Display IP Activity Over Time<br /><a href="https://isc.sans.edu/diary/Vega-Lite%20with%20Kibana%20to%20Parse%20and%20Display%20IP%20Activity%20over%20Time/31210" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Vega-Lite%20with%20Kibana%20to%20Parse%20and%20Display%20IP%20Activity%20over%20Time/31210</a><br /> Attack tool update impairs Windows computers<br /><a href="https://news.sophos.com/en-us/2024/08/27/burnt-cigar-2/" target="_blank" rel="noreferrer noopener">https://news.sophos.com/en-us/2024/08/27/burnt-cigar-2/</a><br /> Iran-based Cyber Actors Enabling Ransomware Attacks on US Organizations<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-241a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-241a</a><br /> Confluence Vulnerabilty Exploited for Crypto Miners<br /><a href="https://www.trendmicro.com/en_us/research/24/h/cve-2023-22527-cryptomining.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_us/research/24/h/cve-2023-22527-cryptomining.html</a><br /> Fortra FileCatalyst Workflow Hard Coded HSQLDB Credentials<br /><a href="https://www.fortra.com/security/advisories/product-security/fi-2024-011" target="_blank" rel="noreferrer noopener">https://www.fortra.com/security/advisories/product-security/fi-2024-011</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9118.mp3</guid><pubDate>Thu, 29 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129327/9118.mp3" length="5191509" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Vega-Lite With Kibana To Parse and Display IP Activity Over Time
https://isc.sans.edu/diary/Vega-Lite%20with%20Kibana%20to%20Parse%20and%20Display%20IP%20Activity%20over%20Time/31210
 Attack tool update impairs Windows computers...</itunes:subtitle><itunes:summary><![CDATA[Vega-Lite With Kibana To Parse and Display IP Activity Over Time<br /><a href="https://isc.sans.edu/diary/Vega-Lite%20with%20Kibana%20to%20Parse%20and%20Display%20IP%20Activity%20over%20Time/31210" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Vega-Lite%20with%20Kibana%20to%20Parse%20and%20Display%20IP%20Activity%20over%20Time/31210</a><br /> Attack tool update impairs Windows computers<br /><a href="https://news.sophos.com/en-us/2024/08/27/burnt-cigar-2/" target="_blank" rel="noreferrer noopener">https://news.sophos.com/en-us/2024/08/27/burnt-cigar-2/</a><br /> Iran-based Cyber Actors Enabling Ransomware Attacks on US Organizations<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-241a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-241a</a><br /> Confluence Vulnerabilty Exploited for Crypto Miners<br /><a href="https://www.trendmicro.com/en_us/research/24/h/cve-2023-22527-cryptomining.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_us/research/24/h/cve-2023-22527-cryptomining.html</a><br /> Fortra FileCatalyst Workflow Hard Coded HSQLDB Credentials<br /><a href="https://www.fortra.com/security/advisories/product-security/fi-2024-011" target="_blank" rel="noreferrer noopener">https://www.fortra.com/security/advisories/product-security/fi-2024-011</a><br />]]></itunes:summary><itunes:duration>349</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,fortra; filecatalyst; workflow,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9118</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, August 29th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-august-29th-2024--61193674</link><description><![CDATA[Vega-Lite With Kibana To Parse and Display IP Activity Over Time<br /><a href="https://isc.sans.edu/diary/Vega-Lite%20with%20Kibana%20to%20Parse%20and%20Display%20IP%20Activity%20over%20Time/31210" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Vega-Lite%20with%20Kibana%20to%20Parse%20and%20Display%20IP%20Activity%20over%20Time/31210</a><br /> Attack tool update impairs Windows computers<br /><a href="https://news.sophos.com/en-us/2024/08/27/burnt-cigar-2/" target="_blank" rel="noreferrer noopener">https://news.sophos.com/en-us/2024/08/27/burnt-cigar-2/</a><br /> Iran-based Cyber Actors Enabling Ransomware Attacks on US Organizations<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-241a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-241a</a><br /> Confluence Vulnerabilty Exploited for Crypto Miners<br /><a href="https://www.trendmicro.com/en_us/research/24/h/cve-2023-22527-cryptomining.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_us/research/24/h/cve-2023-22527-cryptomining.html</a><br /> Fortra FileCatalyst Workflow Hard Coded HSQLDB Credentials<br /><a href="https://www.fortra.com/security/advisories/product-security/fi-2024-011" target="_blank" rel="noreferrer noopener">https://www.fortra.com/security/advisories/product-security/fi-2024-011</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9118.mp3</guid><pubDate>Thu, 29 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61193674/9118.mp3" length="5191509" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Vega-Lite With Kibana To Parse and Display IP Activity Over Time
https://isc.sans.edu/diary/Vega-Lite%20with%20Kibana%20to%20Parse%20and%20Display%20IP%20Activity%20over%20Time/31210
 Attack tool update impairs Windows computers...</itunes:subtitle><itunes:summary><![CDATA[Vega-Lite With Kibana To Parse and Display IP Activity Over Time<br /><a href="https://isc.sans.edu/diary/Vega-Lite%20with%20Kibana%20to%20Parse%20and%20Display%20IP%20Activity%20over%20Time/31210" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Vega-Lite%20with%20Kibana%20to%20Parse%20and%20Display%20IP%20Activity%20over%20Time/31210</a><br /> Attack tool update impairs Windows computers<br /><a href="https://news.sophos.com/en-us/2024/08/27/burnt-cigar-2/" target="_blank" rel="noreferrer noopener">https://news.sophos.com/en-us/2024/08/27/burnt-cigar-2/</a><br /> Iran-based Cyber Actors Enabling Ransomware Attacks on US Organizations<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-241a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-241a</a><br /> Confluence Vulnerabilty Exploited for Crypto Miners<br /><a href="https://www.trendmicro.com/en_us/research/24/h/cve-2023-22527-cryptomining.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_us/research/24/h/cve-2023-22527-cryptomining.html</a><br /> Fortra FileCatalyst Workflow Hard Coded HSQLDB Credentials<br /><a href="https://www.fortra.com/security/advisories/product-security/fi-2024-011" target="_blank" rel="noreferrer noopener">https://www.fortra.com/security/advisories/product-security/fi-2024-011</a><br />]]></itunes:summary><itunes:duration>349</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,fortra; filecatalyst; workflow,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9118</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, August 28th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-august-28th-2024--62129312</link><description><![CDATA[Why is Python so Popular to Infect Windows Hosts<br /><a href="https://isc.sans.edu/diary/Why%20Is%20Python%20so%20Popular%20to%20Infect%20Windows%20Hosts%3F/31208" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Why%20Is%20Python%20so%20Popular%20to%20Infect%20Windows%20Hosts%3F/31208</a><br /> OFBiz Vulnerability Update<br /><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a><br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38856" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2024-38856</a><br /> Versa Directory Vulnerability Exploited<br /><a href="https://versa-networks.com/blog/versa-security-bulletin-update-on-cve-2024-39717-versa-director-dangerous-file-type-upload-vulnerability/" target="_blank" rel="noreferrer noopener">https://versa-networks.com/blog/versa-security-bulletin-update-on-cve-2024-39717-versa-director-dangerous-file-type-upload-vulnerability/</a><br /> Google Chrome Vulnerability Exploited<br /><a href="https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html</a><br /> SGX Key Leak<br /><a href="https://x.com/_markel___/status/1828112469010596347" target="_blank" rel="noreferrer noopener">https://x.com/_markel___/status/1828112469010596347</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9116.mp3</guid><pubDate>Wed, 28 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129312/9116.mp3" length="5465527" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Why is Python so Popular to Infect Windows Hosts
https://isc.sans.edu/diary/Why%20Is%20Python%20so%20Popular%20to%20Infect%20Windows%20Hosts%3F/31208
 OFBiz Vulnerability Update
https://www.cisa.gov/known-exploited-vulnerabilities-catalog...</itunes:subtitle><itunes:summary><![CDATA[Why is Python so Popular to Infect Windows Hosts<br /><a href="https://isc.sans.edu/diary/Why%20Is%20Python%20so%20Popular%20to%20Infect%20Windows%20Hosts%3F/31208" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Why%20Is%20Python%20so%20Popular%20to%20Infect%20Windows%20Hosts%3F/31208</a><br /> OFBiz Vulnerability Update<br /><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a><br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38856" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2024-38856</a><br /> Versa Directory Vulnerability Exploited<br /><a href="https://versa-networks.com/blog/versa-security-bulletin-update-on-cve-2024-39717-versa-director-dangerous-file-type-upload-vulnerability/" target="_blank" rel="noreferrer noopener">https://versa-networks.com/blog/versa-security-bulletin-update-on-cve-2024-39717-versa-director-dangerous-file-type-upload-vulnerability/</a><br /> Google Chrome Vulnerability Exploited<br /><a href="https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html</a><br /> SGX Key Leak<br /><a href="https://x.com/_markel___/status/1828112469010596347" target="_blank" rel="noreferrer noopener">https://x.com/_markel___/status/1828112469010596347</a><br />]]></itunes:summary><itunes:duration>369</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,sgx; intel; google; chrome; ve</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9116</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, August 28th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-august-28th-2024--61180188</link><description><![CDATA[Why is Python so Popular to Infect Windows Hosts<br /><a href="https://isc.sans.edu/diary/Why%20Is%20Python%20so%20Popular%20to%20Infect%20Windows%20Hosts%3F/31208" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Why%20Is%20Python%20so%20Popular%20to%20Infect%20Windows%20Hosts%3F/31208</a><br /> OFBiz Vulnerability Update<br /><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a><br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38856" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2024-38856</a><br /> Versa Directory Vulnerability Exploited<br /><a href="https://versa-networks.com/blog/versa-security-bulletin-update-on-cve-2024-39717-versa-director-dangerous-file-type-upload-vulnerability/" target="_blank" rel="noreferrer noopener">https://versa-networks.com/blog/versa-security-bulletin-update-on-cve-2024-39717-versa-director-dangerous-file-type-upload-vulnerability/</a><br /> Google Chrome Vulnerability Exploited<br /><a href="https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html</a><br /> SGX Key Leak<br /><a href="https://x.com/_markel___/status/1828112469010596347" target="_blank" rel="noreferrer noopener">https://x.com/_markel___/status/1828112469010596347</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9116.mp3</guid><pubDate>Wed, 28 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61180188/9116.mp3" length="5465527" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Why is Python so Popular to Infect Windows Hosts
https://isc.sans.edu/diary/Why%20Is%20Python%20so%20Popular%20to%20Infect%20Windows%20Hosts%3F/31208
 OFBiz Vulnerability Update
https://www.cisa.gov/known-exploited-vulnerabilities-catalog...</itunes:subtitle><itunes:summary><![CDATA[Why is Python so Popular to Infect Windows Hosts<br /><a href="https://isc.sans.edu/diary/Why%20Is%20Python%20so%20Popular%20to%20Infect%20Windows%20Hosts%3F/31208" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Why%20Is%20Python%20so%20Popular%20to%20Infect%20Windows%20Hosts%3F/31208</a><br /> OFBiz Vulnerability Update<br /><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a><br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38856" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2024-38856</a><br /> Versa Directory Vulnerability Exploited<br /><a href="https://versa-networks.com/blog/versa-security-bulletin-update-on-cve-2024-39717-versa-director-dangerous-file-type-upload-vulnerability/" target="_blank" rel="noreferrer noopener">https://versa-networks.com/blog/versa-security-bulletin-update-on-cve-2024-39717-versa-director-dangerous-file-type-upload-vulnerability/</a><br /> Google Chrome Vulnerability Exploited<br /><a href="https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html</a><br /> SGX Key Leak<br /><a href="https://x.com/_markel___/status/1828112469010596347" target="_blank" rel="noreferrer noopener">https://x.com/_markel___/status/1828112469010596347</a><br />]]></itunes:summary><itunes:duration>369</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,sgx; intel; google; chrome; ve</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9116</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, August 27th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-august-27th-2024--62129313</link><description><![CDATA[From Highly Obfuscated Batch File to XWorm and Redline<br /><a href="https://isc.sans.edu/diary/From%20Highly%20Obfuscated%20Batch%20File%20to%20XWorm%20and%20Redline/31204" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/From%20Highly%20Obfuscated%20Batch%20File%20to%20XWorm%20and%20Redline/31204</a><br /> CVE-2024-38063 Windows IPv6 Issue PoC Exploit<br /><a href="https://github.com/ynwarcs/CVE-2024-38063" target="_blank" rel="noreferrer noopener">https://github.com/ynwarcs/CVE-2024-38063</a><br /> Not a vulnerability<br /><a href="https://github.com/juwenyi/CVE-2024-42992" target="_blank" rel="noreferrer noopener">https://github.com/juwenyi/CVE-2024-42992</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9114.mp3</guid><pubDate>Tue, 27 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129313/9114.mp3" length="4979174" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>From Highly Obfuscated Batch File to XWorm and Redline
https://isc.sans.edu/diary/From%20Highly%20Obfuscated%20Batch%20File%20to%20XWorm%20and%20Redline/31204
 CVE-2024-38063 Windows IPv6 Issue PoC Exploit
https://github.com/ynwarcs/CVE-2024-38063...</itunes:subtitle><itunes:summary><![CDATA[From Highly Obfuscated Batch File to XWorm and Redline<br /><a href="https://isc.sans.edu/diary/From%20Highly%20Obfuscated%20Batch%20File%20to%20XWorm%20and%20Redline/31204" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/From%20Highly%20Obfuscated%20Batch%20File%20to%20XWorm%20and%20Redline/31204</a><br /> CVE-2024-38063 Windows IPv6 Issue PoC Exploit<br /><a href="https://github.com/ynwarcs/CVE-2024-38063" target="_blank" rel="noreferrer noopener">https://github.com/ynwarcs/CVE-2024-38063</a><br /> Not a vulnerability<br /><a href="https://github.com/juwenyi/CVE-2024-42992" target="_blank" rel="noreferrer noopener">https://github.com/juwenyi/CVE-2024-42992</a><br />]]></itunes:summary><itunes:duration>334</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,pandas; vulnerability; windows,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9114</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, August 27th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-august-27th-2024--61166001</link><description><![CDATA[From Highly Obfuscated Batch File to XWorm and Redline<br /><a href="https://isc.sans.edu/diary/From%20Highly%20Obfuscated%20Batch%20File%20to%20XWorm%20and%20Redline/31204" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/From%20Highly%20Obfuscated%20Batch%20File%20to%20XWorm%20and%20Redline/31204</a><br /> CVE-2024-38063 Windows IPv6 Issue PoC Exploit<br /><a href="https://github.com/ynwarcs/CVE-2024-38063" target="_blank" rel="noreferrer noopener">https://github.com/ynwarcs/CVE-2024-38063</a><br /> Not a vulnerability<br /><a href="https://github.com/juwenyi/CVE-2024-42992" target="_blank" rel="noreferrer noopener">https://github.com/juwenyi/CVE-2024-42992</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9114.mp3</guid><pubDate>Tue, 27 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61166001/9114.mp3" length="4979174" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>From Highly Obfuscated Batch File to XWorm and Redline
https://isc.sans.edu/diary/From%20Highly%20Obfuscated%20Batch%20File%20to%20XWorm%20and%20Redline/31204
 CVE-2024-38063 Windows IPv6 Issue PoC Exploit
https://github.com/ynwarcs/CVE-2024-38063...</itunes:subtitle><itunes:summary><![CDATA[From Highly Obfuscated Batch File to XWorm and Redline<br /><a href="https://isc.sans.edu/diary/From%20Highly%20Obfuscated%20Batch%20File%20to%20XWorm%20and%20Redline/31204" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/From%20Highly%20Obfuscated%20Batch%20File%20to%20XWorm%20and%20Redline/31204</a><br /> CVE-2024-38063 Windows IPv6 Issue PoC Exploit<br /><a href="https://github.com/ynwarcs/CVE-2024-38063" target="_blank" rel="noreferrer noopener">https://github.com/ynwarcs/CVE-2024-38063</a><br /> Not a vulnerability<br /><a href="https://github.com/juwenyi/CVE-2024-42992" target="_blank" rel="noreferrer noopener">https://github.com/juwenyi/CVE-2024-42992</a><br />]]></itunes:summary><itunes:duration>334</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,pandas; vulnerability; windows,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9114</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, August 26th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-august-26th-2024--62129328</link><description><![CDATA[Pandas Erros: What encoding are my logs in?<br /><a href="https://isc.sans.edu/diary/Pandas%20Errors%3A%20What%20encoding%20are%20my%20logs%20in%3F/31200" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Pandas%20Errors%3A%20What%20encoding%20are%20my%20logs%20in%3F/31200</a><br /> Crowdstrike Performance Issues<br /><a href="https://www.reddit.com/r/sysadmin/comments/1eyfex6/at_least_its_not_on_a_friday/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/sysadmin/comments/1eyfex6/at_least_its_not_on_a_friday/</a><br /> CopyBara Malware<br /><a href="https://www.zscaler.com/blogs/security-research/technical-analysis-copybara#conclusion" target="_blank" rel="noreferrer noopener">https://www.zscaler.com/blogs/security-research/technical-analysis-copybara#conclusion</a><br /> SonicWall Vulnerability<br /><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0015" target="_blank" rel="noreferrer noopener">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0015</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9112.mp3</guid><pubDate>Mon, 26 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129328/9112.mp3" length="4984488" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Pandas Erros: What encoding are my logs in?
https://isc.sans.edu/diary/Pandas%20Errors%3A%20What%20encoding%20are%20my%20logs%20in%3F/31200
 Crowdstrike Performance Issues...</itunes:subtitle><itunes:summary><![CDATA[Pandas Erros: What encoding are my logs in?<br /><a href="https://isc.sans.edu/diary/Pandas%20Errors%3A%20What%20encoding%20are%20my%20logs%20in%3F/31200" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Pandas%20Errors%3A%20What%20encoding%20are%20my%20logs%20in%3F/31200</a><br /> Crowdstrike Performance Issues<br /><a href="https://www.reddit.com/r/sysadmin/comments/1eyfex6/at_least_its_not_on_a_friday/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/sysadmin/comments/1eyfex6/at_least_its_not_on_a_friday/</a><br /> CopyBara Malware<br /><a href="https://www.zscaler.com/blogs/security-research/technical-analysis-copybara#conclusion" target="_blank" rel="noreferrer noopener">https://www.zscaler.com/blogs/security-research/technical-analysis-copybara#conclusion</a><br /> SonicWall Vulnerability<br /><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0015" target="_blank" rel="noreferrer noopener">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0015</a><br />]]></itunes:summary><itunes:duration>334</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,pandas; parsing; encoding; cro,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9112</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, August 26th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-august-26th-2024--61152906</link><description><![CDATA[Pandas Erros: What encoding are my logs in?<br /><a href="https://isc.sans.edu/diary/Pandas%20Errors%3A%20What%20encoding%20are%20my%20logs%20in%3F/31200" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Pandas%20Errors%3A%20What%20encoding%20are%20my%20logs%20in%3F/31200</a><br /> Crowdstrike Performance Issues<br /><a href="https://www.reddit.com/r/sysadmin/comments/1eyfex6/at_least_its_not_on_a_friday/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/sysadmin/comments/1eyfex6/at_least_its_not_on_a_friday/</a><br /> CopyBara Malware<br /><a href="https://www.zscaler.com/blogs/security-research/technical-analysis-copybara#conclusion" target="_blank" rel="noreferrer noopener">https://www.zscaler.com/blogs/security-research/technical-analysis-copybara#conclusion</a><br /> SonicWall Vulnerability<br /><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0015" target="_blank" rel="noreferrer noopener">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0015</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9112.mp3</guid><pubDate>Mon, 26 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61152906/9112.mp3" length="4984488" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Pandas Erros: What encoding are my logs in?
https://isc.sans.edu/diary/Pandas%20Errors%3A%20What%20encoding%20are%20my%20logs%20in%3F/31200
 Crowdstrike Performance Issues...</itunes:subtitle><itunes:summary><![CDATA[Pandas Erros: What encoding are my logs in?<br /><a href="https://isc.sans.edu/diary/Pandas%20Errors%3A%20What%20encoding%20are%20my%20logs%20in%3F/31200" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Pandas%20Errors%3A%20What%20encoding%20are%20my%20logs%20in%3F/31200</a><br /> Crowdstrike Performance Issues<br /><a href="https://www.reddit.com/r/sysadmin/comments/1eyfex6/at_least_its_not_on_a_friday/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/sysadmin/comments/1eyfex6/at_least_its_not_on_a_friday/</a><br /> CopyBara Malware<br /><a href="https://www.zscaler.com/blogs/security-research/technical-analysis-copybara#conclusion" target="_blank" rel="noreferrer noopener">https://www.zscaler.com/blogs/security-research/technical-analysis-copybara#conclusion</a><br /> SonicWall Vulnerability<br /><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0015" target="_blank" rel="noreferrer noopener">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0015</a><br />]]></itunes:summary><itunes:duration>334</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,pandas; parsing; encoding; cro,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9112</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, August 23rd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-august-23rd-2024--62129316</link><description><![CDATA[OpenAI Scans Honeypots<br /><a href="https://isc.sans.edu/diary/OpenAI%20Scans%20for%20Honeypots.%20Artificially%20Malicious%3F%20Action%20Abuse%3F/31196" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/OpenAI%20Scans%20for%20Honeypots.%20Artificially%20Malicious%3F%20Action%20Abuse%3F/31196</a><br /> Broken Linux Boot Partitions after August Microsoft Update<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-23H2#3377msgdesc" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-23H2#3377msgdesc</a><br /> Google Fixes Chrome 0-day<br /><a href="https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html</a><br /> Cisco Zero Day Exploited (now Patched)<br /><a href="https://www.sygnia.co/blog/china-threat-group-velvet-ant-cisco-zero-day/" target="_blank" rel="noreferrer noopener">https://www.sygnia.co/blog/china-threat-group-velvet-ant-cisco-zero-day/</a><br /> Solar Winds Helpdesk Backdoor<br /><a href="https://support.solarwinds.com/SuccessCenter/s/article/SolarWinds-Web-Help-Desk-12-8-3-Hotfix-2" target="_blank" rel="noreferrer noopener">https://support.solarwinds.com/SuccessCenter/s/article/SolarWinds-Web-Help-Desk-12-8-3-Hotfix-2</a><br /> Securing the Future: How Memory-Safe Programming Languages Impact Industry Safety (Christopher Ross)<br /><a href="https://www.sans.edu/cyber-research/securing-future-how-memory-safe-programming-languages-impact-industry-safety/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/securing-future-how-memory-safe-programming-languages-impact-industry-safety/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9110.mp3</guid><pubDate>Fri, 23 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129316/9110.mp3" length="13196574" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>OpenAI Scans Honeypots
https://isc.sans.edu/diary/OpenAI%20Scans%20for%20Honeypots.%20Artificially%20Malicious%3F%20Action%20Abuse%3F/31196
 Broken Linux Boot Partitions after August Microsoft Update...</itunes:subtitle><itunes:summary><![CDATA[OpenAI Scans Honeypots<br /><a href="https://isc.sans.edu/diary/OpenAI%20Scans%20for%20Honeypots.%20Artificially%20Malicious%3F%20Action%20Abuse%3F/31196" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/OpenAI%20Scans%20for%20Honeypots.%20Artificially%20Malicious%3F%20Action%20Abuse%3F/31196</a><br /> Broken Linux Boot Partitions after August Microsoft Update<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-23H2#3377msgdesc" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-23H2#3377msgdesc</a><br /> Google Fixes Chrome 0-day<br /><a href="https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html</a><br /> Cisco Zero Day Exploited (now Patched)<br /><a href="https://www.sygnia.co/blog/china-threat-group-velvet-ant-cisco-zero-day/" target="_blank" rel="noreferrer noopener">https://www.sygnia.co/blog/china-threat-group-velvet-ant-cisco-zero-day/</a><br /> Solar Winds Helpdesk Backdoor<br /><a href="https://support.solarwinds.com/SuccessCenter/s/article/SolarWinds-Web-Help-Desk-12-8-3-Hotfix-2" target="_blank" rel="noreferrer noopener">https://support.solarwinds.com/SuccessCenter/s/article/SolarWinds-Web-Help-Desk-12-8-3-Hotfix-2</a><br /> Securing the Future: How Memory-Safe Programming Languages Impact Industry Safety (Christopher Ross)<br /><a href="https://www.sans.edu/cyber-research/securing-future-how-memory-safe-programming-languages-impact-industry-safety/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/securing-future-how-memory-safe-programming-languages-impact-industry-safety/</a><br />]]></itunes:summary><itunes:duration>921</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,openai; msft; linux; boot; chr,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9110</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, August 23rd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-august-23rd-2024--61120972</link><description><![CDATA[OpenAI Scans Honeypots<br /><a href="https://isc.sans.edu/diary/OpenAI%20Scans%20for%20Honeypots.%20Artificially%20Malicious%3F%20Action%20Abuse%3F/31196" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/OpenAI%20Scans%20for%20Honeypots.%20Artificially%20Malicious%3F%20Action%20Abuse%3F/31196</a><br /> Broken Linux Boot Partitions after August Microsoft Update<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-23H2#3377msgdesc" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-23H2#3377msgdesc</a><br /> Google Fixes Chrome 0-day<br /><a href="https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html</a><br /> Cisco Zero Day Exploited (now Patched)<br /><a href="https://www.sygnia.co/blog/china-threat-group-velvet-ant-cisco-zero-day/" target="_blank" rel="noreferrer noopener">https://www.sygnia.co/blog/china-threat-group-velvet-ant-cisco-zero-day/</a><br /> Solar Winds Helpdesk Backdoor<br /><a href="https://support.solarwinds.com/SuccessCenter/s/article/SolarWinds-Web-Help-Desk-12-8-3-Hotfix-2" target="_blank" rel="noreferrer noopener">https://support.solarwinds.com/SuccessCenter/s/article/SolarWinds-Web-Help-Desk-12-8-3-Hotfix-2</a><br /> Securing the Future: How Memory-Safe Programming Languages Impact Industry Safety (Christopher Ross)<br /><a href="https://www.sans.edu/cyber-research/securing-future-how-memory-safe-programming-languages-impact-industry-safety/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/securing-future-how-memory-safe-programming-languages-impact-industry-safety/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9110.mp3</guid><pubDate>Fri, 23 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61120972/9110.mp3" length="13196574" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>OpenAI Scans Honeypots
https://isc.sans.edu/diary/OpenAI%20Scans%20for%20Honeypots.%20Artificially%20Malicious%3F%20Action%20Abuse%3F/31196
 Broken Linux Boot Partitions after August Microsoft Update...</itunes:subtitle><itunes:summary><![CDATA[OpenAI Scans Honeypots<br /><a href="https://isc.sans.edu/diary/OpenAI%20Scans%20for%20Honeypots.%20Artificially%20Malicious%3F%20Action%20Abuse%3F/31196" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/OpenAI%20Scans%20for%20Honeypots.%20Artificially%20Malicious%3F%20Action%20Abuse%3F/31196</a><br /> Broken Linux Boot Partitions after August Microsoft Update<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-23H2#3377msgdesc" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-23H2#3377msgdesc</a><br /> Google Fixes Chrome 0-day<br /><a href="https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html</a><br /> Cisco Zero Day Exploited (now Patched)<br /><a href="https://www.sygnia.co/blog/china-threat-group-velvet-ant-cisco-zero-day/" target="_blank" rel="noreferrer noopener">https://www.sygnia.co/blog/china-threat-group-velvet-ant-cisco-zero-day/</a><br /> Solar Winds Helpdesk Backdoor<br /><a href="https://support.solarwinds.com/SuccessCenter/s/article/SolarWinds-Web-Help-Desk-12-8-3-Hotfix-2" target="_blank" rel="noreferrer noopener">https://support.solarwinds.com/SuccessCenter/s/article/SolarWinds-Web-Help-Desk-12-8-3-Hotfix-2</a><br /> Securing the Future: How Memory-Safe Programming Languages Impact Industry Safety (Christopher Ross)<br /><a href="https://www.sans.edu/cyber-research/securing-future-how-memory-safe-programming-languages-impact-industry-safety/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/securing-future-how-memory-safe-programming-languages-impact-industry-safety/</a><br />]]></itunes:summary><itunes:duration>921</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,openai; msft; linux; boot; chr,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9110</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, August 22nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-august-22nd-2024--62129317</link><description><![CDATA[Mapping Threats wiht DNSTwist and the Internet Storm Center <br /><a href="https://isc.sans.edu/diary/Mapping%20Threats%20with%20DNSTwist%20and%20the%20Internet%20Storm%20Center%20%5BGuest%20Diary%5D/31188" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Mapping%20Threats%20with%20DNSTwist%20and%20the%20Internet%20Storm%20Center%20%5BGuest%20Diary%5D/31188</a><br /> Slack AI Prompt Injection<br /><a href="https://promptarmor.substack.com/p/slack-ai-data-exfiltration-from-private" target="_blank" rel="noreferrer noopener">https://promptarmor.substack.com/p/slack-ai-data-exfiltration-from-private</a><br /> Phishing in PWA Applications<br /><a href="https://www.welivesecurity.com/en/eset-research/be-careful-what-you-pwish-for-phishing-in-pwa-applications/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/be-careful-what-you-pwish-for-phishing-in-pwa-applications/</a><br /> QNAP Ransomware Security Center<br /><a href="https://www.qnap.com/en/news/2024/qnap-officially-releases-qts-5-2-introducing-security-center-for-active-file-activity-monitoring-elevated-security-and-data-protection" target="_blank" rel="noreferrer noopener">https://www.qnap.com/en/news/2024/qnap-officially-releases-qts-5-2-introducing-security-center-for-active-file-activity-monitoring-elevated-security-and-data-protection</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9108.mp3</guid><pubDate>Thu, 22 Aug 2024 01:23:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129317/9108.mp3" length="6257752" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Mapping Threats wiht DNSTwist and the Internet Storm Center 
https://isc.sans.edu/diary/Mapping%20Threats%20with%20DNSTwist%20and%20the%20Internet%20Storm%20Center%20%5BGuest%20Diary%5D/31188
 Slack AI Prompt Injection...</itunes:subtitle><itunes:summary><![CDATA[Mapping Threats wiht DNSTwist and the Internet Storm Center <br /><a href="https://isc.sans.edu/diary/Mapping%20Threats%20with%20DNSTwist%20and%20the%20Internet%20Storm%20Center%20%5BGuest%20Diary%5D/31188" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Mapping%20Threats%20with%20DNSTwist%20and%20the%20Internet%20Storm%20Center%20%5BGuest%20Diary%5D/31188</a><br /> Slack AI Prompt Injection<br /><a href="https://promptarmor.substack.com/p/slack-ai-data-exfiltration-from-private" target="_blank" rel="noreferrer noopener">https://promptarmor.substack.com/p/slack-ai-data-exfiltration-from-private</a><br /> Phishing in PWA Applications<br /><a href="https://www.welivesecurity.com/en/eset-research/be-careful-what-you-pwish-for-phishing-in-pwa-applications/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/be-careful-what-you-pwish-for-phishing-in-pwa-applications/</a><br /> QNAP Ransomware Security Center<br /><a href="https://www.qnap.com/en/news/2024/qnap-officially-releases-qts-5-2-introducing-security-center-for-active-file-activity-monitoring-elevated-security-and-data-protection" target="_blank" rel="noreferrer noopener">https://www.qnap.com/en/news/2024/qnap-officially-releases-qts-5-2-introducing-security-center-for-active-file-activity-monitoring-elevated-security-and-data-protection</a><br />]]></itunes:summary><itunes:duration>425</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,qnap; phishing; slack ai; dnst,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9108</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, August 22nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-august-22nd-2024--61110073</link><description><![CDATA[Mapping Threats wiht DNSTwist and the Internet Storm Center <br /><a href="https://isc.sans.edu/diary/Mapping%20Threats%20with%20DNSTwist%20and%20the%20Internet%20Storm%20Center%20%5BGuest%20Diary%5D/31188" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Mapping%20Threats%20with%20DNSTwist%20and%20the%20Internet%20Storm%20Center%20%5BGuest%20Diary%5D/31188</a><br /> Slack AI Prompt Injection<br /><a href="https://promptarmor.substack.com/p/slack-ai-data-exfiltration-from-private" target="_blank" rel="noreferrer noopener">https://promptarmor.substack.com/p/slack-ai-data-exfiltration-from-private</a><br /> Phishing in PWA Applications<br /><a href="https://www.welivesecurity.com/en/eset-research/be-careful-what-you-pwish-for-phishing-in-pwa-applications/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/be-careful-what-you-pwish-for-phishing-in-pwa-applications/</a><br /> QNAP Ransomware Security Center<br /><a href="https://www.qnap.com/en/news/2024/qnap-officially-releases-qts-5-2-introducing-security-center-for-active-file-activity-monitoring-elevated-security-and-data-protection" target="_blank" rel="noreferrer noopener">https://www.qnap.com/en/news/2024/qnap-officially-releases-qts-5-2-introducing-security-center-for-active-file-activity-monitoring-elevated-security-and-data-protection</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9108.mp3</guid><pubDate>Thu, 22 Aug 2024 01:23:00 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61110073/9108.mp3" length="6257752" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Mapping Threats wiht DNSTwist and the Internet Storm Center 
https://isc.sans.edu/diary/Mapping%20Threats%20with%20DNSTwist%20and%20the%20Internet%20Storm%20Center%20%5BGuest%20Diary%5D/31188
 Slack AI Prompt Injection...</itunes:subtitle><itunes:summary><![CDATA[Mapping Threats wiht DNSTwist and the Internet Storm Center <br /><a href="https://isc.sans.edu/diary/Mapping%20Threats%20with%20DNSTwist%20and%20the%20Internet%20Storm%20Center%20%5BGuest%20Diary%5D/31188" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Mapping%20Threats%20with%20DNSTwist%20and%20the%20Internet%20Storm%20Center%20%5BGuest%20Diary%5D/31188</a><br /> Slack AI Prompt Injection<br /><a href="https://promptarmor.substack.com/p/slack-ai-data-exfiltration-from-private" target="_blank" rel="noreferrer noopener">https://promptarmor.substack.com/p/slack-ai-data-exfiltration-from-private</a><br /> Phishing in PWA Applications<br /><a href="https://www.welivesecurity.com/en/eset-research/be-careful-what-you-pwish-for-phishing-in-pwa-applications/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/be-careful-what-you-pwish-for-phishing-in-pwa-applications/</a><br /> QNAP Ransomware Security Center<br /><a href="https://www.qnap.com/en/news/2024/qnap-officially-releases-qts-5-2-introducing-security-center-for-active-file-activity-monitoring-elevated-security-and-data-protection" target="_blank" rel="noreferrer noopener">https://www.qnap.com/en/news/2024/qnap-officially-releases-qts-5-2-introducing-security-center-for-active-file-activity-monitoring-elevated-security-and-data-protection</a><br />]]></itunes:summary><itunes:duration>425</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,qnap; phishing; slack ai; dnst,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9108</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, August 21st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-august-21st-2024--62129299</link><description><![CDATA[Where are we with CVE-2024-38063: Microsoft IPv6 Vulnerability<br /><a href="https://isc.sans.edu/diary/Where+are+we+with+CVE202438063+Microsoft+IPv6+Vulnerability/31186" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Where+are+we+with+CVE202438063+Microsoft+IPv6+Vulnerability/31186</a><br /> Microsoft August Update Prevents Linux from Booting<br /><a href="https://community.frame.work/t/sbat-verification-error-booting-linux-after-windows-update/56354" target="_blank" rel="noreferrer noopener">https://community.frame.work/t/sbat-verification-error-booting-linux-after-windows-update/56354</a><br /> PHP CGI Vulnerability Exploited CVE-2024-4577<br /><a href="https://symantec-enterprise-blogs.security.com/threat-intelligence/taiwan-malware-dns" target="_blank" rel="noreferrer noopener">https://symantec-enterprise-blogs.security.com/threat-intelligence/taiwan-malware-dns</a><br /> F5 Updates<br /><a href="https://my.f5.com/manage/s/article/K000140111" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000140111</a><br /><a href="https://my.f5.com/manage/s/article/K000140108" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000140108</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9106.mp3</guid><pubDate>Wed, 21 Aug 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129299/9106.mp3" length="4420004" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Where are we with CVE-2024-38063: Microsoft IPv6 Vulnerability
https://isc.sans.edu/diary/Where+are+we+with+CVE202438063+Microsoft+IPv6+Vulnerability/31186
 Microsoft August Update Prevents Linux from Booting...</itunes:subtitle><itunes:summary><![CDATA[Where are we with CVE-2024-38063: Microsoft IPv6 Vulnerability<br /><a href="https://isc.sans.edu/diary/Where+are+we+with+CVE202438063+Microsoft+IPv6+Vulnerability/31186" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Where+are+we+with+CVE202438063+Microsoft+IPv6+Vulnerability/31186</a><br /> Microsoft August Update Prevents Linux from Booting<br /><a href="https://community.frame.work/t/sbat-verification-error-booting-linux-after-windows-update/56354" target="_blank" rel="noreferrer noopener">https://community.frame.work/t/sbat-verification-error-booting-linux-after-windows-update/56354</a><br /> PHP CGI Vulnerability Exploited CVE-2024-4577<br /><a href="https://symantec-enterprise-blogs.security.com/threat-intelligence/taiwan-malware-dns" target="_blank" rel="noreferrer noopener">https://symantec-enterprise-blogs.security.com/threat-intelligence/taiwan-malware-dns</a><br /> F5 Updates<br /><a href="https://my.f5.com/manage/s/article/K000140111" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000140111</a><br /><a href="https://my.f5.com/manage/s/article/K000140108" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000140108</a><br />]]></itunes:summary><itunes:duration>294</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,f5; big-ip; php; cgi; microsof,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9106</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, August 21st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-august-21st-2024--61099168</link><description><![CDATA[Where are we with CVE-2024-38063: Microsoft IPv6 Vulnerability<br /><a href="https://isc.sans.edu/diary/Where+are+we+with+CVE202438063+Microsoft+IPv6+Vulnerability/31186" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Where+are+we+with+CVE202438063+Microsoft+IPv6+Vulnerability/31186</a><br /> Microsoft August Update Prevents Linux from Booting<br /><a href="https://community.frame.work/t/sbat-verification-error-booting-linux-after-windows-update/56354" target="_blank" rel="noreferrer noopener">https://community.frame.work/t/sbat-verification-error-booting-linux-after-windows-update/56354</a><br /> PHP CGI Vulnerability Exploited CVE-2024-4577<br /><a href="https://symantec-enterprise-blogs.security.com/threat-intelligence/taiwan-malware-dns" target="_blank" rel="noreferrer noopener">https://symantec-enterprise-blogs.security.com/threat-intelligence/taiwan-malware-dns</a><br /> F5 Updates<br /><a href="https://my.f5.com/manage/s/article/K000140111" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000140111</a><br /><a href="https://my.f5.com/manage/s/article/K000140108" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000140108</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9106.mp3</guid><pubDate>Wed, 21 Aug 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61099168/9106.mp3" length="4420004" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Where are we with CVE-2024-38063: Microsoft IPv6 Vulnerability
https://isc.sans.edu/diary/Where+are+we+with+CVE202438063+Microsoft+IPv6+Vulnerability/31186
 Microsoft August Update Prevents Linux from Booting...</itunes:subtitle><itunes:summary><![CDATA[Where are we with CVE-2024-38063: Microsoft IPv6 Vulnerability<br /><a href="https://isc.sans.edu/diary/Where+are+we+with+CVE202438063+Microsoft+IPv6+Vulnerability/31186" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Where+are+we+with+CVE202438063+Microsoft+IPv6+Vulnerability/31186</a><br /> Microsoft August Update Prevents Linux from Booting<br /><a href="https://community.frame.work/t/sbat-verification-error-booting-linux-after-windows-update/56354" target="_blank" rel="noreferrer noopener">https://community.frame.work/t/sbat-verification-error-booting-linux-after-windows-update/56354</a><br /> PHP CGI Vulnerability Exploited CVE-2024-4577<br /><a href="https://symantec-enterprise-blogs.security.com/threat-intelligence/taiwan-malware-dns" target="_blank" rel="noreferrer noopener">https://symantec-enterprise-blogs.security.com/threat-intelligence/taiwan-malware-dns</a><br /> F5 Updates<br /><a href="https://my.f5.com/manage/s/article/K000140111" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000140111</a><br /><a href="https://my.f5.com/manage/s/article/K000140108" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000140108</a><br />]]></itunes:summary><itunes:duration>294</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,f5; big-ip; php; cgi; microsof,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9106</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, August 20th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-august-20th-2024--62129309</link><description><![CDATA[Do you like donuts? Here is a donut Shellcode Delivered Through PowerShell Python<br /><a href="https://isc.sans.edu/diary/Do%20you%20Like%20Donuts%3F%20Here%20is%20a%20Donut%20Shellcode%20Delivered%20Through%20PowerShell%20Python/31182" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Do%20you%20Like%20Donuts%3F%20Here%20is%20a%20Donut%20Shellcode%20Delivered%20Through%20PowerShell%20Python/31182</a><br /> How Vulnerabilities in Microsoft Apps for MacOS allow Stealing Permissions<br /><a href="https://blog.talosintelligence.com/how-multiple-vulnerabilities-in-microsoft-apps-for-macos-pave-the-way-to-stealing-permissions/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/how-multiple-vulnerabilities-in-microsoft-apps-for-macos-pave-the-way-to-stealing-permissions/</a><br /> Digital Wallet Security Loophole<br /><a href="https://www.umass.edu/news/article/new-study-reveals-loophole-digital-wallet-security-even-if-rightful-cardholder-doesnt" target="_blank" rel="noreferrer noopener">https://www.umass.edu/news/article/new-study-reveals-loophole-digital-wallet-security-even-if-rightful-cardholder-doesnt</a><br /> Microsoft IPv6 Vulnerability CVE-2024-38063<br /><a href="https://x.com/f4rmpoet/status/1825472703223992323" target="_blank" rel="noreferrer noopener">https://x.com/f4rmpoet/status/1825472703223992323</a><br /> YouTube Video (going live 10am ET) <br /><a href="https://www.youtube.com/watch?v=miBb1llFOYQ" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=miBb1llFOYQ</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9104.mp3</guid><pubDate>Tue, 20 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129309/9104.mp3" length="6360185" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Do you like donuts? Here is a donut Shellcode Delivered Through PowerShell Python
https://isc.sans.edu/diary/Do%20you%20Like%20Donuts%3F%20Here%20is%20a%20Donut%20Shellcode%20Delivered%20Through%20PowerShell%20Python/31182
 How Vulnerabilities in...</itunes:subtitle><itunes:summary><![CDATA[Do you like donuts? Here is a donut Shellcode Delivered Through PowerShell Python<br /><a href="https://isc.sans.edu/diary/Do%20you%20Like%20Donuts%3F%20Here%20is%20a%20Donut%20Shellcode%20Delivered%20Through%20PowerShell%20Python/31182" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Do%20you%20Like%20Donuts%3F%20Here%20is%20a%20Donut%20Shellcode%20Delivered%20Through%20PowerShell%20Python/31182</a><br /> How Vulnerabilities in Microsoft Apps for MacOS allow Stealing Permissions<br /><a href="https://blog.talosintelligence.com/how-multiple-vulnerabilities-in-microsoft-apps-for-macos-pave-the-way-to-stealing-permissions/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/how-multiple-vulnerabilities-in-microsoft-apps-for-macos-pave-the-way-to-stealing-permissions/</a><br /> Digital Wallet Security Loophole<br /><a href="https://www.umass.edu/news/article/new-study-reveals-loophole-digital-wallet-security-even-if-rightful-cardholder-doesnt" target="_blank" rel="noreferrer noopener">https://www.umass.edu/news/article/new-study-reveals-loophole-digital-wallet-security-even-if-rightful-cardholder-doesnt</a><br /> Microsoft IPv6 Vulnerability CVE-2024-38063<br /><a href="https://x.com/f4rmpoet/status/1825472703223992323" target="_blank" rel="noreferrer noopener">https://x.com/f4rmpoet/status/1825472703223992323</a><br /> YouTube Video (going live 10am ET) <br /><a href="https://www.youtube.com/watch?v=miBb1llFOYQ" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=miBb1llFOYQ</a><br />]]></itunes:summary><itunes:duration>433</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,python; donut; macos; apps; mi,security,youtube; ipv6; microsoft; cve-</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9104</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, August 20th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-august-20th-2024--61087905</link><description><![CDATA[Do you like donuts? Here is a donut Shellcode Delivered Through PowerShell Python<br /><a href="https://isc.sans.edu/diary/Do%20you%20Like%20Donuts%3F%20Here%20is%20a%20Donut%20Shellcode%20Delivered%20Through%20PowerShell%20Python/31182" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Do%20you%20Like%20Donuts%3F%20Here%20is%20a%20Donut%20Shellcode%20Delivered%20Through%20PowerShell%20Python/31182</a><br /> How Vulnerabilities in Microsoft Apps for MacOS allow Stealing Permissions<br /><a href="https://blog.talosintelligence.com/how-multiple-vulnerabilities-in-microsoft-apps-for-macos-pave-the-way-to-stealing-permissions/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/how-multiple-vulnerabilities-in-microsoft-apps-for-macos-pave-the-way-to-stealing-permissions/</a><br /> Digital Wallet Security Loophole<br /><a href="https://www.umass.edu/news/article/new-study-reveals-loophole-digital-wallet-security-even-if-rightful-cardholder-doesnt" target="_blank" rel="noreferrer noopener">https://www.umass.edu/news/article/new-study-reveals-loophole-digital-wallet-security-even-if-rightful-cardholder-doesnt</a><br /> Microsoft IPv6 Vulnerability CVE-2024-38063<br /><a href="https://x.com/f4rmpoet/status/1825472703223992323" target="_blank" rel="noreferrer noopener">https://x.com/f4rmpoet/status/1825472703223992323</a><br /> YouTube Video (going live 10am ET) <br /><a href="https://www.youtube.com/watch?v=miBb1llFOYQ" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=miBb1llFOYQ</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9104.mp3</guid><pubDate>Tue, 20 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61087905/9104.mp3" length="6360185" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Do you like donuts? Here is a donut Shellcode Delivered Through PowerShell Python
https://isc.sans.edu/diary/Do%20you%20Like%20Donuts%3F%20Here%20is%20a%20Donut%20Shellcode%20Delivered%20Through%20PowerShell%20Python/31182
 How Vulnerabilities in...</itunes:subtitle><itunes:summary><![CDATA[Do you like donuts? Here is a donut Shellcode Delivered Through PowerShell Python<br /><a href="https://isc.sans.edu/diary/Do%20you%20Like%20Donuts%3F%20Here%20is%20a%20Donut%20Shellcode%20Delivered%20Through%20PowerShell%20Python/31182" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Do%20you%20Like%20Donuts%3F%20Here%20is%20a%20Donut%20Shellcode%20Delivered%20Through%20PowerShell%20Python/31182</a><br /> How Vulnerabilities in Microsoft Apps for MacOS allow Stealing Permissions<br /><a href="https://blog.talosintelligence.com/how-multiple-vulnerabilities-in-microsoft-apps-for-macos-pave-the-way-to-stealing-permissions/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/how-multiple-vulnerabilities-in-microsoft-apps-for-macos-pave-the-way-to-stealing-permissions/</a><br /> Digital Wallet Security Loophole<br /><a href="https://www.umass.edu/news/article/new-study-reveals-loophole-digital-wallet-security-even-if-rightful-cardholder-doesnt" target="_blank" rel="noreferrer noopener">https://www.umass.edu/news/article/new-study-reveals-loophole-digital-wallet-security-even-if-rightful-cardholder-doesnt</a><br /> Microsoft IPv6 Vulnerability CVE-2024-38063<br /><a href="https://x.com/f4rmpoet/status/1825472703223992323" target="_blank" rel="noreferrer noopener">https://x.com/f4rmpoet/status/1825472703223992323</a><br /> YouTube Video (going live 10am ET) <br /><a href="https://www.youtube.com/watch?v=miBb1llFOYQ" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=miBb1llFOYQ</a><br />]]></itunes:summary><itunes:duration>433</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,python; donut; macos; apps; mi,security,youtube; ipv6; microsoft; cve-</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9104</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, August 19th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-august-19th-2024--62129301</link><description><![CDATA[Summarizing Web Honeypot Logs<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%207%20minutes%20and%204%20steps%20to%20a%20quick%20win%3A%20A%20write-up%20on%20custom%20tools/31170" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%207%20minutes%20and%204%20steps%20to%20a%20quick%20win%3A%20A%20write-up%20on%20custom%20tools/31170</a><br /> Large Scale Cloud Extortion Operation<br /><a href="https://unit42.paloaltonetworks.com/large-scale-cloud-extortion-operation/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/large-scale-cloud-extortion-operation/</a><br /> Chrome Redacting Credit Cards and Passwords when you share Android Screens<br /><a href="https://www.bleepingcomputer.com/news/google/chrome-will-redact-credit-cards-passwords-when-you-share-android-screen/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/google/chrome-will-redact-credit-cards-passwords-when-you-share-android-screen/</a><br /> Google Products Targeted by Search Ad Scammers<br /><a href="https://www.malwarebytes.com/blog/scams/2024/08/dozens-of-google-products-targeted-by-scammers-via-malicious-search-ads" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/scams/2024/08/dozens-of-google-products-targeted-by-scammers-via-malicious-search-ads</a><br /> MakeShift: Security Analysis of Shimano Di2 Wireless Gear Shifting in Bicyles<br /><a href="https://www.usenix.org/system/files/woot24-motallebighomi.pdf" target="_blank" rel="noreferrer noopener">https://www.usenix.org/system/files/woot24-motallebighomi.pdf</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9102.mp3</guid><pubDate>Mon, 19 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129301/9102.mp3" length="5436286" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Summarizing Web Honeypot Logs
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%207%20minutes%20and%204%20steps%20to%20a%20quick%20win%3A%20A%20write-up%20on%20custom%20tools/31170
 Large Scale Cloud Extortion Operation...</itunes:subtitle><itunes:summary><![CDATA[Summarizing Web Honeypot Logs<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%207%20minutes%20and%204%20steps%20to%20a%20quick%20win%3A%20A%20write-up%20on%20custom%20tools/31170" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%207%20minutes%20and%204%20steps%20to%20a%20quick%20win%3A%20A%20write-up%20on%20custom%20tools/31170</a><br /> Large Scale Cloud Extortion Operation<br /><a href="https://unit42.paloaltonetworks.com/large-scale-cloud-extortion-operation/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/large-scale-cloud-extortion-operation/</a><br /> Chrome Redacting Credit Cards and Passwords when you share Android Screens<br /><a href="https://www.bleepingcomputer.com/news/google/chrome-will-redact-credit-cards-passwords-when-you-share-android-screen/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/google/chrome-will-redact-credit-cards-passwords-when-you-share-android-screen/</a><br /> Google Products Targeted by Search Ad Scammers<br /><a href="https://www.malwarebytes.com/blog/scams/2024/08/dozens-of-google-products-targeted-by-scammers-via-malicious-search-ads" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/scams/2024/08/dozens-of-google-products-targeted-by-scammers-via-malicious-search-ads</a><br /> MakeShift: Security Analysis of Shimano Di2 Wireless Gear Shifting in Bicyles<br /><a href="https://www.usenix.org/system/files/woot24-motallebighomi.pdf" target="_blank" rel="noreferrer noopener">https://www.usenix.org/system/files/woot24-motallebighomi.pdf</a><br />]]></itunes:summary><itunes:duration>367</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,shimano; bike; shifter; google</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9102</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, August 19th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-august-19th-2024--61075918</link><description><![CDATA[Summarizing Web Honeypot Logs<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%207%20minutes%20and%204%20steps%20to%20a%20quick%20win%3A%20A%20write-up%20on%20custom%20tools/31170" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%207%20minutes%20and%204%20steps%20to%20a%20quick%20win%3A%20A%20write-up%20on%20custom%20tools/31170</a><br /> Large Scale Cloud Extortion Operation<br /><a href="https://unit42.paloaltonetworks.com/large-scale-cloud-extortion-operation/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/large-scale-cloud-extortion-operation/</a><br /> Chrome Redacting Credit Cards and Passwords when you share Android Screens<br /><a href="https://www.bleepingcomputer.com/news/google/chrome-will-redact-credit-cards-passwords-when-you-share-android-screen/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/google/chrome-will-redact-credit-cards-passwords-when-you-share-android-screen/</a><br /> Google Products Targeted by Search Ad Scammers<br /><a href="https://www.malwarebytes.com/blog/scams/2024/08/dozens-of-google-products-targeted-by-scammers-via-malicious-search-ads" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/scams/2024/08/dozens-of-google-products-targeted-by-scammers-via-malicious-search-ads</a><br /> MakeShift: Security Analysis of Shimano Di2 Wireless Gear Shifting in Bicyles<br /><a href="https://www.usenix.org/system/files/woot24-motallebighomi.pdf" target="_blank" rel="noreferrer noopener">https://www.usenix.org/system/files/woot24-motallebighomi.pdf</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9102.mp3</guid><pubDate>Mon, 19 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61075918/9102.mp3" length="5436286" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Summarizing Web Honeypot Logs
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%207%20minutes%20and%204%20steps%20to%20a%20quick%20win%3A%20A%20write-up%20on%20custom%20tools/31170
 Large Scale Cloud Extortion Operation...</itunes:subtitle><itunes:summary><![CDATA[Summarizing Web Honeypot Logs<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%207%20minutes%20and%204%20steps%20to%20a%20quick%20win%3A%20A%20write-up%20on%20custom%20tools/31170" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%207%20minutes%20and%204%20steps%20to%20a%20quick%20win%3A%20A%20write-up%20on%20custom%20tools/31170</a><br /> Large Scale Cloud Extortion Operation<br /><a href="https://unit42.paloaltonetworks.com/large-scale-cloud-extortion-operation/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/large-scale-cloud-extortion-operation/</a><br /> Chrome Redacting Credit Cards and Passwords when you share Android Screens<br /><a href="https://www.bleepingcomputer.com/news/google/chrome-will-redact-credit-cards-passwords-when-you-share-android-screen/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/google/chrome-will-redact-credit-cards-passwords-when-you-share-android-screen/</a><br /> Google Products Targeted by Search Ad Scammers<br /><a href="https://www.malwarebytes.com/blog/scams/2024/08/dozens-of-google-products-targeted-by-scammers-via-malicious-search-ads" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/scams/2024/08/dozens-of-google-products-targeted-by-scammers-via-malicious-search-ads</a><br /> MakeShift: Security Analysis of Shimano Di2 Wireless Gear Shifting in Bicyles<br /><a href="https://www.usenix.org/system/files/woot24-motallebighomi.pdf" target="_blank" rel="noreferrer noopener">https://www.usenix.org/system/files/woot24-motallebighomi.pdf</a><br />]]></itunes:summary><itunes:duration>367</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,shimano; bike; shifter; google</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9102</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, August 16th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-august-16th-2024--62129305</link><description><![CDATA[Wireshark 4.4.0 rc 1 Custom Columns<br /><a href="https://isc.sans.edu/diary/Wireshark%204.4.0rc1%27s%20Custom%20Columns/31174" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Wireshark%204.4.0rc1%27s%20Custom%20Columns/31174</a><br /> Github Repo Artifact Leak Tokens<br /><a href="https://unit42.paloaltonetworks.com/github-repo-artifacts-leak-tokens/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/github-repo-artifacts-leak-tokens/</a><br /> BitLocker Security Feature Bypass Vulnerability<br /><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-38058" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-38058</a><br /> Solarwindws Hotfix<br /><a href="https://support.solarwinds.com/SuccessCenter/s/article/WHD-12-8-3-Hotfix-1" target="_blank" rel="noreferrer noopener">https://support.solarwinds.com/SuccessCenter/s/article/WHD-12-8-3-Hotfix-1</a><br /> Ed Skoudis, Paul Maurer: The Code of Honor<br /><a href="https://cybercodeofhonor.com/" target="_blank" rel="noreferrer noopener">https://cybercodeofhonor.com/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9100.mp3</guid><pubDate>Fri, 16 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129305/9100.mp3" length="14914019" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Wireshark 4.4.0 rc 1 Custom Columns
https://isc.sans.edu/diary/Wireshark%204.4.0rc1%27s%20Custom%20Columns/31174
 Github Repo Artifact Leak Tokens
https://unit42.paloaltonetworks.com/github-repo-artifacts-leak-tokens/
 BitLocker Security Feature...</itunes:subtitle><itunes:summary><![CDATA[Wireshark 4.4.0 rc 1 Custom Columns<br /><a href="https://isc.sans.edu/diary/Wireshark%204.4.0rc1%27s%20Custom%20Columns/31174" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Wireshark%204.4.0rc1%27s%20Custom%20Columns/31174</a><br /> Github Repo Artifact Leak Tokens<br /><a href="https://unit42.paloaltonetworks.com/github-repo-artifacts-leak-tokens/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/github-repo-artifacts-leak-tokens/</a><br /> BitLocker Security Feature Bypass Vulnerability<br /><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-38058" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-38058</a><br /> Solarwindws Hotfix<br /><a href="https://support.solarwinds.com/SuccessCenter/s/article/WHD-12-8-3-Hotfix-1" target="_blank" rel="noreferrer noopener">https://support.solarwinds.com/SuccessCenter/s/article/WHD-12-8-3-Hotfix-1</a><br /> Ed Skoudis, Paul Maurer: The Code of Honor<br /><a href="https://cybercodeofhonor.com/" target="_blank" rel="noreferrer noopener">https://cybercodeofhonor.com/</a><br />]]></itunes:summary><itunes:duration>1044</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,honor; code; ethids; skoudis; ,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9100</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, August 16th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-august-16th-2024--61047643</link><description><![CDATA[Wireshark 4.4.0 rc 1 Custom Columns<br /><a href="https://isc.sans.edu/diary/Wireshark%204.4.0rc1%27s%20Custom%20Columns/31174" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Wireshark%204.4.0rc1%27s%20Custom%20Columns/31174</a><br /> Github Repo Artifact Leak Tokens<br /><a href="https://unit42.paloaltonetworks.com/github-repo-artifacts-leak-tokens/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/github-repo-artifacts-leak-tokens/</a><br /> BitLocker Security Feature Bypass Vulnerability<br /><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-38058" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-38058</a><br /> Solarwindws Hotfix<br /><a href="https://support.solarwinds.com/SuccessCenter/s/article/WHD-12-8-3-Hotfix-1" target="_blank" rel="noreferrer noopener">https://support.solarwinds.com/SuccessCenter/s/article/WHD-12-8-3-Hotfix-1</a><br /> Ed Skoudis, Paul Maurer: The Code of Honor<br /><a href="https://cybercodeofhonor.com/" target="_blank" rel="noreferrer noopener">https://cybercodeofhonor.com/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9100.mp3</guid><pubDate>Fri, 16 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61047643/9100.mp3" length="14914019" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Wireshark 4.4.0 rc 1 Custom Columns
https://isc.sans.edu/diary/Wireshark%204.4.0rc1%27s%20Custom%20Columns/31174
 Github Repo Artifact Leak Tokens
https://unit42.paloaltonetworks.com/github-repo-artifacts-leak-tokens/
 BitLocker Security Feature...</itunes:subtitle><itunes:summary><![CDATA[Wireshark 4.4.0 rc 1 Custom Columns<br /><a href="https://isc.sans.edu/diary/Wireshark%204.4.0rc1%27s%20Custom%20Columns/31174" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Wireshark%204.4.0rc1%27s%20Custom%20Columns/31174</a><br /> Github Repo Artifact Leak Tokens<br /><a href="https://unit42.paloaltonetworks.com/github-repo-artifacts-leak-tokens/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/github-repo-artifacts-leak-tokens/</a><br /> BitLocker Security Feature Bypass Vulnerability<br /><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-38058" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-38058</a><br /> Solarwindws Hotfix<br /><a href="https://support.solarwinds.com/SuccessCenter/s/article/WHD-12-8-3-Hotfix-1" target="_blank" rel="noreferrer noopener">https://support.solarwinds.com/SuccessCenter/s/article/WHD-12-8-3-Hotfix-1</a><br /> Ed Skoudis, Paul Maurer: The Code of Honor<br /><a href="https://cybercodeofhonor.com/" target="_blank" rel="noreferrer noopener">https://cybercodeofhonor.com/</a><br />]]></itunes:summary><itunes:duration>1044</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,honor; code; ethids; skoudis; ,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9100</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, August 15th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-august-15th-2024--62129314</link><description><![CDATA[MSI Malware<br /><a href="https://isc.sans.edu/diary/Multiple%20Malware%20Dropped%20Through%20MSI%20Package/31168" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Multiple%20Malware%20Dropped%20Through%20MSI%20Package/31168</a><br /> Microsoft IPv6 Vulnerablity CVE-2024-38063<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38063" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38063</a><br /><a href="https://x.com/XiaoWei___/status/1823532146679799993/photo/1" target="_blank" rel="noreferrer noopener">https://x.com/XiaoWei___/status/1823532146679799993/photo/1</a><br /> Critical Ivanti Virtual Traffic Manager Patch CVE-2024-7593<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Virtual-Traffic-Manager-vTM-CVE-2024-7593?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Virtual-Traffic-Manager-vTM-CVE-2024-7593?language=en_US</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9098.mp3</guid><pubDate>Thu, 15 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129314/9098.mp3" length="5921768" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>MSI Malware
https://isc.sans.edu/diary/Multiple%20Malware%20Dropped%20Through%20MSI%20Package/31168
 Microsoft IPv6 Vulnerablity CVE-2024-38063
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38063...</itunes:subtitle><itunes:summary><![CDATA[MSI Malware<br /><a href="https://isc.sans.edu/diary/Multiple%20Malware%20Dropped%20Through%20MSI%20Package/31168" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Multiple%20Malware%20Dropped%20Through%20MSI%20Package/31168</a><br /> Microsoft IPv6 Vulnerablity CVE-2024-38063<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38063" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38063</a><br /><a href="https://x.com/XiaoWei___/status/1823532146679799993/photo/1" target="_blank" rel="noreferrer noopener">https://x.com/XiaoWei___/status/1823532146679799993/photo/1</a><br /> Critical Ivanti Virtual Traffic Manager Patch CVE-2024-7593<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Virtual-Traffic-Manager-vTM-CVE-2024-7593?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Virtual-Traffic-Manager-vTM-CVE-2024-7593?language=en_US</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br />]]></itunes:summary><itunes:duration>401</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,ivanti; adobe; traffic manager,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9098</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, August 15th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-august-15th-2024--61032722</link><description><![CDATA[MSI Malware<br /><a href="https://isc.sans.edu/diary/Multiple%20Malware%20Dropped%20Through%20MSI%20Package/31168" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Multiple%20Malware%20Dropped%20Through%20MSI%20Package/31168</a><br /> Microsoft IPv6 Vulnerablity CVE-2024-38063<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38063" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38063</a><br /><a href="https://x.com/XiaoWei___/status/1823532146679799993/photo/1" target="_blank" rel="noreferrer noopener">https://x.com/XiaoWei___/status/1823532146679799993/photo/1</a><br /> Critical Ivanti Virtual Traffic Manager Patch CVE-2024-7593<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Virtual-Traffic-Manager-vTM-CVE-2024-7593?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Virtual-Traffic-Manager-vTM-CVE-2024-7593?language=en_US</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9098.mp3</guid><pubDate>Thu, 15 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61032722/9098.mp3" length="5921768" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>MSI Malware
https://isc.sans.edu/diary/Multiple%20Malware%20Dropped%20Through%20MSI%20Package/31168
 Microsoft IPv6 Vulnerablity CVE-2024-38063
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38063...</itunes:subtitle><itunes:summary><![CDATA[MSI Malware<br /><a href="https://isc.sans.edu/diary/Multiple%20Malware%20Dropped%20Through%20MSI%20Package/31168" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Multiple%20Malware%20Dropped%20Through%20MSI%20Package/31168</a><br /> Microsoft IPv6 Vulnerablity CVE-2024-38063<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38063" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38063</a><br /><a href="https://x.com/XiaoWei___/status/1823532146679799993/photo/1" target="_blank" rel="noreferrer noopener">https://x.com/XiaoWei___/status/1823532146679799993/photo/1</a><br /> Critical Ivanti Virtual Traffic Manager Patch CVE-2024-7593<br /><a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Virtual-Traffic-Manager-vTM-CVE-2024-7593?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Virtual-Traffic-Manager-vTM-CVE-2024-7593?language=en_US</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br />]]></itunes:summary><itunes:duration>401</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,ivanti; adobe; traffic manager,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9098</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, August 14th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-august-14th-2024--62129315</link><description><![CDATA[Microsoft August 2024 Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20August%202024%20Patch%20Tuesday/31164" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20August%202024%20Patch%20Tuesday/31164</a><br /> NIST Finalizes Post Quantum Encryption Standards<br /><a href="https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards" target="_blank" rel="noreferrer noopener">https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards</a><br /> Zabbix Network Monitoring Updates<br /><a href="https://support.zabbix.com/browse/ZBX-25016" target="_blank" rel="noreferrer noopener">https://support.zabbix.com/browse/ZBX-25016</a><br /><a href="https://support.zabbix.com/browse/ZBX-25013" target="_blank" rel="noreferrer noopener">https://support.zabbix.com/browse/ZBX-25013</a><br />  (and others)<br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9096.mp3</guid><pubDate>Wed, 14 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129315/9096.mp3" length="5498760" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft August 2024 Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20August%202024%20Patch%20Tuesday/31164
 NIST Finalizes Post Quantum Encryption Standards...</itunes:subtitle><itunes:summary><![CDATA[Microsoft August 2024 Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20August%202024%20Patch%20Tuesday/31164" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20August%202024%20Patch%20Tuesday/31164</a><br /> NIST Finalizes Post Quantum Encryption Standards<br /><a href="https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards" target="_blank" rel="noreferrer noopener">https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards</a><br /> Zabbix Network Monitoring Updates<br /><a href="https://support.zabbix.com/browse/ZBX-25016" target="_blank" rel="noreferrer noopener">https://support.zabbix.com/browse/ZBX-25016</a><br /><a href="https://support.zabbix.com/browse/ZBX-25013" target="_blank" rel="noreferrer noopener">https://support.zabbix.com/browse/ZBX-25013</a><br />  (and others)<br />]]></itunes:summary><itunes:duration>371</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,zabbix; nist; microsoft; patch</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9096</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, August 14th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-august-14th-2024--61020976</link><description><![CDATA[Microsoft August 2024 Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20August%202024%20Patch%20Tuesday/31164" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20August%202024%20Patch%20Tuesday/31164</a><br /> NIST Finalizes Post Quantum Encryption Standards<br /><a href="https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards" target="_blank" rel="noreferrer noopener">https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards</a><br /> Zabbix Network Monitoring Updates<br /><a href="https://support.zabbix.com/browse/ZBX-25016" target="_blank" rel="noreferrer noopener">https://support.zabbix.com/browse/ZBX-25016</a><br /><a href="https://support.zabbix.com/browse/ZBX-25013" target="_blank" rel="noreferrer noopener">https://support.zabbix.com/browse/ZBX-25013</a><br />  (and others)<br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9096.mp3</guid><pubDate>Wed, 14 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61020976/9096.mp3" length="5498760" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft August 2024 Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20August%202024%20Patch%20Tuesday/31164
 NIST Finalizes Post Quantum Encryption Standards...</itunes:subtitle><itunes:summary><![CDATA[Microsoft August 2024 Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20August%202024%20Patch%20Tuesday/31164" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20August%202024%20Patch%20Tuesday/31164</a><br /> NIST Finalizes Post Quantum Encryption Standards<br /><a href="https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards" target="_blank" rel="noreferrer noopener">https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards</a><br /> Zabbix Network Monitoring Updates<br /><a href="https://support.zabbix.com/browse/ZBX-25016" target="_blank" rel="noreferrer noopener">https://support.zabbix.com/browse/ZBX-25016</a><br /><a href="https://support.zabbix.com/browse/ZBX-25013" target="_blank" rel="noreferrer noopener">https://support.zabbix.com/browse/ZBX-25013</a><br />  (and others)<br />]]></itunes:summary><itunes:duration>371</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,zabbix; nist; microsoft; patch</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9096</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, August 13th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-august-13th-2024--62129320</link><description><![CDATA[QuickShell: Sharing is Caring about an RCE Attack Chain on Quick Share<br /><a href="https://www.safebreach.com/blog/rce-attack-chain-on-quick-share" target="_blank" rel="noreferrer noopener">https://www.safebreach.com/blog/rce-attack-chain-on-quick-share</a><br /> Chrome, Edge users beset by malicious extensions that can t be easily removed<br /><a href="https://www.helpnetsecurity.com/2024/08/12/chrome-edge-malicious-browser-extensions/" target="_blank" rel="noreferrer noopener">https://www.helpnetsecurity.com/2024/08/12/chrome-edge-malicious-browser-extensions/</a><br /> AMD Guest Memory Vulnerabilities<br /><a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7014.html" target="_blank" rel="noreferrer noopener">https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7014.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9094.mp3</guid><pubDate>Tue, 13 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129320/9094.mp3" length="4943090" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>QuickShell: Sharing is Caring about an RCE Attack Chain on Quick Share
https://www.safebreach.com/blog/rce-attack-chain-on-quick-share
 Chrome, Edge users beset by malicious extensions that can t be easily removed...</itunes:subtitle><itunes:summary><![CDATA[QuickShell: Sharing is Caring about an RCE Attack Chain on Quick Share<br /><a href="https://www.safebreach.com/blog/rce-attack-chain-on-quick-share" target="_blank" rel="noreferrer noopener">https://www.safebreach.com/blog/rce-attack-chain-on-quick-share</a><br /> Chrome, Edge users beset by malicious extensions that can t be easily removed<br /><a href="https://www.helpnetsecurity.com/2024/08/12/chrome-edge-malicious-browser-extensions/" target="_blank" rel="noreferrer noopener">https://www.helpnetsecurity.com/2024/08/12/chrome-edge-malicious-browser-extensions/</a><br /> AMD Guest Memory Vulnerabilities<br /><a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7014.html" target="_blank" rel="noreferrer noopener">https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7014.html</a><br />]]></itunes:summary><itunes:duration>331</itunes:duration><itunes:keywords>amd; flaw; smm; chrome; edge; ,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9094</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, August 13th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-august-13th-2024--61009032</link><description><![CDATA[QuickShell: Sharing is Caring about an RCE Attack Chain on Quick Share<br /><a href="https://www.safebreach.com/blog/rce-attack-chain-on-quick-share" target="_blank" rel="noreferrer noopener">https://www.safebreach.com/blog/rce-attack-chain-on-quick-share</a><br /> Chrome, Edge users beset by malicious extensions that can t be easily removed<br /><a href="https://www.helpnetsecurity.com/2024/08/12/chrome-edge-malicious-browser-extensions/" target="_blank" rel="noreferrer noopener">https://www.helpnetsecurity.com/2024/08/12/chrome-edge-malicious-browser-extensions/</a><br /> AMD Guest Memory Vulnerabilities<br /><a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7014.html" target="_blank" rel="noreferrer noopener">https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7014.html</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9094.mp3</guid><pubDate>Tue, 13 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/61009032/9094.mp3" length="4943090" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>QuickShell: Sharing is Caring about an RCE Attack Chain on Quick Share
https://www.safebreach.com/blog/rce-attack-chain-on-quick-share
 Chrome, Edge users beset by malicious extensions that can t be easily removed...</itunes:subtitle><itunes:summary><![CDATA[QuickShell: Sharing is Caring about an RCE Attack Chain on Quick Share<br /><a href="https://www.safebreach.com/blog/rce-attack-chain-on-quick-share" target="_blank" rel="noreferrer noopener">https://www.safebreach.com/blog/rce-attack-chain-on-quick-share</a><br /> Chrome, Edge users beset by malicious extensions that can t be easily removed<br /><a href="https://www.helpnetsecurity.com/2024/08/12/chrome-edge-malicious-browser-extensions/" target="_blank" rel="noreferrer noopener">https://www.helpnetsecurity.com/2024/08/12/chrome-edge-malicious-browser-extensions/</a><br /> AMD Guest Memory Vulnerabilities<br /><a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7014.html" target="_blank" rel="noreferrer noopener">https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7014.html</a><br />]]></itunes:summary><itunes:duration>331</itunes:duration><itunes:keywords>amd; flaw; smm; chrome; edge; ,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9094</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, August 12th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-august-12th-2024--62129325</link><description><![CDATA[CORS/SameOrigin Video<br /><a href="https://isc.sans.edu/forums/diary/Video%3A%20Same%20Origin%2C%20CORS%2C%20DNS%20Rebinding%20and%20Localhost/31158/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Video%3A%20Same%20Origin%2C%20CORS%2C%20DNS%20Rebinding%20and%20Localhost/31158/</a><br /> Splitting the email atom: exploiting parsers to bypass access controls<br /><a href="https://portswigger.net/research/splitting-the-email-atom#parser-discrepancies" target="_blank" rel="noreferrer noopener">https://portswigger.net/research/splitting-the-email-atom#parser-discrepancies</a><br /> Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!<br /><a href="https://blog.orange.tw/2024/08/confusion-attacks-en.html" target="_blank" rel="noreferrer noopener">https://blog.orange.tw/2024/08/confusion-attacks-en.html</a><br /> GL-Inet Patches<br /><a href="https://www.gl-inet.com/security-updates/security-advisories-vulnerabilities-and-cves-aug-1-2024/" target="_blank" rel="noreferrer noopener">https://www.gl-inet.com/security-updates/security-advisories-vulnerabilities-and-cves-aug-1-2024/</a><br /> Microsoft Office Spoofing Vulnerability<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38200" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38200</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9092.mp3</guid><pubDate>Mon, 12 Aug 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129325/9092.mp3" length="5217017" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>CORS/SameOrigin Video
https://isc.sans.edu/forums/diary/Video%3A%20Same%20Origin%2C%20CORS%2C%20DNS%20Rebinding%20and%20Localhost/31158/
 Splitting the email atom: exploiting parsers to bypass access controls...</itunes:subtitle><itunes:summary><![CDATA[CORS/SameOrigin Video<br /><a href="https://isc.sans.edu/forums/diary/Video%3A%20Same%20Origin%2C%20CORS%2C%20DNS%20Rebinding%20and%20Localhost/31158/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Video%3A%20Same%20Origin%2C%20CORS%2C%20DNS%20Rebinding%20and%20Localhost/31158/</a><br /> Splitting the email atom: exploiting parsers to bypass access controls<br /><a href="https://portswigger.net/research/splitting-the-email-atom#parser-discrepancies" target="_blank" rel="noreferrer noopener">https://portswigger.net/research/splitting-the-email-atom#parser-discrepancies</a><br /> Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!<br /><a href="https://blog.orange.tw/2024/08/confusion-attacks-en.html" target="_blank" rel="noreferrer noopener">https://blog.orange.tw/2024/08/confusion-attacks-en.html</a><br /> GL-Inet Patches<br /><a href="https://www.gl-inet.com/security-updates/security-advisories-vulnerabilities-and-cves-aug-1-2024/" target="_blank" rel="noreferrer noopener">https://www.gl-inet.com/security-updates/security-advisories-vulnerabilities-and-cves-aug-1-2024/</a><br /> Microsoft Office Spoofing Vulnerability<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38200" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38200</a><br />]]></itunes:summary><itunes:duration>351</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microsoft; office; gl-inet; co,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9092</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, August 12th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-august-12th-2024--60995466</link><description><![CDATA[CORS/SameOrigin Video<br /><a href="https://isc.sans.edu/forums/diary/Video%3A%20Same%20Origin%2C%20CORS%2C%20DNS%20Rebinding%20and%20Localhost/31158/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Video%3A%20Same%20Origin%2C%20CORS%2C%20DNS%20Rebinding%20and%20Localhost/31158/</a><br /> Splitting the email atom: exploiting parsers to bypass access controls<br /><a href="https://portswigger.net/research/splitting-the-email-atom#parser-discrepancies" target="_blank" rel="noreferrer noopener">https://portswigger.net/research/splitting-the-email-atom#parser-discrepancies</a><br /> Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!<br /><a href="https://blog.orange.tw/2024/08/confusion-attacks-en.html" target="_blank" rel="noreferrer noopener">https://blog.orange.tw/2024/08/confusion-attacks-en.html</a><br /> GL-Inet Patches<br /><a href="https://www.gl-inet.com/security-updates/security-advisories-vulnerabilities-and-cves-aug-1-2024/" target="_blank" rel="noreferrer noopener">https://www.gl-inet.com/security-updates/security-advisories-vulnerabilities-and-cves-aug-1-2024/</a><br /> Microsoft Office Spoofing Vulnerability<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38200" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38200</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9092.mp3</guid><pubDate>Mon, 12 Aug 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60995466/9092.mp3" length="5217017" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>CORS/SameOrigin Video
https://isc.sans.edu/forums/diary/Video%3A%20Same%20Origin%2C%20CORS%2C%20DNS%20Rebinding%20and%20Localhost/31158/
 Splitting the email atom: exploiting parsers to bypass access controls...</itunes:subtitle><itunes:summary><![CDATA[CORS/SameOrigin Video<br /><a href="https://isc.sans.edu/forums/diary/Video%3A%20Same%20Origin%2C%20CORS%2C%20DNS%20Rebinding%20and%20Localhost/31158/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Video%3A%20Same%20Origin%2C%20CORS%2C%20DNS%20Rebinding%20and%20Localhost/31158/</a><br /> Splitting the email atom: exploiting parsers to bypass access controls<br /><a href="https://portswigger.net/research/splitting-the-email-atom#parser-discrepancies" target="_blank" rel="noreferrer noopener">https://portswigger.net/research/splitting-the-email-atom#parser-discrepancies</a><br /> Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!<br /><a href="https://blog.orange.tw/2024/08/confusion-attacks-en.html" target="_blank" rel="noreferrer noopener">https://blog.orange.tw/2024/08/confusion-attacks-en.html</a><br /> GL-Inet Patches<br /><a href="https://www.gl-inet.com/security-updates/security-advisories-vulnerabilities-and-cves-aug-1-2024/" target="_blank" rel="noreferrer noopener">https://www.gl-inet.com/security-updates/security-advisories-vulnerabilities-and-cves-aug-1-2024/</a><br /> Microsoft Office Spoofing Vulnerability<br /><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38200" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38200</a><br />]]></itunes:summary><itunes:duration>351</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microsoft; office; gl-inet; co,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9092</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, August 9th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-august-9th-2024--62129296</link><description><![CDATA[Exploring Anti-Phishing Measures in Microsoft 365<br /><a href="https://certitude.consulting/blog/en/o365-anti-phishing-measures/" target="_blank" rel="noreferrer noopener">https://certitude.consulting/blog/en/o365-anti-phishing-measures/</a><br /> SSHamble Security Testing Tool<br /><a href="https://www.runzero.com/blog/sshamble-unexpected-exposures-in-the-secure-shell/" target="_blank" rel="noreferrer noopener">https://www.runzero.com/blog/sshamble-unexpected-exposures-in-the-secure-shell/</a><br /> macOS Sequoia Weekly Permission Prompts<br /><a href="https://9to5mac.com/2024/08/06/macos-sequoia-screen-recording-privacy-prompt/" target="_blank" rel="noreferrer noopener">https://9to5mac.com/2024/08/06/macos-sequoia-screen-recording-privacy-prompt/</a><br /> .internal domain<br /><a href="https://www.icann.org/en/public-comment/proceeding/proposed-top-level-domain-string-for-private-use-24-01-2024" target="_blank" rel="noreferrer noopener">https://www.icann.org/en/public-comment/proceeding/proposed-top-level-domain-string-for-private-use-24-01-2024</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9090.mp3</guid><pubDate>Fri, 09 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129296/9090.mp3" length="5588406" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Exploring Anti-Phishing Measures in Microsoft 365
https://certitude.consulting/blog/en/o365-anti-phishing-measures/
 SSHamble Security Testing Tool
https://www.runzero.com/blog/sshamble-unexpected-exposures-in-the-secure-shell/
 macOS Sequoia Weekly...</itunes:subtitle><itunes:summary><![CDATA[Exploring Anti-Phishing Measures in Microsoft 365<br /><a href="https://certitude.consulting/blog/en/o365-anti-phishing-measures/" target="_blank" rel="noreferrer noopener">https://certitude.consulting/blog/en/o365-anti-phishing-measures/</a><br /> SSHamble Security Testing Tool<br /><a href="https://www.runzero.com/blog/sshamble-unexpected-exposures-in-the-secure-shell/" target="_blank" rel="noreferrer noopener">https://www.runzero.com/blog/sshamble-unexpected-exposures-in-the-secure-shell/</a><br /> macOS Sequoia Weekly Permission Prompts<br /><a href="https://9to5mac.com/2024/08/06/macos-sequoia-screen-recording-privacy-prompt/" target="_blank" rel="noreferrer noopener">https://9to5mac.com/2024/08/06/macos-sequoia-screen-recording-privacy-prompt/</a><br /> .internal domain<br /><a href="https://www.icann.org/en/public-comment/proceeding/proposed-top-level-domain-string-for-private-use-24-01-2024" target="_blank" rel="noreferrer noopener">https://www.icann.org/en/public-comment/proceeding/proposed-top-level-domain-string-for-private-use-24-01-2024</a><br />]]></itunes:summary><itunes:duration>378</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internal,internet,it,macos; sequoia; sshamble; micr,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9090</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, August 9th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-august-9th-2024--60963869</link><description><![CDATA[Exploring Anti-Phishing Measures in Microsoft 365<br /><a href="https://certitude.consulting/blog/en/o365-anti-phishing-measures/" target="_blank" rel="noreferrer noopener">https://certitude.consulting/blog/en/o365-anti-phishing-measures/</a><br /> SSHamble Security Testing Tool<br /><a href="https://www.runzero.com/blog/sshamble-unexpected-exposures-in-the-secure-shell/" target="_blank" rel="noreferrer noopener">https://www.runzero.com/blog/sshamble-unexpected-exposures-in-the-secure-shell/</a><br /> macOS Sequoia Weekly Permission Prompts<br /><a href="https://9to5mac.com/2024/08/06/macos-sequoia-screen-recording-privacy-prompt/" target="_blank" rel="noreferrer noopener">https://9to5mac.com/2024/08/06/macos-sequoia-screen-recording-privacy-prompt/</a><br /> .internal domain<br /><a href="https://www.icann.org/en/public-comment/proceeding/proposed-top-level-domain-string-for-private-use-24-01-2024" target="_blank" rel="noreferrer noopener">https://www.icann.org/en/public-comment/proceeding/proposed-top-level-domain-string-for-private-use-24-01-2024</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9090.mp3</guid><pubDate>Fri, 09 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60963869/9090.mp3" length="5588406" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Exploring Anti-Phishing Measures in Microsoft 365
https://certitude.consulting/blog/en/o365-anti-phishing-measures/
 SSHamble Security Testing Tool
https://www.runzero.com/blog/sshamble-unexpected-exposures-in-the-secure-shell/
 macOS Sequoia Weekly...</itunes:subtitle><itunes:summary><![CDATA[Exploring Anti-Phishing Measures in Microsoft 365<br /><a href="https://certitude.consulting/blog/en/o365-anti-phishing-measures/" target="_blank" rel="noreferrer noopener">https://certitude.consulting/blog/en/o365-anti-phishing-measures/</a><br /> SSHamble Security Testing Tool<br /><a href="https://www.runzero.com/blog/sshamble-unexpected-exposures-in-the-secure-shell/" target="_blank" rel="noreferrer noopener">https://www.runzero.com/blog/sshamble-unexpected-exposures-in-the-secure-shell/</a><br /> macOS Sequoia Weekly Permission Prompts<br /><a href="https://9to5mac.com/2024/08/06/macos-sequoia-screen-recording-privacy-prompt/" target="_blank" rel="noreferrer noopener">https://9to5mac.com/2024/08/06/macos-sequoia-screen-recording-privacy-prompt/</a><br /> .internal domain<br /><a href="https://www.icann.org/en/public-comment/proceeding/proposed-top-level-domain-string-for-private-use-24-01-2024" target="_blank" rel="noreferrer noopener">https://www.icann.org/en/public-comment/proceeding/proposed-top-level-domain-string-for-private-use-24-01-2024</a><br />]]></itunes:summary><itunes:duration>378</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internal,internet,it,macos; sequoia; sshamble; micr,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9090</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, August 8th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-august-8th-2024--62129332</link><description><![CDATA[0.0.0.0 Day Exploiting Localhost APIs from the Browser<br /><a href="https://www.oligo.security/blog/0-0-0-0-day-exploiting-localhost-apis-from-the-browser" target="_blank" rel="noreferrer noopener">https://www.oligo.security/blog/0-0-0-0-day-exploiting-localhost-apis-from-the-browser</a><br /> Apple Hardens Gatekeeper<br /><a href="https://developer.apple.com/news/?id=saqachfa" target="_blank" rel="noreferrer noopener">https://developer.apple.com/news/?id=saqachfa</a><br /> Downgrade Attacks Using Windows Updates<br /><a href="https://www.safebreach.com/blog/downgrade-attacks-using-windows-updates/" target="_blank" rel="noreferrer noopener">https://www.safebreach.com/blog/downgrade-attacks-using-windows-updates/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9088.mp3</guid><pubDate>Thu, 08 Aug 2024 10:50:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129332/9088.mp3" length="5625801" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>0.0.0.0 Day Exploiting Localhost APIs from the Browser
https://www.oligo.security/blog/0-0-0-0-day-exploiting-localhost-apis-from-the-browser
 Apple Hardens Gatekeeper
https://developer.apple.com/news/?id=saqachfa
 Downgrade Attacks Using Windows...</itunes:subtitle><itunes:summary><![CDATA[0.0.0.0 Day Exploiting Localhost APIs from the Browser<br /><a href="https://www.oligo.security/blog/0-0-0-0-day-exploiting-localhost-apis-from-the-browser" target="_blank" rel="noreferrer noopener">https://www.oligo.security/blog/0-0-0-0-day-exploiting-localhost-apis-from-the-browser</a><br /> Apple Hardens Gatekeeper<br /><a href="https://developer.apple.com/news/?id=saqachfa" target="_blank" rel="noreferrer noopener">https://developer.apple.com/news/?id=saqachfa</a><br /> Downgrade Attacks Using Windows Updates<br /><a href="https://www.safebreach.com/blog/downgrade-attacks-using-windows-updates/" target="_blank" rel="noreferrer noopener">https://www.safebreach.com/blog/downgrade-attacks-using-windows-updates/</a><br />]]></itunes:summary><itunes:duration>380</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,windows; updates; apple; gatek</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9088</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, August 8th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-august-8th-2024--60956633</link><description><![CDATA[0.0.0.0 Day Exploiting Localhost APIs from the Browser<br /><a href="https://www.oligo.security/blog/0-0-0-0-day-exploiting-localhost-apis-from-the-browser" target="_blank" rel="noreferrer noopener">https://www.oligo.security/blog/0-0-0-0-day-exploiting-localhost-apis-from-the-browser</a><br /> Apple Hardens Gatekeeper<br /><a href="https://developer.apple.com/news/?id=saqachfa" target="_blank" rel="noreferrer noopener">https://developer.apple.com/news/?id=saqachfa</a><br /> Downgrade Attacks Using Windows Updates<br /><a href="https://www.safebreach.com/blog/downgrade-attacks-using-windows-updates/" target="_blank" rel="noreferrer noopener">https://www.safebreach.com/blog/downgrade-attacks-using-windows-updates/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9088.mp3</guid><pubDate>Thu, 08 Aug 2024 10:50:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60956633/9088.mp3" length="5625801" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>0.0.0.0 Day Exploiting Localhost APIs from the Browser
https://www.oligo.security/blog/0-0-0-0-day-exploiting-localhost-apis-from-the-browser
 Apple Hardens Gatekeeper
https://developer.apple.com/news/?id=saqachfa
 Downgrade Attacks Using Windows...</itunes:subtitle><itunes:summary><![CDATA[0.0.0.0 Day Exploiting Localhost APIs from the Browser<br /><a href="https://www.oligo.security/blog/0-0-0-0-day-exploiting-localhost-apis-from-the-browser" target="_blank" rel="noreferrer noopener">https://www.oligo.security/blog/0-0-0-0-day-exploiting-localhost-apis-from-the-browser</a><br /> Apple Hardens Gatekeeper<br /><a href="https://developer.apple.com/news/?id=saqachfa" target="_blank" rel="noreferrer noopener">https://developer.apple.com/news/?id=saqachfa</a><br /> Downgrade Attacks Using Windows Updates<br /><a href="https://www.safebreach.com/blog/downgrade-attacks-using-windows-updates/" target="_blank" rel="noreferrer noopener">https://www.safebreach.com/blog/downgrade-attacks-using-windows-updates/</a><br />]]></itunes:summary><itunes:duration>380</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,windows; updates; apple; gatek</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9088</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, August 7th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-august-7th-2024--62129339</link><description><![CDATA[A Survey of Scans For GeoServer Vulnerabilities<br /><a href="https://isc.sans.edu/diary/A%20Survey%20of%20Scans%20for%20GeoServer%20Vulnerabilities/31148" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20Survey%20of%20Scans%20for%20GeoServer%20Vulnerabilities/31148</a><br /> Crowdstrike Root Cause Analysis<br /><a href="https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/" target="_blank" rel="noreferrer noopener">https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/</a><br /> Kibana Vulnerability<br /><a href="https://discuss.elastic.co/t/kibana-8-14-2-7-17-23-security-update-esa-2024-22/364424" target="_blank" rel="noreferrer noopener">https://discuss.elastic.co/t/kibana-8-14-2-7-17-23-security-update-esa-2024-22/364424</a><br /> Android August 2024 Bulletin<br /><a href="https://source.android.com/docs/security/bulletin/2024-08-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2024-08-01</a><br /> Ubiquity Amplication Attack Vulnerability Update<br /><a href="https://blog.checkpoint.com/research/over-20000-ubiquiti-cameras-and-routers-are-vulnerable-to-amplification-attacks-and-privacy-risks/" target="_blank" rel="noreferrer noopener">https://blog.checkpoint.com/research/over-20000-ubiquiti-cameras-and-routers-are-vulnerable-to-amplification-attacks-and-privacy-risks/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9086.mp3</guid><pubDate>Wed, 07 Aug 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129339/9086.mp3" length="5323160" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>A Survey of Scans For GeoServer Vulnerabilities
https://isc.sans.edu/diary/A%20Survey%20of%20Scans%20for%20GeoServer%20Vulnerabilities/31148
 Crowdstrike Root Cause Analysis...</itunes:subtitle><itunes:summary><![CDATA[A Survey of Scans For GeoServer Vulnerabilities<br /><a href="https://isc.sans.edu/diary/A%20Survey%20of%20Scans%20for%20GeoServer%20Vulnerabilities/31148" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20Survey%20of%20Scans%20for%20GeoServer%20Vulnerabilities/31148</a><br /> Crowdstrike Root Cause Analysis<br /><a href="https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/" target="_blank" rel="noreferrer noopener">https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/</a><br /> Kibana Vulnerability<br /><a href="https://discuss.elastic.co/t/kibana-8-14-2-7-17-23-security-update-esa-2024-22/364424" target="_blank" rel="noreferrer noopener">https://discuss.elastic.co/t/kibana-8-14-2-7-17-23-security-update-esa-2024-22/364424</a><br /> Android August 2024 Bulletin<br /><a href="https://source.android.com/docs/security/bulletin/2024-08-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2024-08-01</a><br /> Ubiquity Amplication Attack Vulnerability Update<br /><a href="https://blog.checkpoint.com/research/over-20000-ubiquiti-cameras-and-routers-are-vulnerable-to-amplification-attacks-and-privacy-risks/" target="_blank" rel="noreferrer noopener">https://blog.checkpoint.com/research/over-20000-ubiquiti-cameras-and-routers-are-vulnerable-to-amplification-attacks-and-privacy-risks/</a><br />]]></itunes:summary><itunes:duration>359</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,geoserver; crowdstrike; kibana,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9086</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, August 7th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-august-7th-2024--60943419</link><description><![CDATA[A Survey of Scans For GeoServer Vulnerabilities<br /><a href="https://isc.sans.edu/diary/A%20Survey%20of%20Scans%20for%20GeoServer%20Vulnerabilities/31148" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20Survey%20of%20Scans%20for%20GeoServer%20Vulnerabilities/31148</a><br /> Crowdstrike Root Cause Analysis<br /><a href="https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/" target="_blank" rel="noreferrer noopener">https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/</a><br /> Kibana Vulnerability<br /><a href="https://discuss.elastic.co/t/kibana-8-14-2-7-17-23-security-update-esa-2024-22/364424" target="_blank" rel="noreferrer noopener">https://discuss.elastic.co/t/kibana-8-14-2-7-17-23-security-update-esa-2024-22/364424</a><br /> Android August 2024 Bulletin<br /><a href="https://source.android.com/docs/security/bulletin/2024-08-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2024-08-01</a><br /> Ubiquity Amplication Attack Vulnerability Update<br /><a href="https://blog.checkpoint.com/research/over-20000-ubiquiti-cameras-and-routers-are-vulnerable-to-amplification-attacks-and-privacy-risks/" target="_blank" rel="noreferrer noopener">https://blog.checkpoint.com/research/over-20000-ubiquiti-cameras-and-routers-are-vulnerable-to-amplification-attacks-and-privacy-risks/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9086.mp3</guid><pubDate>Wed, 07 Aug 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60943419/9086.mp3" length="5323160" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>A Survey of Scans For GeoServer Vulnerabilities
https://isc.sans.edu/diary/A%20Survey%20of%20Scans%20for%20GeoServer%20Vulnerabilities/31148
 Crowdstrike Root Cause Analysis...</itunes:subtitle><itunes:summary><![CDATA[A Survey of Scans For GeoServer Vulnerabilities<br /><a href="https://isc.sans.edu/diary/A%20Survey%20of%20Scans%20for%20GeoServer%20Vulnerabilities/31148" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20Survey%20of%20Scans%20for%20GeoServer%20Vulnerabilities/31148</a><br /> Crowdstrike Root Cause Analysis<br /><a href="https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/" target="_blank" rel="noreferrer noopener">https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/</a><br /> Kibana Vulnerability<br /><a href="https://discuss.elastic.co/t/kibana-8-14-2-7-17-23-security-update-esa-2024-22/364424" target="_blank" rel="noreferrer noopener">https://discuss.elastic.co/t/kibana-8-14-2-7-17-23-security-update-esa-2024-22/364424</a><br /> Android August 2024 Bulletin<br /><a href="https://source.android.com/docs/security/bulletin/2024-08-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2024-08-01</a><br /> Ubiquity Amplication Attack Vulnerability Update<br /><a href="https://blog.checkpoint.com/research/over-20000-ubiquiti-cameras-and-routers-are-vulnerable-to-amplification-attacks-and-privacy-risks/" target="_blank" rel="noreferrer noopener">https://blog.checkpoint.com/research/over-20000-ubiquiti-cameras-and-routers-are-vulnerable-to-amplification-attacks-and-privacy-risks/</a><br />]]></itunes:summary><itunes:duration>359</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,geoserver; crowdstrike; kibana,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9086</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, August 6th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-august-6th-2024--62129323</link><description><![CDATA[Script Obfuscation Using Multiple Instances of the Same Function<br /><a href="https://isc.sans.edu/diary/Script%20obfuscation%20using%20multiple%20instances%20of%20the%20same%20function/31144" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Script%20obfuscation%20using%20multiple%20instances%20of%20the%20same%20function/31144</a><br /> Disclosure of key technical details of CrowdStrike's large-scale blue screen<br /><a href="https://mp.weixin.qq.com/s/uD7mhzyRSX1dTW-TMg4UhQ" target="_blank" rel="noreferrer noopener">https://mp.weixin.qq.com/s/uD7mhzyRSX1dTW-TMg4UhQ</a><br /> New OFBiz Vulnerability<br /><a href="https://issues.apache.org/jira/browse/OFBIZ-13128" target="_blank" rel="noreferrer noopener">https://issues.apache.org/jira/browse/OFBIZ-13128</a><br /><a href="https://www.youtube.com/watch?v=J_IxCBjd4Pw" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=J_IxCBjd4Pw</a><br /> Roundcube XSS Vulnerabilities<br /><a href="https://securityonline.info/roundcube-webmail-releases-security-updates-to-patch-multiple-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://securityonline.info/roundcube-webmail-releases-security-updates-to-patch-multiple-vulnerabilities/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9084.mp3</guid><pubDate>Tue, 06 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129323/9084.mp3" length="5644379" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Script Obfuscation Using Multiple Instances of the Same Function
https://isc.sans.edu/diary/Script%20obfuscation%20using%20multiple%20instances%20of%20the%20same%20function/31144
 Disclosure of key technical details of CrowdStrike's large-scale blue...</itunes:subtitle><itunes:summary><![CDATA[Script Obfuscation Using Multiple Instances of the Same Function<br /><a href="https://isc.sans.edu/diary/Script%20obfuscation%20using%20multiple%20instances%20of%20the%20same%20function/31144" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Script%20obfuscation%20using%20multiple%20instances%20of%20the%20same%20function/31144</a><br /> Disclosure of key technical details of CrowdStrike's large-scale blue screen<br /><a href="https://mp.weixin.qq.com/s/uD7mhzyRSX1dTW-TMg4UhQ" target="_blank" rel="noreferrer noopener">https://mp.weixin.qq.com/s/uD7mhzyRSX1dTW-TMg4UhQ</a><br /> New OFBiz Vulnerability<br /><a href="https://issues.apache.org/jira/browse/OFBIZ-13128" target="_blank" rel="noreferrer noopener">https://issues.apache.org/jira/browse/OFBIZ-13128</a><br /><a href="https://www.youtube.com/watch?v=J_IxCBjd4Pw" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=J_IxCBjd4Pw</a><br /> Roundcube XSS Vulnerabilities<br /><a href="https://securityonline.info/roundcube-webmail-releases-security-updates-to-patch-multiple-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://securityonline.info/roundcube-webmail-releases-security-updates-to-patch-multiple-vulnerabilities/</a><br />]]></itunes:summary><itunes:duration>382</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,roundcube; xss; ofbiz; crowdst,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9084</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, August 6th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-august-6th-2024--60932375</link><description><![CDATA[Script Obfuscation Using Multiple Instances of the Same Function<br /><a href="https://isc.sans.edu/diary/Script%20obfuscation%20using%20multiple%20instances%20of%20the%20same%20function/31144" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Script%20obfuscation%20using%20multiple%20instances%20of%20the%20same%20function/31144</a><br /> Disclosure of key technical details of CrowdStrike's large-scale blue screen<br /><a href="https://mp.weixin.qq.com/s/uD7mhzyRSX1dTW-TMg4UhQ" target="_blank" rel="noreferrer noopener">https://mp.weixin.qq.com/s/uD7mhzyRSX1dTW-TMg4UhQ</a><br /> New OFBiz Vulnerability<br /><a href="https://issues.apache.org/jira/browse/OFBIZ-13128" target="_blank" rel="noreferrer noopener">https://issues.apache.org/jira/browse/OFBIZ-13128</a><br /><a href="https://www.youtube.com/watch?v=J_IxCBjd4Pw" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=J_IxCBjd4Pw</a><br /> Roundcube XSS Vulnerabilities<br /><a href="https://securityonline.info/roundcube-webmail-releases-security-updates-to-patch-multiple-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://securityonline.info/roundcube-webmail-releases-security-updates-to-patch-multiple-vulnerabilities/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9084.mp3</guid><pubDate>Tue, 06 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60932375/9084.mp3" length="5644379" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Script Obfuscation Using Multiple Instances of the Same Function
https://isc.sans.edu/diary/Script%20obfuscation%20using%20multiple%20instances%20of%20the%20same%20function/31144
 Disclosure of key technical details of CrowdStrike's large-scale blue...</itunes:subtitle><itunes:summary><![CDATA[Script Obfuscation Using Multiple Instances of the Same Function<br /><a href="https://isc.sans.edu/diary/Script%20obfuscation%20using%20multiple%20instances%20of%20the%20same%20function/31144" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Script%20obfuscation%20using%20multiple%20instances%20of%20the%20same%20function/31144</a><br /> Disclosure of key technical details of CrowdStrike's large-scale blue screen<br /><a href="https://mp.weixin.qq.com/s/uD7mhzyRSX1dTW-TMg4UhQ" target="_blank" rel="noreferrer noopener">https://mp.weixin.qq.com/s/uD7mhzyRSX1dTW-TMg4UhQ</a><br /> New OFBiz Vulnerability<br /><a href="https://issues.apache.org/jira/browse/OFBIZ-13128" target="_blank" rel="noreferrer noopener">https://issues.apache.org/jira/browse/OFBIZ-13128</a><br /><a href="https://www.youtube.com/watch?v=J_IxCBjd4Pw" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=J_IxCBjd4Pw</a><br /> Roundcube XSS Vulnerabilities<br /><a href="https://securityonline.info/roundcube-webmail-releases-security-updates-to-patch-multiple-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://securityonline.info/roundcube-webmail-releases-security-updates-to-patch-multiple-vulnerabilities/</a><br />]]></itunes:summary><itunes:duration>382</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,roundcube; xss; ofbiz; crowdst,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9084</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, August 5th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-august-5th-2024--62129304</link><description><![CDATA[Current Secure Boot Certifiate Authority Expires in 2026<br /><a href="https://isc.sans.edu/diary/Even+Linux+users+should+take+a+look+at+this+Microsoft+KB+article/31140" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Even+Linux+users+should+take+a+look+at+this+Microsoft+KB+article/31140</a><br /> OOXML Spreadsheets Protected by Verifier Hashes<br /><a href="https://isc.sans.edu/diary/OOXML%20Spreadsheets%20Protected%20By%20Verifier%20Hashes/31072" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/OOXML%20Spreadsheets%20Protected%20By%20Verifier%20Hashes/31072</a><br /> StormBamboo Compromises ISP to Abuse Insecure Software Update Mechanisms<br /><a href="https://www.volexity.com/blog/2024/08/02/stormbamboo-compromises-isp-to-abuse-insecure-software-update-mechanisms/" target="_blank" rel="noreferrer noopener">https://www.volexity.com/blog/2024/08/02/stormbamboo-compromises-isp-to-abuse-insecure-software-update-mechanisms/</a><br /> DARPA TRACTOR Program for Translating C to Rust<br /><a href="https://www.darpa.mil/news-events/2024-07-31a" target="_blank" rel="noreferrer noopener">https://www.darpa.mil/news-events/2024-07-31a</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9082.mp3</guid><pubDate>Mon, 05 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129304/9082.mp3" length="5639109" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Current Secure Boot Certifiate Authority Expires in 2026
https://isc.sans.edu/diary/Even+Linux+users+should+take+a+look+at+this+Microsoft+KB+article/31140
 OOXML Spreadsheets Protected by Verifier Hashes...</itunes:subtitle><itunes:summary><![CDATA[Current Secure Boot Certifiate Authority Expires in 2026<br /><a href="https://isc.sans.edu/diary/Even+Linux+users+should+take+a+look+at+this+Microsoft+KB+article/31140" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Even+Linux+users+should+take+a+look+at+this+Microsoft+KB+article/31140</a><br /> OOXML Spreadsheets Protected by Verifier Hashes<br /><a href="https://isc.sans.edu/diary/OOXML%20Spreadsheets%20Protected%20By%20Verifier%20Hashes/31072" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/OOXML%20Spreadsheets%20Protected%20By%20Verifier%20Hashes/31072</a><br /> StormBamboo Compromises ISP to Abuse Insecure Software Update Mechanisms<br /><a href="https://www.volexity.com/blog/2024/08/02/stormbamboo-compromises-isp-to-abuse-insecure-software-update-mechanisms/" target="_blank" rel="noreferrer noopener">https://www.volexity.com/blog/2024/08/02/stormbamboo-compromises-isp-to-abuse-insecure-software-update-mechanisms/</a><br /> DARPA TRACTOR Program for Translating C to Rust<br /><a href="https://www.darpa.mil/news-events/2024-07-31a" target="_blank" rel="noreferrer noopener">https://www.darpa.mil/news-events/2024-07-31a</a><br />]]></itunes:summary><itunes:duration>381</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,darpa; tractor; rust; c; storm,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9082</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, August 5th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-august-5th-2024--60921473</link><description><![CDATA[Current Secure Boot Certifiate Authority Expires in 2026<br /><a href="https://isc.sans.edu/diary/Even+Linux+users+should+take+a+look+at+this+Microsoft+KB+article/31140" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Even+Linux+users+should+take+a+look+at+this+Microsoft+KB+article/31140</a><br /> OOXML Spreadsheets Protected by Verifier Hashes<br /><a href="https://isc.sans.edu/diary/OOXML%20Spreadsheets%20Protected%20By%20Verifier%20Hashes/31072" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/OOXML%20Spreadsheets%20Protected%20By%20Verifier%20Hashes/31072</a><br /> StormBamboo Compromises ISP to Abuse Insecure Software Update Mechanisms<br /><a href="https://www.volexity.com/blog/2024/08/02/stormbamboo-compromises-isp-to-abuse-insecure-software-update-mechanisms/" target="_blank" rel="noreferrer noopener">https://www.volexity.com/blog/2024/08/02/stormbamboo-compromises-isp-to-abuse-insecure-software-update-mechanisms/</a><br /> DARPA TRACTOR Program for Translating C to Rust<br /><a href="https://www.darpa.mil/news-events/2024-07-31a" target="_blank" rel="noreferrer noopener">https://www.darpa.mil/news-events/2024-07-31a</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9082.mp3</guid><pubDate>Mon, 05 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60921473/9082.mp3" length="5639109" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Current Secure Boot Certifiate Authority Expires in 2026
https://isc.sans.edu/diary/Even+Linux+users+should+take+a+look+at+this+Microsoft+KB+article/31140
 OOXML Spreadsheets Protected by Verifier Hashes...</itunes:subtitle><itunes:summary><![CDATA[Current Secure Boot Certifiate Authority Expires in 2026<br /><a href="https://isc.sans.edu/diary/Even+Linux+users+should+take+a+look+at+this+Microsoft+KB+article/31140" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Even+Linux+users+should+take+a+look+at+this+Microsoft+KB+article/31140</a><br /> OOXML Spreadsheets Protected by Verifier Hashes<br /><a href="https://isc.sans.edu/diary/OOXML%20Spreadsheets%20Protected%20By%20Verifier%20Hashes/31072" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/OOXML%20Spreadsheets%20Protected%20By%20Verifier%20Hashes/31072</a><br /> StormBamboo Compromises ISP to Abuse Insecure Software Update Mechanisms<br /><a href="https://www.volexity.com/blog/2024/08/02/stormbamboo-compromises-isp-to-abuse-insecure-software-update-mechanisms/" target="_blank" rel="noreferrer noopener">https://www.volexity.com/blog/2024/08/02/stormbamboo-compromises-isp-to-abuse-insecure-software-update-mechanisms/</a><br /> DARPA TRACTOR Program for Translating C to Rust<br /><a href="https://www.darpa.mil/news-events/2024-07-31a" target="_blank" rel="noreferrer noopener">https://www.darpa.mil/news-events/2024-07-31a</a><br />]]></itunes:summary><itunes:duration>381</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,darpa; tractor; rust; c; storm,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9082</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, August 2nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-august-2nd-2024--62129322</link><description><![CDATA[Tracking Proxy Scans with IPv4.Games<br /><a href="https://isc.sans.edu/diary/Tracking%20Proxy%20Scans%20with%20IPv4.Games/31136" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Tracking%20Proxy%20Scans%20with%20IPv4.Games/31136</a><br /> Threat Actor Impersonates Google via Fake Ad For Authenticator<br /><a href="https://www.malwarebytes.com/blog/news/2024/07/threat-actor-impersonates-google-via-fake-ad-for-authenticator" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/news/2024/07/threat-actor-impersonates-google-via-fake-ad-for-authenticator</a><br /> Who Knew? Domain Hijacking is so easy<br /><a href="https://blogs.infoblox.com/threat-intelligence/who-knew-domain-hijacking-is-so-easy/" target="_blank" rel="noreferrer noopener">https://blogs.infoblox.com/threat-intelligence/who-knew-domain-hijacking-is-so-easy/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9080.mp3</guid><pubDate>Fri, 02 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129322/9080.mp3" length="5536942" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Tracking Proxy Scans with IPv4.Games
https://isc.sans.edu/diary/Tracking%20Proxy%20Scans%20with%20IPv4.Games/31136
 Threat Actor Impersonates Google via Fake Ad For Authenticator...</itunes:subtitle><itunes:summary><![CDATA[Tracking Proxy Scans with IPv4.Games<br /><a href="https://isc.sans.edu/diary/Tracking%20Proxy%20Scans%20with%20IPv4.Games/31136" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Tracking%20Proxy%20Scans%20with%20IPv4.Games/31136</a><br /> Threat Actor Impersonates Google via Fake Ad For Authenticator<br /><a href="https://www.malwarebytes.com/blog/news/2024/07/threat-actor-impersonates-google-via-fake-ad-for-authenticator" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/news/2024/07/threat-actor-impersonates-google-via-fake-ad-for-authenticator</a><br /> Who Knew? Domain Hijacking is so easy<br /><a href="https://blogs.infoblox.com/threat-intelligence/who-knew-domain-hijacking-is-so-easy/" target="_blank" rel="noreferrer noopener">https://blogs.infoblox.com/threat-intelligence/who-knew-domain-hijacking-is-so-easy/</a><br />]]></itunes:summary><itunes:duration>374</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,domain; hijacking; google; ads,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9080</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, August 2nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-august-2nd-2024--60892429</link><description><![CDATA[Tracking Proxy Scans with IPv4.Games<br /><a href="https://isc.sans.edu/diary/Tracking%20Proxy%20Scans%20with%20IPv4.Games/31136" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Tracking%20Proxy%20Scans%20with%20IPv4.Games/31136</a><br /> Threat Actor Impersonates Google via Fake Ad For Authenticator<br /><a href="https://www.malwarebytes.com/blog/news/2024/07/threat-actor-impersonates-google-via-fake-ad-for-authenticator" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/news/2024/07/threat-actor-impersonates-google-via-fake-ad-for-authenticator</a><br /> Who Knew? Domain Hijacking is so easy<br /><a href="https://blogs.infoblox.com/threat-intelligence/who-knew-domain-hijacking-is-so-easy/" target="_blank" rel="noreferrer noopener">https://blogs.infoblox.com/threat-intelligence/who-knew-domain-hijacking-is-so-easy/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9080.mp3</guid><pubDate>Fri, 02 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60892429/9080.mp3" length="5536942" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Tracking Proxy Scans with IPv4.Games
https://isc.sans.edu/diary/Tracking%20Proxy%20Scans%20with%20IPv4.Games/31136
 Threat Actor Impersonates Google via Fake Ad For Authenticator...</itunes:subtitle><itunes:summary><![CDATA[Tracking Proxy Scans with IPv4.Games<br /><a href="https://isc.sans.edu/diary/Tracking%20Proxy%20Scans%20with%20IPv4.Games/31136" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Tracking%20Proxy%20Scans%20with%20IPv4.Games/31136</a><br /> Threat Actor Impersonates Google via Fake Ad For Authenticator<br /><a href="https://www.malwarebytes.com/blog/news/2024/07/threat-actor-impersonates-google-via-fake-ad-for-authenticator" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/news/2024/07/threat-actor-impersonates-google-via-fake-ad-for-authenticator</a><br /> Who Knew? Domain Hijacking is so easy<br /><a href="https://blogs.infoblox.com/threat-intelligence/who-knew-domain-hijacking-is-so-easy/" target="_blank" rel="noreferrer noopener">https://blogs.infoblox.com/threat-intelligence/who-knew-domain-hijacking-is-so-easy/</a><br />]]></itunes:summary><itunes:duration>374</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,domain; hijacking; google; ads,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9080</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, August 1st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-august-1st-2024--62129341</link><description><![CDATA[Increased Activity Against Apache OFBiz CVS-2024-32113<br /><a href="https://isc.sans.edu/diary/Increased%20Activity%20Against%20Apache%20OFBiz%20CVE-2024-32113/31132" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Increased%20Activity%20Against%20Apache%20OFBiz%20CVE-2024-32113/31132</a><br /> Digicert Certificate Revocation Incident<br /><a href="https://www.digicert.com/support/certificate-revocation-incident" target="_blank" rel="noreferrer noopener">https://www.digicert.com/support/certificate-revocation-incident</a><br /> Microsoft Azure Outage<br /><a href="https://azure.status.microsoft/en-us/status/history/" target="_blank" rel="noreferrer noopener">https://azure.status.microsoft/en-us/status/history/</a><br /> Improving Security of Chrome Cookies<br /><a href="https://security.googleblog.com/2024/07/improving-security-of-chrome-cookies-on.html" target="_blank" rel="noreferrer noopener">https://security.googleblog.com/2024/07/improving-security-of-chrome-cookies-on.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9078.mp3</guid><pubDate>Thu, 01 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129341/9078.mp3" length="5817476" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Increased Activity Against Apache OFBiz CVS-2024-32113
https://isc.sans.edu/diary/Increased%20Activity%20Against%20Apache%20OFBiz%20CVE-2024-32113/31132
 Digicert Certificate Revocation Incident...</itunes:subtitle><itunes:summary><![CDATA[Increased Activity Against Apache OFBiz CVS-2024-32113<br /><a href="https://isc.sans.edu/diary/Increased%20Activity%20Against%20Apache%20OFBiz%20CVE-2024-32113/31132" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Increased%20Activity%20Against%20Apache%20OFBiz%20CVE-2024-32113/31132</a><br /> Digicert Certificate Revocation Incident<br /><a href="https://www.digicert.com/support/certificate-revocation-incident" target="_blank" rel="noreferrer noopener">https://www.digicert.com/support/certificate-revocation-incident</a><br /> Microsoft Azure Outage<br /><a href="https://azure.status.microsoft/en-us/status/history/" target="_blank" rel="noreferrer noopener">https://azure.status.microsoft/en-us/status/history/</a><br /> Improving Security of Chrome Cookies<br /><a href="https://security.googleblog.com/2024/07/improving-security-of-chrome-cookies-on.html" target="_blank" rel="noreferrer noopener">https://security.googleblog.com/2024/07/improving-security-of-chrome-cookies-on.html</a><br />]]></itunes:summary><itunes:duration>394</itunes:duration><itunes:keywords>business,computer,cookies; chrome; google; micro,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9078</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, August 1st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-august-1st-2024--60880410</link><description><![CDATA[Increased Activity Against Apache OFBiz CVS-2024-32113<br /><a href="https://isc.sans.edu/diary/Increased%20Activity%20Against%20Apache%20OFBiz%20CVE-2024-32113/31132" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Increased%20Activity%20Against%20Apache%20OFBiz%20CVE-2024-32113/31132</a><br /> Digicert Certificate Revocation Incident<br /><a href="https://www.digicert.com/support/certificate-revocation-incident" target="_blank" rel="noreferrer noopener">https://www.digicert.com/support/certificate-revocation-incident</a><br /> Microsoft Azure Outage<br /><a href="https://azure.status.microsoft/en-us/status/history/" target="_blank" rel="noreferrer noopener">https://azure.status.microsoft/en-us/status/history/</a><br /> Improving Security of Chrome Cookies<br /><a href="https://security.googleblog.com/2024/07/improving-security-of-chrome-cookies-on.html" target="_blank" rel="noreferrer noopener">https://security.googleblog.com/2024/07/improving-security-of-chrome-cookies-on.html</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9078.mp3</guid><pubDate>Thu, 01 Aug 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60880410/9078.mp3" length="5817476" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Increased Activity Against Apache OFBiz CVS-2024-32113
https://isc.sans.edu/diary/Increased%20Activity%20Against%20Apache%20OFBiz%20CVE-2024-32113/31132
 Digicert Certificate Revocation Incident...</itunes:subtitle><itunes:summary><![CDATA[Increased Activity Against Apache OFBiz CVS-2024-32113<br /><a href="https://isc.sans.edu/diary/Increased%20Activity%20Against%20Apache%20OFBiz%20CVE-2024-32113/31132" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Increased%20Activity%20Against%20Apache%20OFBiz%20CVE-2024-32113/31132</a><br /> Digicert Certificate Revocation Incident<br /><a href="https://www.digicert.com/support/certificate-revocation-incident" target="_blank" rel="noreferrer noopener">https://www.digicert.com/support/certificate-revocation-incident</a><br /> Microsoft Azure Outage<br /><a href="https://azure.status.microsoft/en-us/status/history/" target="_blank" rel="noreferrer noopener">https://azure.status.microsoft/en-us/status/history/</a><br /> Improving Security of Chrome Cookies<br /><a href="https://security.googleblog.com/2024/07/improving-security-of-chrome-cookies-on.html" target="_blank" rel="noreferrer noopener">https://security.googleblog.com/2024/07/improving-security-of-chrome-cookies-on.html</a><br />]]></itunes:summary><itunes:duration>394</itunes:duration><itunes:keywords>business,computer,cookies; chrome; google; micro,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9078</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, July 31st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-july-31st-2024--62129308</link><description><![CDATA[Apple Updates Everything: July 2024 Edition<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20July%202024%20Edition/31128" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20July%202024%20Edition/31128</a><br /> VMWare ESXi Vulnerability Actively Exploited CVE-2024-37085<br /><a href="https://www.microsoft.com/en-us/security/blog/2024/07/29/ransomware-operators-exploit-esxi-hypervisor-vulnerability-for-mass-encryption/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2024/07/29/ransomware-operators-exploit-esxi-hypervisor-vulnerability-for-mass-encryption/</a><br /> Weak VoWiFi Encryption CVE-2024-22064<br /><a href="https://idw-online.de/en/news837652" target="_blank" rel="noreferrer noopener">https://idw-online.de/en/news837652</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9076.mp3</guid><pubDate>Wed, 31 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129308/9076.mp3" length="4889528" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Apple Updates Everything: July 2024 Edition
https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20July%202024%20Edition/31128
 VMWare ESXi Vulnerability Actively Exploited CVE-2024-37085...</itunes:subtitle><itunes:summary><![CDATA[Apple Updates Everything: July 2024 Edition<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20July%202024%20Edition/31128" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20July%202024%20Edition/31128</a><br /> VMWare ESXi Vulnerability Actively Exploited CVE-2024-37085<br /><a href="https://www.microsoft.com/en-us/security/blog/2024/07/29/ransomware-operators-exploit-esxi-hypervisor-vulnerability-for-mass-encryption/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2024/07/29/ransomware-operators-exploit-esxi-hypervisor-vulnerability-for-mass-encryption/</a><br /> Weak VoWiFi Encryption CVE-2024-22064<br /><a href="https://idw-online.de/en/news837652" target="_blank" rel="noreferrer noopener">https://idw-online.de/en/news837652</a><br />]]></itunes:summary><itunes:duration>328</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,vowifi; zte; vmware; esxi; app</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9076</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, July 31st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-july-31st-2024--60870535</link><description><![CDATA[Apple Updates Everything: July 2024 Edition<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20July%202024%20Edition/31128" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20July%202024%20Edition/31128</a><br /> VMWare ESXi Vulnerability Actively Exploited CVE-2024-37085<br /><a href="https://www.microsoft.com/en-us/security/blog/2024/07/29/ransomware-operators-exploit-esxi-hypervisor-vulnerability-for-mass-encryption/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2024/07/29/ransomware-operators-exploit-esxi-hypervisor-vulnerability-for-mass-encryption/</a><br /> Weak VoWiFi Encryption CVE-2024-22064<br /><a href="https://idw-online.de/en/news837652" target="_blank" rel="noreferrer noopener">https://idw-online.de/en/news837652</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9076.mp3</guid><pubDate>Wed, 31 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60870535/9076.mp3" length="4889528" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Apple Updates Everything: July 2024 Edition
https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20July%202024%20Edition/31128
 VMWare ESXi Vulnerability Actively Exploited CVE-2024-37085...</itunes:subtitle><itunes:summary><![CDATA[Apple Updates Everything: July 2024 Edition<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20July%202024%20Edition/31128" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20July%202024%20Edition/31128</a><br /> VMWare ESXi Vulnerability Actively Exploited CVE-2024-37085<br /><a href="https://www.microsoft.com/en-us/security/blog/2024/07/29/ransomware-operators-exploit-esxi-hypervisor-vulnerability-for-mass-encryption/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2024/07/29/ransomware-operators-exploit-esxi-hypervisor-vulnerability-for-mass-encryption/</a><br /> Weak VoWiFi Encryption CVE-2024-22064<br /><a href="https://idw-online.de/en/news837652" target="_blank" rel="noreferrer noopener">https://idw-online.de/en/news837652</a><br />]]></itunes:summary><itunes:duration>328</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,vowifi; zte; vmware; esxi; app</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9076</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, July 30th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-july-30th-2024--62129311</link><description><![CDATA[CrowdStrike Outage Themed Maldoc<br /><a href="https://isc.sans.edu/diary/CrowdStrike%20Outage%20Themed%20Maldoc/31116" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CrowdStrike%20Outage%20Themed%20Maldoc/31116</a><br /> HotJar XSS Puts OAuth at Risk<br /><a href="https://salt.security/blog/over-1-million-websites-are-at-risk-of-sensitive-information-leakage---xss-is-dead-long-live-xss" target="_blank" rel="noreferrer noopener">https://salt.security/blog/over-1-million-websites-are-at-risk-of-sensitive-information-leakage---xss-is-dead-long-live-xss</a><br /> Proofpoint Echospoofing<br /><a href="https://labs.guard.io/echospoofing-a-massive-phishing-campaign-exploiting-proofpoints-email-protection-to-dispatch-3dd6b5417db6" target="_blank" rel="noreferrer noopener">https://labs.guard.io/echospoofing-a-massive-phishing-campaign-exploiting-proofpoints-email-protection-to-dispatch-3dd6b5417db6</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9074.mp3</guid><pubDate>Tue, 30 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129311/9074.mp3" length="5154405" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>CrowdStrike Outage Themed Maldoc
https://isc.sans.edu/diary/CrowdStrike%20Outage%20Themed%20Maldoc/31116
 HotJar XSS Puts OAuth at Risk...</itunes:subtitle><itunes:summary><![CDATA[CrowdStrike Outage Themed Maldoc<br /><a href="https://isc.sans.edu/diary/CrowdStrike%20Outage%20Themed%20Maldoc/31116" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CrowdStrike%20Outage%20Themed%20Maldoc/31116</a><br /> HotJar XSS Puts OAuth at Risk<br /><a href="https://salt.security/blog/over-1-million-websites-are-at-risk-of-sensitive-information-leakage---xss-is-dead-long-live-xss" target="_blank" rel="noreferrer noopener">https://salt.security/blog/over-1-million-websites-are-at-risk-of-sensitive-information-leakage---xss-is-dead-long-live-xss</a><br /> Proofpoint Echospoofing<br /><a href="https://labs.guard.io/echospoofing-a-massive-phishing-campaign-exploiting-proofpoints-email-protection-to-dispatch-3dd6b5417db6" target="_blank" rel="noreferrer noopener">https://labs.guard.io/echospoofing-a-massive-phishing-campaign-exploiting-proofpoints-email-protection-to-dispatch-3dd6b5417db6</a><br />]]></itunes:summary><itunes:duration>347</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,proofpoint; echospoofing; dkim,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9074</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, July 30th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-july-30th-2024--60856618</link><description><![CDATA[CrowdStrike Outage Themed Maldoc<br /><a href="https://isc.sans.edu/diary/CrowdStrike%20Outage%20Themed%20Maldoc/31116" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CrowdStrike%20Outage%20Themed%20Maldoc/31116</a><br /> HotJar XSS Puts OAuth at Risk<br /><a href="https://salt.security/blog/over-1-million-websites-are-at-risk-of-sensitive-information-leakage---xss-is-dead-long-live-xss" target="_blank" rel="noreferrer noopener">https://salt.security/blog/over-1-million-websites-are-at-risk-of-sensitive-information-leakage---xss-is-dead-long-live-xss</a><br /> Proofpoint Echospoofing<br /><a href="https://labs.guard.io/echospoofing-a-massive-phishing-campaign-exploiting-proofpoints-email-protection-to-dispatch-3dd6b5417db6" target="_blank" rel="noreferrer noopener">https://labs.guard.io/echospoofing-a-massive-phishing-campaign-exploiting-proofpoints-email-protection-to-dispatch-3dd6b5417db6</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9074.mp3</guid><pubDate>Tue, 30 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60856618/9074.mp3" length="5154405" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>CrowdStrike Outage Themed Maldoc
https://isc.sans.edu/diary/CrowdStrike%20Outage%20Themed%20Maldoc/31116
 HotJar XSS Puts OAuth at Risk...</itunes:subtitle><itunes:summary><![CDATA[CrowdStrike Outage Themed Maldoc<br /><a href="https://isc.sans.edu/diary/CrowdStrike%20Outage%20Themed%20Maldoc/31116" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CrowdStrike%20Outage%20Themed%20Maldoc/31116</a><br /> HotJar XSS Puts OAuth at Risk<br /><a href="https://salt.security/blog/over-1-million-websites-are-at-risk-of-sensitive-information-leakage---xss-is-dead-long-live-xss" target="_blank" rel="noreferrer noopener">https://salt.security/blog/over-1-million-websites-are-at-risk-of-sensitive-information-leakage---xss-is-dead-long-live-xss</a><br /> Proofpoint Echospoofing<br /><a href="https://labs.guard.io/echospoofing-a-massive-phishing-campaign-exploiting-proofpoints-email-protection-to-dispatch-3dd6b5417db6" target="_blank" rel="noreferrer noopener">https://labs.guard.io/echospoofing-a-massive-phishing-campaign-exploiting-proofpoints-email-protection-to-dispatch-3dd6b5417db6</a><br />]]></itunes:summary><itunes:duration>347</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,proofpoint; echospoofing; dkim,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9074</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, July 29th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-july-29th-2024--62129306</link><description><![CDATA[ExelaStealer Delivered "From Russia With Love"<br /><a href="https://isc.sans.edu/diary/31118" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/31118</a><br /> Create Your Own BSOD: NotMyFault<br /><a href="https://isc.sans.edu/diary/Create%20Your%20Own%20BSOD%3A%20NotMyFault/31120" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Create%20Your%20Own%20BSOD%3A%20NotMyFault/31120</a><br /> PKFail Vulnerability<br /><a href="https://pk.fail/" target="_blank" rel="noreferrer noopener">https://pk.fail/</a><br /> CrowdStrike Recovery<br /><a href="https://arstechnica.com/information-technology/2024/07/97-of-crowdstrike-systems-are-back-online-microsoft-suggests-windows-changes/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/information-technology/2024/07/97-of-crowdstrike-systems-are-back-online-microsoft-suggests-windows-changes/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9072.mp3</guid><pubDate>Mon, 29 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129306/9072.mp3" length="5392044" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>ExelaStealer Delivered "From Russia With Love"
https://isc.sans.edu/diary/31118
 Create Your Own BSOD: NotMyFault
https://isc.sans.edu/diary/Create%20Your%20Own%20BSOD%3A%20NotMyFault/31120
 PKFail Vulnerability
https://pk.fail/
 CrowdStrike Recovery...</itunes:subtitle><itunes:summary><![CDATA[ExelaStealer Delivered "From Russia With Love"<br /><a href="https://isc.sans.edu/diary/31118" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/31118</a><br /> Create Your Own BSOD: NotMyFault<br /><a href="https://isc.sans.edu/diary/Create%20Your%20Own%20BSOD%3A%20NotMyFault/31120" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Create%20Your%20Own%20BSOD%3A%20NotMyFault/31120</a><br /> PKFail Vulnerability<br /><a href="https://pk.fail/" target="_blank" rel="noreferrer noopener">https://pk.fail/</a><br /> CrowdStrike Recovery<br /><a href="https://arstechnica.com/information-technology/2024/07/97-of-crowdstrike-systems-are-back-online-microsoft-suggests-windows-changes/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/information-technology/2024/07/97-of-crowdstrike-systems-are-back-online-microsoft-suggests-windows-changes/</a><br />]]></itunes:summary><itunes:duration>364</itunes:duration><itunes:keywords>business,computer,crowdstrike; pkfail; bsod; not,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9072</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, July 29th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-july-29th-2024--60841278</link><description><![CDATA[ExelaStealer Delivered "From Russia With Love"<br /><a href="https://isc.sans.edu/diary/31118" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/31118</a><br /> Create Your Own BSOD: NotMyFault<br /><a href="https://isc.sans.edu/diary/Create%20Your%20Own%20BSOD%3A%20NotMyFault/31120" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Create%20Your%20Own%20BSOD%3A%20NotMyFault/31120</a><br /> PKFail Vulnerability<br /><a href="https://pk.fail/" target="_blank" rel="noreferrer noopener">https://pk.fail/</a><br /> CrowdStrike Recovery<br /><a href="https://arstechnica.com/information-technology/2024/07/97-of-crowdstrike-systems-are-back-online-microsoft-suggests-windows-changes/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/information-technology/2024/07/97-of-crowdstrike-systems-are-back-online-microsoft-suggests-windows-changes/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9072.mp3</guid><pubDate>Mon, 29 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60841278/9072.mp3" length="5392044" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>ExelaStealer Delivered "From Russia With Love"
https://isc.sans.edu/diary/31118
 Create Your Own BSOD: NotMyFault
https://isc.sans.edu/diary/Create%20Your%20Own%20BSOD%3A%20NotMyFault/31120
 PKFail Vulnerability
https://pk.fail/
 CrowdStrike Recovery...</itunes:subtitle><itunes:summary><![CDATA[ExelaStealer Delivered "From Russia With Love"<br /><a href="https://isc.sans.edu/diary/31118" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/31118</a><br /> Create Your Own BSOD: NotMyFault<br /><a href="https://isc.sans.edu/diary/Create%20Your%20Own%20BSOD%3A%20NotMyFault/31120" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Create%20Your%20Own%20BSOD%3A%20NotMyFault/31120</a><br /> PKFail Vulnerability<br /><a href="https://pk.fail/" target="_blank" rel="noreferrer noopener">https://pk.fail/</a><br /> CrowdStrike Recovery<br /><a href="https://arstechnica.com/information-technology/2024/07/97-of-crowdstrike-systems-are-back-online-microsoft-suggests-windows-changes/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/information-technology/2024/07/97-of-crowdstrike-systems-are-back-online-microsoft-suggests-windows-changes/</a><br />]]></itunes:summary><itunes:duration>364</itunes:duration><itunes:keywords>business,computer,crowdstrike; pkfail; bsod; not,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9072</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, July 26th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-july-26th-2024--62129333</link><description><![CDATA[X-Worm Hidden With Process Hollowing<br /><a href="https://isc.sans.edu/diary/XWorm%20Hidden%20With%20Process%20Hollowing/31112" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/XWorm%20Hidden%20With%20Process%20Hollowing/31112</a><br /> Anyone Can Access Deleted and Private Repo Data on GitHub<br /><a href="https://trufflesecurity.com/blog/anyone-can-access-deleted-and-private-repo-data-github" target="_blank" rel="noreferrer noopener">https://trufflesecurity.com/blog/anyone-can-access-deleted-and-private-repo-data-github</a><br /> Google Chrome Scanning Encrypted Files<br /><a href="https://arstechnica.com/security/2024/07/google-overhauls-chromes-safe-browsing-protection-to-scan-password-protected-files/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2024/07/google-overhauls-chromes-safe-browsing-protection-to-scan-password-protected-files/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9070.mp3</guid><pubDate>Fri, 26 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129333/9070.mp3" length="5263480" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>X-Worm Hidden With Process Hollowing
https://isc.sans.edu/diary/XWorm%20Hidden%20With%20Process%20Hollowing/31112
 Anyone Can Access Deleted and Private Repo Data on GitHub...</itunes:subtitle><itunes:summary><![CDATA[X-Worm Hidden With Process Hollowing<br /><a href="https://isc.sans.edu/diary/XWorm%20Hidden%20With%20Process%20Hollowing/31112" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/XWorm%20Hidden%20With%20Process%20Hollowing/31112</a><br /> Anyone Can Access Deleted and Private Repo Data on GitHub<br /><a href="https://trufflesecurity.com/blog/anyone-can-access-deleted-and-private-repo-data-github" target="_blank" rel="noreferrer noopener">https://trufflesecurity.com/blog/anyone-can-access-deleted-and-private-repo-data-github</a><br /> Google Chrome Scanning Encrypted Files<br /><a href="https://arstechnica.com/security/2024/07/google-overhauls-chromes-safe-browsing-protection-to-scan-password-protected-files/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2024/07/google-overhauls-chromes-safe-browsing-protection-to-scan-password-protected-files/</a><br />]]></itunes:summary><itunes:duration>354</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,google; chrome; repo; github; ,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9070</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, July 26th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-july-26th-2024--60812956</link><description><![CDATA[X-Worm Hidden With Process Hollowing<br /><a href="https://isc.sans.edu/diary/XWorm%20Hidden%20With%20Process%20Hollowing/31112" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/XWorm%20Hidden%20With%20Process%20Hollowing/31112</a><br /> Anyone Can Access Deleted and Private Repo Data on GitHub<br /><a href="https://trufflesecurity.com/blog/anyone-can-access-deleted-and-private-repo-data-github" target="_blank" rel="noreferrer noopener">https://trufflesecurity.com/blog/anyone-can-access-deleted-and-private-repo-data-github</a><br /> Google Chrome Scanning Encrypted Files<br /><a href="https://arstechnica.com/security/2024/07/google-overhauls-chromes-safe-browsing-protection-to-scan-password-protected-files/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2024/07/google-overhauls-chromes-safe-browsing-protection-to-scan-password-protected-files/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9070.mp3</guid><pubDate>Fri, 26 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60812956/9070.mp3" length="5263480" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>X-Worm Hidden With Process Hollowing
https://isc.sans.edu/diary/XWorm%20Hidden%20With%20Process%20Hollowing/31112
 Anyone Can Access Deleted and Private Repo Data on GitHub...</itunes:subtitle><itunes:summary><![CDATA[X-Worm Hidden With Process Hollowing<br /><a href="https://isc.sans.edu/diary/XWorm%20Hidden%20With%20Process%20Hollowing/31112" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/XWorm%20Hidden%20With%20Process%20Hollowing/31112</a><br /> Anyone Can Access Deleted and Private Repo Data on GitHub<br /><a href="https://trufflesecurity.com/blog/anyone-can-access-deleted-and-private-repo-data-github" target="_blank" rel="noreferrer noopener">https://trufflesecurity.com/blog/anyone-can-access-deleted-and-private-repo-data-github</a><br /> Google Chrome Scanning Encrypted Files<br /><a href="https://arstechnica.com/security/2024/07/google-overhauls-chromes-safe-browsing-protection-to-scan-password-protected-files/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2024/07/google-overhauls-chromes-safe-browsing-protection-to-scan-password-protected-files/</a><br />]]></itunes:summary><itunes:duration>354</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,google; chrome; repo; github; ,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9070</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, July 25th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-july-25th-2024--62129319</link><description><![CDATA["Mouse Logger" Malicious Python Script<br /><a href="https://isc.sans.edu/diary/%22Mouse%20Logger%22%20Malicious%20Python%20Script/31106" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%22Mouse%20Logger%22%20Malicious%20Python%20Script/31106</a><br /> Crowdstrike Preliminary Post Incident Review<br /><a href="https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/" target="_blank" rel="noreferrer noopener">https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/</a><br /> How a North Korean Fake IT Worker Tried to Infiltrate Us<br /><a href="https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us" target="_blank" rel="noreferrer noopener">https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9068.mp3</guid><pubDate>Thu, 25 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129319/9068.mp3" length="4960766" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>"Mouse Logger" Malicious Python Script
https://isc.sans.edu/diary/%22Mouse%20Logger%22%20Malicious%20Python%20Script/31106
 Crowdstrike Preliminary Post Incident Review
https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/...</itunes:subtitle><itunes:summary><![CDATA["Mouse Logger" Malicious Python Script<br /><a href="https://isc.sans.edu/diary/%22Mouse%20Logger%22%20Malicious%20Python%20Script/31106" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%22Mouse%20Logger%22%20Malicious%20Python%20Script/31106</a><br /> Crowdstrike Preliminary Post Incident Review<br /><a href="https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/" target="_blank" rel="noreferrer noopener">https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/</a><br /> How a North Korean Fake IT Worker Tried to Infiltrate Us<br /><a href="https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us" target="_blank" rel="noreferrer noopener">https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us</a><br />]]></itunes:summary><itunes:duration>333</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,north korea; developer; fake; ,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9068</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, July 25th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-july-25th-2024--60796773</link><description><![CDATA["Mouse Logger" Malicious Python Script<br /><a href="https://isc.sans.edu/diary/%22Mouse%20Logger%22%20Malicious%20Python%20Script/31106" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%22Mouse%20Logger%22%20Malicious%20Python%20Script/31106</a><br /> Crowdstrike Preliminary Post Incident Review<br /><a href="https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/" target="_blank" rel="noreferrer noopener">https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/</a><br /> How a North Korean Fake IT Worker Tried to Infiltrate Us<br /><a href="https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us" target="_blank" rel="noreferrer noopener">https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9068.mp3</guid><pubDate>Thu, 25 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60796773/9068.mp3" length="4960766" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>"Mouse Logger" Malicious Python Script
https://isc.sans.edu/diary/%22Mouse%20Logger%22%20Malicious%20Python%20Script/31106
 Crowdstrike Preliminary Post Incident Review
https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/...</itunes:subtitle><itunes:summary><![CDATA["Mouse Logger" Malicious Python Script<br /><a href="https://isc.sans.edu/diary/%22Mouse%20Logger%22%20Malicious%20Python%20Script/31106" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%22Mouse%20Logger%22%20Malicious%20Python%20Script/31106</a><br /> Crowdstrike Preliminary Post Incident Review<br /><a href="https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/" target="_blank" rel="noreferrer noopener">https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/</a><br /> How a North Korean Fake IT Worker Tried to Infiltrate Us<br /><a href="https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us" target="_blank" rel="noreferrer noopener">https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us</a><br />]]></itunes:summary><itunes:duration>333</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,north korea; developer; fake; ,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9068</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, July 24th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-july-24th-2024--62129326</link><description><![CDATA[New Exploit Variation Against D-Link NAS Devices<br /><a href="https://isc.sans.edu/diary/New%20Exploit%20Variation%20Against%20D-Link%20NAS%20Devices%20%28CVE-2024-3273%29/31102" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/New%20Exploit%20Variation%20Against%20D-Link%20NAS%20Devices%20%28CVE-2024-3273%29/31102</a><br /> APKs Masquerading as Videos on Telegram<br /><a href="https://www.welivesecurity.com/en/eset-research/cursed-tapes-exploiting-evilvideo-vulnerability-telegram-android/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/cursed-tapes-exploiting-evilvideo-vulnerability-telegram-android/</a><br /> Goodbye Attackers can Bypass Windows Hello Strong Authentication<br /><a href="https://www.darkreading.com/endpoint-security/goodbye-attackers-can-bypass-windows-hello-strong-authentication" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/endpoint-security/goodbye-attackers-can-bypass-windows-hello-strong-authentication</a><br /> Let's Encrypt Intends to End OCSP Service<br /><a href="https://letsencrypt.org/2024/07/23/replacing-ocsp-with-crls.html" target="_blank" rel="noreferrer noopener">https://letsencrypt.org/2024/07/23/replacing-ocsp-with-crls.html</a><br /> Google Third-Party Cookies are hanging around<br /><a href="https://privacysandbox.com/intl/en_us/news/privacy-sandbox-update/" target="_blank" rel="noreferrer noopener">https://privacysandbox.com/intl/en_us/news/privacy-sandbox-update/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9066.mp3</guid><pubDate>Wed, 24 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129326/9066.mp3" length="5672334" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>New Exploit Variation Against D-Link NAS Devices
https://isc.sans.edu/diary/New%20Exploit%20Variation%20Against%20D-Link%20NAS%20Devices%20%28CVE-2024-3273%29/31102
 APKs Masquerading as Videos on Telegram...</itunes:subtitle><itunes:summary><![CDATA[New Exploit Variation Against D-Link NAS Devices<br /><a href="https://isc.sans.edu/diary/New%20Exploit%20Variation%20Against%20D-Link%20NAS%20Devices%20%28CVE-2024-3273%29/31102" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/New%20Exploit%20Variation%20Against%20D-Link%20NAS%20Devices%20%28CVE-2024-3273%29/31102</a><br /> APKs Masquerading as Videos on Telegram<br /><a href="https://www.welivesecurity.com/en/eset-research/cursed-tapes-exploiting-evilvideo-vulnerability-telegram-android/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/cursed-tapes-exploiting-evilvideo-vulnerability-telegram-android/</a><br /> Goodbye Attackers can Bypass Windows Hello Strong Authentication<br /><a href="https://www.darkreading.com/endpoint-security/goodbye-attackers-can-bypass-windows-hello-strong-authentication" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/endpoint-security/goodbye-attackers-can-bypass-windows-hello-strong-authentication</a><br /> Let's Encrypt Intends to End OCSP Service<br /><a href="https://letsencrypt.org/2024/07/23/replacing-ocsp-with-crls.html" target="_blank" rel="noreferrer noopener">https://letsencrypt.org/2024/07/23/replacing-ocsp-with-crls.html</a><br /> Google Third-Party Cookies are hanging around<br /><a href="https://privacysandbox.com/intl/en_us/news/privacy-sandbox-update/" target="_blank" rel="noreferrer noopener">https://privacysandbox.com/intl/en_us/news/privacy-sandbox-update/</a><br />]]></itunes:summary><itunes:duration>383</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,google; cookies; dlink; apk; v,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9066</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, July 24th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-july-24th-2024--60784801</link><description><![CDATA[New Exploit Variation Against D-Link NAS Devices<br /><a href="https://isc.sans.edu/diary/New%20Exploit%20Variation%20Against%20D-Link%20NAS%20Devices%20%28CVE-2024-3273%29/31102" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/New%20Exploit%20Variation%20Against%20D-Link%20NAS%20Devices%20%28CVE-2024-3273%29/31102</a><br /> APKs Masquerading as Videos on Telegram<br /><a href="https://www.welivesecurity.com/en/eset-research/cursed-tapes-exploiting-evilvideo-vulnerability-telegram-android/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/cursed-tapes-exploiting-evilvideo-vulnerability-telegram-android/</a><br /> Goodbye Attackers can Bypass Windows Hello Strong Authentication<br /><a href="https://www.darkreading.com/endpoint-security/goodbye-attackers-can-bypass-windows-hello-strong-authentication" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/endpoint-security/goodbye-attackers-can-bypass-windows-hello-strong-authentication</a><br /> Let's Encrypt Intends to End OCSP Service<br /><a href="https://letsencrypt.org/2024/07/23/replacing-ocsp-with-crls.html" target="_blank" rel="noreferrer noopener">https://letsencrypt.org/2024/07/23/replacing-ocsp-with-crls.html</a><br /> Google Third-Party Cookies are hanging around<br /><a href="https://privacysandbox.com/intl/en_us/news/privacy-sandbox-update/" target="_blank" rel="noreferrer noopener">https://privacysandbox.com/intl/en_us/news/privacy-sandbox-update/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9066.mp3</guid><pubDate>Wed, 24 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60784801/9066.mp3" length="5672334" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>New Exploit Variation Against D-Link NAS Devices
https://isc.sans.edu/diary/New%20Exploit%20Variation%20Against%20D-Link%20NAS%20Devices%20%28CVE-2024-3273%29/31102
 APKs Masquerading as Videos on Telegram...</itunes:subtitle><itunes:summary><![CDATA[New Exploit Variation Against D-Link NAS Devices<br /><a href="https://isc.sans.edu/diary/New%20Exploit%20Variation%20Against%20D-Link%20NAS%20Devices%20%28CVE-2024-3273%29/31102" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/New%20Exploit%20Variation%20Against%20D-Link%20NAS%20Devices%20%28CVE-2024-3273%29/31102</a><br /> APKs Masquerading as Videos on Telegram<br /><a href="https://www.welivesecurity.com/en/eset-research/cursed-tapes-exploiting-evilvideo-vulnerability-telegram-android/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/cursed-tapes-exploiting-evilvideo-vulnerability-telegram-android/</a><br /> Goodbye Attackers can Bypass Windows Hello Strong Authentication<br /><a href="https://www.darkreading.com/endpoint-security/goodbye-attackers-can-bypass-windows-hello-strong-authentication" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/endpoint-security/goodbye-attackers-can-bypass-windows-hello-strong-authentication</a><br /> Let's Encrypt Intends to End OCSP Service<br /><a href="https://letsencrypt.org/2024/07/23/replacing-ocsp-with-crls.html" target="_blank" rel="noreferrer noopener">https://letsencrypt.org/2024/07/23/replacing-ocsp-with-crls.html</a><br /> Google Third-Party Cookies are hanging around<br /><a href="https://privacysandbox.com/intl/en_us/news/privacy-sandbox-update/" target="_blank" rel="noreferrer noopener">https://privacysandbox.com/intl/en_us/news/privacy-sandbox-update/</a><br />]]></itunes:summary><itunes:duration>383</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,google; cookies; dlink; apk; v,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9066</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, July 23rd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-july-23rd-2024--62129344</link><description><![CDATA[CrowdStrike Update<br /><a href="https://isc.sans.edu/diary/CrowdStrike%3A%20The%20Monday%20After/31098" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CrowdStrike%3A%20The%20Monday%20After/31098</a><br /><a href="https://www.theregister.com/2024/07/21/crowdstrike_linux_crashes_restoration_tools/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2024/07/21/crowdstrike_linux_crashes_restoration_tools/</a><br /> Keynote Recording<br /><a href="https://www.sans.org/webcasts/sansfire-2024-keynote-25-years-of-the-internet-storm-center-time-traveling-through-sensor-data/" target="_blank" rel="noreferrer noopener">https://www.sans.org/webcasts/sansfire-2024-keynote-25-years-of-the-internet-storm-center-time-traveling-through-sensor-data/</a>]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9064.mp3</guid><pubDate>Tue, 23 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129344/9064.mp3" length="4697905" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>CrowdStrike Update
https://isc.sans.edu/diary/CrowdStrike%3A%20The%20Monday%20After/31098
https://www.theregister.com/2024/07/21/crowdstrike_linux_crashes_restoration_tools/
 Keynote Recording...</itunes:subtitle><itunes:summary><![CDATA[CrowdStrike Update<br /><a href="https://isc.sans.edu/diary/CrowdStrike%3A%20The%20Monday%20After/31098" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CrowdStrike%3A%20The%20Monday%20After/31098</a><br /><a href="https://www.theregister.com/2024/07/21/crowdstrike_linux_crashes_restoration_tools/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2024/07/21/crowdstrike_linux_crashes_restoration_tools/</a><br /> Keynote Recording<br /><a href="https://www.sans.org/webcasts/sansfire-2024-keynote-25-years-of-the-internet-storm-center-time-traveling-through-sensor-data/" target="_blank" rel="noreferrer noopener">https://www.sans.org/webcasts/sansfire-2024-keynote-25-years-of-the-internet-storm-center-time-traveling-through-sensor-data/</a>]]></itunes:summary><itunes:duration>314</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,sansfire; keynote; crowdstrike,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9064</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, July 23rd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-july-23rd-2024--60772817</link><description><![CDATA[CrowdStrike Update<br /><a href="https://isc.sans.edu/diary/CrowdStrike%3A%20The%20Monday%20After/31098" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CrowdStrike%3A%20The%20Monday%20After/31098</a><br /><a href="https://www.theregister.com/2024/07/21/crowdstrike_linux_crashes_restoration_tools/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2024/07/21/crowdstrike_linux_crashes_restoration_tools/</a><br /> Keynote Recording<br /><a href="https://www.sans.org/services/video-player/?key=1goL2vPrltnj" target="_blank" rel="noreferrer noopener">https://www.sans.org/services/video-player/?key=1goL2vPrltnj</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9064.mp3</guid><pubDate>Tue, 23 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60772817/9064.mp3" length="4697905" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>CrowdStrike Update
https://isc.sans.edu/diary/CrowdStrike%3A%20The%20Monday%20After/31098
https://www.theregister.com/2024/07/21/crowdstrike_linux_crashes_restoration_tools/
 Keynote Recording
https://www.sans.org/services/video-player/?key=1goL2vPrltnj
</itunes:subtitle><itunes:summary><![CDATA[CrowdStrike Update<br /><a href="https://isc.sans.edu/diary/CrowdStrike%3A%20The%20Monday%20After/31098" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CrowdStrike%3A%20The%20Monday%20After/31098</a><br /><a href="https://www.theregister.com/2024/07/21/crowdstrike_linux_crashes_restoration_tools/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2024/07/21/crowdstrike_linux_crashes_restoration_tools/</a><br /> Keynote Recording<br /><a href="https://www.sans.org/services/video-player/?key=1goL2vPrltnj" target="_blank" rel="noreferrer noopener">https://www.sans.org/services/video-player/?key=1goL2vPrltnj</a><br />]]></itunes:summary><itunes:duration>314</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,sansfire; keynote; crowdstrike,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9064</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, July 22nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-july-22nd-2024--62129335</link><description><![CDATA[Widespread Windows Crashes Due to Crowdstrike Updates<br /><a href="https://isc.sans.edu/diary/Widespread%20Windows%20Crashes%20Due%20to%20Crowdstrike%20Updates/31094" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Widespread%20Windows%20Crashes%20Due%20to%20Crowdstrike%20Updates/31094</a><br /><a href="https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/" target="_blank" rel="noreferrer noopener">https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/</a><br /><a href="https://www.crowdstrike.com/blog/falcon-update-for-windows-hosts-technical-details/" target="_blank" rel="noreferrer noopener">https://www.crowdstrike.com/blog/falcon-update-for-windows-hosts-technical-details/</a><br /><a href="https://techcommunity.microsoft.com/t5/intune-customer-success/new-recovery-tool-to-help-with-crowdstrike-issue-impacting/ba-p/4196959" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/intune-customer-success/new-recovery-tool-to-help-with-crowdstrike-issue-impacting/ba-p/4196959</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9062.mp3</guid><pubDate>Mon, 22 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129335/9062.mp3" length="7559382" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Widespread Windows Crashes Due to Crowdstrike Updates
https://isc.sans.edu/diary/Widespread%20Windows%20Crashes%20Due%20to%20Crowdstrike%20Updates/31094
https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/...</itunes:subtitle><itunes:summary><![CDATA[Widespread Windows Crashes Due to Crowdstrike Updates<br /><a href="https://isc.sans.edu/diary/Widespread%20Windows%20Crashes%20Due%20to%20Crowdstrike%20Updates/31094" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Widespread%20Windows%20Crashes%20Due%20to%20Crowdstrike%20Updates/31094</a><br /><a href="https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/" target="_blank" rel="noreferrer noopener">https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/</a><br /><a href="https://www.crowdstrike.com/blog/falcon-update-for-windows-hosts-technical-details/" target="_blank" rel="noreferrer noopener">https://www.crowdstrike.com/blog/falcon-update-for-windows-hosts-technical-details/</a><br /><a href="https://techcommunity.microsoft.com/t5/intune-customer-success/new-recovery-tool-to-help-with-crowdstrike-issue-impacting/ba-p/4196959" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/intune-customer-success/new-recovery-tool-to-help-with-crowdstrike-issue-impacting/ba-p/4196959</a><br />]]></itunes:summary><itunes:duration>518</itunes:duration><itunes:keywords>business,computer,crowdstrike; windows; crash;,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9062</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, July 22nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-july-22nd-2024--60762582</link><description><![CDATA[Widespread Windows Crashes Due to Crowdstrike Updates<br /><a href="https://isc.sans.edu/diary/Widespread%20Windows%20Crashes%20Due%20to%20Crowdstrike%20Updates/31094" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Widespread%20Windows%20Crashes%20Due%20to%20Crowdstrike%20Updates/31094</a><br /><a href="https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/" target="_blank" rel="noreferrer noopener">https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/</a><br /><a href="https://www.crowdstrike.com/blog/falcon-update-for-windows-hosts-technical-details/" target="_blank" rel="noreferrer noopener">https://www.crowdstrike.com/blog/falcon-update-for-windows-hosts-technical-details/</a><br /><a href="https://techcommunity.microsoft.com/t5/intune-customer-success/new-recovery-tool-to-help-with-crowdstrike-issue-impacting/ba-p/4196959" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/intune-customer-success/new-recovery-tool-to-help-with-crowdstrike-issue-impacting/ba-p/4196959</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9062.mp3</guid><pubDate>Mon, 22 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60762582/9062.mp3" length="7559382" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Widespread Windows Crashes Due to Crowdstrike Updates
https://isc.sans.edu/diary/Widespread%20Windows%20Crashes%20Due%20to%20Crowdstrike%20Updates/31094
https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/...</itunes:subtitle><itunes:summary><![CDATA[Widespread Windows Crashes Due to Crowdstrike Updates<br /><a href="https://isc.sans.edu/diary/Widespread%20Windows%20Crashes%20Due%20to%20Crowdstrike%20Updates/31094" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Widespread%20Windows%20Crashes%20Due%20to%20Crowdstrike%20Updates/31094</a><br /><a href="https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/" target="_blank" rel="noreferrer noopener">https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/</a><br /><a href="https://www.crowdstrike.com/blog/falcon-update-for-windows-hosts-technical-details/" target="_blank" rel="noreferrer noopener">https://www.crowdstrike.com/blog/falcon-update-for-windows-hosts-technical-details/</a><br /><a href="https://techcommunity.microsoft.com/t5/intune-customer-success/new-recovery-tool-to-help-with-crowdstrike-issue-impacting/ba-p/4196959" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/intune-customer-success/new-recovery-tool-to-help-with-crowdstrike-issue-impacting/ba-p/4196959</a><br />]]></itunes:summary><itunes:duration>518</itunes:duration><itunes:keywords>business,computer,crowdstrike; windows; crash;,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9062</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, July 19th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-july-19th-2024--62129342</link><description><![CDATA[Oracle Quarterly Critical Patch Update<br /><a href="https://www.oracle.com/security-alerts/cpujul2024.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpujul2024.html</a><br /> Exchange Online Implementing Inbound SMTP DANE with DNSSEC<br /><a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/announcing-public-preview-of-inbound-smtp-dane-with-dnssec-for/ba-p/4155257" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/exchange-team-blog/announcing-public-preview-of-inbound-smtp-dane-with-dnssec-for/ba-p/4155257</a><br /> VPN Port Shadowing Vulnerability<br /><a href="https://petsymposium.org/popets/2024/popets-2024-0070.pdf" target="_blank" rel="noreferrer noopener">https://petsymposium.org/popets/2024/popets-2024-0070.pdf</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9060.mp3</guid><pubDate>Fri, 19 Jul 2024 02:05:06 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129342/9060.mp3" length="5046352" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Oracle Quarterly Critical Patch Update
https://www.oracle.com/security-alerts/cpujul2024.html
 Exchange Online Implementing Inbound SMTP DANE with DNSSEC...</itunes:subtitle><itunes:summary><![CDATA[Oracle Quarterly Critical Patch Update<br /><a href="https://www.oracle.com/security-alerts/cpujul2024.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpujul2024.html</a><br /> Exchange Online Implementing Inbound SMTP DANE with DNSSEC<br /><a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/announcing-public-preview-of-inbound-smtp-dane-with-dnssec-for/ba-p/4155257" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/exchange-team-blog/announcing-public-preview-of-inbound-smtp-dane-with-dnssec-for/ba-p/4155257</a><br /> VPN Port Shadowing Vulnerability<br /><a href="https://petsymposium.org/popets/2024/popets-2024-0070.pdf" target="_blank" rel="noreferrer noopener">https://petsymposium.org/popets/2024/popets-2024-0070.pdf</a><br />]]></itunes:summary><itunes:duration>339</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,vpn; shadow; port; shadowing; </itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9060</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, July 19th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-july-19th-2024--60737085</link><description><![CDATA[Oracle Quarterly Critical Patch Update<br /><a href="https://www.oracle.com/security-alerts/cpujul2024.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpujul2024.html</a><br /> Exchange Online Implementing Inbound SMTP DANE with DNSSEC<br /><a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/announcing-public-preview-of-inbound-smtp-dane-with-dnssec-for/ba-p/4155257" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/exchange-team-blog/announcing-public-preview-of-inbound-smtp-dane-with-dnssec-for/ba-p/4155257</a><br /> VPN Port Shadowing Vulnerability<br /><a href="https://petsymposium.org/popets/2024/popets-2024-0070.pdf" target="_blank" rel="noreferrer noopener">https://petsymposium.org/popets/2024/popets-2024-0070.pdf</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9060.mp3</guid><pubDate>Fri, 19 Jul 2024 02:05:06 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60737085/9060.mp3" length="5046352" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Oracle Quarterly Critical Patch Update
https://www.oracle.com/security-alerts/cpujul2024.html
 Exchange Online Implementing Inbound SMTP DANE with DNSSEC...</itunes:subtitle><itunes:summary><![CDATA[Oracle Quarterly Critical Patch Update<br /><a href="https://www.oracle.com/security-alerts/cpujul2024.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpujul2024.html</a><br /> Exchange Online Implementing Inbound SMTP DANE with DNSSEC<br /><a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/announcing-public-preview-of-inbound-smtp-dane-with-dnssec-for/ba-p/4155257" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/exchange-team-blog/announcing-public-preview-of-inbound-smtp-dane-with-dnssec-for/ba-p/4155257</a><br /> VPN Port Shadowing Vulnerability<br /><a href="https://petsymposium.org/popets/2024/popets-2024-0070.pdf" target="_blank" rel="noreferrer noopener">https://petsymposium.org/popets/2024/popets-2024-0070.pdf</a><br />]]></itunes:summary><itunes:duration>339</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,vpn; shadow; port; shadowing; </itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9060</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, July 18th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-july-18th-2024--62129321</link><description><![CDATA[Who You Gonna Call: Androx Gh0st Busters!<br /><a href="https://isc.sans.edu/diary/Who%20You%20Gonna%20Call%3F%20AndroxGh0st%20Busters!%20%5BGuest%20Diary%5D/31086" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Who%20You%20Gonna%20Call%3F%20AndroxGh0st%20Busters!%20%5BGuest%20Diary%5D/31086</a><br /> Cisco Smart Software Manager Vulnerability CVE-2024-20419<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-auth-sLw3uhUy" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-auth-sLw3uhUy</a><br /> Critical Security Flaw in Cisco Secure Email Gateway: CVE-2024-20401<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-afw-bGG2UsjH" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-afw-bGG2UsjH</a><br /> Microsoft Introducing Checkpoint Updates<br /><a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/introducing-windows-11-checkpoint-cumulative-updates/ba-p/4182552" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/windows-it-pro-blog/introducing-windows-11-checkpoint-cumulative-updates/ba-p/4182552</a><br /> GeoServer Patches<br /><a href="https://github.com/geoserver/geoserver/security/advisories/GHSA-6jj6-gm7p-fcvv" target="_blank" rel="noreferrer noopener">https://github.com/geoserver/geoserver/security/advisories/GHSA-6jj6-gm7p-fcvv</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9058.mp3</guid><pubDate>Thu, 18 Jul 2024 02:55:11 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129321/9058.mp3" length="5412745" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Who You Gonna Call: Androx Gh0st Busters!
https://isc.sans.edu/diary/Who%20You%20Gonna%20Call%3F%20AndroxGh0st%20Busters!%20%5BGuest%20Diary%5D/31086
 Cisco Smart Software Manager Vulnerability CVE-2024-20419...</itunes:subtitle><itunes:summary><![CDATA[Who You Gonna Call: Androx Gh0st Busters!<br /><a href="https://isc.sans.edu/diary/Who%20You%20Gonna%20Call%3F%20AndroxGh0st%20Busters!%20%5BGuest%20Diary%5D/31086" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Who%20You%20Gonna%20Call%3F%20AndroxGh0st%20Busters!%20%5BGuest%20Diary%5D/31086</a><br /> Cisco Smart Software Manager Vulnerability CVE-2024-20419<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-auth-sLw3uhUy" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-auth-sLw3uhUy</a><br /> Critical Security Flaw in Cisco Secure Email Gateway: CVE-2024-20401<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-afw-bGG2UsjH" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-afw-bGG2UsjH</a><br /> Microsoft Introducing Checkpoint Updates<br /><a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/introducing-windows-11-checkpoint-cumulative-updates/ba-p/4182552" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/windows-it-pro-blog/introducing-windows-11-checkpoint-cumulative-updates/ba-p/4182552</a><br /> GeoServer Patches<br /><a href="https://github.com/geoserver/geoserver/security/advisories/GHSA-6jj6-gm7p-fcvv" target="_blank" rel="noreferrer noopener">https://github.com/geoserver/geoserver/security/advisories/GHSA-6jj6-gm7p-fcvv</a><br />]]></itunes:summary><itunes:duration>365</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,geoserver; msft; checkpoint; u,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9058</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, July 18th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-july-18th-2024--60726045</link><description><![CDATA[Who You Gonna Call: Androx Gh0st Busters!<br /><a href="https://isc.sans.edu/diary/Who%20You%20Gonna%20Call%3F%20AndroxGh0st%20Busters!%20%5BGuest%20Diary%5D/31086" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Who%20You%20Gonna%20Call%3F%20AndroxGh0st%20Busters!%20%5BGuest%20Diary%5D/31086</a><br /> Cisco Smart Software Manager Vulnerability CVE-2024-20419<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-auth-sLw3uhUy" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-auth-sLw3uhUy</a><br /> Critical Security Flaw in Cisco Secure Email Gateway: CVE-2024-20401<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-afw-bGG2UsjH" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-afw-bGG2UsjH</a><br /> Microsoft Introducing Checkpoint Updates<br /><a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/introducing-windows-11-checkpoint-cumulative-updates/ba-p/4182552" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/windows-it-pro-blog/introducing-windows-11-checkpoint-cumulative-updates/ba-p/4182552</a><br /> GeoServer Patches<br /><a href="https://github.com/geoserver/geoserver/security/advisories/GHSA-6jj6-gm7p-fcvv" target="_blank" rel="noreferrer noopener">https://github.com/geoserver/geoserver/security/advisories/GHSA-6jj6-gm7p-fcvv</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9058.mp3</guid><pubDate>Thu, 18 Jul 2024 02:55:11 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60726045/9058.mp3" length="5412745" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Who You Gonna Call: Androx Gh0st Busters!
https://isc.sans.edu/diary/Who%20You%20Gonna%20Call%3F%20AndroxGh0st%20Busters!%20%5BGuest%20Diary%5D/31086
 Cisco Smart Software Manager Vulnerability CVE-2024-20419...</itunes:subtitle><itunes:summary><![CDATA[Who You Gonna Call: Androx Gh0st Busters!<br /><a href="https://isc.sans.edu/diary/Who%20You%20Gonna%20Call%3F%20AndroxGh0st%20Busters!%20%5BGuest%20Diary%5D/31086" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Who%20You%20Gonna%20Call%3F%20AndroxGh0st%20Busters!%20%5BGuest%20Diary%5D/31086</a><br /> Cisco Smart Software Manager Vulnerability CVE-2024-20419<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-auth-sLw3uhUy" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-auth-sLw3uhUy</a><br /> Critical Security Flaw in Cisco Secure Email Gateway: CVE-2024-20401<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-afw-bGG2UsjH" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-afw-bGG2UsjH</a><br /> Microsoft Introducing Checkpoint Updates<br /><a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/introducing-windows-11-checkpoint-cumulative-updates/ba-p/4182552" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/windows-it-pro-blog/introducing-windows-11-checkpoint-cumulative-updates/ba-p/4182552</a><br /> GeoServer Patches<br /><a href="https://github.com/geoserver/geoserver/security/advisories/GHSA-6jj6-gm7p-fcvv" target="_blank" rel="noreferrer noopener">https://github.com/geoserver/geoserver/security/advisories/GHSA-6jj6-gm7p-fcvv</a><br />]]></itunes:summary><itunes:duration>365</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,geoserver; msft; checkpoint; u,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9058</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, July 17th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-july-17th-2024--62129346</link><description><![CDATA[Reply Chain Phishing With a Twist<br /><a href="https://isc.sans.edu/diary/%22Reply-chain%20phishing%22%20with%20a%20twist/31084" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%22Reply-chain%20phishing%22%20with%20a%20twist/31084</a><br /> Claroty TP-Link and Synology IP Camera Exploits<br /><a href="https://claroty.com/team82/research/pivoting-from-wan-to-lan-synology-bc500-ip-camera" target="_blank" rel="noreferrer noopener">https://claroty.com/team82/research/pivoting-from-wan-to-lan-synology-bc500-ip-camera</a><br /><a href="https://claroty.com/team82/research/pwn2own-wan-to-lan-exploit-showcase" target="_blank" rel="noreferrer noopener">https://claroty.com/team82/research/pwn2own-wan-to-lan-exploit-showcase</a><br /> Cosmic Sting Hits Adobe Commerce Stores<br /><a href="https://sansec.io/research/cosmicsting-hitting-major-stores" target="_blank" rel="noreferrer noopener">https://sansec.io/research/cosmicsting-hitting-major-stores</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9056.mp3</guid><pubDate>Wed, 17 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129346/9056.mp3" length="5051152" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Reply Chain Phishing With a Twist
https://isc.sans.edu/diary/%22Reply-chain%20phishing%22%20with%20a%20twist/31084
 Claroty TP-Link and Synology IP Camera Exploits
https://claroty.com/team82/research/pivoting-from-wan-to-lan-synology-bc500-ip-camera...</itunes:subtitle><itunes:summary><![CDATA[Reply Chain Phishing With a Twist<br /><a href="https://isc.sans.edu/diary/%22Reply-chain%20phishing%22%20with%20a%20twist/31084" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%22Reply-chain%20phishing%22%20with%20a%20twist/31084</a><br /> Claroty TP-Link and Synology IP Camera Exploits<br /><a href="https://claroty.com/team82/research/pivoting-from-wan-to-lan-synology-bc500-ip-camera" target="_blank" rel="noreferrer noopener">https://claroty.com/team82/research/pivoting-from-wan-to-lan-synology-bc500-ip-camera</a><br /><a href="https://claroty.com/team82/research/pwn2own-wan-to-lan-exploit-showcase" target="_blank" rel="noreferrer noopener">https://claroty.com/team82/research/pwn2own-wan-to-lan-exploit-showcase</a><br /> Cosmic Sting Hits Adobe Commerce Stores<br /><a href="https://sansec.io/research/cosmicsting-hitting-major-stores" target="_blank" rel="noreferrer noopener">https://sansec.io/research/cosmicsting-hitting-major-stores</a><br />]]></itunes:summary><itunes:duration>339</itunes:duration><itunes:keywords>business,computer,cosmic string; adobe; commerce,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9056</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, July 17th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-july-17th-2024--60714508</link><description><![CDATA[Reply Chain Phishing With a Twist<br /><a href="https://isc.sans.edu/diary/%22Reply-chain%20phishing%22%20with%20a%20twist/31084" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%22Reply-chain%20phishing%22%20with%20a%20twist/31084</a><br /> Claroty TP-Link and Synology IP Camera Exploits<br /><a href="https://claroty.com/team82/research/pivoting-from-wan-to-lan-synology-bc500-ip-camera" target="_blank" rel="noreferrer noopener">https://claroty.com/team82/research/pivoting-from-wan-to-lan-synology-bc500-ip-camera</a><br /><a href="https://claroty.com/team82/research/pwn2own-wan-to-lan-exploit-showcase" target="_blank" rel="noreferrer noopener">https://claroty.com/team82/research/pwn2own-wan-to-lan-exploit-showcase</a><br /> Cosmic Sting Hits Adobe Commerce Stores<br /><a href="https://sansec.io/research/cosmicsting-hitting-major-stores" target="_blank" rel="noreferrer noopener">https://sansec.io/research/cosmicsting-hitting-major-stores</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9056.mp3</guid><pubDate>Wed, 17 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60714508/9056.mp3" length="5051152" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Reply Chain Phishing With a Twist
https://isc.sans.edu/diary/%22Reply-chain%20phishing%22%20with%20a%20twist/31084
 Claroty TP-Link and Synology IP Camera Exploits
https://claroty.com/team82/research/pivoting-from-wan-to-lan-synology-bc500-ip-camera...</itunes:subtitle><itunes:summary><![CDATA[Reply Chain Phishing With a Twist<br /><a href="https://isc.sans.edu/diary/%22Reply-chain%20phishing%22%20with%20a%20twist/31084" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%22Reply-chain%20phishing%22%20with%20a%20twist/31084</a><br /> Claroty TP-Link and Synology IP Camera Exploits<br /><a href="https://claroty.com/team82/research/pivoting-from-wan-to-lan-synology-bc500-ip-camera" target="_blank" rel="noreferrer noopener">https://claroty.com/team82/research/pivoting-from-wan-to-lan-synology-bc500-ip-camera</a><br /><a href="https://claroty.com/team82/research/pwn2own-wan-to-lan-exploit-showcase" target="_blank" rel="noreferrer noopener">https://claroty.com/team82/research/pwn2own-wan-to-lan-exploit-showcase</a><br /> Cosmic Sting Hits Adobe Commerce Stores<br /><a href="https://sansec.io/research/cosmicsting-hitting-major-stores" target="_blank" rel="noreferrer noopener">https://sansec.io/research/cosmicsting-hitting-major-stores</a><br />]]></itunes:summary><itunes:duration>339</itunes:duration><itunes:keywords>business,computer,cosmic string; adobe; commerce,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9056</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, July 16th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-july-16th-2024--62129329</link><description><![CDATA[Protected OOXML Spreadsheets<br /><a href="https://isc.sans.edu/diary/Protected%20OOXML%20Spreadsheets/31070" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Protected%20OOXML%20Spreadsheets/31070</a><br /> Leaked PyPi Secret Token Revealed in Binary<br /><a href="https://jfrog.com/blog/leaked-pypi-secret-token-revealed-in-binary-preventing-suppy-chain-attack/" target="_blank" rel="noreferrer noopener">https://jfrog.com/blog/leaked-pypi-secret-token-revealed-in-binary-preventing-suppy-chain-attack/</a><br /> Microsoft 365 Defender Affected by June Update<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-server-2022#network-data-reporting-from-microsoft-365-defender-may-be-interrupted" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/status-windows-server-2022#network-data-reporting-from-microsoft-365-defender-may-be-interrupted</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9054.mp3</guid><pubDate>Tue, 16 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129329/9054.mp3" length="5333841" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Protected OOXML Spreadsheets
https://isc.sans.edu/diary/Protected%20OOXML%20Spreadsheets/31070
 Leaked PyPi Secret Token Revealed in Binary
https://jfrog.com/blog/leaked-pypi-secret-token-revealed-in-binary-preventing-suppy-chain-attack/
 Microsoft...</itunes:subtitle><itunes:summary><![CDATA[Protected OOXML Spreadsheets<br /><a href="https://isc.sans.edu/diary/Protected%20OOXML%20Spreadsheets/31070" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Protected%20OOXML%20Spreadsheets/31070</a><br /> Leaked PyPi Secret Token Revealed in Binary<br /><a href="https://jfrog.com/blog/leaked-pypi-secret-token-revealed-in-binary-preventing-suppy-chain-attack/" target="_blank" rel="noreferrer noopener">https://jfrog.com/blog/leaked-pypi-secret-token-revealed-in-binary-preventing-suppy-chain-attack/</a><br /> Microsoft 365 Defender Affected by June Update<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-server-2022#network-data-reporting-from-microsoft-365-defender-may-be-interrupted" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/status-windows-server-2022#network-data-reporting-from-microsoft-365-defender-may-be-interrupted</a><br />]]></itunes:summary><itunes:duration>359</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microsoft; patch; defender; ju,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9054</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, July 16th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-july-16th-2024--60702838</link><description><![CDATA[Protected OOXML Spreadsheets<br /><a href="https://isc.sans.edu/diary/Protected%20OOXML%20Spreadsheets/31070" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Protected%20OOXML%20Spreadsheets/31070</a><br /> Leaked PyPi Secret Token Revealed in Binary<br /><a href="https://jfrog.com/blog/leaked-pypi-secret-token-revealed-in-binary-preventing-suppy-chain-attack/" target="_blank" rel="noreferrer noopener">https://jfrog.com/blog/leaked-pypi-secret-token-revealed-in-binary-preventing-suppy-chain-attack/</a><br /> Microsoft 365 Defender Affected by June Update<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-server-2022#network-data-reporting-from-microsoft-365-defender-may-be-interrupted" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/status-windows-server-2022#network-data-reporting-from-microsoft-365-defender-may-be-interrupted</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9054.mp3</guid><pubDate>Tue, 16 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60702838/9054.mp3" length="5333841" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Protected OOXML Spreadsheets
https://isc.sans.edu/diary/Protected%20OOXML%20Spreadsheets/31070
 Leaked PyPi Secret Token Revealed in Binary
https://jfrog.com/blog/leaked-pypi-secret-token-revealed-in-binary-preventing-suppy-chain-attack/
 Microsoft...</itunes:subtitle><itunes:summary><![CDATA[Protected OOXML Spreadsheets<br /><a href="https://isc.sans.edu/diary/Protected%20OOXML%20Spreadsheets/31070" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Protected%20OOXML%20Spreadsheets/31070</a><br /> Leaked PyPi Secret Token Revealed in Binary<br /><a href="https://jfrog.com/blog/leaked-pypi-secret-token-revealed-in-binary-preventing-suppy-chain-attack/" target="_blank" rel="noreferrer noopener">https://jfrog.com/blog/leaked-pypi-secret-token-revealed-in-binary-preventing-suppy-chain-attack/</a><br /> Microsoft 365 Defender Affected by June Update<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-server-2022#network-data-reporting-from-microsoft-365-defender-may-be-interrupted" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/status-windows-server-2022#network-data-reporting-from-microsoft-365-defender-may-be-interrupted</a><br />]]></itunes:summary><itunes:duration>359</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microsoft; patch; defender; ju,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9054</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, July 15th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-july-15th-2024--62129334</link><description><![CDATA[16-Bit Hash Collisions in XLS Spreadsheets<br /><a href="https://isc.sans.edu/diary/16-bit%20Hash%20Collisions%20in%20.xls%20Spreadsheets/31066" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/16-bit%20Hash%20Collisions%20in%20.xls%20Spreadsheets/31066</a><br /> Attacks against the "Nette" PHP framework CVE-2020-15227<br /><a href="https://isc.sans.edu/forums/diary/Attacks+against+the+Nette+PHP+framework+CVE202015227/31076/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Attacks+against+the+Nette+PHP+framework+CVE202015227/31076/</a><br /> Squarespace Hijacked Domains<br /><a href="https://github.com/security-alliance/advisories/blob/main/2024-07-squarespace.pdf" target="_blank" rel="noreferrer noopener">https://github.com/security-alliance/advisories/blob/main/2024-07-squarespace.pdf</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9052.mp3</guid><pubDate>Mon, 15 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129334/9052.mp3" length="5767998" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>16-Bit Hash Collisions in XLS Spreadsheets
https://isc.sans.edu/diary/16-bit%20Hash%20Collisions%20in%20.xls%20Spreadsheets/31066
 Attacks against the "Nette" PHP framework CVE-2020-15227...</itunes:subtitle><itunes:summary><![CDATA[16-Bit Hash Collisions in XLS Spreadsheets<br /><a href="https://isc.sans.edu/diary/16-bit%20Hash%20Collisions%20in%20.xls%20Spreadsheets/31066" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/16-bit%20Hash%20Collisions%20in%20.xls%20Spreadsheets/31066</a><br /> Attacks against the "Nette" PHP framework CVE-2020-15227<br /><a href="https://isc.sans.edu/forums/diary/Attacks+against+the+Nette+PHP+framework+CVE202015227/31076/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Attacks+against+the+Nette+PHP+framework+CVE202015227/31076/</a><br /> Squarespace Hijacked Domains<br /><a href="https://github.com/security-alliance/advisories/blob/main/2024-07-squarespace.pdf" target="_blank" rel="noreferrer noopener">https://github.com/security-alliance/advisories/blob/main/2024-07-squarespace.pdf</a><br />]]></itunes:summary><itunes:duration>390</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,squarespace; google; domains; </itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9052</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, July 15th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-july-15th-2024--60692862</link><description><![CDATA[16-Bit Hash Collisions in XLS Spreadsheets<br /><a href="https://isc.sans.edu/diary/16-bit%20Hash%20Collisions%20in%20.xls%20Spreadsheets/31066" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/16-bit%20Hash%20Collisions%20in%20.xls%20Spreadsheets/31066</a><br /> Attacks against the "Nette" PHP framework CVE-2020-15227<br /><a href="https://isc.sans.edu/forums/diary/Attacks+against+the+Nette+PHP+framework+CVE202015227/31076/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Attacks+against+the+Nette+PHP+framework+CVE202015227/31076/</a><br /> Squarespace Hijacked Domains<br /><a href="https://github.com/security-alliance/advisories/blob/main/2024-07-squarespace.pdf" target="_blank" rel="noreferrer noopener">https://github.com/security-alliance/advisories/blob/main/2024-07-squarespace.pdf</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9052.mp3</guid><pubDate>Mon, 15 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60692862/9052.mp3" length="5767998" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>16-Bit Hash Collisions in XLS Spreadsheets
https://isc.sans.edu/diary/16-bit%20Hash%20Collisions%20in%20.xls%20Spreadsheets/31066
 Attacks against the "Nette" PHP framework CVE-2020-15227...</itunes:subtitle><itunes:summary><![CDATA[16-Bit Hash Collisions in XLS Spreadsheets<br /><a href="https://isc.sans.edu/diary/16-bit%20Hash%20Collisions%20in%20.xls%20Spreadsheets/31066" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/16-bit%20Hash%20Collisions%20in%20.xls%20Spreadsheets/31066</a><br /> Attacks against the "Nette" PHP framework CVE-2020-15227<br /><a href="https://isc.sans.edu/forums/diary/Attacks+against+the+Nette+PHP+framework+CVE202015227/31076/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Attacks+against+the+Nette+PHP+framework+CVE202015227/31076/</a><br /> Squarespace Hijacked Domains<br /><a href="https://github.com/security-alliance/advisories/blob/main/2024-07-squarespace.pdf" target="_blank" rel="noreferrer noopener">https://github.com/security-alliance/advisories/blob/main/2024-07-squarespace.pdf</a><br />]]></itunes:summary><itunes:duration>390</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,squarespace; google; domains; </itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9052</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, July 12th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-july-12th-2024--62129348</link><description><![CDATA[Understanding SSH Honeypot Logs: Attackers Fingerprinting Honeypots<br /><a href="https://isc.sans.edu/diary/Understanding%20SSH%20Honeypot%20Logs%3A%20Attackers%20Fingerprinting%20Honeypots/31064" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Understanding%20SSH%20Honeypot%20Logs%3A%20Attackers%20Fingerprinting%20Honeypots/31064</a><br /> Patch or Peril: A Veeam Vulnerability Incident<br /><a href="https://www.group-ib.com/blog/estate-ransomware/" target="_blank" rel="noreferrer noopener">https://www.group-ib.com/blog/estate-ransomware/</a><br /> Juniper Patches<br /><a href="https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;f:ctype=%5BSecurity%20Advisories%5D" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;f:ctype=[Security%20Advisories]</a><br /> VMWare Aria Automation SQL Injection Vuln;<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24598" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24598</a><br /> Leaked SMS Messages<br /><a href="https://www.ccc.de/de/updates/2024/2fa-sms" target="_blank" rel="noreferrer noopener">https://www.ccc.de/de/updates/2024/2fa-sms</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9050.mp3</guid><pubDate>Fri, 12 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129348/9050.mp3" length="6610690" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Understanding SSH Honeypot Logs: Attackers Fingerprinting Honeypots
https://isc.sans.edu/diary/Understanding%20SSH%20Honeypot%20Logs%3A%20Attackers%20Fingerprinting%20Honeypots/31064
 Patch or Peril: A Veeam Vulnerability Incident...</itunes:subtitle><itunes:summary><![CDATA[Understanding SSH Honeypot Logs: Attackers Fingerprinting Honeypots<br /><a href="https://isc.sans.edu/diary/Understanding%20SSH%20Honeypot%20Logs%3A%20Attackers%20Fingerprinting%20Honeypots/31064" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Understanding%20SSH%20Honeypot%20Logs%3A%20Attackers%20Fingerprinting%20Honeypots/31064</a><br /> Patch or Peril: A Veeam Vulnerability Incident<br /><a href="https://www.group-ib.com/blog/estate-ransomware/" target="_blank" rel="noreferrer noopener">https://www.group-ib.com/blog/estate-ransomware/</a><br /> Juniper Patches<br /><a href="https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;f:ctype=%5BSecurity%20Advisories%5D" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;f:ctype=[Security%20Advisories]</a><br /> VMWare Aria Automation SQL Injection Vuln;<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24598" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24598</a><br /> Leaked SMS Messages<br /><a href="https://www.ccc.de/de/updates/2024/2fa-sms" target="_blank" rel="noreferrer noopener">https://www.ccc.de/de/updates/2024/2fa-sms</a><br />]]></itunes:summary><itunes:duration>451</itunes:duration><itunes:keywords>business,ccc; sms; vmware; aria; junipe,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9050</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, July 12th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-july-12th-2024--60669856</link><description><![CDATA[Understanding SSH Honeypot Logs: Attackers Fingerprinting Honeypots<br /><a href="https://isc.sans.edu/diary/Understanding%20SSH%20Honeypot%20Logs%3A%20Attackers%20Fingerprinting%20Honeypots/31064" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Understanding%20SSH%20Honeypot%20Logs%3A%20Attackers%20Fingerprinting%20Honeypots/31064</a><br /> Patch or Peril: A Veeam Vulnerability Incident<br /><a href="https://www.group-ib.com/blog/estate-ransomware/" target="_blank" rel="noreferrer noopener">https://www.group-ib.com/blog/estate-ransomware/</a><br /> Juniper Patches<br /><a href="https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;f:ctype=%5BSecurity%20Advisories%5D" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;f:ctype=[Security%20Advisories]</a><br /> VMWare Aria Automation SQL Injection Vuln;<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24598" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24598</a><br /> Leaked SMS Messages<br /><a href="https://www.ccc.de/de/updates/2024/2fa-sms" target="_blank" rel="noreferrer noopener">https://www.ccc.de/de/updates/2024/2fa-sms</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9050.mp3</guid><pubDate>Fri, 12 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60669856/9050.mp3" length="6610690" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Understanding SSH Honeypot Logs: Attackers Fingerprinting Honeypots
https://isc.sans.edu/diary/Understanding%20SSH%20Honeypot%20Logs%3A%20Attackers%20Fingerprinting%20Honeypots/31064
 Patch or Peril: A Veeam Vulnerability Incident...</itunes:subtitle><itunes:summary><![CDATA[Understanding SSH Honeypot Logs: Attackers Fingerprinting Honeypots<br /><a href="https://isc.sans.edu/diary/Understanding%20SSH%20Honeypot%20Logs%3A%20Attackers%20Fingerprinting%20Honeypots/31064" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Understanding%20SSH%20Honeypot%20Logs%3A%20Attackers%20Fingerprinting%20Honeypots/31064</a><br /> Patch or Peril: A Veeam Vulnerability Incident<br /><a href="https://www.group-ib.com/blog/estate-ransomware/" target="_blank" rel="noreferrer noopener">https://www.group-ib.com/blog/estate-ransomware/</a><br /> Juniper Patches<br /><a href="https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;f:ctype=%5BSecurity%20Advisories%5D" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;f:ctype=[Security%20Advisories]</a><br /> VMWare Aria Automation SQL Injection Vuln;<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24598" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24598</a><br /> Leaked SMS Messages<br /><a href="https://www.ccc.de/de/updates/2024/2fa-sms" target="_blank" rel="noreferrer noopener">https://www.ccc.de/de/updates/2024/2fa-sms</a><br />]]></itunes:summary><itunes:duration>451</itunes:duration><itunes:keywords>business,ccc; sms; vmware; aria; junipe,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9050</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, July 11th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-july-11th-2024--62129331</link><description><![CDATA[Finding Honeypot Data Clusters Using DBSCAN Part 1<br /><a href="https://isc.sans.edu/diary/Finding%20Honeypot%20Data%20Clusters%20Using%20DBSCAN%3A%20Part%201/31050" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Finding%20Honeypot%20Data%20Clusters%20Using%20DBSCAN%3A%20Part%201/31050</a><br /> Second RegreSSHion Like OpenSSH Vulnerability<br /><a href="https://lwn.net/ml/all/20240708162106.GA4920@openwall.com/" target="_blank" rel="noreferrer noopener">https://lwn.net/ml/all/20240708162106.GA4920@openwall.com/</a><br /> Resurrecting Internet Explorer: Threat Actors Using Zero-Day Tricks in Internet Shortcut File CVE-2024-38112<br /><a href="https://research.checkpoint.com/2024/resurrecting-internet-explorer-threat-actors-using-zero-day-tricks-in-internet-shortcut-file-to-lure-victims-cve-2024-38112/" target="_blank" rel="noreferrer noopener">https://research.checkpoint.com/2024/resurrecting-internet-explorer-threat-actors-using-zero-day-tricks-in-internet-shortcut-file-to-lure-victims-cve-2024-38112/</a><br /> SharePoint Proof of Concept Exploit CVE-2024-38094 CVE-2024-38024 CVE-2024-38023<br /><a href="https://github.com/testanull/MS-SharePoint-July-Patch-RCE-PoC/blob/main/poc_filtered.py" target="_blank" rel="noreferrer noopener">https://github.com/testanull/MS-SharePoint-July-Patch-RCE-PoC/blob/main/poc_filtered.py</a><br /> Citrix Netscaler, Agent and SDX Security Bulletin CVE-2024-6235 CVE-2024-6236<br /><a href="https://support.citrix.com/article/CTX677998/netscaler-console-agent-and-sdx-security-bulletin-for-cve20246235-and-cve20246236" target="_blank" rel="noreferrer noopener">https://support.citrix.com/article/CTX677998/netscaler-console-agent-and-sdx-security-bulletin-for-cve20246235-and-cve20246236</a><br /> OpenVPN Updates<br /><a href="https://openvpn.net/security-advisory/ovpnx-vulnerability-cve-2024-27903-cve-2024-27459-cve-2024-24974/" target="_blank" rel="noreferrer noopener">https://openvpn.net/security-advisory/ovpnx-vulnerability-cve-2024-27903-cve-2024-27459-cve-2024-24974/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9048.mp3</guid><pubDate>Thu, 11 Jul 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129331/9048.mp3" length="4979516" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Finding Honeypot Data Clusters Using DBSCAN Part 1
https://isc.sans.edu/diary/Finding%20Honeypot%20Data%20Clusters%20Using%20DBSCAN%3A%20Part%201/31050
 Second RegreSSHion Like OpenSSH Vulnerability...</itunes:subtitle><itunes:summary><![CDATA[Finding Honeypot Data Clusters Using DBSCAN Part 1<br /><a href="https://isc.sans.edu/diary/Finding%20Honeypot%20Data%20Clusters%20Using%20DBSCAN%3A%20Part%201/31050" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Finding%20Honeypot%20Data%20Clusters%20Using%20DBSCAN%3A%20Part%201/31050</a><br /> Second RegreSSHion Like OpenSSH Vulnerability<br /><a href="https://lwn.net/ml/all/20240708162106.GA4920@openwall.com/" target="_blank" rel="noreferrer noopener">https://lwn.net/ml/all/20240708162106.GA4920@openwall.com/</a><br /> Resurrecting Internet Explorer: Threat Actors Using Zero-Day Tricks in Internet Shortcut File CVE-2024-38112<br /><a href="https://research.checkpoint.com/2024/resurrecting-internet-explorer-threat-actors-using-zero-day-tricks-in-internet-shortcut-file-to-lure-victims-cve-2024-38112/" target="_blank" rel="noreferrer noopener">https://research.checkpoint.com/2024/resurrecting-internet-explorer-threat-actors-using-zero-day-tricks-in-internet-shortcut-file-to-lure-victims-cve-2024-38112/</a><br /> SharePoint Proof of Concept Exploit CVE-2024-38094 CVE-2024-38024 CVE-2024-38023<br /><a href="https://github.com/testanull/MS-SharePoint-July-Patch-RCE-PoC/blob/main/poc_filtered.py" target="_blank" rel="noreferrer noopener">https://github.com/testanull/MS-SharePoint-July-Patch-RCE-PoC/blob/main/poc_filtered.py</a><br /> Citrix Netscaler, Agent and SDX Security Bulletin CVE-2024-6235 CVE-2024-6236<br /><a href="https://support.citrix.com/article/CTX677998/netscaler-console-agent-and-sdx-security-bulletin-for-cve20246235-and-cve20246236" target="_blank" rel="noreferrer noopener">https://support.citrix.com/article/CTX677998/netscaler-console-agent-and-sdx-security-bulletin-for-cve20246235-and-cve20246236</a><br /> OpenVPN Updates<br /><a href="https://openvpn.net/security-advisory/ovpnx-vulnerability-cve-2024-27903-cve-2024-27459-cve-2024-24974/" target="_blank" rel="noreferrer noopener">https://openvpn.net/security-advisory/ovpnx-vulnerability-cve-2024-27903-cve-2024-27459-cve-2024-24974/</a><br />]]></itunes:summary><itunes:duration>334</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,openvpn; citrix; netscaler; sh,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9048</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, July 11th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-july-11th-2024--60659569</link><description><![CDATA[Finding Honeypot Data Clusters Using DBSCAN Part 1<br /><a href="https://isc.sans.edu/diary/Finding%20Honeypot%20Data%20Clusters%20Using%20DBSCAN%3A%20Part%201/31050" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Finding%20Honeypot%20Data%20Clusters%20Using%20DBSCAN%3A%20Part%201/31050</a><br /> Second RegreSSHion Like OpenSSH Vulnerability<br /><a href="https://lwn.net/ml/all/20240708162106.GA4920@openwall.com/" target="_blank" rel="noreferrer noopener">https://lwn.net/ml/all/20240708162106.GA4920@openwall.com/</a><br /> Resurrecting Internet Explorer: Threat Actors Using Zero-Day Tricks in Internet Shortcut File CVE-2024-38112<br /><a href="https://research.checkpoint.com/2024/resurrecting-internet-explorer-threat-actors-using-zero-day-tricks-in-internet-shortcut-file-to-lure-victims-cve-2024-38112/" target="_blank" rel="noreferrer noopener">https://research.checkpoint.com/2024/resurrecting-internet-explorer-threat-actors-using-zero-day-tricks-in-internet-shortcut-file-to-lure-victims-cve-2024-38112/</a><br /> SharePoint Proof of Concept Exploit CVE-2024-38094 CVE-2024-38024 CVE-2024-38023<br /><a href="https://github.com/testanull/MS-SharePoint-July-Patch-RCE-PoC/blob/main/poc_filtered.py" target="_blank" rel="noreferrer noopener">https://github.com/testanull/MS-SharePoint-July-Patch-RCE-PoC/blob/main/poc_filtered.py</a><br /> Citrix Netscaler, Agent and SDX Security Bulletin CVE-2024-6235 CVE-2024-6236<br /><a href="https://support.citrix.com/article/CTX677998/netscaler-console-agent-and-sdx-security-bulletin-for-cve20246235-and-cve20246236" target="_blank" rel="noreferrer noopener">https://support.citrix.com/article/CTX677998/netscaler-console-agent-and-sdx-security-bulletin-for-cve20246235-and-cve20246236</a><br /> OpenVPN Updates<br /><a href="https://openvpn.net/security-advisory/ovpnx-vulnerability-cve-2024-27903-cve-2024-27459-cve-2024-24974/" target="_blank" rel="noreferrer noopener">https://openvpn.net/security-advisory/ovpnx-vulnerability-cve-2024-27903-cve-2024-27459-cve-2024-24974/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9048.mp3</guid><pubDate>Thu, 11 Jul 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60659569/9048.mp3" length="4979516" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Finding Honeypot Data Clusters Using DBSCAN Part 1
https://isc.sans.edu/diary/Finding%20Honeypot%20Data%20Clusters%20Using%20DBSCAN%3A%20Part%201/31050
 Second RegreSSHion Like OpenSSH Vulnerability...</itunes:subtitle><itunes:summary><![CDATA[Finding Honeypot Data Clusters Using DBSCAN Part 1<br /><a href="https://isc.sans.edu/diary/Finding%20Honeypot%20Data%20Clusters%20Using%20DBSCAN%3A%20Part%201/31050" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Finding%20Honeypot%20Data%20Clusters%20Using%20DBSCAN%3A%20Part%201/31050</a><br /> Second RegreSSHion Like OpenSSH Vulnerability<br /><a href="https://lwn.net/ml/all/20240708162106.GA4920@openwall.com/" target="_blank" rel="noreferrer noopener">https://lwn.net/ml/all/20240708162106.GA4920@openwall.com/</a><br /> Resurrecting Internet Explorer: Threat Actors Using Zero-Day Tricks in Internet Shortcut File CVE-2024-38112<br /><a href="https://research.checkpoint.com/2024/resurrecting-internet-explorer-threat-actors-using-zero-day-tricks-in-internet-shortcut-file-to-lure-victims-cve-2024-38112/" target="_blank" rel="noreferrer noopener">https://research.checkpoint.com/2024/resurrecting-internet-explorer-threat-actors-using-zero-day-tricks-in-internet-shortcut-file-to-lure-victims-cve-2024-38112/</a><br /> SharePoint Proof of Concept Exploit CVE-2024-38094 CVE-2024-38024 CVE-2024-38023<br /><a href="https://github.com/testanull/MS-SharePoint-July-Patch-RCE-PoC/blob/main/poc_filtered.py" target="_blank" rel="noreferrer noopener">https://github.com/testanull/MS-SharePoint-July-Patch-RCE-PoC/blob/main/poc_filtered.py</a><br /> Citrix Netscaler, Agent and SDX Security Bulletin CVE-2024-6235 CVE-2024-6236<br /><a href="https://support.citrix.com/article/CTX677998/netscaler-console-agent-and-sdx-security-bulletin-for-cve20246235-and-cve20246236" target="_blank" rel="noreferrer noopener">https://support.citrix.com/article/CTX677998/netscaler-console-agent-and-sdx-security-bulletin-for-cve20246235-and-cve20246236</a><br /> OpenVPN Updates<br /><a href="https://openvpn.net/security-advisory/ovpnx-vulnerability-cve-2024-27903-cve-2024-27459-cve-2024-24974/" target="_blank" rel="noreferrer noopener">https://openvpn.net/security-advisory/ovpnx-vulnerability-cve-2024-27903-cve-2024-27459-cve-2024-24974/</a><br />]]></itunes:summary><itunes:duration>334</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,openvpn; citrix; netscaler; sh,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9048</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, July 10th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-july-10th-2024--62129330</link><description><![CDATA[Microsoft Patch Tuesday July 2024<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20July%202024/31058" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20July%202024/31058</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> RADIUS protocol susceptible to forgery attacks<br /><a href="https://kb.cert.org/vuls/id/456537" target="_blank" rel="noreferrer noopener">https://kb.cert.org/vuls/id/456537</a><br /><a href="https://www.inkbridgenetworks.com/blastradius/faq" target="_blank" rel="noreferrer noopener">https://www.inkbridgenetworks.com/blastradius/faq</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9046.mp3</guid><pubDate>Wed, 10 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129330/9046.mp3" length="5696585" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft Patch Tuesday July 2024
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20July%202024/31058
 Adobe Patches
https://helpx.adobe.com/security/security-bulletin.html
 RADIUS protocol susceptible to forgery attacks...</itunes:subtitle><itunes:summary><![CDATA[Microsoft Patch Tuesday July 2024<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20July%202024/31058" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20July%202024/31058</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> RADIUS protocol susceptible to forgery attacks<br /><a href="https://kb.cert.org/vuls/id/456537" target="_blank" rel="noreferrer noopener">https://kb.cert.org/vuls/id/456537</a><br /><a href="https://www.inkbridgenetworks.com/blastradius/faq" target="_blank" rel="noreferrer noopener">https://www.inkbridgenetworks.com/blastradius/faq</a><br />]]></itunes:summary><itunes:duration>385</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,radius; blastradius; adobe; mi,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9046</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, July 10th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-july-10th-2024--60648876</link><description><![CDATA[Microsoft Patch Tuesday July 2024<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20July%202024/31058" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20July%202024/31058</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> RADIUS protocol susceptible to forgery attacks<br /><a href="https://kb.cert.org/vuls/id/456537" target="_blank" rel="noreferrer noopener">https://kb.cert.org/vuls/id/456537</a><br /><a href="https://www.inkbridgenetworks.com/blastradius/faq" target="_blank" rel="noreferrer noopener">https://www.inkbridgenetworks.com/blastradius/faq</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9046.mp3</guid><pubDate>Wed, 10 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60648876/9046.mp3" length="5696585" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft Patch Tuesday July 2024
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20July%202024/31058
 Adobe Patches
https://helpx.adobe.com/security/security-bulletin.html
 RADIUS protocol susceptible to forgery attacks...</itunes:subtitle><itunes:summary><![CDATA[Microsoft Patch Tuesday July 2024<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20July%202024/31058" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20July%202024/31058</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> RADIUS protocol susceptible to forgery attacks<br /><a href="https://kb.cert.org/vuls/id/456537" target="_blank" rel="noreferrer noopener">https://kb.cert.org/vuls/id/456537</a><br /><a href="https://www.inkbridgenetworks.com/blastradius/faq" target="_blank" rel="noreferrer noopener">https://www.inkbridgenetworks.com/blastradius/faq</a><br />]]></itunes:summary><itunes:duration>385</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,radius; blastradius; adobe; mi,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9046</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, July 9th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-july-9th-2024--62129352</link><description><![CDATA[Kunai: Keep an Eye on your Linux Hosts Activity<br /><a href="https://isc.sans.edu/diary/Kunai%3A%20Keep%20an%20Eye%20on%20your%20Linux%20Hosts%20Activity/31054" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Kunai%3A%20Keep%20an%20Eye%20on%20your%20Linux%20Hosts%20Activity/31054</a><br /> Decryptor for DoNex Ransomware<br /><a href="https://decoded.avast.io/threatresearch/decrypted-donex-ransomware-and-its-predecessors/" target="_blank" rel="noreferrer noopener">https://decoded.avast.io/threatresearch/decrypted-donex-ransomware-and-its-predecessors/</a><br /> Shelltorch Explained: Multiple Vulnerabilities in Pytorch Model Server (Torchserve)<br /><a href="https://www.oligo.security/blog/shelltorch-explained-multiple-vulnerabilities-in-pytorch-model-server" target="_blank" rel="noreferrer noopener">https://www.oligo.security/blog/shelltorch-explained-multiple-vulnerabilities-in-pytorch-model-server</a><br /> Exim Bypass Attachment Inspection<br /><a href="https://bugs.exim.org/show_bug.cgi?id=3099#c4" target="_blank" rel="noreferrer noopener">https://bugs.exim.org/show_bug.cgi?id=3099#c4</a><br /> Toshiba/Sharp Printer vulnerabilities<br /><a href="https://pierrekim.github.io/blog/2024-06-27-toshiba-mfp-40-vulnerabilities.html" target="_blank" rel="noreferrer noopener">https://pierrekim.github.io/blog/2024-06-27-toshiba-mfp-40-vulnerabilities.html</a><br /><a href="https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html" target="_blank" rel="noreferrer noopener">https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9044.mp3</guid><pubDate>Tue, 09 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129352/9044.mp3" length="4965288" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Kunai: Keep an Eye on your Linux Hosts Activity
https://isc.sans.edu/diary/Kunai%3A%20Keep%20an%20Eye%20on%20your%20Linux%20Hosts%20Activity/31054
 Decryptor for DoNex Ransomware...</itunes:subtitle><itunes:summary><![CDATA[Kunai: Keep an Eye on your Linux Hosts Activity<br /><a href="https://isc.sans.edu/diary/Kunai%3A%20Keep%20an%20Eye%20on%20your%20Linux%20Hosts%20Activity/31054" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Kunai%3A%20Keep%20an%20Eye%20on%20your%20Linux%20Hosts%20Activity/31054</a><br /> Decryptor for DoNex Ransomware<br /><a href="https://decoded.avast.io/threatresearch/decrypted-donex-ransomware-and-its-predecessors/" target="_blank" rel="noreferrer noopener">https://decoded.avast.io/threatresearch/decrypted-donex-ransomware-and-its-predecessors/</a><br /> Shelltorch Explained: Multiple Vulnerabilities in Pytorch Model Server (Torchserve)<br /><a href="https://www.oligo.security/blog/shelltorch-explained-multiple-vulnerabilities-in-pytorch-model-server" target="_blank" rel="noreferrer noopener">https://www.oligo.security/blog/shelltorch-explained-multiple-vulnerabilities-in-pytorch-model-server</a><br /> Exim Bypass Attachment Inspection<br /><a href="https://bugs.exim.org/show_bug.cgi?id=3099#c4" target="_blank" rel="noreferrer noopener">https://bugs.exim.org/show_bug.cgi?id=3099#c4</a><br /> Toshiba/Sharp Printer vulnerabilities<br /><a href="https://pierrekim.github.io/blog/2024-06-27-toshiba-mfp-40-vulnerabilities.html" target="_blank" rel="noreferrer noopener">https://pierrekim.github.io/blog/2024-06-27-toshiba-mfp-40-vulnerabilities.html</a><br /><a href="https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html" target="_blank" rel="noreferrer noopener">https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html</a><br />]]></itunes:summary><itunes:duration>333</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,toshiba; sharp; exim; shelltor</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9044</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, July 9th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-july-9th-2024--60639259</link><description><![CDATA[Kunai: Keep an Eye on your Linux Hosts Activity<br /><a href="https://isc.sans.edu/diary/Kunai%3A%20Keep%20an%20Eye%20on%20your%20Linux%20Hosts%20Activity/31054" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Kunai%3A%20Keep%20an%20Eye%20on%20your%20Linux%20Hosts%20Activity/31054</a><br /> Decryptor for DoNex Ransomware<br /><a href="https://decoded.avast.io/threatresearch/decrypted-donex-ransomware-and-its-predecessors/" target="_blank" rel="noreferrer noopener">https://decoded.avast.io/threatresearch/decrypted-donex-ransomware-and-its-predecessors/</a><br /> Shelltorch Explained: Multiple Vulnerabilities in Pytorch Model Server (Torchserve)<br /><a href="https://www.oligo.security/blog/shelltorch-explained-multiple-vulnerabilities-in-pytorch-model-server" target="_blank" rel="noreferrer noopener">https://www.oligo.security/blog/shelltorch-explained-multiple-vulnerabilities-in-pytorch-model-server</a><br /> Exim Bypass Attachment Inspection<br /><a href="https://bugs.exim.org/show_bug.cgi?id=3099#c4" target="_blank" rel="noreferrer noopener">https://bugs.exim.org/show_bug.cgi?id=3099#c4</a><br /> Toshiba/Sharp Printer vulnerabilities<br /><a href="https://pierrekim.github.io/blog/2024-06-27-toshiba-mfp-40-vulnerabilities.html" target="_blank" rel="noreferrer noopener">https://pierrekim.github.io/blog/2024-06-27-toshiba-mfp-40-vulnerabilities.html</a><br /><a href="https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html" target="_blank" rel="noreferrer noopener">https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9044.mp3</guid><pubDate>Tue, 09 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60639259/9044.mp3" length="4965288" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Kunai: Keep an Eye on your Linux Hosts Activity
https://isc.sans.edu/diary/Kunai%3A%20Keep%20an%20Eye%20on%20your%20Linux%20Hosts%20Activity/31054
 Decryptor for DoNex Ransomware...</itunes:subtitle><itunes:summary><![CDATA[Kunai: Keep an Eye on your Linux Hosts Activity<br /><a href="https://isc.sans.edu/diary/Kunai%3A%20Keep%20an%20Eye%20on%20your%20Linux%20Hosts%20Activity/31054" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Kunai%3A%20Keep%20an%20Eye%20on%20your%20Linux%20Hosts%20Activity/31054</a><br /> Decryptor for DoNex Ransomware<br /><a href="https://decoded.avast.io/threatresearch/decrypted-donex-ransomware-and-its-predecessors/" target="_blank" rel="noreferrer noopener">https://decoded.avast.io/threatresearch/decrypted-donex-ransomware-and-its-predecessors/</a><br /> Shelltorch Explained: Multiple Vulnerabilities in Pytorch Model Server (Torchserve)<br /><a href="https://www.oligo.security/blog/shelltorch-explained-multiple-vulnerabilities-in-pytorch-model-server" target="_blank" rel="noreferrer noopener">https://www.oligo.security/blog/shelltorch-explained-multiple-vulnerabilities-in-pytorch-model-server</a><br /> Exim Bypass Attachment Inspection<br /><a href="https://bugs.exim.org/show_bug.cgi?id=3099#c4" target="_blank" rel="noreferrer noopener">https://bugs.exim.org/show_bug.cgi?id=3099#c4</a><br /> Toshiba/Sharp Printer vulnerabilities<br /><a href="https://pierrekim.github.io/blog/2024-06-27-toshiba-mfp-40-vulnerabilities.html" target="_blank" rel="noreferrer noopener">https://pierrekim.github.io/blog/2024-06-27-toshiba-mfp-40-vulnerabilities.html</a><br /><a href="https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html" target="_blank" rel="noreferrer noopener">https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html</a><br />]]></itunes:summary><itunes:duration>333</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,toshiba; sharp; exim; shelltor</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9044</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, July 8th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-july-8th-2024--62129337</link><description><![CDATA[OpenSSH RegreSSHion Vulnerability<br /><a href="https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt" target="_blank" rel="noreferrer noopener">https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt</a><br /><a href="https://isc.sans.edu/diary/SSH%20%22regreSSHion%22%20Remote%20Code%20Execution%20Vulnerability%20in%20OpenSSH./31046" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SSH%20%22regreSSHion%22%20Remote%20Code%20Execution%20Vulnerability%20in%20OpenSSH./31046</a><br /> Overlooked Domain Name Resliency Issues: Registrar Communications<br /><a href="https://isc.sans.edu/diary/Overlooked%20Domain%20Name%20Resiliency%20Issues%3A%20Registrar%20Communications/31048" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Overlooked%20Domain%20Name%20Resiliency%20Issues%3A%20Registrar%20Communications/31048</a><br /> Cloudflare 1.1.1.1 incident on Juine 27th 2024<br /><a href="https://blog.cloudflare.com/cloudflare-1111-incident-on-june-27-2024" target="_blank" rel="noreferrer noopener">https://blog.cloudflare.com/cloudflare-1111-incident-on-june-27-2024</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9042.mp3</guid><pubDate>Mon, 08 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129337/9042.mp3" length="8232693" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>OpenSSH RegreSSHion Vulnerability
https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt
https://isc.sans.edu/diary/SSH%20%22regreSSHion%22%20Remote%20Code%20Execution%20Vulnerability%20in%20OpenSSH./31046
 Overlooked Domain Name Resliency...</itunes:subtitle><itunes:summary><![CDATA[OpenSSH RegreSSHion Vulnerability<br /><a href="https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt" target="_blank" rel="noreferrer noopener">https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt</a><br /><a href="https://isc.sans.edu/diary/SSH%20%22regreSSHion%22%20Remote%20Code%20Execution%20Vulnerability%20in%20OpenSSH./31046" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SSH%20%22regreSSHion%22%20Remote%20Code%20Execution%20Vulnerability%20in%20OpenSSH./31046</a><br /> Overlooked Domain Name Resliency Issues: Registrar Communications<br /><a href="https://isc.sans.edu/diary/Overlooked%20Domain%20Name%20Resiliency%20Issues%3A%20Registrar%20Communications/31048" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Overlooked%20Domain%20Name%20Resiliency%20Issues%3A%20Registrar%20Communications/31048</a><br /> Cloudflare 1.1.1.1 incident on Juine 27th 2024<br /><a href="https://blog.cloudflare.com/cloudflare-1111-incident-on-june-27-2024" target="_blank" rel="noreferrer noopener">https://blog.cloudflare.com/cloudflare-1111-incident-on-june-27-2024</a><br />]]></itunes:summary><itunes:duration>566</itunes:duration><itunes:keywords>business,cloudflare; dos; bgp; dns; reg,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9042</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, July 8th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-july-8th-2024--60628910</link><description><![CDATA[OpenSSH RegreSSHion Vulnerability<br /><a href="https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt" target="_blank" rel="noreferrer noopener">https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt</a><br /><a href="https://isc.sans.edu/diary/SSH%20%22regreSSHion%22%20Remote%20Code%20Execution%20Vulnerability%20in%20OpenSSH./31046" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SSH%20%22regreSSHion%22%20Remote%20Code%20Execution%20Vulnerability%20in%20OpenSSH./31046</a><br /> Overlooked Domain Name Resliency Issues: Registrar Communications<br /><a href="https://isc.sans.edu/diary/Overlooked%20Domain%20Name%20Resiliency%20Issues%3A%20Registrar%20Communications/31048" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Overlooked%20Domain%20Name%20Resiliency%20Issues%3A%20Registrar%20Communications/31048</a><br /> Cloudflare 1.1.1.1 incident on Juine 27th 2024<br /><a href="https://blog.cloudflare.com/cloudflare-1111-incident-on-june-27-2024" target="_blank" rel="noreferrer noopener">https://blog.cloudflare.com/cloudflare-1111-incident-on-june-27-2024</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9042.mp3</guid><pubDate>Mon, 08 Jul 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60628910/9042.mp3" length="8232693" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>OpenSSH RegreSSHion Vulnerability
https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt
https://isc.sans.edu/diary/SSH%20%22regreSSHion%22%20Remote%20Code%20Execution%20Vulnerability%20in%20OpenSSH./31046
 Overlooked Domain Name Resliency...</itunes:subtitle><itunes:summary><![CDATA[OpenSSH RegreSSHion Vulnerability<br /><a href="https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt" target="_blank" rel="noreferrer noopener">https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt</a><br /><a href="https://isc.sans.edu/diary/SSH%20%22regreSSHion%22%20Remote%20Code%20Execution%20Vulnerability%20in%20OpenSSH./31046" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SSH%20%22regreSSHion%22%20Remote%20Code%20Execution%20Vulnerability%20in%20OpenSSH./31046</a><br /> Overlooked Domain Name Resliency Issues: Registrar Communications<br /><a href="https://isc.sans.edu/diary/Overlooked%20Domain%20Name%20Resiliency%20Issues%3A%20Registrar%20Communications/31048" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Overlooked%20Domain%20Name%20Resiliency%20Issues%3A%20Registrar%20Communications/31048</a><br /> Cloudflare 1.1.1.1 incident on Juine 27th 2024<br /><a href="https://blog.cloudflare.com/cloudflare-1111-incident-on-june-27-2024" target="_blank" rel="noreferrer noopener">https://blog.cloudflare.com/cloudflare-1111-incident-on-june-27-2024</a><br />]]></itunes:summary><itunes:duration>566</itunes:duration><itunes:keywords>business,cloudflare; dos; bgp; dns; reg,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9042</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, June 28th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-june-28th-2024--62129357</link><description><![CDATA[What Setting Live Traps For Cybercriminals Taught Me About Security<br /><a href="https://isc.sans.edu/diary/What%20Setting%20Live%20Traps%20for%20Cybercriminals%20Taught%20Me%20About%20Security%20%5BGuest%20Diary%5D/31038" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20Setting%20Live%20Traps%20for%20Cybercriminals%20Taught%20Me%20About%20Security%20%5BGuest%20Diary%5D/31038</a><br /> TeamViewer Compromise<br /><a href="https://www.teamviewer.com/en-us/resources/trust-center/statement/" target="_blank" rel="noreferrer noopener">https://www.teamviewer.com/en-us/resources/trust-center/statement/</a><br /> Fortra File Catalyst Vulnerability and PoC<br /><a href="https://support.fortra.com/filecatalyst/kb-articles/advisory-6-24-2024-filecatalyst-workflow-sql-injection-vulnerability-YmYwYWY4OTYtNTUzMi1lZjExLTg0MGEtNjA0NWJkMDg3MDA0" target="_blank" rel="noreferrer noopener">https://support.fortra.com/filecatalyst/kb-articles/advisory-6-24-2024-filecatalyst-workflow-sql-injection-vulnerability-YmYwYWY4OTYtNTUzMi1lZjExLTg0MGEtNjA0NWJkMDg3MDA0</a><br /><a href="https://www.tenable.com/security/research/tra-2024-25" target="_blank" rel="noreferrer noopener">https://www.tenable.com/security/research/tra-2024-25</a><br /> GitLab Critical Update<br /><a href="https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/" target="_blank" rel="noreferrer noopener">https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/</a><br /> When Prompts Go Rogue: Analyzing a Prompt Injection Code Execution in Vanna.AI<br /><a href="https://jfrog.com/blog/prompt-injection-attack-code-execution-in-vanna-ai-cve-2024-5565/" target="_blank" rel="noreferrer noopener">https://jfrog.com/blog/prompt-injection-attack-code-execution-in-vanna-ai-cve-2024-5565/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9040.mp3</guid><pubDate>Fri, 28 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129357/9040.mp3" length="6595631" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>What Setting Live Traps For Cybercriminals Taught Me About Security
https://isc.sans.edu/diary/What%20Setting%20Live%20Traps%20for%20Cybercriminals%20Taught%20Me%20About%20Security%20%5BGuest%20Diary%5D/31038
 TeamViewer Compromise...</itunes:subtitle><itunes:summary><![CDATA[What Setting Live Traps For Cybercriminals Taught Me About Security<br /><a href="https://isc.sans.edu/diary/What%20Setting%20Live%20Traps%20for%20Cybercriminals%20Taught%20Me%20About%20Security%20%5BGuest%20Diary%5D/31038" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20Setting%20Live%20Traps%20for%20Cybercriminals%20Taught%20Me%20About%20Security%20%5BGuest%20Diary%5D/31038</a><br /> TeamViewer Compromise<br /><a href="https://www.teamviewer.com/en-us/resources/trust-center/statement/" target="_blank" rel="noreferrer noopener">https://www.teamviewer.com/en-us/resources/trust-center/statement/</a><br /> Fortra File Catalyst Vulnerability and PoC<br /><a href="https://support.fortra.com/filecatalyst/kb-articles/advisory-6-24-2024-filecatalyst-workflow-sql-injection-vulnerability-YmYwYWY4OTYtNTUzMi1lZjExLTg0MGEtNjA0NWJkMDg3MDA0" target="_blank" rel="noreferrer noopener">https://support.fortra.com/filecatalyst/kb-articles/advisory-6-24-2024-filecatalyst-workflow-sql-injection-vulnerability-YmYwYWY4OTYtNTUzMi1lZjExLTg0MGEtNjA0NWJkMDg3MDA0</a><br /><a href="https://www.tenable.com/security/research/tra-2024-25" target="_blank" rel="noreferrer noopener">https://www.tenable.com/security/research/tra-2024-25</a><br /> GitLab Critical Update<br /><a href="https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/" target="_blank" rel="noreferrer noopener">https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/</a><br /> When Prompts Go Rogue: Analyzing a Prompt Injection Code Execution in Vanna.AI<br /><a href="https://jfrog.com/blog/prompt-injection-attack-code-execution-in-vanna-ai-cve-2024-5565/" target="_blank" rel="noreferrer noopener">https://jfrog.com/blog/prompt-injection-attack-code-execution-in-vanna-ai-cve-2024-5565/</a><br />]]></itunes:summary><itunes:duration>449</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,vanna.ai; prompt injection; sq</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9040</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, June 28th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-june-28th-2024--60535316</link><description><![CDATA[What Setting Live Traps For Cybercriminals Taught Me About Security<br /><a href="https://isc.sans.edu/diary/What%20Setting%20Live%20Traps%20for%20Cybercriminals%20Taught%20Me%20About%20Security%20%5BGuest%20Diary%5D/31038" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20Setting%20Live%20Traps%20for%20Cybercriminals%20Taught%20Me%20About%20Security%20%5BGuest%20Diary%5D/31038</a><br /> TeamViewer Compromise<br /><a href="https://www.teamviewer.com/en-us/resources/trust-center/statement/" target="_blank" rel="noreferrer noopener">https://www.teamviewer.com/en-us/resources/trust-center/statement/</a><br /> Fortra File Catalyst Vulnerability and PoC<br /><a href="https://support.fortra.com/filecatalyst/kb-articles/advisory-6-24-2024-filecatalyst-workflow-sql-injection-vulnerability-YmYwYWY4OTYtNTUzMi1lZjExLTg0MGEtNjA0NWJkMDg3MDA0" target="_blank" rel="noreferrer noopener">https://support.fortra.com/filecatalyst/kb-articles/advisory-6-24-2024-filecatalyst-workflow-sql-injection-vulnerability-YmYwYWY4OTYtNTUzMi1lZjExLTg0MGEtNjA0NWJkMDg3MDA0</a><br /><a href="https://www.tenable.com/security/research/tra-2024-25" target="_blank" rel="noreferrer noopener">https://www.tenable.com/security/research/tra-2024-25</a><br /> GitLab Critical Update<br /><a href="https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/" target="_blank" rel="noreferrer noopener">https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/</a><br /> When Prompts Go Rogue: Analyzing a Prompt Injection Code Execution in Vanna.AI<br /><a href="https://jfrog.com/blog/prompt-injection-attack-code-execution-in-vanna-ai-cve-2024-5565/" target="_blank" rel="noreferrer noopener">https://jfrog.com/blog/prompt-injection-attack-code-execution-in-vanna-ai-cve-2024-5565/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9040.mp3</guid><pubDate>Fri, 28 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60535316/9040.mp3" length="6595631" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>What Setting Live Traps For Cybercriminals Taught Me About Security
https://isc.sans.edu/diary/What%20Setting%20Live%20Traps%20for%20Cybercriminals%20Taught%20Me%20About%20Security%20%5BGuest%20Diary%5D/31038
 TeamViewer Compromise...</itunes:subtitle><itunes:summary><![CDATA[What Setting Live Traps For Cybercriminals Taught Me About Security<br /><a href="https://isc.sans.edu/diary/What%20Setting%20Live%20Traps%20for%20Cybercriminals%20Taught%20Me%20About%20Security%20%5BGuest%20Diary%5D/31038" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20Setting%20Live%20Traps%20for%20Cybercriminals%20Taught%20Me%20About%20Security%20%5BGuest%20Diary%5D/31038</a><br /> TeamViewer Compromise<br /><a href="https://www.teamviewer.com/en-us/resources/trust-center/statement/" target="_blank" rel="noreferrer noopener">https://www.teamviewer.com/en-us/resources/trust-center/statement/</a><br /> Fortra File Catalyst Vulnerability and PoC<br /><a href="https://support.fortra.com/filecatalyst/kb-articles/advisory-6-24-2024-filecatalyst-workflow-sql-injection-vulnerability-YmYwYWY4OTYtNTUzMi1lZjExLTg0MGEtNjA0NWJkMDg3MDA0" target="_blank" rel="noreferrer noopener">https://support.fortra.com/filecatalyst/kb-articles/advisory-6-24-2024-filecatalyst-workflow-sql-injection-vulnerability-YmYwYWY4OTYtNTUzMi1lZjExLTg0MGEtNjA0NWJkMDg3MDA0</a><br /><a href="https://www.tenable.com/security/research/tra-2024-25" target="_blank" rel="noreferrer noopener">https://www.tenable.com/security/research/tra-2024-25</a><br /> GitLab Critical Update<br /><a href="https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/" target="_blank" rel="noreferrer noopener">https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/</a><br /> When Prompts Go Rogue: Analyzing a Prompt Injection Code Execution in Vanna.AI<br /><a href="https://jfrog.com/blog/prompt-injection-attack-code-execution-in-vanna-ai-cve-2024-5565/" target="_blank" rel="noreferrer noopener">https://jfrog.com/blog/prompt-injection-attack-code-execution-in-vanna-ai-cve-2024-5565/</a><br />]]></itunes:summary><itunes:duration>449</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,vanna.ai; prompt injection; sq</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9040</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, June 27th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-june-27th-2024--62129359</link><description><![CDATA[Critical Progress MOVEit Authentication Bypass Vulnerability<br /><a href="https://labs.watchtowr.com/auth-bypass-in-un-limited-scenarios-progress-moveit-transfer-cve-2024-5806/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/auth-bypass-in-un-limited-scenarios-progress-moveit-transfer-cve-2024-5806/</a><br /><a href="https://community.progress.com/s/article/MOVEit-Transfer-Product-Security-Alert-Bulletin-June-2024-CVE-2024-5806" target="_blank" rel="noreferrer noopener">https://community.progress.com/s/article/MOVEit-Transfer-Product-Security-Alert-Bulletin-June-2024-CVE-2024-5806</a><br /> Polyfill.io Supply Chain Attack<br /><a href="https://cside.dev/blog/more-than-100k-websites-targeted-in-web-supply-chain-attack" target="_blank" rel="noreferrer noopener">https://cside.dev/blog/more-than-100k-websites-targeted-in-web-supply-chain-attack</a><br /> Apple AirPods Firmware Update<br /><a href="https://support.apple.com/en-us/HT214111" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/HT214111</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9038.mp3</guid><pubDate>Thu, 27 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129359/9038.mp3" length="5660654" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Critical Progress MOVEit Authentication Bypass Vulnerability
https://labs.watchtowr.com/auth-bypass-in-un-limited-scenarios-progress-moveit-transfer-cve-2024-5806/...</itunes:subtitle><itunes:summary><![CDATA[Critical Progress MOVEit Authentication Bypass Vulnerability<br /><a href="https://labs.watchtowr.com/auth-bypass-in-un-limited-scenarios-progress-moveit-transfer-cve-2024-5806/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/auth-bypass-in-un-limited-scenarios-progress-moveit-transfer-cve-2024-5806/</a><br /><a href="https://community.progress.com/s/article/MOVEit-Transfer-Product-Security-Alert-Bulletin-June-2024-CVE-2024-5806" target="_blank" rel="noreferrer noopener">https://community.progress.com/s/article/MOVEit-Transfer-Product-Security-Alert-Bulletin-June-2024-CVE-2024-5806</a><br /> Polyfill.io Supply Chain Attack<br /><a href="https://cside.dev/blog/more-than-100k-websites-targeted-in-web-supply-chain-attack" target="_blank" rel="noreferrer noopener">https://cside.dev/blog/more-than-100k-websites-targeted-in-web-supply-chain-attack</a><br /> Apple AirPods Firmware Update<br /><a href="https://support.apple.com/en-us/HT214111" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/HT214111</a><br />]]></itunes:summary><itunes:duration>383</itunes:duration><itunes:keywords>airpods; polyfill; moveit;,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9038</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, June 27th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-june-27th-2024--60522800</link><description><![CDATA[Critical Progress MOVEit Authentication Bypass Vulnerability<br /><a href="https://labs.watchtowr.com/auth-bypass-in-un-limited-scenarios-progress-moveit-transfer-cve-2024-5806/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/auth-bypass-in-un-limited-scenarios-progress-moveit-transfer-cve-2024-5806/</a><br /><a href="https://community.progress.com/s/article/MOVEit-Transfer-Product-Security-Alert-Bulletin-June-2024-CVE-2024-5806" target="_blank" rel="noreferrer noopener">https://community.progress.com/s/article/MOVEit-Transfer-Product-Security-Alert-Bulletin-June-2024-CVE-2024-5806</a><br /> Polyfill.io Supply Chain Attack<br /><a href="https://cside.dev/blog/more-than-100k-websites-targeted-in-web-supply-chain-attack" target="_blank" rel="noreferrer noopener">https://cside.dev/blog/more-than-100k-websites-targeted-in-web-supply-chain-attack</a><br /> Apple AirPods Firmware Update<br /><a href="https://support.apple.com/en-us/HT214111" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/HT214111</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9038.mp3</guid><pubDate>Thu, 27 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60522800/9038.mp3" length="5660654" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Critical Progress MOVEit Authentication Bypass Vulnerability
https://labs.watchtowr.com/auth-bypass-in-un-limited-scenarios-progress-moveit-transfer-cve-2024-5806/...</itunes:subtitle><itunes:summary><![CDATA[Critical Progress MOVEit Authentication Bypass Vulnerability<br /><a href="https://labs.watchtowr.com/auth-bypass-in-un-limited-scenarios-progress-moveit-transfer-cve-2024-5806/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/auth-bypass-in-un-limited-scenarios-progress-moveit-transfer-cve-2024-5806/</a><br /><a href="https://community.progress.com/s/article/MOVEit-Transfer-Product-Security-Alert-Bulletin-June-2024-CVE-2024-5806" target="_blank" rel="noreferrer noopener">https://community.progress.com/s/article/MOVEit-Transfer-Product-Security-Alert-Bulletin-June-2024-CVE-2024-5806</a><br /> Polyfill.io Supply Chain Attack<br /><a href="https://cside.dev/blog/more-than-100k-websites-targeted-in-web-supply-chain-attack" target="_blank" rel="noreferrer noopener">https://cside.dev/blog/more-than-100k-websites-targeted-in-web-supply-chain-attack</a><br /> Apple AirPods Firmware Update<br /><a href="https://support.apple.com/en-us/HT214111" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/HT214111</a><br />]]></itunes:summary><itunes:duration>383</itunes:duration><itunes:keywords>airpods; polyfill; moveit;,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9038</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, June 26th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-june-26th-2024--62129369</link><description><![CDATA[TCP Latency Sidechannel<br /><a href="https://www.snailload.com/snailload.pdf" target="_blank" rel="noreferrer noopener">https://www.snailload.com/snailload.pdf</a><br /> Microsoft Management Console for Intial Access and Evasion<br /><a href="https://www.elastic.co/security-labs/grimresource" target="_blank" rel="noreferrer noopener">https://www.elastic.co/security-labs/grimresource</a><br /> Wyze Camera Vulnerabilities<br /><a href="https://forums.wyze.com/t/security-advisory/289256" target="_blank" rel="noreferrer noopener">https://forums.wyze.com/t/security-advisory/289256</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9036.mp3</guid><pubDate>Wed, 26 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129369/9036.mp3" length="5675182" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>TCP Latency Sidechannel
https://www.snailload.com/snailload.pdf
 Microsoft Management Console for Intial Access and Evasion
https://www.elastic.co/security-labs/grimresource
 Wyze Camera Vulnerabilities
https://forums.wyze.com/t/security-advisory/289256
</itunes:subtitle><itunes:summary><![CDATA[TCP Latency Sidechannel<br /><a href="https://www.snailload.com/snailload.pdf" target="_blank" rel="noreferrer noopener">https://www.snailload.com/snailload.pdf</a><br /> Microsoft Management Console for Intial Access and Evasion<br /><a href="https://www.elastic.co/security-labs/grimresource" target="_blank" rel="noreferrer noopener">https://www.elastic.co/security-labs/grimresource</a><br /> Wyze Camera Vulnerabilities<br /><a href="https://forums.wyze.com/t/security-advisory/289256" target="_blank" rel="noreferrer noopener">https://forums.wyze.com/t/security-advisory/289256</a><br />]]></itunes:summary><itunes:duration>384</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,wyze; camera; mmc; snailload; </itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9036</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, June 26th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-june-26th-2024--60512382</link><description><![CDATA[TCP Latency Sidechannel<br /><a href="https://www.snailload.com/snailload.pdf" target="_blank" rel="noreferrer noopener">https://www.snailload.com/snailload.pdf</a><br /> Microsoft Management Console for Intial Access and Evasion<br /><a href="https://www.elastic.co/security-labs/grimresource" target="_blank" rel="noreferrer noopener">https://www.elastic.co/security-labs/grimresource</a><br /> Wyze Camera Vulnerabilities<br /><a href="https://forums.wyze.com/t/security-advisory/289256" target="_blank" rel="noreferrer noopener">https://forums.wyze.com/t/security-advisory/289256</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9036.mp3</guid><pubDate>Wed, 26 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60512382/9036.mp3" length="5675182" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>TCP Latency Sidechannel
https://www.snailload.com/snailload.pdf
 Microsoft Management Console for Intial Access and Evasion
https://www.elastic.co/security-labs/grimresource
 Wyze Camera Vulnerabilities
https://forums.wyze.com/t/security-advisory/289256
</itunes:subtitle><itunes:summary><![CDATA[TCP Latency Sidechannel<br /><a href="https://www.snailload.com/snailload.pdf" target="_blank" rel="noreferrer noopener">https://www.snailload.com/snailload.pdf</a><br /> Microsoft Management Console for Intial Access and Evasion<br /><a href="https://www.elastic.co/security-labs/grimresource" target="_blank" rel="noreferrer noopener">https://www.elastic.co/security-labs/grimresource</a><br /> Wyze Camera Vulnerabilities<br /><a href="https://forums.wyze.com/t/security-advisory/289256" target="_blank" rel="noreferrer noopener">https://forums.wyze.com/t/security-advisory/289256</a><br />]]></itunes:summary><itunes:duration>384</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,wyze; camera; mmc; snailload; </itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9036</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, June 25th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-june-25th-2024--62129340</link><description><![CDATA[Configuration Scans Expand<br /><a href="https://isc.sans.edu/diary/Configuration%20Scanners%20Adding%20Java%20Specific%20Configuration%20Files/31032" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Configuration%20Scanners%20Adding%20Java%20Specific%20Configuration%20Files/31032</a><br /> SQL Server Emergency Fix<br /><a href="https://support.microsoft.com/en-us/topic/june-20-2024-kb5041054-os-build-20348-2529-out-of-band-b746ffbd-934e-42ac-9c66-ed0636edf7f1" target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-us/topic/june-20-2024-kb5041054-os-build-20348-2529-out-of-band-b746ffbd-934e-42ac-9c66-ed0636edf7f1</a><br /> Juniper Security Analytics Update<br /><a href="https://supportportal.juniper.net/s/article/On-Demand-JSA-Series-Multiple-vulnerabilities-resolved-in-Juniper-Secure-Analytics-in-7-5-0-UP8-IF03?language=en_US" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/article/On-Demand-JSA-Series-Multiple-vulnerabilities-resolved-in-Juniper-Secure-Analytics-in-7-5-0-UP8-IF03?language=en_US</a><br /> MacOS/iOS XNU Buffer Overflow Exploit CVE-2024-27815<br /><a href="https://jprx.io/cve-2024-27815/" target="_blank" rel="noreferrer noopener">https://jprx.io/cve-2024-27815/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9034.mp3</guid><pubDate>Tue, 25 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129340/9034.mp3" length="4860488" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Configuration Scans Expand
https://isc.sans.edu/diary/Configuration%20Scanners%20Adding%20Java%20Specific%20Configuration%20Files/31032
 SQL Server Emergency Fix...</itunes:subtitle><itunes:summary><![CDATA[Configuration Scans Expand<br /><a href="https://isc.sans.edu/diary/Configuration%20Scanners%20Adding%20Java%20Specific%20Configuration%20Files/31032" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Configuration%20Scanners%20Adding%20Java%20Specific%20Configuration%20Files/31032</a><br /> SQL Server Emergency Fix<br /><a href="https://support.microsoft.com/en-us/topic/june-20-2024-kb5041054-os-build-20348-2529-out-of-band-b746ffbd-934e-42ac-9c66-ed0636edf7f1" target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-us/topic/june-20-2024-kb5041054-os-build-20348-2529-out-of-band-b746ffbd-934e-42ac-9c66-ed0636edf7f1</a><br /> Juniper Security Analytics Update<br /><a href="https://supportportal.juniper.net/s/article/On-Demand-JSA-Series-Multiple-vulnerabilities-resolved-in-Juniper-Secure-Analytics-in-7-5-0-UP8-IF03?language=en_US" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/article/On-Demand-JSA-Series-Multiple-vulnerabilities-resolved-in-Juniper-Secure-Analytics-in-7-5-0-UP8-IF03?language=en_US</a><br /> MacOS/iOS XNU Buffer Overflow Exploit CVE-2024-27815<br /><a href="https://jprx.io/cve-2024-27815/" target="_blank" rel="noreferrer noopener">https://jprx.io/cve-2024-27815/</a><br />]]></itunes:summary><itunes:duration>326</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,macos; ios; buffer overflow; j,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9034</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, June 25th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-june-25th-2024--60497378</link><description><![CDATA[Configuration Scans Expand<br /><a href="https://isc.sans.edu/diary/Configuration%20Scanners%20Adding%20Java%20Specific%20Configuration%20Files/31032" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Configuration%20Scanners%20Adding%20Java%20Specific%20Configuration%20Files/31032</a><br /> SQL Server Emergency Fix<br /><a href="https://support.microsoft.com/en-us/topic/june-20-2024-kb5041054-os-build-20348-2529-out-of-band-b746ffbd-934e-42ac-9c66-ed0636edf7f1" target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-us/topic/june-20-2024-kb5041054-os-build-20348-2529-out-of-band-b746ffbd-934e-42ac-9c66-ed0636edf7f1</a><br /> Juniper Security Analytics Update<br /><a href="https://supportportal.juniper.net/s/article/On-Demand-JSA-Series-Multiple-vulnerabilities-resolved-in-Juniper-Secure-Analytics-in-7-5-0-UP8-IF03?language=en_US" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/article/On-Demand-JSA-Series-Multiple-vulnerabilities-resolved-in-Juniper-Secure-Analytics-in-7-5-0-UP8-IF03?language=en_US</a><br /> MacOS/iOS XNU Buffer Overflow Exploit CVE-2024-27815<br /><a href="https://jprx.io/cve-2024-27815/" target="_blank" rel="noreferrer noopener">https://jprx.io/cve-2024-27815/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9034.mp3</guid><pubDate>Tue, 25 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60497378/9034.mp3" length="4860488" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Configuration Scans Expand
https://isc.sans.edu/diary/Configuration%20Scanners%20Adding%20Java%20Specific%20Configuration%20Files/31032
 SQL Server Emergency Fix...</itunes:subtitle><itunes:summary><![CDATA[Configuration Scans Expand<br /><a href="https://isc.sans.edu/diary/Configuration%20Scanners%20Adding%20Java%20Specific%20Configuration%20Files/31032" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Configuration%20Scanners%20Adding%20Java%20Specific%20Configuration%20Files/31032</a><br /> SQL Server Emergency Fix<br /><a href="https://support.microsoft.com/en-us/topic/june-20-2024-kb5041054-os-build-20348-2529-out-of-band-b746ffbd-934e-42ac-9c66-ed0636edf7f1" target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-us/topic/june-20-2024-kb5041054-os-build-20348-2529-out-of-band-b746ffbd-934e-42ac-9c66-ed0636edf7f1</a><br /> Juniper Security Analytics Update<br /><a href="https://supportportal.juniper.net/s/article/On-Demand-JSA-Series-Multiple-vulnerabilities-resolved-in-Juniper-Secure-Analytics-in-7-5-0-UP8-IF03?language=en_US" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/article/On-Demand-JSA-Series-Multiple-vulnerabilities-resolved-in-Juniper-Secure-Analytics-in-7-5-0-UP8-IF03?language=en_US</a><br /> MacOS/iOS XNU Buffer Overflow Exploit CVE-2024-27815<br /><a href="https://jprx.io/cve-2024-27815/" target="_blank" rel="noreferrer noopener">https://jprx.io/cve-2024-27815/</a><br />]]></itunes:summary><itunes:duration>326</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,macos; ios; buffer overflow; j,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9034</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, June 24th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-june-24th-2024--62129349</link><description><![CDATA[Sysinternals Process Monitor Version 4 Released<br /><a href="https://isc.sans.edu/diary/Sysinternals%27%20Process%20Monitor%20Version%204%20Released/31026" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Sysinternals%27%20Process%20Monitor%20Version%204%20Released/31026</a><br /> Kaspersky Sanctions<br /><a href="https://home.treasury.gov/news/press-releases/jy2420" target="_blank" rel="noreferrer noopener">https://home.treasury.gov/news/press-releases/jy2420</a><br /> Phoenix UEFI Buffer Overflow Affects Wide Range of Systems<br /><a href="https://eclypsium.com/blog/ueficanhazbufferoverflow-widespread-impact-from-vulnerability-in-popular-pc-and-server-firmware/" target="_blank" rel="noreferrer noopener">https://eclypsium.com/blog/ueficanhazbufferoverflow-widespread-impact-from-vulnerability-in-popular-pc-and-server-firmware/</a><br /> Ghostscript Update<br /><a href="https://ghostscript.readthedocs.io/en/gs10.03.1/News.html" target="_blank" rel="noreferrer noopener">https://ghostscript.readthedocs.io/en/gs10.03.1/News.html</a><br /> js2py vulnerability<br /><a href="https://github.com/Marven11/CVE-2024-28397-js2py-Sandbox-Escape" target="_blank" rel="noreferrer noopener">https://github.com/Marven11/CVE-2024-28397-js2py-Sandbox-Escape</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9032.mp3</guid><pubDate>Mon, 24 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129349/9032.mp3" length="6268086" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Sysinternals Process Monitor Version 4 Released
https://isc.sans.edu/diary/Sysinternals%27%20Process%20Monitor%20Version%204%20Released/31026
 Kaspersky Sanctions
https://home.treasury.gov/news/press-releases/jy2420
 Phoenix UEFI Buffer Overflow...</itunes:subtitle><itunes:summary><![CDATA[Sysinternals Process Monitor Version 4 Released<br /><a href="https://isc.sans.edu/diary/Sysinternals%27%20Process%20Monitor%20Version%204%20Released/31026" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Sysinternals%27%20Process%20Monitor%20Version%204%20Released/31026</a><br /> Kaspersky Sanctions<br /><a href="https://home.treasury.gov/news/press-releases/jy2420" target="_blank" rel="noreferrer noopener">https://home.treasury.gov/news/press-releases/jy2420</a><br /> Phoenix UEFI Buffer Overflow Affects Wide Range of Systems<br /><a href="https://eclypsium.com/blog/ueficanhazbufferoverflow-widespread-impact-from-vulnerability-in-popular-pc-and-server-firmware/" target="_blank" rel="noreferrer noopener">https://eclypsium.com/blog/ueficanhazbufferoverflow-widespread-impact-from-vulnerability-in-popular-pc-and-server-firmware/</a><br /> Ghostscript Update<br /><a href="https://ghostscript.readthedocs.io/en/gs10.03.1/News.html" target="_blank" rel="noreferrer noopener">https://ghostscript.readthedocs.io/en/gs10.03.1/News.html</a><br /> js2py vulnerability<br /><a href="https://github.com/Marven11/CVE-2024-28397-js2py-Sandbox-Escape" target="_blank" rel="noreferrer noopener">https://github.com/Marven11/CVE-2024-28397-js2py-Sandbox-Escape</a><br />]]></itunes:summary><itunes:duration>426</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,js2py; ghostscript; pdf; posts,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9032</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, June 24th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-june-24th-2024--60484925</link><description><![CDATA[Sysinternals Process Monitor Version 4 Released<br /><a href="https://isc.sans.edu/diary/Sysinternals%27%20Process%20Monitor%20Version%204%20Released/31026" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Sysinternals%27%20Process%20Monitor%20Version%204%20Released/31026</a><br /> Kaspersky Sanctions<br /><a href="https://home.treasury.gov/news/press-releases/jy2420" target="_blank" rel="noreferrer noopener">https://home.treasury.gov/news/press-releases/jy2420</a><br /> Phoenix UEFI Buffer Overflow Affects Wide Range of Systems<br /><a href="https://eclypsium.com/blog/ueficanhazbufferoverflow-widespread-impact-from-vulnerability-in-popular-pc-and-server-firmware/" target="_blank" rel="noreferrer noopener">https://eclypsium.com/blog/ueficanhazbufferoverflow-widespread-impact-from-vulnerability-in-popular-pc-and-server-firmware/</a><br /> Ghostscript Update<br /><a href="https://ghostscript.readthedocs.io/en/gs10.03.1/News.html" target="_blank" rel="noreferrer noopener">https://ghostscript.readthedocs.io/en/gs10.03.1/News.html</a><br /> js2py vulnerability<br /><a href="https://github.com/Marven11/CVE-2024-28397-js2py-Sandbox-Escape" target="_blank" rel="noreferrer noopener">https://github.com/Marven11/CVE-2024-28397-js2py-Sandbox-Escape</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9032.mp3</guid><pubDate>Mon, 24 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60484925/9032.mp3" length="6268086" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Sysinternals Process Monitor Version 4 Released
https://isc.sans.edu/diary/Sysinternals%27%20Process%20Monitor%20Version%204%20Released/31026
 Kaspersky Sanctions
https://home.treasury.gov/news/press-releases/jy2420
 Phoenix UEFI Buffer Overflow...</itunes:subtitle><itunes:summary><![CDATA[Sysinternals Process Monitor Version 4 Released<br /><a href="https://isc.sans.edu/diary/Sysinternals%27%20Process%20Monitor%20Version%204%20Released/31026" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Sysinternals%27%20Process%20Monitor%20Version%204%20Released/31026</a><br /> Kaspersky Sanctions<br /><a href="https://home.treasury.gov/news/press-releases/jy2420" target="_blank" rel="noreferrer noopener">https://home.treasury.gov/news/press-releases/jy2420</a><br /> Phoenix UEFI Buffer Overflow Affects Wide Range of Systems<br /><a href="https://eclypsium.com/blog/ueficanhazbufferoverflow-widespread-impact-from-vulnerability-in-popular-pc-and-server-firmware/" target="_blank" rel="noreferrer noopener">https://eclypsium.com/blog/ueficanhazbufferoverflow-widespread-impact-from-vulnerability-in-popular-pc-and-server-firmware/</a><br /> Ghostscript Update<br /><a href="https://ghostscript.readthedocs.io/en/gs10.03.1/News.html" target="_blank" rel="noreferrer noopener">https://ghostscript.readthedocs.io/en/gs10.03.1/News.html</a><br /> js2py vulnerability<br /><a href="https://github.com/Marven11/CVE-2024-28397-js2py-Sandbox-Escape" target="_blank" rel="noreferrer noopener">https://github.com/Marven11/CVE-2024-28397-js2py-Sandbox-Escape</a><br />]]></itunes:summary><itunes:duration>426</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,js2py; ghostscript; pdf; posts,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9032</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, June 21st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-june-21st-2024--62129338</link><description><![CDATA[No Excuses: Free Tools to Help Secure Authentication in Ubuntu<br /><a href="https://isc.sans.edu/diary/No%20Excuses%2C%20Free%20Tools%20to%20Help%20Secure%20Authentication%20in%20Ubuntu%20Linux%20%5BGuest%20Diary%5D/31024" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/No%20Excuses%2C%20Free%20Tools%20to%20Help%20Secure%20Authentication%20in%20Ubuntu%20Linux%20%5BGuest%20Diary%5D/31024</a><br /> Handling BOM MIME Files<br /><a href="https://isc.sans.edu/diary/Handling+BOM+MIME+Files/31022" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Handling+BOM+MIME+Files/31022</a><br /> Atlasiun Confluence Data Center and Server Vuln<br /><a href="https://confluence.atlassian.com/security/security-bulletin-june-18-2024-1409286211.html" target="_blank" rel="noreferrer noopener">https://confluence.atlassian.com/security/security-bulletin-june-18-2024-1409286211.html</a><br /> Beyond the @ Symbol: Exploiting the Flexibility of Email Addresses For Offensive Purposes<br /><a href="https://modzero.com/en/blog/beyond_the_at_symbol/" target="_blank" rel="noreferrer noopener">https://modzero.com/en/blog/beyond_the_at_symbol/</a><br /> VMWare Patches<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9030.mp3</guid><pubDate>Fri, 21 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129338/9030.mp3" length="4634145" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>No Excuses: Free Tools to Help Secure Authentication in Ubuntu
https://isc.sans.edu/diary/No%20Excuses%2C%20Free%20Tools%20to%20Help%20Secure%20Authentication%20in%20Ubuntu%20Linux%20%5BGuest%20Diary%5D/31024
 Handling BOM MIME Files...</itunes:subtitle><itunes:summary><![CDATA[No Excuses: Free Tools to Help Secure Authentication in Ubuntu<br /><a href="https://isc.sans.edu/diary/No%20Excuses%2C%20Free%20Tools%20to%20Help%20Secure%20Authentication%20in%20Ubuntu%20Linux%20%5BGuest%20Diary%5D/31024" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/No%20Excuses%2C%20Free%20Tools%20to%20Help%20Secure%20Authentication%20in%20Ubuntu%20Linux%20%5BGuest%20Diary%5D/31024</a><br /> Handling BOM MIME Files<br /><a href="https://isc.sans.edu/diary/Handling+BOM+MIME+Files/31022" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Handling+BOM+MIME+Files/31022</a><br /> Atlasiun Confluence Data Center and Server Vuln<br /><a href="https://confluence.atlassian.com/security/security-bulletin-june-18-2024-1409286211.html" target="_blank" rel="noreferrer noopener">https://confluence.atlassian.com/security/security-bulletin-june-18-2024-1409286211.html</a><br /> Beyond the @ Symbol: Exploiting the Flexibility of Email Addresses For Offensive Purposes<br /><a href="https://modzero.com/en/blog/beyond_the_at_symbol/" target="_blank" rel="noreferrer noopener">https://modzero.com/en/blog/beyond_the_at_symbol/</a><br /> VMWare Patches<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453</a><br />]]></itunes:summary><itunes:duration>309</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,ubuntu; authentcation; mfa; vm</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9030</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, June 21st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-june-21st-2024--60470194</link><description><![CDATA[No Excuses: Free Tools to Help Secure Authentication in Ubuntu<br /><a href="https://isc.sans.edu/diary/No%20Excuses%2C%20Free%20Tools%20to%20Help%20Secure%20Authentication%20in%20Ubuntu%20Linux%20%5BGuest%20Diary%5D/31024" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/No%20Excuses%2C%20Free%20Tools%20to%20Help%20Secure%20Authentication%20in%20Ubuntu%20Linux%20%5BGuest%20Diary%5D/31024</a><br /> Handling BOM MIME Files<br /><a href="https://isc.sans.edu/diary/Handling+BOM+MIME+Files/31022" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Handling+BOM+MIME+Files/31022</a><br /> Atlasiun Confluence Data Center and Server Vuln<br /><a href="https://confluence.atlassian.com/security/security-bulletin-june-18-2024-1409286211.html" target="_blank" rel="noreferrer noopener">https://confluence.atlassian.com/security/security-bulletin-june-18-2024-1409286211.html</a><br /> Beyond the @ Symbol: Exploiting the Flexibility of Email Addresses For Offensive Purposes<br /><a href="https://modzero.com/en/blog/beyond_the_at_symbol/" target="_blank" rel="noreferrer noopener">https://modzero.com/en/blog/beyond_the_at_symbol/</a><br /> VMWare Patches<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9030.mp3</guid><pubDate>Fri, 21 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60470194/9030.mp3" length="4634145" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>No Excuses: Free Tools to Help Secure Authentication in Ubuntu
https://isc.sans.edu/diary/No%20Excuses%2C%20Free%20Tools%20to%20Help%20Secure%20Authentication%20in%20Ubuntu%20Linux%20%5BGuest%20Diary%5D/31024
 Handling BOM MIME Files...</itunes:subtitle><itunes:summary><![CDATA[No Excuses: Free Tools to Help Secure Authentication in Ubuntu<br /><a href="https://isc.sans.edu/diary/No%20Excuses%2C%20Free%20Tools%20to%20Help%20Secure%20Authentication%20in%20Ubuntu%20Linux%20%5BGuest%20Diary%5D/31024" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/No%20Excuses%2C%20Free%20Tools%20to%20Help%20Secure%20Authentication%20in%20Ubuntu%20Linux%20%5BGuest%20Diary%5D/31024</a><br /> Handling BOM MIME Files<br /><a href="https://isc.sans.edu/diary/Handling+BOM+MIME+Files/31022" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Handling+BOM+MIME+Files/31022</a><br /> Atlasiun Confluence Data Center and Server Vuln<br /><a href="https://confluence.atlassian.com/security/security-bulletin-june-18-2024-1409286211.html" target="_blank" rel="noreferrer noopener">https://confluence.atlassian.com/security/security-bulletin-june-18-2024-1409286211.html</a><br /> Beyond the @ Symbol: Exploiting the Flexibility of Email Addresses For Offensive Purposes<br /><a href="https://modzero.com/en/blog/beyond_the_at_symbol/" target="_blank" rel="noreferrer noopener">https://modzero.com/en/blog/beyond_the_at_symbol/</a><br /> VMWare Patches<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453</a><br />]]></itunes:summary><itunes:duration>309</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,ubuntu; authentcation; mfa; vm</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9030</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, June 18th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-june-18th-2024--62129350</link><description><![CDATA[New NetSupport Campaign Deleivered Through MSIX Packages<br /><a href="https://isc.sans.edu/diary/New%20NetSupport%20Campaign%20Delivered%20Through%20MSIX%20Packages/31018" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/New%20NetSupport%20Campaign%20Delivered%20Through%20MSIX%20Packages/31018</a><br /> D-Link Router Backdoor<br /><a href="https://www.twcert.org.tw/en/cp-139-7880-629f5-2.html" target="_blank" rel="noreferrer noopener">https://www.twcert.org.tw/en/cp-139-7880-629f5-2.html</a><br /><a href="https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10398" target="_blank" rel="noreferrer noopener">https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10398</a><br /> iTerm2 Vulnerablity<br /><a href="https://vin01.github.io/piptagole/escape-sequences/iterm2/rce/2024/06/16/iterm2-rce-window-title-tmux-integration.html" target="_blank" rel="noreferrer noopener">https://vin01.github.io/piptagole/escape-sequences/iterm2/rce/2024/06/16/iterm2-rce-window-title-tmux-integration.html</a><br /> NextCloud Vulnerability<br /><a href="https://github.com/nextcloud/security-advisories/security/advisories/GHSA-9v72-9xv5-3p7c" target="_blank" rel="noreferrer noopener">https://github.com/nextcloud/security-advisories/security/advisories/GHSA-9v72-9xv5-3p7c</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9028.mp3</guid><pubDate>Tue, 18 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129350/9028.mp3" length="4323331" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>New NetSupport Campaign Deleivered Through MSIX Packages
https://isc.sans.edu/diary/New%20NetSupport%20Campaign%20Delivered%20Through%20MSIX%20Packages/31018
 D-Link Router Backdoor
https://www.twcert.org.tw/en/cp-139-7880-629f5-2.html...</itunes:subtitle><itunes:summary><![CDATA[New NetSupport Campaign Deleivered Through MSIX Packages<br /><a href="https://isc.sans.edu/diary/New%20NetSupport%20Campaign%20Delivered%20Through%20MSIX%20Packages/31018" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/New%20NetSupport%20Campaign%20Delivered%20Through%20MSIX%20Packages/31018</a><br /> D-Link Router Backdoor<br /><a href="https://www.twcert.org.tw/en/cp-139-7880-629f5-2.html" target="_blank" rel="noreferrer noopener">https://www.twcert.org.tw/en/cp-139-7880-629f5-2.html</a><br /><a href="https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10398" target="_blank" rel="noreferrer noopener">https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10398</a><br /> iTerm2 Vulnerablity<br /><a href="https://vin01.github.io/piptagole/escape-sequences/iterm2/rce/2024/06/16/iterm2-rce-window-title-tmux-integration.html" target="_blank" rel="noreferrer noopener">https://vin01.github.io/piptagole/escape-sequences/iterm2/rce/2024/06/16/iterm2-rce-window-title-tmux-integration.html</a><br /> NextCloud Vulnerability<br /><a href="https://github.com/nextcloud/security-advisories/security/advisories/GHSA-9v72-9xv5-3p7c" target="_blank" rel="noreferrer noopener">https://github.com/nextcloud/security-advisories/security/advisories/GHSA-9v72-9xv5-3p7c</a><br />]]></itunes:summary><itunes:duration>287</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,nextcloud; iterm2; d-link; dli,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9028</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, June 18th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-june-18th-2024--60419356</link><description><![CDATA[New NetSupport Campaign Deleivered Through MSIX Packages<br /><a href="https://isc.sans.edu/diary/New%20NetSupport%20Campaign%20Delivered%20Through%20MSIX%20Packages/31018" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/New%20NetSupport%20Campaign%20Delivered%20Through%20MSIX%20Packages/31018</a><br /> D-Link Router Backdoor<br /><a href="https://www.twcert.org.tw/en/cp-139-7880-629f5-2.html" target="_blank" rel="noreferrer noopener">https://www.twcert.org.tw/en/cp-139-7880-629f5-2.html</a><br /><a href="https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10398" target="_blank" rel="noreferrer noopener">https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10398</a><br /> iTerm2 Vulnerablity<br /><a href="https://vin01.github.io/piptagole/escape-sequences/iterm2/rce/2024/06/16/iterm2-rce-window-title-tmux-integration.html" target="_blank" rel="noreferrer noopener">https://vin01.github.io/piptagole/escape-sequences/iterm2/rce/2024/06/16/iterm2-rce-window-title-tmux-integration.html</a><br /> NextCloud Vulnerability<br /><a href="https://github.com/nextcloud/security-advisories/security/advisories/GHSA-9v72-9xv5-3p7c" target="_blank" rel="noreferrer noopener">https://github.com/nextcloud/security-advisories/security/advisories/GHSA-9v72-9xv5-3p7c</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9028.mp3</guid><pubDate>Tue, 18 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60419356/9028.mp3" length="4323331" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>New NetSupport Campaign Deleivered Through MSIX Packages
https://isc.sans.edu/diary/New%20NetSupport%20Campaign%20Delivered%20Through%20MSIX%20Packages/31018
 D-Link Router Backdoor
https://www.twcert.org.tw/en/cp-139-7880-629f5-2.html...</itunes:subtitle><itunes:summary><![CDATA[New NetSupport Campaign Deleivered Through MSIX Packages<br /><a href="https://isc.sans.edu/diary/New%20NetSupport%20Campaign%20Delivered%20Through%20MSIX%20Packages/31018" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/New%20NetSupport%20Campaign%20Delivered%20Through%20MSIX%20Packages/31018</a><br /> D-Link Router Backdoor<br /><a href="https://www.twcert.org.tw/en/cp-139-7880-629f5-2.html" target="_blank" rel="noreferrer noopener">https://www.twcert.org.tw/en/cp-139-7880-629f5-2.html</a><br /><a href="https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10398" target="_blank" rel="noreferrer noopener">https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10398</a><br /> iTerm2 Vulnerablity<br /><a href="https://vin01.github.io/piptagole/escape-sequences/iterm2/rce/2024/06/16/iterm2-rce-window-title-tmux-integration.html" target="_blank" rel="noreferrer noopener">https://vin01.github.io/piptagole/escape-sequences/iterm2/rce/2024/06/16/iterm2-rce-window-title-tmux-integration.html</a><br /> NextCloud Vulnerability<br /><a href="https://github.com/nextcloud/security-advisories/security/advisories/GHSA-9v72-9xv5-3p7c" target="_blank" rel="noreferrer noopener">https://github.com/nextcloud/security-advisories/security/advisories/GHSA-9v72-9xv5-3p7c</a><br />]]></itunes:summary><itunes:duration>287</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,nextcloud; iterm2; d-link; dli,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9028</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, June 17th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-june-17th-2024--62129351</link><description><![CDATA[Overview of My Tools That Handle JSON Data<br /><a href="https://isc.sans.edu/diary/Overview%20of%20My%20Tools%20That%20Handle%20JSON%20Data/31012" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Overview%20of%20My%20Tools%20That%20Handle%20JSON%20Data/31012</a><br /> Python Serialization and "Sleepy Pickle"<br /><a href="https://x.com/MarkBaggett/status/1801732554740969561" target="_blank" rel="noreferrer noopener">https://x.com/MarkBaggett/status/1801732554740969561</a><br /> Detecting Headless Chrome<br /><a href="https://deviceandbrowserinfo.com/learning_zone/articles/detecting-headless-chrome-puppeteer-2024" target="_blank" rel="noreferrer noopener">https://deviceandbrowserinfo.com/learning_zone/articles/detecting-headless-chrome-puppeteer-2024</a><br /> Detecting Malicious VS Code Extensions<br /><a href="https://medium.com/@amitassaraf/4-6-introducing-extensiontotal-how-to-assess-risk-in-vs-code-extensions-3ac5bfd83fb1" target="_blank" rel="noreferrer noopener">https://medium.com/@amitassaraf/4-6-introducing-extensiontotal-how-to-assess-risk-in-vs-code-extensions-3ac5bfd83fb1</a><br /> ASUS Router Critical Vulnerability<br /><a href="https://www.asus.com/content/asus-product-security-advisory/" target="_blank" rel="noreferrer noopener">https://www.asus.com/content/asus-product-security-advisory/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9026.mp3</guid><pubDate>Mon, 17 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129351/9026.mp3" length="4875296" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Overview of My Tools That Handle JSON Data
https://isc.sans.edu/diary/Overview%20of%20My%20Tools%20That%20Handle%20JSON%20Data/31012
 Python Serialization and "Sleepy Pickle"
https://x.com/MarkBaggett/status/1801732554740969561
 Detecting Headless...</itunes:subtitle><itunes:summary><![CDATA[Overview of My Tools That Handle JSON Data<br /><a href="https://isc.sans.edu/diary/Overview%20of%20My%20Tools%20That%20Handle%20JSON%20Data/31012" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Overview%20of%20My%20Tools%20That%20Handle%20JSON%20Data/31012</a><br /> Python Serialization and "Sleepy Pickle"<br /><a href="https://x.com/MarkBaggett/status/1801732554740969561" target="_blank" rel="noreferrer noopener">https://x.com/MarkBaggett/status/1801732554740969561</a><br /> Detecting Headless Chrome<br /><a href="https://deviceandbrowserinfo.com/learning_zone/articles/detecting-headless-chrome-puppeteer-2024" target="_blank" rel="noreferrer noopener">https://deviceandbrowserinfo.com/learning_zone/articles/detecting-headless-chrome-puppeteer-2024</a><br /> Detecting Malicious VS Code Extensions<br /><a href="https://medium.com/@amitassaraf/4-6-introducing-extensiontotal-how-to-assess-risk-in-vs-code-extensions-3ac5bfd83fb1" target="_blank" rel="noreferrer noopener">https://medium.com/@amitassaraf/4-6-introducing-extensiontotal-how-to-assess-risk-in-vs-code-extensions-3ac5bfd83fb1</a><br /> ASUS Router Critical Vulnerability<br /><a href="https://www.asus.com/content/asus-product-security-advisory/" target="_blank" rel="noreferrer noopener">https://www.asus.com/content/asus-product-security-advisory/</a><br />]]></itunes:summary><itunes:duration>327</itunes:duration><itunes:keywords>asus; vscode; headless; chrome,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9026</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, June 17th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-june-17th-2024--60407058</link><description><![CDATA[Overview of My Tools That Handle JSON Data<br /><a href="https://isc.sans.edu/diary/Overview%20of%20My%20Tools%20That%20Handle%20JSON%20Data/31012" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Overview%20of%20My%20Tools%20That%20Handle%20JSON%20Data/31012</a><br /> Python Serialization and "Sleepy Pickle"<br /><a href="https://x.com/MarkBaggett/status/1801732554740969561" target="_blank" rel="noreferrer noopener">https://x.com/MarkBaggett/status/1801732554740969561</a><br /> Detecting Headless Chrome<br /><a href="https://deviceandbrowserinfo.com/learning_zone/articles/detecting-headless-chrome-puppeteer-2024" target="_blank" rel="noreferrer noopener">https://deviceandbrowserinfo.com/learning_zone/articles/detecting-headless-chrome-puppeteer-2024</a><br /> Detecting Malicious VS Code Extensions<br /><a href="https://medium.com/@amitassaraf/4-6-introducing-extensiontotal-how-to-assess-risk-in-vs-code-extensions-3ac5bfd83fb1" target="_blank" rel="noreferrer noopener">https://medium.com/@amitassaraf/4-6-introducing-extensiontotal-how-to-assess-risk-in-vs-code-extensions-3ac5bfd83fb1</a><br /> ASUS Router Critical Vulnerability<br /><a href="https://www.asus.com/content/asus-product-security-advisory/" target="_blank" rel="noreferrer noopener">https://www.asus.com/content/asus-product-security-advisory/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9026.mp3</guid><pubDate>Mon, 17 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60407058/9026.mp3" length="4875296" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Overview of My Tools That Handle JSON Data
https://isc.sans.edu/diary/Overview%20of%20My%20Tools%20That%20Handle%20JSON%20Data/31012
 Python Serialization and "Sleepy Pickle"
https://x.com/MarkBaggett/status/1801732554740969561
 Detecting Headless...</itunes:subtitle><itunes:summary><![CDATA[Overview of My Tools That Handle JSON Data<br /><a href="https://isc.sans.edu/diary/Overview%20of%20My%20Tools%20That%20Handle%20JSON%20Data/31012" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Overview%20of%20My%20Tools%20That%20Handle%20JSON%20Data/31012</a><br /> Python Serialization and "Sleepy Pickle"<br /><a href="https://x.com/MarkBaggett/status/1801732554740969561" target="_blank" rel="noreferrer noopener">https://x.com/MarkBaggett/status/1801732554740969561</a><br /> Detecting Headless Chrome<br /><a href="https://deviceandbrowserinfo.com/learning_zone/articles/detecting-headless-chrome-puppeteer-2024" target="_blank" rel="noreferrer noopener">https://deviceandbrowserinfo.com/learning_zone/articles/detecting-headless-chrome-puppeteer-2024</a><br /> Detecting Malicious VS Code Extensions<br /><a href="https://medium.com/@amitassaraf/4-6-introducing-extensiontotal-how-to-assess-risk-in-vs-code-extensions-3ac5bfd83fb1" target="_blank" rel="noreferrer noopener">https://medium.com/@amitassaraf/4-6-introducing-extensiontotal-how-to-assess-risk-in-vs-code-extensions-3ac5bfd83fb1</a><br /> ASUS Router Critical Vulnerability<br /><a href="https://www.asus.com/content/asus-product-security-advisory/" target="_blank" rel="noreferrer noopener">https://www.asus.com/content/asus-product-security-advisory/</a><br />]]></itunes:summary><itunes:duration>327</itunes:duration><itunes:keywords>asus; vscode; headless; chrome,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9026</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, June 14th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-june-14th-2024--62129353</link><description><![CDATA[The Art of JQ and Command-Line Fu<br /><a href="https://isc.sans.edu/diary/The%20Art%20of%20JQ%20and%20Command-line%20Fu%20%5BGuest%20Diary%5D/31006" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20Art%20of%20JQ%20and%20Command-line%20Fu%20%5BGuest%20Diary%5D/31006</a><br /> Microsoft Outlook Vulnerablity Details<br /><a href="https://blog.morphisec.com/cve-2024-30103-microsoft-outlook-vulnerability" target="_blank" rel="noreferrer noopener">https://blog.morphisec.com/cve-2024-30103-microsoft-outlook-vulnerability</a><br /> Keeping our Outlook Personal Email Users Safe<br /><a href="https://techcommunity.microsoft.com/t5/outlook-blog/keeping-our-outlook-personal-email-users-safe-reinforcing-our/ba-p/4164184" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/outlook-blog/keeping-our-outlook-personal-email-users-safe-reinforcing-our/ba-p/4164184</a><br /> Exploiting ML models with pickle file attacks<br /><a href="https://blog.trailofbits.com/2024/06/11/exploiting-ml-models-with-pickle-file-attacks-part-1/" target="_blank" rel="noreferrer noopener">https://blog.trailofbits.com/2024/06/11/exploiting-ml-models-with-pickle-file-attacks-part-1/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9024.mp3</guid><pubDate>Fri, 14 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129353/9024.mp3" length="4985620" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>The Art of JQ and Command-Line Fu
https://isc.sans.edu/diary/The%20Art%20of%20JQ%20and%20Command-line%20Fu%20%5BGuest%20Diary%5D/31006
 Microsoft Outlook Vulnerablity Details
https://blog.morphisec.com/cve-2024-30103-microsoft-outlook-vulnerability...</itunes:subtitle><itunes:summary><![CDATA[The Art of JQ and Command-Line Fu<br /><a href="https://isc.sans.edu/diary/The%20Art%20of%20JQ%20and%20Command-line%20Fu%20%5BGuest%20Diary%5D/31006" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20Art%20of%20JQ%20and%20Command-line%20Fu%20%5BGuest%20Diary%5D/31006</a><br /> Microsoft Outlook Vulnerablity Details<br /><a href="https://blog.morphisec.com/cve-2024-30103-microsoft-outlook-vulnerability" target="_blank" rel="noreferrer noopener">https://blog.morphisec.com/cve-2024-30103-microsoft-outlook-vulnerability</a><br /> Keeping our Outlook Personal Email Users Safe<br /><a href="https://techcommunity.microsoft.com/t5/outlook-blog/keeping-our-outlook-personal-email-users-safe-reinforcing-our/ba-p/4164184" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/outlook-blog/keeping-our-outlook-personal-email-users-safe-reinforcing-our/ba-p/4164184</a><br /> Exploiting ML models with pickle file attacks<br /><a href="https://blog.trailofbits.com/2024/06/11/exploiting-ml-models-with-pickle-file-attacks-part-1/" target="_blank" rel="noreferrer noopener">https://blog.trailofbits.com/2024/06/11/exploiting-ml-models-with-pickle-file-attacks-part-1/</a><br />]]></itunes:summary><itunes:duration>335</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,ml; pickle; outlook; email; mf,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9024</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, June 14th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-june-14th-2024--60380886</link><description><![CDATA[The Art of JQ and Command-Line Fu<br /><a href="https://isc.sans.edu/diary/The%20Art%20of%20JQ%20and%20Command-line%20Fu%20%5BGuest%20Diary%5D/31006" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20Art%20of%20JQ%20and%20Command-line%20Fu%20%5BGuest%20Diary%5D/31006</a><br /> Microsoft Outlook Vulnerablity Details<br /><a href="https://blog.morphisec.com/cve-2024-30103-microsoft-outlook-vulnerability" target="_blank" rel="noreferrer noopener">https://blog.morphisec.com/cve-2024-30103-microsoft-outlook-vulnerability</a><br /> Keeping our Outlook Personal Email Users Safe<br /><a href="https://techcommunity.microsoft.com/t5/outlook-blog/keeping-our-outlook-personal-email-users-safe-reinforcing-our/ba-p/4164184" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/outlook-blog/keeping-our-outlook-personal-email-users-safe-reinforcing-our/ba-p/4164184</a><br /> Exploiting ML models with pickle file attacks<br /><a href="https://blog.trailofbits.com/2024/06/11/exploiting-ml-models-with-pickle-file-attacks-part-1/" target="_blank" rel="noreferrer noopener">https://blog.trailofbits.com/2024/06/11/exploiting-ml-models-with-pickle-file-attacks-part-1/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9024.mp3</guid><pubDate>Fri, 14 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60380886/9024.mp3" length="4985620" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>The Art of JQ and Command-Line Fu
https://isc.sans.edu/diary/The%20Art%20of%20JQ%20and%20Command-line%20Fu%20%5BGuest%20Diary%5D/31006
 Microsoft Outlook Vulnerablity Details
https://blog.morphisec.com/cve-2024-30103-microsoft-outlook-vulnerability...</itunes:subtitle><itunes:summary><![CDATA[The Art of JQ and Command-Line Fu<br /><a href="https://isc.sans.edu/diary/The%20Art%20of%20JQ%20and%20Command-line%20Fu%20%5BGuest%20Diary%5D/31006" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20Art%20of%20JQ%20and%20Command-line%20Fu%20%5BGuest%20Diary%5D/31006</a><br /> Microsoft Outlook Vulnerablity Details<br /><a href="https://blog.morphisec.com/cve-2024-30103-microsoft-outlook-vulnerability" target="_blank" rel="noreferrer noopener">https://blog.morphisec.com/cve-2024-30103-microsoft-outlook-vulnerability</a><br /> Keeping our Outlook Personal Email Users Safe<br /><a href="https://techcommunity.microsoft.com/t5/outlook-blog/keeping-our-outlook-personal-email-users-safe-reinforcing-our/ba-p/4164184" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/outlook-blog/keeping-our-outlook-personal-email-users-safe-reinforcing-our/ba-p/4164184</a><br /> Exploiting ML models with pickle file attacks<br /><a href="https://blog.trailofbits.com/2024/06/11/exploiting-ml-models-with-pickle-file-attacks-part-1/" target="_blank" rel="noreferrer noopener">https://blog.trailofbits.com/2024/06/11/exploiting-ml-models-with-pickle-file-attacks-part-1/</a><br />]]></itunes:summary><itunes:duration>334</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,ml; pickle; outlook; email; mf,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9024</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, June 13th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-june-13th-2024--62129358</link><description><![CDATA[MSMQ Packets<br /><a href="https://isc.sans.edu/diary/Port%201801%20Traffic%3A%20Microsoft%20Message%20Queue/31004" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Port%201801%20Traffic%3A%20Microsoft%20Message%20Queue/31004</a><br /> Adobe Updates<br /><a href="https://helpx.adobe.com/security/products/magento/apsb24-40.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/products/magento/apsb24-40.html</a><br /> Black Basta Exploited CVE-2024-26169 Prior to Patch<br /><a href="https://symantec-enterprise-blogs.security.com/threat-intelligence/black-basta-ransomware-zero-day" target="_blank" rel="noreferrer noopener">https://symantec-enterprise-blogs.security.com/threat-intelligence/black-basta-ransomware-zero-day</a><br /> Pixel Phone 0-Day Patched<br /><a href="https://source.android.com/docs/security/bulletin/pixel/2024-06-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/pixel/2024-06-01</a><br /><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9022.mp3</guid><pubDate>Thu, 13 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129358/9022.mp3" length="4795282" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>MSMQ Packets
https://isc.sans.edu/diary/Port%201801%20Traffic%3A%20Microsoft%20Message%20Queue/31004
 Adobe Updates
https://helpx.adobe.com/security/products/magento/apsb24-40.html
 Black Basta Exploited CVE-2024-26169 Prior to Patch...</itunes:subtitle><itunes:summary><![CDATA[MSMQ Packets<br /><a href="https://isc.sans.edu/diary/Port%201801%20Traffic%3A%20Microsoft%20Message%20Queue/31004" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Port%201801%20Traffic%3A%20Microsoft%20Message%20Queue/31004</a><br /> Adobe Updates<br /><a href="https://helpx.adobe.com/security/products/magento/apsb24-40.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/products/magento/apsb24-40.html</a><br /> Black Basta Exploited CVE-2024-26169 Prior to Patch<br /><a href="https://symantec-enterprise-blogs.security.com/threat-intelligence/black-basta-ransomware-zero-day" target="_blank" rel="noreferrer noopener">https://symantec-enterprise-blogs.security.com/threat-intelligence/black-basta-ransomware-zero-day</a><br /> Pixel Phone 0-Day Patched<br /><a href="https://source.android.com/docs/security/bulletin/pixel/2024-06-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/pixel/2024-06-01</a><br /><br />]]></itunes:summary><itunes:duration>321</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,pixel; phone; black basta; ado,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9022</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, June 13th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-june-13th-2024--60368289</link><description><![CDATA[MSMQ Packets<br /><a href="https://isc.sans.edu/diary/Port%201801%20Traffic%3A%20Microsoft%20Message%20Queue/31004" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Port%201801%20Traffic%3A%20Microsoft%20Message%20Queue/31004</a><br /> Adobe Updates<br /><a href="https://helpx.adobe.com/security/products/magento/apsb24-40.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/products/magento/apsb24-40.html</a><br /> Black Basta Exploited CVE-2024-26169 Prior to Patch<br /><a href="https://symantec-enterprise-blogs.security.com/threat-intelligence/black-basta-ransomware-zero-day" target="_blank" rel="noreferrer noopener">https://symantec-enterprise-blogs.security.com/threat-intelligence/black-basta-ransomware-zero-day</a><br /> Pixel Phone 0-Day Patched<br /><a href="https://source.android.com/docs/security/bulletin/pixel/2024-06-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/pixel/2024-06-01</a><br /><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9022.mp3</guid><pubDate>Thu, 13 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60368289/9022.mp3" length="4795282" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>MSMQ Packets
https://isc.sans.edu/diary/Port%201801%20Traffic%3A%20Microsoft%20Message%20Queue/31004
 Adobe Updates
https://helpx.adobe.com/security/products/magento/apsb24-40.html
 Black Basta Exploited CVE-2024-26169 Prior to Patch...</itunes:subtitle><itunes:summary><![CDATA[MSMQ Packets<br /><a href="https://isc.sans.edu/diary/Port%201801%20Traffic%3A%20Microsoft%20Message%20Queue/31004" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Port%201801%20Traffic%3A%20Microsoft%20Message%20Queue/31004</a><br /> Adobe Updates<br /><a href="https://helpx.adobe.com/security/products/magento/apsb24-40.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/products/magento/apsb24-40.html</a><br /> Black Basta Exploited CVE-2024-26169 Prior to Patch<br /><a href="https://symantec-enterprise-blogs.security.com/threat-intelligence/black-basta-ransomware-zero-day" target="_blank" rel="noreferrer noopener">https://symantec-enterprise-blogs.security.com/threat-intelligence/black-basta-ransomware-zero-day</a><br /> Pixel Phone 0-Day Patched<br /><a href="https://source.android.com/docs/security/bulletin/pixel/2024-06-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/pixel/2024-06-01</a><br /><br />]]></itunes:summary><itunes:duration>321</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,pixel; phone; black basta; ado,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9022</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, June 12th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-june-12th-2024--62129363</link><description><![CDATA[Microsoft Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20June%202024/31000" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20June%202024/31000</a><br /> JetBrains IntelliJ Based IDE GitHub Plugin Vulnerability<br /><a href="https://blog.jetbrains.com/security/2024/06/updates-for-security-issue-affecting-intellij-based-ides-2023-1-and-github-plugin/" target="_blank" rel="noreferrer noopener">https://blog.jetbrains.com/security/2024/06/updates-for-security-issue-affecting-intellij-based-ides-2023-1-and-github-plugin/</a><br /> Veeam Recovery Orchestrator (VRO) vulnerability CVE-2024-29855<br /><a href="https://www.veeam.com/kb4585" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4585</a><br /> Precor Threadmill Vulnerablity<br /><a href="https://securityintelligence.com/x-force/internet-connected-treadmill-vulnerabilities-discovered/" target="_blank" rel="noreferrer noopener">https://securityintelligence.com/x-force/internet-connected-treadmill-vulnerabilities-discovered/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9020.mp3</guid><pubDate>Wed, 12 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129363/9020.mp3" length="5060221" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20June%202024/31000
 JetBrains IntelliJ Based IDE GitHub Plugin Vulnerability...</itunes:subtitle><itunes:summary><![CDATA[Microsoft Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20June%202024/31000" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20June%202024/31000</a><br /> JetBrains IntelliJ Based IDE GitHub Plugin Vulnerability<br /><a href="https://blog.jetbrains.com/security/2024/06/updates-for-security-issue-affecting-intellij-based-ides-2023-1-and-github-plugin/" target="_blank" rel="noreferrer noopener">https://blog.jetbrains.com/security/2024/06/updates-for-security-issue-affecting-intellij-based-ides-2023-1-and-github-plugin/</a><br /> Veeam Recovery Orchestrator (VRO) vulnerability CVE-2024-29855<br /><a href="https://www.veeam.com/kb4585" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4585</a><br /> Precor Threadmill Vulnerablity<br /><a href="https://securityintelligence.com/x-force/internet-connected-treadmill-vulnerabilities-discovered/" target="_blank" rel="noreferrer noopener">https://securityintelligence.com/x-force/internet-connected-treadmill-vulnerabilities-discovered/</a><br />]]></itunes:summary><itunes:duration>340</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,precore; threadmill; veeam; je,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9020</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, June 12th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-june-12th-2024--60357369</link><description><![CDATA[Microsoft Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20June%202024/31000" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20June%202024/31000</a><br /> JetBrains IntelliJ Based IDE GitHub Plugin Vulnerability<br /><a href="https://blog.jetbrains.com/security/2024/06/updates-for-security-issue-affecting-intellij-based-ides-2023-1-and-github-plugin/" target="_blank" rel="noreferrer noopener">https://blog.jetbrains.com/security/2024/06/updates-for-security-issue-affecting-intellij-based-ides-2023-1-and-github-plugin/</a><br /> Veeam Recovery Orchestrator (VRO) vulnerability CVE-2024-29855<br /><a href="https://www.veeam.com/kb4585" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4585</a><br /> Precor Threadmill Vulnerablity<br /><a href="https://securityintelligence.com/x-force/internet-connected-treadmill-vulnerabilities-discovered/" target="_blank" rel="noreferrer noopener">https://securityintelligence.com/x-force/internet-connected-treadmill-vulnerabilities-discovered/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9020.mp3</guid><pubDate>Wed, 12 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60357369/9020.mp3" length="5060221" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20June%202024/31000
 JetBrains IntelliJ Based IDE GitHub Plugin Vulnerability...</itunes:subtitle><itunes:summary><![CDATA[Microsoft Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20June%202024/31000" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20June%202024/31000</a><br /> JetBrains IntelliJ Based IDE GitHub Plugin Vulnerability<br /><a href="https://blog.jetbrains.com/security/2024/06/updates-for-security-issue-affecting-intellij-based-ides-2023-1-and-github-plugin/" target="_blank" rel="noreferrer noopener">https://blog.jetbrains.com/security/2024/06/updates-for-security-issue-affecting-intellij-based-ides-2023-1-and-github-plugin/</a><br /> Veeam Recovery Orchestrator (VRO) vulnerability CVE-2024-29855<br /><a href="https://www.veeam.com/kb4585" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4585</a><br /> Precor Threadmill Vulnerablity<br /><a href="https://securityintelligence.com/x-force/internet-connected-treadmill-vulnerabilities-discovered/" target="_blank" rel="noreferrer noopener">https://securityintelligence.com/x-force/internet-connected-treadmill-vulnerabilities-discovered/</a><br />]]></itunes:summary><itunes:duration>340</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,precore; threadmill; veeam; je,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9020</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, June 11th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-june-11th-2024--62129345</link><description><![CDATA[Veeam Exploit CVE-2024-29849<br /><a href="https://summoning.team/blog/veeam-enterprise-manager-cve-2024-29849-auth-bypass/" target="_blank" rel="noreferrer noopener">https://summoning.team/blog/veeam-enterprise-manager-cve-2024-29849-auth-bypass/</a><br /> SORBS Shutdown<br /><a href="https://www.theregister.com/2024/06/07/sorbs_closed/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2024/06/07/sorbs_closed/</a><br /> Rogue Cell Tower Shut Down in London<br /><a href="https://www.cityoflondon.police.uk/news/city-of-london/news/2024/june/two-people-arrested-in-connection-with-investigation-into-homemade-mobile-antenna-used-to-send-thousands-of-smishing-text-messages-to-the-public/" target="_blank" rel="noreferrer noopener">https://www.cityoflondon.police.uk/news/city-of-london/news/2024/june/two-people-arrested-in-connection-with-investigation-into-homemade-mobile-antenna-used-to-send-thousands-of-smishing-text-messages-to-the-public/</a><br /> Malicious Comfyui Modules<br /><a href="https://www.youtube.com/watch?v=ntwGHjBCbeQ" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=ntwGHjBCbeQ</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9018.mp3</guid><pubDate>Tue, 11 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129345/9018.mp3" length="5395052" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Veeam Exploit CVE-2024-29849
https://summoning.team/blog/veeam-enterprise-manager-cve-2024-29849-auth-bypass/
 SORBS Shutdown
https://www.theregister.com/2024/06/07/sorbs_closed/
 Rogue Cell Tower Shut Down in London...</itunes:subtitle><itunes:summary><![CDATA[Veeam Exploit CVE-2024-29849<br /><a href="https://summoning.team/blog/veeam-enterprise-manager-cve-2024-29849-auth-bypass/" target="_blank" rel="noreferrer noopener">https://summoning.team/blog/veeam-enterprise-manager-cve-2024-29849-auth-bypass/</a><br /> SORBS Shutdown<br /><a href="https://www.theregister.com/2024/06/07/sorbs_closed/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2024/06/07/sorbs_closed/</a><br /> Rogue Cell Tower Shut Down in London<br /><a href="https://www.cityoflondon.police.uk/news/city-of-london/news/2024/june/two-people-arrested-in-connection-with-investigation-into-homemade-mobile-antenna-used-to-send-thousands-of-smishing-text-messages-to-the-public/" target="_blank" rel="noreferrer noopener">https://www.cityoflondon.police.uk/news/city-of-london/news/2024/june/two-people-arrested-in-connection-with-investigation-into-homemade-mobile-antenna-used-to-send-thousands-of-smishing-text-messages-to-the-public/</a><br /> Malicious Comfyui Modules<br /><a href="https://www.youtube.com/watch?v=ntwGHjBCbeQ" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=ntwGHjBCbeQ</a><br />]]></itunes:summary><itunes:duration>364</itunes:duration><itunes:keywords>business,comfyui; cell tower; sorbs; ve,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9018</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, June 11th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-june-11th-2024--60345624</link><description><![CDATA[Veeam Exploit CVE-2024-29849<br /><a href="https://summoning.team/blog/veeam-enterprise-manager-cve-2024-29849-auth-bypass/" target="_blank" rel="noreferrer noopener">https://summoning.team/blog/veeam-enterprise-manager-cve-2024-29849-auth-bypass/</a><br /> SORBS Shutdown<br /><a href="https://www.theregister.com/2024/06/07/sorbs_closed/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2024/06/07/sorbs_closed/</a><br /> Rogue Cell Tower Shut Down in London<br /><a href="https://www.cityoflondon.police.uk/news/city-of-london/news/2024/june/two-people-arrested-in-connection-with-investigation-into-homemade-mobile-antenna-used-to-send-thousands-of-smishing-text-messages-to-the-public/" target="_blank" rel="noreferrer noopener">https://www.cityoflondon.police.uk/news/city-of-london/news/2024/june/two-people-arrested-in-connection-with-investigation-into-homemade-mobile-antenna-used-to-send-thousands-of-smishing-text-messages-to-the-public/</a><br /> Malicious Comfyui Modules<br /><a href="https://www.youtube.com/watch?v=ntwGHjBCbeQ" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=ntwGHjBCbeQ</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9018.mp3</guid><pubDate>Tue, 11 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60345624/9018.mp3" length="5395052" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Veeam Exploit CVE-2024-29849
https://summoning.team/blog/veeam-enterprise-manager-cve-2024-29849-auth-bypass/
 SORBS Shutdown
https://www.theregister.com/2024/06/07/sorbs_closed/
 Rogue Cell Tower Shut Down in London...</itunes:subtitle><itunes:summary><![CDATA[Veeam Exploit CVE-2024-29849<br /><a href="https://summoning.team/blog/veeam-enterprise-manager-cve-2024-29849-auth-bypass/" target="_blank" rel="noreferrer noopener">https://summoning.team/blog/veeam-enterprise-manager-cve-2024-29849-auth-bypass/</a><br /> SORBS Shutdown<br /><a href="https://www.theregister.com/2024/06/07/sorbs_closed/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2024/06/07/sorbs_closed/</a><br /> Rogue Cell Tower Shut Down in London<br /><a href="https://www.cityoflondon.police.uk/news/city-of-london/news/2024/june/two-people-arrested-in-connection-with-investigation-into-homemade-mobile-antenna-used-to-send-thousands-of-smishing-text-messages-to-the-public/" target="_blank" rel="noreferrer noopener">https://www.cityoflondon.police.uk/news/city-of-london/news/2024/june/two-people-arrested-in-connection-with-investigation-into-homemade-mobile-antenna-used-to-send-thousands-of-smishing-text-messages-to-the-public/</a><br /> Malicious Comfyui Modules<br /><a href="https://www.youtube.com/watch?v=ntwGHjBCbeQ" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=ntwGHjBCbeQ</a><br />]]></itunes:summary><itunes:duration>364</itunes:duration><itunes:keywords>business,comfyui; cell tower; sorbs; ve,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9018</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, June 10th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-june-10th-2024--62129370</link><description><![CDATA[PHP Unicode Remote Code Execution Exploit<br /><a href="https://blog.orange.tw/2024/06/cve-2024-4577-yet-another-php-rce.html" target="_blank" rel="noreferrer noopener">https://blog.orange.tw/2024/06/cve-2024-4577-yet-another-php-rce.html</a><br /><a href="https://labs.watchtowr.com/no-way-php-strikes-again-cve-2024-4577/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/no-way-php-strikes-again-cve-2024-4577/</a><br /> PyTorch Distributed RPC Framework Remote Code Execution<br /><a href="https://huntr.com/bounties/39811836-c5b3-4999-831e-46fee8fcade3" target="_blank" rel="noreferrer noopener">https://huntr.com/bounties/39811836-c5b3-4999-831e-46fee8fcade3</a><br /><a href="https://www.cve.org/CVERecord?id=CVE-2024-5480" target="_blank" rel="noreferrer noopener">https://www.cve.org/CVERecord?id=CVE-2024-5480</a><br /> Malicious VSCode Extensions Used by Researchers<br /><a href="https://www.bleepingcomputer.com/news/security/malicious-visual-studio-code-extensions-with-millions-of-installs-discovered/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/malicious-visual-studio-code-extensions-with-millions-of-installs-discovered/</a>]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9016.mp3</guid><pubDate>Mon, 10 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129370/9016.mp3" length="7169887" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>PHP Unicode Remote Code Execution Exploit
https://blog.orange.tw/2024/06/cve-2024-4577-yet-another-php-rce.html
https://labs.watchtowr.com/no-way-php-strikes-again-cve-2024-4577/
 PyTorch Distributed RPC Framework Remote Code Execution...</itunes:subtitle><itunes:summary><![CDATA[PHP Unicode Remote Code Execution Exploit<br /><a href="https://blog.orange.tw/2024/06/cve-2024-4577-yet-another-php-rce.html" target="_blank" rel="noreferrer noopener">https://blog.orange.tw/2024/06/cve-2024-4577-yet-another-php-rce.html</a><br /><a href="https://labs.watchtowr.com/no-way-php-strikes-again-cve-2024-4577/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/no-way-php-strikes-again-cve-2024-4577/</a><br /> PyTorch Distributed RPC Framework Remote Code Execution<br /><a href="https://huntr.com/bounties/39811836-c5b3-4999-831e-46fee8fcade3" target="_blank" rel="noreferrer noopener">https://huntr.com/bounties/39811836-c5b3-4999-831e-46fee8fcade3</a><br /><a href="https://www.cve.org/CVERecord?id=CVE-2024-5480" target="_blank" rel="noreferrer noopener">https://www.cve.org/CVERecord?id=CVE-2024-5480</a><br /> Malicious VSCode Extensions Used by Researchers<br /><a href="https://www.bleepingcomputer.com/news/security/malicious-visual-studio-code-extensions-with-millions-of-installs-discovered/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/malicious-visual-studio-code-extensions-with-millions-of-installs-discovered/</a>]]></itunes:summary><itunes:duration>491</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,vscode; extensions; pytorch; r</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9016</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, June 10th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-june-10th-2024--60335461</link><description><![CDATA[PHP Unicode Remote Code Execution Exploit<br /><a href="https://www.bleepingcomputer.com/news/security/malicious-visual-studio-code-extensions-with-millions-of-installs-discovered/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/malicious-visual-studio-code-extensions-with-millions-of-installs-discovered/</a><br /> PyTorch Distributed RPC Framework Remote Code Execution<br /><a href="https://huntr.com/bounties/39811836-c5b3-4999-831e-46fee8fcade3" target="_blank" rel="noreferrer noopener">https://huntr.com/bounties/39811836-c5b3-4999-831e-46fee8fcade3</a><br /><a href="https://www.cve.org/CVERecord?id=CVE-2024-5480" target="_blank" rel="noreferrer noopener">https://www.cve.org/CVERecord?id=CVE-2024-5480</a><br /> Malicious VSCode Extensions Used by Researchers<br /><a href="https://www.bleepingcomputer.com/news/security/malicious-visual-studio-code-extensions-with-millions-of-installs-discovered/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/malicious-visual-studio-code-extensions-with-millions-of-installs-discovered/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9016.mp3</guid><pubDate>Mon, 10 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60335461/9016.mp3" length="7169887" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>PHP Unicode Remote Code Execution Exploit
https://www.bleepingcomputer.com/news/security/malicious-visual-studio-code-extensions-with-millions-of-installs-discovered/
 PyTorch Distributed RPC Framework Remote Code Execution...</itunes:subtitle><itunes:summary><![CDATA[PHP Unicode Remote Code Execution Exploit<br /><a href="https://www.bleepingcomputer.com/news/security/malicious-visual-studio-code-extensions-with-millions-of-installs-discovered/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/malicious-visual-studio-code-extensions-with-millions-of-installs-discovered/</a><br /> PyTorch Distributed RPC Framework Remote Code Execution<br /><a href="https://huntr.com/bounties/39811836-c5b3-4999-831e-46fee8fcade3" target="_blank" rel="noreferrer noopener">https://huntr.com/bounties/39811836-c5b3-4999-831e-46fee8fcade3</a><br /><a href="https://www.cve.org/CVERecord?id=CVE-2024-5480" target="_blank" rel="noreferrer noopener">https://www.cve.org/CVERecord?id=CVE-2024-5480</a><br /> Malicious VSCode Extensions Used by Researchers<br /><a href="https://www.bleepingcomputer.com/news/security/malicious-visual-studio-code-extensions-with-millions-of-installs-discovered/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/malicious-visual-studio-code-extensions-with-millions-of-installs-discovered/</a><br />]]></itunes:summary><itunes:duration>491</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,vscode; extensions; pytorch; r</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9016</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, June 7th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-june-7th-2024--62129343</link><description><![CDATA[Malicious Python Script with a "Best Before" Date<br /><a href="https://isc.sans.edu/diary/Malicious%20Python%20Script%20with%20a%20%22Best%20Before%22%20Date/30988" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Malicious%20Python%20Script%20with%20a%20%22Best%20Before%22%20Date/30988</a><br /> FBI Obtained 7,000 LockBit Ransomware Keys<br /><a href="https://www.fbi.gov/news/speeches/fbi-cyber-assistant-director-bryan-vorndran-s-remarks-at-the-2024-boston-conference-on-cyber-security" target="_blank" rel="noreferrer noopener">https://www.fbi.gov/news/speeches/fbi-cyber-assistant-director-bryan-vorndran-s-remarks-at-the-2024-boston-conference-on-cyber-security</a><br /> Apple Guarantees 5 Years of Security Updates<br /><a href="https://www.androidauthority.com/iphone-software-support-commitment-3449135/" target="_blank" rel="noreferrer noopener">https://www.androidauthority.com/iphone-software-support-commitment-3449135/</a><br /> FCC Proposes New Rule for Security Routing<br /><a href="https://www.fcc.gov/document/fcc-proposes-internet-routing-security-reporting-requirements" target="_blank" rel="noreferrer noopener">https://www.fcc.gov/document/fcc-proposes-internet-routing-security-reporting-requirements</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9014.mp3</guid><pubDate>Fri, 07 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129343/9014.mp3" length="5503715" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Malicious Python Script with a "Best Before" Date
https://isc.sans.edu/diary/Malicious%20Python%20Script%20with%20a%20%22Best%20Before%22%20Date/30988
 FBI Obtained 7,000 LockBit Ransomware Keys...</itunes:subtitle><itunes:summary><![CDATA[Malicious Python Script with a "Best Before" Date<br /><a href="https://isc.sans.edu/diary/Malicious%20Python%20Script%20with%20a%20%22Best%20Before%22%20Date/30988" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Malicious%20Python%20Script%20with%20a%20%22Best%20Before%22%20Date/30988</a><br /> FBI Obtained 7,000 LockBit Ransomware Keys<br /><a href="https://www.fbi.gov/news/speeches/fbi-cyber-assistant-director-bryan-vorndran-s-remarks-at-the-2024-boston-conference-on-cyber-security" target="_blank" rel="noreferrer noopener">https://www.fbi.gov/news/speeches/fbi-cyber-assistant-director-bryan-vorndran-s-remarks-at-the-2024-boston-conference-on-cyber-security</a><br /> Apple Guarantees 5 Years of Security Updates<br /><a href="https://www.androidauthority.com/iphone-software-support-commitment-3449135/" target="_blank" rel="noreferrer noopener">https://www.androidauthority.com/iphone-software-support-commitment-3449135/</a><br /> FCC Proposes New Rule for Security Routing<br /><a href="https://www.fcc.gov/document/fcc-proposes-internet-routing-security-reporting-requirements" target="_blank" rel="noreferrer noopener">https://www.fcc.gov/document/fcc-proposes-internet-routing-security-reporting-requirements</a><br />]]></itunes:summary><itunes:duration>371</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,fbi; lockbit; uk; apple; samsu,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9014</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, June 7th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-june-7th-2024--60307064</link><description><![CDATA[Malicious Python Script with a "Best Before" Date<br /><a href="https://isc.sans.edu/diary/Malicious%20Python%20Script%20with%20a%20%22Best%20Before%22%20Date/30988" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Malicious%20Python%20Script%20with%20a%20%22Best%20Before%22%20Date/30988</a><br /> FBI Obtained 7,000 LockBit Ransomware Keys<br /><a href="https://www.fbi.gov/news/speeches/fbi-cyber-assistant-director-bryan-vorndran-s-remarks-at-the-2024-boston-conference-on-cyber-security" target="_blank" rel="noreferrer noopener">https://www.fbi.gov/news/speeches/fbi-cyber-assistant-director-bryan-vorndran-s-remarks-at-the-2024-boston-conference-on-cyber-security</a><br /> Apple Guarantees 5 Years of Security Updates<br /><a href="https://www.androidauthority.com/iphone-software-support-commitment-3449135/" target="_blank" rel="noreferrer noopener">https://www.androidauthority.com/iphone-software-support-commitment-3449135/</a><br /> FCC Proposes New Rule for Security Routing<br /><a href="https://www.fcc.gov/document/fcc-proposes-internet-routing-security-reporting-requirements" target="_blank" rel="noreferrer noopener">https://www.fcc.gov/document/fcc-proposes-internet-routing-security-reporting-requirements</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9014.mp3</guid><pubDate>Fri, 07 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60307064/9014.mp3" length="5503715" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Malicious Python Script with a "Best Before" Date
https://isc.sans.edu/diary/Malicious%20Python%20Script%20with%20a%20%22Best%20Before%22%20Date/30988
 FBI Obtained 7,000 LockBit Ransomware Keys...</itunes:subtitle><itunes:summary><![CDATA[Malicious Python Script with a "Best Before" Date<br /><a href="https://isc.sans.edu/diary/Malicious%20Python%20Script%20with%20a%20%22Best%20Before%22%20Date/30988" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Malicious%20Python%20Script%20with%20a%20%22Best%20Before%22%20Date/30988</a><br /> FBI Obtained 7,000 LockBit Ransomware Keys<br /><a href="https://www.fbi.gov/news/speeches/fbi-cyber-assistant-director-bryan-vorndran-s-remarks-at-the-2024-boston-conference-on-cyber-security" target="_blank" rel="noreferrer noopener">https://www.fbi.gov/news/speeches/fbi-cyber-assistant-director-bryan-vorndran-s-remarks-at-the-2024-boston-conference-on-cyber-security</a><br /> Apple Guarantees 5 Years of Security Updates<br /><a href="https://www.androidauthority.com/iphone-software-support-commitment-3449135/" target="_blank" rel="noreferrer noopener">https://www.androidauthority.com/iphone-software-support-commitment-3449135/</a><br /> FCC Proposes New Rule for Security Routing<br /><a href="https://www.fcc.gov/document/fcc-proposes-internet-routing-security-reporting-requirements" target="_blank" rel="noreferrer noopener">https://www.fcc.gov/document/fcc-proposes-internet-routing-security-reporting-requirements</a><br />]]></itunes:summary><itunes:duration>371</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,fbi; lockbit; uk; apple; samsu,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9014</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, June 6th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-june-6th-2024--62129375</link><description><![CDATA[WatchGuard VPN Brutefording<br /><a href="https://isc.sans.edu/diary/Brute%20Force%20Attacks%20Against%20Watchguard%20VPN%20Endpoints/30984" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Brute%20Force%20Attacks%20Against%20Watchguard%20VPN%20Endpoints/30984</a><br /> TotalRecall Tool To Extract Data from Microsoft Recall<br /><a href="https://github.com/xaitax/TotalRecall" target="_blank" rel="noreferrer noopener">https://github.com/xaitax/TotalRecall</a><br /> WebEx Flaw<br /><a href="https://www.helpnetsecurity.com/2024/06/05/cisco-webex-cloud-vulnerability/" target="_blank" rel="noreferrer noopener">https://www.helpnetsecurity.com/2024/06/05/cisco-webex-cloud-vulnerability/</a><br /><a href="https://netzbegruenung.de/blog/netzbegruenung-findet-schwachstellen-auch-im-cisco-webex-clouddienst-behoerden-und-unternehmen-in-ganz-europa-betroffen/" target="_blank" rel="noreferrer noopener">https://netzbegruenung.de/blog/netzbegruenung-findet-schwachstellen-auch-im-cisco-webex-clouddienst-behoerden-und-unternehmen-in-ganz-europa-betroffen/</a> (in german)<br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9012.mp3</guid><pubDate>Thu, 06 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129375/9012.mp3" length="5736091" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>WatchGuard VPN Brutefording
https://isc.sans.edu/diary/Brute%20Force%20Attacks%20Against%20Watchguard%20VPN%20Endpoints/30984
 TotalRecall Tool To Extract Data from Microsoft Recall
https://github.com/xaitax/TotalRecall
 WebEx Flaw...</itunes:subtitle><itunes:summary><![CDATA[WatchGuard VPN Brutefording<br /><a href="https://isc.sans.edu/diary/Brute%20Force%20Attacks%20Against%20Watchguard%20VPN%20Endpoints/30984" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Brute%20Force%20Attacks%20Against%20Watchguard%20VPN%20Endpoints/30984</a><br /> TotalRecall Tool To Extract Data from Microsoft Recall<br /><a href="https://github.com/xaitax/TotalRecall" target="_blank" rel="noreferrer noopener">https://github.com/xaitax/TotalRecall</a><br /> WebEx Flaw<br /><a href="https://www.helpnetsecurity.com/2024/06/05/cisco-webex-cloud-vulnerability/" target="_blank" rel="noreferrer noopener">https://www.helpnetsecurity.com/2024/06/05/cisco-webex-cloud-vulnerability/</a><br /><a href="https://netzbegruenung.de/blog/netzbegruenung-findet-schwachstellen-auch-im-cisco-webex-clouddienst-behoerden-und-unternehmen-in-ganz-europa-betroffen/" target="_blank" rel="noreferrer noopener">https://netzbegruenung.de/blog/netzbegruenung-findet-schwachstellen-auch-im-cisco-webex-clouddienst-behoerden-und-unternehmen-in-ganz-europa-betroffen/</a> (in german)<br />]]></itunes:summary><itunes:duration>388</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,webex; totalrecall; recall; wa</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9012</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, June 6th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-june-6th-2024--60294584</link><description><![CDATA[WatchGuard VPN Brutefording<br /><a href="https://isc.sans.edu/diary/Brute%20Force%20Attacks%20Against%20Watchguard%20VPN%20Endpoints/30984" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Brute%20Force%20Attacks%20Against%20Watchguard%20VPN%20Endpoints/30984</a><br /> TotalRecall Tool To Extract Data from Microsoft Recall<br /><a href="https://github.com/xaitax/TotalRecall" target="_blank" rel="noreferrer noopener">https://github.com/xaitax/TotalRecall</a><br /> WebEx Flaw<br /><a href="https://www.helpnetsecurity.com/2024/06/05/cisco-webex-cloud-vulnerability/" target="_blank" rel="noreferrer noopener">https://www.helpnetsecurity.com/2024/06/05/cisco-webex-cloud-vulnerability/</a><br /><a href="https://netzbegruenung.de/blog/netzbegruenung-findet-schwachstellen-auch-im-cisco-webex-clouddienst-behoerden-und-unternehmen-in-ganz-europa-betroffen/" target="_blank" rel="noreferrer noopener">https://netzbegruenung.de/blog/netzbegruenung-findet-schwachstellen-auch-im-cisco-webex-clouddienst-behoerden-und-unternehmen-in-ganz-europa-betroffen/</a> (in german)<br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9012.mp3</guid><pubDate>Thu, 06 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60294584/9012.mp3" length="5736091" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>WatchGuard VPN Brutefording
https://isc.sans.edu/diary/Brute%20Force%20Attacks%20Against%20Watchguard%20VPN%20Endpoints/30984
 TotalRecall Tool To Extract Data from Microsoft Recall
https://github.com/xaitax/TotalRecall
 WebEx Flaw...</itunes:subtitle><itunes:summary><![CDATA[WatchGuard VPN Brutefording<br /><a href="https://isc.sans.edu/diary/Brute%20Force%20Attacks%20Against%20Watchguard%20VPN%20Endpoints/30984" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Brute%20Force%20Attacks%20Against%20Watchguard%20VPN%20Endpoints/30984</a><br /> TotalRecall Tool To Extract Data from Microsoft Recall<br /><a href="https://github.com/xaitax/TotalRecall" target="_blank" rel="noreferrer noopener">https://github.com/xaitax/TotalRecall</a><br /> WebEx Flaw<br /><a href="https://www.helpnetsecurity.com/2024/06/05/cisco-webex-cloud-vulnerability/" target="_blank" rel="noreferrer noopener">https://www.helpnetsecurity.com/2024/06/05/cisco-webex-cloud-vulnerability/</a><br /><a href="https://netzbegruenung.de/blog/netzbegruenung-findet-schwachstellen-auch-im-cisco-webex-clouddienst-behoerden-und-unternehmen-in-ganz-europa-betroffen/" target="_blank" rel="noreferrer noopener">https://netzbegruenung.de/blog/netzbegruenung-findet-schwachstellen-auch-im-cisco-webex-clouddienst-behoerden-und-unternehmen-in-ganz-europa-betroffen/</a> (in german)<br />]]></itunes:summary><itunes:duration>388</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,webex; totalrecall; recall; wa</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9012</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, June 5th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-june-5th-2024--62129384</link><description><![CDATA[No Defender Yes Defender<br /><a href="https://isc.sans.edu/diary/No-Defender%2C%20Yes-Defender/30980" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/No-Defender%2C%20Yes-Defender/30980</a><br /> Fake Job Ads Lead to Stolen Crypto Currency<br /><a href="https://www.ic3.gov/Media/Y2024/PSA240604" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/Media/Y2024/PSA240604</a><br /> Zyxel NAS Vulnerabilities<br /><a href="https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9010.mp3</guid><pubDate>Wed, 05 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129384/9010.mp3" length="4977741" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>No Defender Yes Defender
https://isc.sans.edu/diary/No-Defender%2C%20Yes-Defender/30980
 Fake Job Ads Lead to Stolen Crypto Currency
https://www.ic3.gov/Media/Y2024/PSA240604
 Zyxel NAS Vulnerabilities...</itunes:subtitle><itunes:summary><![CDATA[No Defender Yes Defender<br /><a href="https://isc.sans.edu/diary/No-Defender%2C%20Yes-Defender/30980" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/No-Defender%2C%20Yes-Defender/30980</a><br /> Fake Job Ads Lead to Stolen Crypto Currency<br /><a href="https://www.ic3.gov/Media/Y2024/PSA240604" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/Media/Y2024/PSA240604</a><br /> Zyxel NAS Vulnerabilities<br /><a href="https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/</a><br />]]></itunes:summary><itunes:duration>334</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,zyxel; nas; fake job ads; defe</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9010</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, June 5th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-june-5th-2024--60280863</link><description><![CDATA[No Defender Yes Defender<br /><a href="https://isc.sans.edu/diary/No-Defender%2C%20Yes-Defender/30980" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/No-Defender%2C%20Yes-Defender/30980</a><br /> Fake Job Ads Lead to Stolen Crypto Currency<br /><a href="https://www.ic3.gov/Media/Y2024/PSA240604" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/Media/Y2024/PSA240604</a><br /> Zyxel NAS Vulnerabilities<br /><a href="https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9010.mp3</guid><pubDate>Wed, 05 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60280863/9010.mp3" length="4977741" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>No Defender Yes Defender
https://isc.sans.edu/diary/No-Defender%2C%20Yes-Defender/30980
 Fake Job Ads Lead to Stolen Crypto Currency
https://www.ic3.gov/Media/Y2024/PSA240604
 Zyxel NAS Vulnerabilities...</itunes:subtitle><itunes:summary><![CDATA[No Defender Yes Defender<br /><a href="https://isc.sans.edu/diary/No-Defender%2C%20Yes-Defender/30980" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/No-Defender%2C%20Yes-Defender/30980</a><br /> Fake Job Ads Lead to Stolen Crypto Currency<br /><a href="https://www.ic3.gov/Media/Y2024/PSA240604" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/Media/Y2024/PSA240604</a><br /> Zyxel NAS Vulnerabilities<br /><a href="https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/</a><br />]]></itunes:summary><itunes:duration>334</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,zyxel; nas; fake job ads; defe</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9010</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, June 4th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-june-4th-2024--62129395</link><description><![CDATA[A Wireshark Lua Dissector for Fixed Field Length Protocols<br /><a href="https://isc.sans.edu/diary/A%20Wireshark%20Lua%20Dissector%20for%20Fixed%20Field%20Length%20Protocols/30976" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20Wireshark%20Lua%20Dissector%20for%20Fixed%20Field%20Length%20Protocols/30976</a><br /> COX Cable Modem Admin API Weakness<br /><a href="https://samcurry.net/hacking-millions-of-modems" target="_blank" rel="noreferrer noopener">https://samcurry.net/hacking-millions-of-modems</a><br /> Malicous Stack Overflow Answers<br /><a href="https://www.bleepingcomputer.com/news/security/cybercriminals-pose-as-helpful-stack-overflow-users-to-push-malware/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/cybercriminals-pose-as-helpful-stack-overflow-users-to-push-malware/</a><br /> Atlasian Confluence Data Center and SErver Remote Code Execution Vuln CVE-2024-21683<br /><a href="https://blog.sonicwall.com/en-us/2024/05/confluence-data-center-and-server-remote-code-execution-vulnerability/" target="_blank" rel="noreferrer noopener">https://blog.sonicwall.com/en-us/2024/05/confluence-data-center-and-server-remote-code-execution-vulnerability/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9008.mp3</guid><pubDate>Tue, 04 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129395/9008.mp3" length="4970797" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>A Wireshark Lua Dissector for Fixed Field Length Protocols
https://isc.sans.edu/diary/A%20Wireshark%20Lua%20Dissector%20for%20Fixed%20Field%20Length%20Protocols/30976
 COX Cable Modem Admin API Weakness
https://samcurry.net/hacking-millions-of-modems...</itunes:subtitle><itunes:summary><![CDATA[A Wireshark Lua Dissector for Fixed Field Length Protocols<br /><a href="https://isc.sans.edu/diary/A%20Wireshark%20Lua%20Dissector%20for%20Fixed%20Field%20Length%20Protocols/30976" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20Wireshark%20Lua%20Dissector%20for%20Fixed%20Field%20Length%20Protocols/30976</a><br /> COX Cable Modem Admin API Weakness<br /><a href="https://samcurry.net/hacking-millions-of-modems" target="_blank" rel="noreferrer noopener">https://samcurry.net/hacking-millions-of-modems</a><br /> Malicous Stack Overflow Answers<br /><a href="https://www.bleepingcomputer.com/news/security/cybercriminals-pose-as-helpful-stack-overflow-users-to-push-malware/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/cybercriminals-pose-as-helpful-stack-overflow-users-to-push-malware/</a><br /> Atlasian Confluence Data Center and SErver Remote Code Execution Vuln CVE-2024-21683<br /><a href="https://blog.sonicwall.com/en-us/2024/05/confluence-data-center-and-server-remote-code-execution-vulnerability/" target="_blank" rel="noreferrer noopener">https://blog.sonicwall.com/en-us/2024/05/confluence-data-center-and-server-remote-code-execution-vulnerability/</a><br />]]></itunes:summary><itunes:duration>333</itunes:duration><itunes:keywords>atlasian; confluence; stack ov,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9008</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, June 4th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-june-4th-2024--60269497</link><description><![CDATA[A Wireshark Lua Dissector for Fixed Field Length Protocols<br /><a href="https://isc.sans.edu/diary/A%20Wireshark%20Lua%20Dissector%20for%20Fixed%20Field%20Length%20Protocols/30976" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20Wireshark%20Lua%20Dissector%20for%20Fixed%20Field%20Length%20Protocols/30976</a><br /> COX Cable Modem Admin API Weakness<br /><a href="https://samcurry.net/hacking-millions-of-modems" target="_blank" rel="noreferrer noopener">https://samcurry.net/hacking-millions-of-modems</a><br /> Malicous Stack Overflow Answers<br /><a href="https://www.bleepingcomputer.com/news/security/cybercriminals-pose-as-helpful-stack-overflow-users-to-push-malware/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/cybercriminals-pose-as-helpful-stack-overflow-users-to-push-malware/</a><br /> Atlasian Confluence Data Center and SErver Remote Code Execution Vuln CVE-2024-21683<br /><a href="https://blog.sonicwall.com/en-us/2024/05/confluence-data-center-and-server-remote-code-execution-vulnerability/" target="_blank" rel="noreferrer noopener">https://blog.sonicwall.com/en-us/2024/05/confluence-data-center-and-server-remote-code-execution-vulnerability/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9008.mp3</guid><pubDate>Tue, 04 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60269497/9008.mp3" length="4970797" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>A Wireshark Lua Dissector for Fixed Field Length Protocols
https://isc.sans.edu/diary/A%20Wireshark%20Lua%20Dissector%20for%20Fixed%20Field%20Length%20Protocols/30976
 COX Cable Modem Admin API Weakness
https://samcurry.net/hacking-millions-of-modems...</itunes:subtitle><itunes:summary><![CDATA[A Wireshark Lua Dissector for Fixed Field Length Protocols<br /><a href="https://isc.sans.edu/diary/A%20Wireshark%20Lua%20Dissector%20for%20Fixed%20Field%20Length%20Protocols/30976" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20Wireshark%20Lua%20Dissector%20for%20Fixed%20Field%20Length%20Protocols/30976</a><br /> COX Cable Modem Admin API Weakness<br /><a href="https://samcurry.net/hacking-millions-of-modems" target="_blank" rel="noreferrer noopener">https://samcurry.net/hacking-millions-of-modems</a><br /> Malicous Stack Overflow Answers<br /><a href="https://www.bleepingcomputer.com/news/security/cybercriminals-pose-as-helpful-stack-overflow-users-to-push-malware/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/cybercriminals-pose-as-helpful-stack-overflow-users-to-push-malware/</a><br /> Atlasian Confluence Data Center and SErver Remote Code Execution Vuln CVE-2024-21683<br /><a href="https://blog.sonicwall.com/en-us/2024/05/confluence-data-center-and-server-remote-code-execution-vulnerability/" target="_blank" rel="noreferrer noopener">https://blog.sonicwall.com/en-us/2024/05/confluence-data-center-and-server-remote-code-execution-vulnerability/</a><br />]]></itunes:summary><itunes:duration>333</itunes:duration><itunes:keywords>atlasian; confluence; stack ov,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9008</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, June 3rd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-june-3rd-2024--62129376</link><description><![CDATA[K1w1 Infostealer Uses gofile.io for Exfiltration<br /><a href="https://isc.sans.edu/diary/%22K1w1%22%20InfoStealer%20Uses%20gofile.io%20for%20Exfiltration/30972" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%22K1w1%22%20InfoStealer%20Uses%20gofile.io%20for%20Exfiltration/30972</a><br /> Kaspersky Linux Malware Scanner<br /><a href="https://www.kaspersky.com/blog/kvrt-for-linux/51375/" target="_blank" rel="noreferrer noopener">https://www.kaspersky.com/blog/kvrt-for-linux/51375/</a><br /> Snowflake Incident<br /><a href="https://www.helpnetsecurity.com/2024/06/01/snowflake-breach-data-theft/" target="_blank" rel="noreferrer noopener">https://www.helpnetsecurity.com/2024/06/01/snowflake-breach-data-theft/</a><br /> HuggingFace Space Secrets Leak<br /><a href="https://huggingface.co/blog/space-secrets-disclosure" target="_blank" rel="noreferrer noopener">https://huggingface.co/blog/space-secrets-disclosure</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9006.mp3</guid><pubDate>Mon, 03 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129376/9006.mp3" length="5034699" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>K1w1 Infostealer Uses gofile.io for Exfiltration
https://isc.sans.edu/diary/%22K1w1%22%20InfoStealer%20Uses%20gofile.io%20for%20Exfiltration/30972
 Kaspersky Linux Malware Scanner
https://www.kaspersky.com/blog/kvrt-for-linux/51375/
 Snowflake...</itunes:subtitle><itunes:summary><![CDATA[K1w1 Infostealer Uses gofile.io for Exfiltration<br /><a href="https://isc.sans.edu/diary/%22K1w1%22%20InfoStealer%20Uses%20gofile.io%20for%20Exfiltration/30972" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%22K1w1%22%20InfoStealer%20Uses%20gofile.io%20for%20Exfiltration/30972</a><br /> Kaspersky Linux Malware Scanner<br /><a href="https://www.kaspersky.com/blog/kvrt-for-linux/51375/" target="_blank" rel="noreferrer noopener">https://www.kaspersky.com/blog/kvrt-for-linux/51375/</a><br /> Snowflake Incident<br /><a href="https://www.helpnetsecurity.com/2024/06/01/snowflake-breach-data-theft/" target="_blank" rel="noreferrer noopener">https://www.helpnetsecurity.com/2024/06/01/snowflake-breach-data-theft/</a><br /> HuggingFace Space Secrets Leak<br /><a href="https://huggingface.co/blog/space-secrets-disclosure" target="_blank" rel="noreferrer noopener">https://huggingface.co/blog/space-secrets-disclosure</a><br />]]></itunes:summary><itunes:duration>338</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,huggingface; ai; snowflake; cr,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9006</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, June 3rd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-june-3rd-2024--60258795</link><description><![CDATA[K1w1 Infostealer Uses gofile.io for Exfiltration<br /><a href="https://isc.sans.edu/diary/%22K1w1%22%20InfoStealer%20Uses%20gofile.io%20for%20Exfiltration/30972" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%22K1w1%22%20InfoStealer%20Uses%20gofile.io%20for%20Exfiltration/30972</a><br /> Kaspersky Linux Malware Scanner<br /><a href="https://www.kaspersky.com/blog/kvrt-for-linux/51375/" target="_blank" rel="noreferrer noopener">https://www.kaspersky.com/blog/kvrt-for-linux/51375/</a><br /> Snowflake Incident<br /><a href="https://www.helpnetsecurity.com/2024/06/01/snowflake-breach-data-theft/" target="_blank" rel="noreferrer noopener">https://www.helpnetsecurity.com/2024/06/01/snowflake-breach-data-theft/</a><br /> HuggingFace Space Secrets Leak<br /><a href="https://huggingface.co/blog/space-secrets-disclosure" target="_blank" rel="noreferrer noopener">https://huggingface.co/blog/space-secrets-disclosure</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9006.mp3</guid><pubDate>Mon, 03 Jun 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60258795/9006.mp3" length="5034699" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>K1w1 Infostealer Uses gofile.io for Exfiltration
https://isc.sans.edu/diary/%22K1w1%22%20InfoStealer%20Uses%20gofile.io%20for%20Exfiltration/30972
 Kaspersky Linux Malware Scanner
https://www.kaspersky.com/blog/kvrt-for-linux/51375/
 Snowflake...</itunes:subtitle><itunes:summary><![CDATA[K1w1 Infostealer Uses gofile.io for Exfiltration<br /><a href="https://isc.sans.edu/diary/%22K1w1%22%20InfoStealer%20Uses%20gofile.io%20for%20Exfiltration/30972" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%22K1w1%22%20InfoStealer%20Uses%20gofile.io%20for%20Exfiltration/30972</a><br /> Kaspersky Linux Malware Scanner<br /><a href="https://www.kaspersky.com/blog/kvrt-for-linux/51375/" target="_blank" rel="noreferrer noopener">https://www.kaspersky.com/blog/kvrt-for-linux/51375/</a><br /> Snowflake Incident<br /><a href="https://www.helpnetsecurity.com/2024/06/01/snowflake-breach-data-theft/" target="_blank" rel="noreferrer noopener">https://www.helpnetsecurity.com/2024/06/01/snowflake-breach-data-theft/</a><br /> HuggingFace Space Secrets Leak<br /><a href="https://huggingface.co/blog/space-secrets-disclosure" target="_blank" rel="noreferrer noopener">https://huggingface.co/blog/space-secrets-disclosure</a><br />]]></itunes:summary><itunes:duration>338</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,huggingface; ai; snowflake; cr,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9006</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, May 31st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-may-31st-2024--62129354</link><description><![CDATA[Feeding MISP with OSSEC<br /><a href="https://isc.sans.edu/diary/Feeding%20MISP%20with%20OSSEC/30968" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Feeding%20MISP%20with%20OSSEC/30968</a><br /> Checkpoint VPN<br /><a href="https://labs.watchtowr.com/check-point-wrong-check-point-cve-2024-24919/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/check-point-wrong-check-point-cve-2024-24919/</a><br /> The Pumpkin Eclipse<br /><a href="https://blog.lumen.com/the-pumpkin-eclipse/" target="_blank" rel="noreferrer noopener">https://blog.lumen.com/the-pumpkin-eclipse/</a><br /> Michael Dunking: Detecting Cypher Injection with Open-Source Network Intrusion Detection<br /><a href="https://www.sans.edu/cyber-research/detecting-cypher-injection-with-open-source-network-intrusion-detection/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/detecting-cypher-injection-with-open-source-network-intrusion-detection/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9004.mp3</guid><pubDate>Fri, 31 May 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129354/9004.mp3" length="13248030" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Feeding MISP with OSSEC
https://isc.sans.edu/diary/Feeding%20MISP%20with%20OSSEC/30968
 Checkpoint VPN
https://labs.watchtowr.com/check-point-wrong-check-point-cve-2024-24919/
 The Pumpkin Eclipse
https://blog.lumen.com/the-pumpkin-eclipse/
 Michael...</itunes:subtitle><itunes:summary><![CDATA[Feeding MISP with OSSEC<br /><a href="https://isc.sans.edu/diary/Feeding%20MISP%20with%20OSSEC/30968" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Feeding%20MISP%20with%20OSSEC/30968</a><br /> Checkpoint VPN<br /><a href="https://labs.watchtowr.com/check-point-wrong-check-point-cve-2024-24919/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/check-point-wrong-check-point-cve-2024-24919/</a><br /> The Pumpkin Eclipse<br /><a href="https://blog.lumen.com/the-pumpkin-eclipse/" target="_blank" rel="noreferrer noopener">https://blog.lumen.com/the-pumpkin-eclipse/</a><br /> Michael Dunking: Detecting Cypher Injection with Open-Source Network Intrusion Detection<br /><a href="https://www.sans.edu/cyber-research/detecting-cypher-injection-with-open-source-network-intrusion-detection/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/detecting-cypher-injection-with-open-source-network-intrusion-detection/</a><br />]]></itunes:summary><itunes:duration>925</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,cypher; pumpkin; checkpoint; v,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9004</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, May 31st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-may-31st-2024--60230216</link><description><![CDATA[Feeding MISP with OSSEC<br /><a href="https://isc.sans.edu/diary/Feeding%20MISP%20with%20OSSEC/30968" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Feeding%20MISP%20with%20OSSEC/30968</a><br /> Checkpoint VPN<br /><a href="https://labs.watchtowr.com/check-point-wrong-check-point-cve-2024-24919/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/check-point-wrong-check-point-cve-2024-24919/</a><br /> The Pumpkin Eclipse<br /><a href="https://blog.lumen.com/the-pumpkin-eclipse/" target="_blank" rel="noreferrer noopener">https://blog.lumen.com/the-pumpkin-eclipse/</a><br /> Michael Dunking: Detecting Cypher Injection with Open-Source Network Intrusion Detection<br /><a href="https://www.sans.edu/cyber-research/detecting-cypher-injection-with-open-source-network-intrusion-detection/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/detecting-cypher-injection-with-open-source-network-intrusion-detection/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9004.mp3</guid><pubDate>Fri, 31 May 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60230216/9004.mp3" length="13248030" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Feeding MISP with OSSEC
https://isc.sans.edu/diary/Feeding%20MISP%20with%20OSSEC/30968
 Checkpoint VPN
https://labs.watchtowr.com/check-point-wrong-check-point-cve-2024-24919/
 The Pumpkin Eclipse
https://blog.lumen.com/the-pumpkin-eclipse/
 Michael...</itunes:subtitle><itunes:summary><![CDATA[Feeding MISP with OSSEC<br /><a href="https://isc.sans.edu/diary/Feeding%20MISP%20with%20OSSEC/30968" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Feeding%20MISP%20with%20OSSEC/30968</a><br /> Checkpoint VPN<br /><a href="https://labs.watchtowr.com/check-point-wrong-check-point-cve-2024-24919/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/check-point-wrong-check-point-cve-2024-24919/</a><br /> The Pumpkin Eclipse<br /><a href="https://blog.lumen.com/the-pumpkin-eclipse/" target="_blank" rel="noreferrer noopener">https://blog.lumen.com/the-pumpkin-eclipse/</a><br /> Michael Dunking: Detecting Cypher Injection with Open-Source Network Intrusion Detection<br /><a href="https://www.sans.edu/cyber-research/detecting-cypher-injection-with-open-source-network-intrusion-detection/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/detecting-cypher-injection-with-open-source-network-intrusion-detection/</a><br />]]></itunes:summary><itunes:duration>925</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,cypher; pumpkin; checkpoint; v,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9004</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, May 30th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-may-30th-2024--62129393</link><description><![CDATA[Is that It? Finding the Unknown: Correlations Between Honeypot Logs and PCAPs<br /><a href="https://isc.sans.edu/diary/Is%20that%20It%3F%20%20Finding%20the%20Unknown%3A%20Correlations%20Between%20Honeypot%20Logs%20%26%20PCAPs%20%5BGuest%20Diary%5D/30962" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Is%20that%20It%3F%20%20Finding%20the%20Unknown%3A%20Correlations%20Between%20Honeypot%20Logs%20%26%20PCAPs%20%5BGuest%20Diary%5D/30962</a><br /> Checkpoint 0-Day<br /><a href="https://blog.checkpoint.com/security/enhance-your-vpn-security-posture" target="_blank" rel="noreferrer noopener">https://blog.checkpoint.com/security/enhance-your-vpn-security-posture</a><br /> Okta warns of Credential Stuffing Against Customer Identity Cloud<br /><a href="https://sec.okta.com/articles/2024/05/detecting-cross-origin-authentication-credential-stuffing-attacks" target="_blank" rel="noreferrer noopener">https://sec.okta.com/articles/2024/05/detecting-cross-origin-authentication-credential-stuffing-attacks</a><br /> Brute Forcing Old Bitcoin Wallet Password<br /><a href="https://www.youtube.com/watch?v=o5IySpAkThg" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=o5IySpAkThg</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9002.mp3</guid><pubDate>Thu, 30 May 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129393/9002.mp3" length="4973409" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Is that It? Finding the Unknown: Correlations Between Honeypot Logs and PCAPs
https://isc.sans.edu/diary/Is%20that%20It%3F%20%20Finding%20the%20Unknown%3A%20Correlations%20Between%20Honeypot%20Logs%20%26%20PCAPs%20%5BGuest%20Diary%5D/30962
 Checkpoint...</itunes:subtitle><itunes:summary><![CDATA[Is that It? Finding the Unknown: Correlations Between Honeypot Logs and PCAPs<br /><a href="https://isc.sans.edu/diary/Is%20that%20It%3F%20%20Finding%20the%20Unknown%3A%20Correlations%20Between%20Honeypot%20Logs%20%26%20PCAPs%20%5BGuest%20Diary%5D/30962" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Is%20that%20It%3F%20%20Finding%20the%20Unknown%3A%20Correlations%20Between%20Honeypot%20Logs%20%26%20PCAPs%20%5BGuest%20Diary%5D/30962</a><br /> Checkpoint 0-Day<br /><a href="https://blog.checkpoint.com/security/enhance-your-vpn-security-posture" target="_blank" rel="noreferrer noopener">https://blog.checkpoint.com/security/enhance-your-vpn-security-posture</a><br /> Okta warns of Credential Stuffing Against Customer Identity Cloud<br /><a href="https://sec.okta.com/articles/2024/05/detecting-cross-origin-authentication-credential-stuffing-attacks" target="_blank" rel="noreferrer noopener">https://sec.okta.com/articles/2024/05/detecting-cross-origin-authentication-credential-stuffing-attacks</a><br /> Brute Forcing Old Bitcoin Wallet Password<br /><a href="https://www.youtube.com/watch?v=o5IySpAkThg" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=o5IySpAkThg</a><br />]]></itunes:summary><itunes:duration>334</itunes:duration><itunes:keywords>bitcoin; okta; checkpoint; sie,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9002</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, May 30th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-may-30th-2024--60216155</link><description><![CDATA[Is that It? Finding the Unknown: Correlations Between Honeypot Logs and PCAPs<br /><a href="https://isc.sans.edu/diary/Is%20that%20It%3F%20%20Finding%20the%20Unknown%3A%20Correlations%20Between%20Honeypot%20Logs%20%26%20PCAPs%20%5BGuest%20Diary%5D/30962" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Is%20that%20It%3F%20%20Finding%20the%20Unknown%3A%20Correlations%20Between%20Honeypot%20Logs%20%26%20PCAPs%20%5BGuest%20Diary%5D/30962</a><br /> Checkpoint 0-Day<br /><a href="https://blog.checkpoint.com/security/enhance-your-vpn-security-posture" target="_blank" rel="noreferrer noopener">https://blog.checkpoint.com/security/enhance-your-vpn-security-posture</a><br /> Okta warns of Credential Stuffing Against Customer Identity Cloud<br /><a href="https://sec.okta.com/articles/2024/05/detecting-cross-origin-authentication-credential-stuffing-attacks" target="_blank" rel="noreferrer noopener">https://sec.okta.com/articles/2024/05/detecting-cross-origin-authentication-credential-stuffing-attacks</a><br /> Brute Forcing Old Bitcoin Wallet Password<br /><a href="https://www.youtube.com/watch?v=o5IySpAkThg" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=o5IySpAkThg</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9002.mp3</guid><pubDate>Thu, 30 May 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60216155/9002.mp3" length="4973409" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Is that It? Finding the Unknown: Correlations Between Honeypot Logs and PCAPs
https://isc.sans.edu/diary/Is%20that%20It%3F%20%20Finding%20the%20Unknown%3A%20Correlations%20Between%20Honeypot%20Logs%20%26%20PCAPs%20%5BGuest%20Diary%5D/30962
 Checkpoint...</itunes:subtitle><itunes:summary><![CDATA[Is that It? Finding the Unknown: Correlations Between Honeypot Logs and PCAPs<br /><a href="https://isc.sans.edu/diary/Is%20that%20It%3F%20%20Finding%20the%20Unknown%3A%20Correlations%20Between%20Honeypot%20Logs%20%26%20PCAPs%20%5BGuest%20Diary%5D/30962" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Is%20that%20It%3F%20%20Finding%20the%20Unknown%3A%20Correlations%20Between%20Honeypot%20Logs%20%26%20PCAPs%20%5BGuest%20Diary%5D/30962</a><br /> Checkpoint 0-Day<br /><a href="https://blog.checkpoint.com/security/enhance-your-vpn-security-posture" target="_blank" rel="noreferrer noopener">https://blog.checkpoint.com/security/enhance-your-vpn-security-posture</a><br /> Okta warns of Credential Stuffing Against Customer Identity Cloud<br /><a href="https://sec.okta.com/articles/2024/05/detecting-cross-origin-authentication-credential-stuffing-attacks" target="_blank" rel="noreferrer noopener">https://sec.okta.com/articles/2024/05/detecting-cross-origin-authentication-credential-stuffing-attacks</a><br /> Brute Forcing Old Bitcoin Wallet Password<br /><a href="https://www.youtube.com/watch?v=o5IySpAkThg" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=o5IySpAkThg</a><br />]]></itunes:summary><itunes:duration>334</itunes:duration><itunes:keywords>bitcoin; okta; checkpoint; sie,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9002</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, May 29th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-may-29th-2024--62129355</link><description><![CDATA[Preventing SQL Injection with Python<br /><a href="https://www.youtube.com/watch?v=1cQy9N1Xndk" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=1cQy9N1Xndk</a><br /> PoC Exploit for CVE-2024-23108 in Fortinet FortiSIEM<br /><a href="https://www.horizon3.ai/attack-research/cve-2024-23108-fortinet-fortisiem-2nd-order-command-injection-deep-dive/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/cve-2024-23108-fortinet-fortisiem-2nd-order-command-injection-deep-dive/</a><br /> ShrinkLocker: Turning BitLocker into ransomware<br /><a href="https://securelist.com/ransomware-abuses-bitlocker/112643/" target="_blank" rel="noreferrer noopener">https://securelist.com/ransomware-abuses-bitlocker/112643/</a><br /> iconv buffer overflow PoC 2024-2961<br /><a href="https://github.com/ambionics/cnext-exploits/" target="_blank" rel="noreferrer noopener">https://github.com/ambionics/cnext-exploits/</a><br /> PoC for Apple Priv. Escalation bug  CVE-2024-27842<br /><a href="https://github.com/wangtielei/POCs/tree/main/CVE-2024-27842" target="_blank" rel="noreferrer noopener">https://github.com/wangtielei/POCs/tree/main/CVE-2024-27842</a><br /><a href="https://x.com/WangTielei" target="_blank" rel="noreferrer noopener">https://x.com/WangTielei</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/9000.mp3</guid><pubDate>Wed, 29 May 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129355/9000.mp3" length="4286528" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Preventing SQL Injection with Python
https://www.youtube.com/watch?v=1cQy9N1Xndk
 PoC Exploit for CVE-2024-23108 in Fortinet FortiSIEM
https://www.horizon3.ai/attack-research/cve-2024-23108-fortinet-fortisiem-2nd-order-command-injection-deep-dive/...</itunes:subtitle><itunes:summary><![CDATA[Preventing SQL Injection with Python<br /><a href="https://www.youtube.com/watch?v=1cQy9N1Xndk" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=1cQy9N1Xndk</a><br /> PoC Exploit for CVE-2024-23108 in Fortinet FortiSIEM<br /><a href="https://www.horizon3.ai/attack-research/cve-2024-23108-fortinet-fortisiem-2nd-order-command-injection-deep-dive/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/cve-2024-23108-fortinet-fortisiem-2nd-order-command-injection-deep-dive/</a><br /> ShrinkLocker: Turning BitLocker into ransomware<br /><a href="https://securelist.com/ransomware-abuses-bitlocker/112643/" target="_blank" rel="noreferrer noopener">https://securelist.com/ransomware-abuses-bitlocker/112643/</a><br /> iconv buffer overflow PoC 2024-2961<br /><a href="https://github.com/ambionics/cnext-exploits/" target="_blank" rel="noreferrer noopener">https://github.com/ambionics/cnext-exploits/</a><br /> PoC for Apple Priv. Escalation bug  CVE-2024-27842<br /><a href="https://github.com/wangtielei/POCs/tree/main/CVE-2024-27842" target="_blank" rel="noreferrer noopener">https://github.com/wangtielei/POCs/tree/main/CVE-2024-27842</a><br /><a href="https://x.com/WangTielei" target="_blank" rel="noreferrer noopener">https://x.com/WangTielei</a><br />]]></itunes:summary><itunes:duration>285</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,poc; apple; macos; iconv; php;,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9000</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, May 29th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-may-29th-2024--60203947</link><description><![CDATA[Preventing SQL Injection with Python<br /><a href="https://www.youtube.com/watch?v=1cQy9N1Xndk" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=1cQy9N1Xndk</a><br /> PoC Exploit for CVE-2024-23108 in Fortinet FortiSIEM<br /><a href="https://www.horizon3.ai/attack-research/cve-2024-23108-fortinet-fortisiem-2nd-order-command-injection-deep-dive/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/cve-2024-23108-fortinet-fortisiem-2nd-order-command-injection-deep-dive/</a><br /> ShrinkLocker: Turning BitLocker into ransomware<br /><a href="https://securelist.com/ransomware-abuses-bitlocker/112643/" target="_blank" rel="noreferrer noopener">https://securelist.com/ransomware-abuses-bitlocker/112643/</a><br /> iconv buffer overflow PoC 2024-2961<br /><a href="https://github.com/ambionics/cnext-exploits/" target="_blank" rel="noreferrer noopener">https://github.com/ambionics/cnext-exploits/</a><br /> PoC for Apple Priv. Escalation bug  CVE-2024-27842<br /><a href="https://github.com/wangtielei/POCs/tree/main/CVE-2024-27842" target="_blank" rel="noreferrer noopener">https://github.com/wangtielei/POCs/tree/main/CVE-2024-27842</a><br /><a href="https://x.com/WangTielei" target="_blank" rel="noreferrer noopener">https://x.com/WangTielei</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/9000.mp3</guid><pubDate>Wed, 29 May 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60203947/9000.mp3" length="4286528" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Preventing SQL Injection with Python
https://www.youtube.com/watch?v=1cQy9N1Xndk
 PoC Exploit for CVE-2024-23108 in Fortinet FortiSIEM
https://www.horizon3.ai/attack-research/cve-2024-23108-fortinet-fortisiem-2nd-order-command-injection-deep-dive/...</itunes:subtitle><itunes:summary><![CDATA[Preventing SQL Injection with Python<br /><a href="https://www.youtube.com/watch?v=1cQy9N1Xndk" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=1cQy9N1Xndk</a><br /> PoC Exploit for CVE-2024-23108 in Fortinet FortiSIEM<br /><a href="https://www.horizon3.ai/attack-research/cve-2024-23108-fortinet-fortisiem-2nd-order-command-injection-deep-dive/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/cve-2024-23108-fortinet-fortisiem-2nd-order-command-injection-deep-dive/</a><br /> ShrinkLocker: Turning BitLocker into ransomware<br /><a href="https://securelist.com/ransomware-abuses-bitlocker/112643/" target="_blank" rel="noreferrer noopener">https://securelist.com/ransomware-abuses-bitlocker/112643/</a><br /> iconv buffer overflow PoC 2024-2961<br /><a href="https://github.com/ambionics/cnext-exploits/" target="_blank" rel="noreferrer noopener">https://github.com/ambionics/cnext-exploits/</a><br /> PoC for Apple Priv. Escalation bug  CVE-2024-27842<br /><a href="https://github.com/wangtielei/POCs/tree/main/CVE-2024-27842" target="_blank" rel="noreferrer noopener">https://github.com/wangtielei/POCs/tree/main/CVE-2024-27842</a><br /><a href="https://x.com/WangTielei" target="_blank" rel="noreferrer noopener">https://x.com/WangTielei</a><br />]]></itunes:summary><itunes:duration>285</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,poc; apple; macos; iconv; php;,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>9000</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, May 28th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-may-28th-2024--62129360</link><description><![CDATA[Files with TGZ Extension used as malspam attachements<br /><a href="https://isc.sans.edu/diary/Files%20with%20TXZ%20extension%20used%20as%20malspam%20attachments/30958" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Files%20with%20TXZ%20extension%20used%20as%20malspam%20attachments/30958</a><br /> Google 0-Day<br /><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_23.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_23.html</a><br /> Google Stops Trusting Globaltrust CA<br /><a href="https://groups.google.com/a/ccadb.org/g/public/c/wRs-zec8w7k/m/G_9QprJ2AQAJ" target="_blank" rel="noreferrer noopener">https://groups.google.com/a/ccadb.org/g/public/c/wRs-zec8w7k/m/G_9QprJ2AQAJ</a><br /> Checkpoint warns of password bruteforcing<br /><a href="https://blog.checkpoint.com/security/enhance-your-vpn-security-posture?campaign=checkpoint&amp;eid=guvrs&amp;advisory=1" target="_blank" rel="noreferrer noopener">https://blog.checkpoint.com/security/enhance-your-vpn-security-posture?campaign=checkpoint&amp;eid=guvrs&amp;advisory=1</a><br /> SEC522: Defending Web Applications<br />  isc.sans.edu/j/sec522<br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8998.mp3</guid><pubDate>Tue, 28 May 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129360/8998.mp3" length="5415316" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Files with TGZ Extension used as malspam attachements
https://isc.sans.edu/diary/Files%20with%20TXZ%20extension%20used%20as%20malspam%20attachments/30958
 Google 0-Day...</itunes:subtitle><itunes:summary><![CDATA[Files with TGZ Extension used as malspam attachements<br /><a href="https://isc.sans.edu/diary/Files%20with%20TXZ%20extension%20used%20as%20malspam%20attachments/30958" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Files%20with%20TXZ%20extension%20used%20as%20malspam%20attachments/30958</a><br /> Google 0-Day<br /><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_23.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_23.html</a><br /> Google Stops Trusting Globaltrust CA<br /><a href="https://groups.google.com/a/ccadb.org/g/public/c/wRs-zec8w7k/m/G_9QprJ2AQAJ" target="_blank" rel="noreferrer noopener">https://groups.google.com/a/ccadb.org/g/public/c/wRs-zec8w7k/m/G_9QprJ2AQAJ</a><br /> Checkpoint warns of password bruteforcing<br /><a href="https://blog.checkpoint.com/security/enhance-your-vpn-security-posture?campaign=checkpoint&amp;eid=guvrs&amp;advisory=1" target="_blank" rel="noreferrer noopener">https://blog.checkpoint.com/security/enhance-your-vpn-security-posture?campaign=checkpoint&amp;eid=guvrs&amp;advisory=1</a><br /> SEC522: Defending Web Applications<br />  isc.sans.edu/j/sec522<br />]]></itunes:summary><itunes:duration>365</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dc; washington; txz; malspam; ,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8998</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, May 28th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-may-28th-2024--60193524</link><description><![CDATA[Files with TGZ Extension used as malspam attachements<br /><a href="https://isc.sans.edu/diary/Files%20with%20TXZ%20extension%20used%20as%20malspam%20attachments/30958" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Files%20with%20TXZ%20extension%20used%20as%20malspam%20attachments/30958</a><br /> Google 0-Day<br /><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_23.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_23.html</a><br /> Google Stops Trusting Globaltrust CA<br /><a href="https://groups.google.com/a/ccadb.org/g/public/c/wRs-zec8w7k/m/G_9QprJ2AQAJ" target="_blank" rel="noreferrer noopener">https://groups.google.com/a/ccadb.org/g/public/c/wRs-zec8w7k/m/G_9QprJ2AQAJ</a><br /> Checkpoint warns of password bruteforcing<br /><a href="https://blog.checkpoint.com/security/enhance-your-vpn-security-posture?campaign=checkpoint&amp;eid=guvrs&amp;advisory=1" target="_blank" rel="noreferrer noopener">https://blog.checkpoint.com/security/enhance-your-vpn-security-posture?campaign=checkpoint&amp;eid=guvrs&amp;advisory=1</a><br /> SEC522: Defending Web Applications<br />  isc.sans.edu/j/sec522<br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8998.mp3</guid><pubDate>Tue, 28 May 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60193524/8998.mp3" length="5415316" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Files with TGZ Extension used as malspam attachements
https://isc.sans.edu/diary/Files%20with%20TXZ%20extension%20used%20as%20malspam%20attachments/30958
 Google 0-Day...</itunes:subtitle><itunes:summary><![CDATA[Files with TGZ Extension used as malspam attachements<br /><a href="https://isc.sans.edu/diary/Files%20with%20TXZ%20extension%20used%20as%20malspam%20attachments/30958" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Files%20with%20TXZ%20extension%20used%20as%20malspam%20attachments/30958</a><br /> Google 0-Day<br /><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_23.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_23.html</a><br /> Google Stops Trusting Globaltrust CA<br /><a href="https://groups.google.com/a/ccadb.org/g/public/c/wRs-zec8w7k/m/G_9QprJ2AQAJ" target="_blank" rel="noreferrer noopener">https://groups.google.com/a/ccadb.org/g/public/c/wRs-zec8w7k/m/G_9QprJ2AQAJ</a><br /> Checkpoint warns of password bruteforcing<br /><a href="https://blog.checkpoint.com/security/enhance-your-vpn-security-posture?campaign=checkpoint&amp;eid=guvrs&amp;advisory=1" target="_blank" rel="noreferrer noopener">https://blog.checkpoint.com/security/enhance-your-vpn-security-posture?campaign=checkpoint&amp;eid=guvrs&amp;advisory=1</a><br /> SEC522: Defending Web Applications<br />  isc.sans.edu/j/sec522<br />]]></itunes:summary><itunes:duration>365</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dc; washington; txz; malspam; ,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8998</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, May 24th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-may-24th-2024--62129394</link><description><![CDATA[Analysis of 'redtail' file uploads to ISC Honeypot<br /><a href="https://isc.sans.edu/diary/Analysis%20of%20%3Fredtail%3F%20File%20Uploads%20to%20ICS%20Honeypot%2C%20a%20Multi-Architecture%20Coin%20Miner%20%5BGuest%20Diary%5D/30950" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analysis%20of%20%3Fredtail%3F%20File%20Uploads%20to%20ICS%20Honeypot%2C%20a%20Multi-Architecture%20Coin%20Miner%20%5BGuest%20Diary%5D/30950</a><br /> Veeam Vulnerablity<br /><a href="https://www.veeam.com/kb4581" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4581</a><br /> C-Root Server Lost Touch With Peers<br /><a href="https://arstechnica.com/security/2024/05/dns-glitch-that-threatened-internet-stability-fixed-cause-remains-unclear/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2024/05/dns-glitch-that-threatened-internet-stability-fixed-cause-remains-unclear/</a><br /> Ivanti Vulnerabilities<br /><a href="https://forums.ivanti.com/s/article/Avalanche-6-4-3-602-additional-security-hardening-and-CVE-fixed?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Avalanche-6-4-3-602-additional-security-hardening-and-CVE-fixed?language=en_US</a><br /> Justice AV Solutions Software Backdoor<br /><a href="https://www.rapid7.com/blog/post/2024/05/23/cve-2024-4978-backdoored-justice-av-solutions-viewer-software-used-in-apparent-supply-chain-attack/" target="_blank" rel="noreferrer noopener">https://www.rapid7.com/blog/post/2024/05/23/cve-2024-4978-backdoored-justice-av-solutions-viewer-software-used-in-apparent-supply-chain-attack/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8996.mp3</guid><pubDate>Fri, 24 May 2024 02:35:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129394/8996.mp3" length="6397807" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Analysis of 'redtail' file uploads to ISC Honeypot
https://isc.sans.edu/diary/Analysis%20of%20%3Fredtail%3F%20File%20Uploads%20to%20ICS%20Honeypot%2C%20a%20Multi-Architecture%20Coin%20Miner%20%5BGuest%20Diary%5D/30950
 Veeam Vulnerablity...</itunes:subtitle><itunes:summary><![CDATA[Analysis of 'redtail' file uploads to ISC Honeypot<br /><a href="https://isc.sans.edu/diary/Analysis%20of%20%3Fredtail%3F%20File%20Uploads%20to%20ICS%20Honeypot%2C%20a%20Multi-Architecture%20Coin%20Miner%20%5BGuest%20Diary%5D/30950" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analysis%20of%20%3Fredtail%3F%20File%20Uploads%20to%20ICS%20Honeypot%2C%20a%20Multi-Architecture%20Coin%20Miner%20%5BGuest%20Diary%5D/30950</a><br /> Veeam Vulnerablity<br /><a href="https://www.veeam.com/kb4581" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4581</a><br /> C-Root Server Lost Touch With Peers<br /><a href="https://arstechnica.com/security/2024/05/dns-glitch-that-threatened-internet-stability-fixed-cause-remains-unclear/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2024/05/dns-glitch-that-threatened-internet-stability-fixed-cause-remains-unclear/</a><br /> Ivanti Vulnerabilities<br /><a href="https://forums.ivanti.com/s/article/Avalanche-6-4-3-602-additional-security-hardening-and-CVE-fixed?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Avalanche-6-4-3-602-additional-security-hardening-and-CVE-fixed?language=en_US</a><br /> Justice AV Solutions Software Backdoor<br /><a href="https://www.rapid7.com/blog/post/2024/05/23/cve-2024-4978-backdoored-justice-av-solutions-viewer-software-used-in-apparent-supply-chain-attack/" target="_blank" rel="noreferrer noopener">https://www.rapid7.com/blog/post/2024/05/23/cve-2024-4978-backdoored-justice-av-solutions-viewer-software-used-in-apparent-supply-chain-attack/</a><br />]]></itunes:summary><itunes:duration>435</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,justice; av; ivanti; firepower,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8996</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, May 24th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-may-24th-2024--60157107</link><description><![CDATA[Analysis of 'redtail' file uploads to ISC Honeypot<br /><a href="https://isc.sans.edu/diary/Analysis%20of%20%3Fredtail%3F%20File%20Uploads%20to%20ICS%20Honeypot%2C%20a%20Multi-Architecture%20Coin%20Miner%20%5BGuest%20Diary%5D/30950" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analysis%20of%20%3Fredtail%3F%20File%20Uploads%20to%20ICS%20Honeypot%2C%20a%20Multi-Architecture%20Coin%20Miner%20%5BGuest%20Diary%5D/30950</a><br /> Veeam Vulnerablity<br /><a href="https://www.veeam.com/kb4581" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4581</a><br /> C-Root Server Lost Touch With Peers<br /><a href="https://arstechnica.com/security/2024/05/dns-glitch-that-threatened-internet-stability-fixed-cause-remains-unclear/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2024/05/dns-glitch-that-threatened-internet-stability-fixed-cause-remains-unclear/</a><br /> Ivanti Vulnerabilities<br /><a href="https://forums.ivanti.com/s/article/Avalanche-6-4-3-602-additional-security-hardening-and-CVE-fixed?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Avalanche-6-4-3-602-additional-security-hardening-and-CVE-fixed?language=en_US</a><br /> Justice AV Solutions Software Backdoor<br /><a href="https://www.rapid7.com/blog/post/2024/05/23/cve-2024-4978-backdoored-justice-av-solutions-viewer-software-used-in-apparent-supply-chain-attack/" target="_blank" rel="noreferrer noopener">https://www.rapid7.com/blog/post/2024/05/23/cve-2024-4978-backdoored-justice-av-solutions-viewer-software-used-in-apparent-supply-chain-attack/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8996.mp3</guid><pubDate>Fri, 24 May 2024 02:35:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60157107/8996.mp3" length="6397807" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Analysis of 'redtail' file uploads to ISC Honeypot
https://isc.sans.edu/diary/Analysis%20of%20%3Fredtail%3F%20File%20Uploads%20to%20ICS%20Honeypot%2C%20a%20Multi-Architecture%20Coin%20Miner%20%5BGuest%20Diary%5D/30950
 Veeam Vulnerablity...</itunes:subtitle><itunes:summary><![CDATA[Analysis of 'redtail' file uploads to ISC Honeypot<br /><a href="https://isc.sans.edu/diary/Analysis%20of%20%3Fredtail%3F%20File%20Uploads%20to%20ICS%20Honeypot%2C%20a%20Multi-Architecture%20Coin%20Miner%20%5BGuest%20Diary%5D/30950" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analysis%20of%20%3Fredtail%3F%20File%20Uploads%20to%20ICS%20Honeypot%2C%20a%20Multi-Architecture%20Coin%20Miner%20%5BGuest%20Diary%5D/30950</a><br /> Veeam Vulnerablity<br /><a href="https://www.veeam.com/kb4581" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4581</a><br /> C-Root Server Lost Touch With Peers<br /><a href="https://arstechnica.com/security/2024/05/dns-glitch-that-threatened-internet-stability-fixed-cause-remains-unclear/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2024/05/dns-glitch-that-threatened-internet-stability-fixed-cause-remains-unclear/</a><br /> Ivanti Vulnerabilities<br /><a href="https://forums.ivanti.com/s/article/Avalanche-6-4-3-602-additional-security-hardening-and-CVE-fixed?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Avalanche-6-4-3-602-additional-security-hardening-and-CVE-fixed?language=en_US</a><br /> Justice AV Solutions Software Backdoor<br /><a href="https://www.rapid7.com/blog/post/2024/05/23/cve-2024-4978-backdoored-justice-av-solutions-viewer-software-used-in-apparent-supply-chain-attack/" target="_blank" rel="noreferrer noopener">https://www.rapid7.com/blog/post/2024/05/23/cve-2024-4978-backdoored-justice-av-solutions-viewer-software-used-in-apparent-supply-chain-attack/</a><br />]]></itunes:summary><itunes:duration>435</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,justice; av; ivanti; firepower,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8996</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, May 23rd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-may-23rd-2024--62129356</link><description><![CDATA[NMAP Scanning Without Scanning - The ipinfo API<br /><a href="https://isc.sans.edu/diary/NMAP%20Scanning%20without%20Scanning%20%28Part%202%29%20-%20The%20ipinfo%20API/30948" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/NMAP%20Scanning%20without%20Scanning%20%28Part%202%29%20-%20The%20ipinfo%20API/30948</a><br /> Why Your WiFi Router Doubles As An Apple Airtag<br /><a href="https://krebsonsecurity.com/2024/05/why-your-wi-fi-router-doubles-as-an-apple-airtag/#more-67551" target="_blank" rel="noreferrer noopener">https://krebsonsecurity.com/2024/05/why-your-wi-fi-router-doubles-as-an-apple-airtag/#more-67551</a><br /><a href="https://account.microsoft.com/privacy/location-services-opt-out" target="_blank" rel="noreferrer noopener">https://account.microsoft.com/privacy/location-services-opt-out</a><br /><a href="https://answers.microsoft.com/en-us/windows/forum/all/wifi-sense-my-ssid-includes-optout-why-do-windows/1453142a-755a-476f-aa48-56d05b89e33c" target="_blank" rel="noreferrer noopener">https://answers.microsoft.com/en-us/windows/forum/all/wifi-sense-my-ssid-includes-optout-why-do-windows/1453142a-755a-476f-aa48-56d05b89e33c</a><br /><a href="https://www.computerworld.com/article/1484722/here-s-how-to-opt-out-of-google-s-wi-fi-snooping.html" target="_blank" rel="noreferrer noopener">https://www.computerworld.com/article/1484722/here-s-how-to-opt-out-of-google-s-wi-fi-snooping.html</a><br /><a href="https://www.privacy.org.nz/publications/commissioner-inquiries/google-s-collection-of-wifi-information-during-street-view-filming/" target="_blank" rel="noreferrer noopener">https://www.privacy.org.nz/publications/commissioner-inquiries/google-s-collection-of-wifi-information-during-street-view-filming/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8994.mp3</guid><pubDate>Thu, 23 May 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129356/8994.mp3" length="8085426" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>NMAP Scanning Without Scanning - The ipinfo API
https://isc.sans.edu/diary/NMAP%20Scanning%20without%20Scanning%20%28Part%202%29%20-%20The%20ipinfo%20API/30948
 Why Your WiFi Router Doubles As An Apple Airtag...</itunes:subtitle><itunes:summary><![CDATA[NMAP Scanning Without Scanning - The ipinfo API<br /><a href="https://isc.sans.edu/diary/NMAP%20Scanning%20without%20Scanning%20%28Part%202%29%20-%20The%20ipinfo%20API/30948" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/NMAP%20Scanning%20without%20Scanning%20%28Part%202%29%20-%20The%20ipinfo%20API/30948</a><br /> Why Your WiFi Router Doubles As An Apple Airtag<br /><a href="https://krebsonsecurity.com/2024/05/why-your-wi-fi-router-doubles-as-an-apple-airtag/#more-67551" target="_blank" rel="noreferrer noopener">https://krebsonsecurity.com/2024/05/why-your-wi-fi-router-doubles-as-an-apple-airtag/#more-67551</a><br /><a href="https://account.microsoft.com/privacy/location-services-opt-out" target="_blank" rel="noreferrer noopener">https://account.microsoft.com/privacy/location-services-opt-out</a><br /><a href="https://answers.microsoft.com/en-us/windows/forum/all/wifi-sense-my-ssid-includes-optout-why-do-windows/1453142a-755a-476f-aa48-56d05b89e33c" target="_blank" rel="noreferrer noopener">https://answers.microsoft.com/en-us/windows/forum/all/wifi-sense-my-ssid-includes-optout-why-do-windows/1453142a-755a-476f-aa48-56d05b89e33c</a><br /><a href="https://www.computerworld.com/article/1484722/here-s-how-to-opt-out-of-google-s-wi-fi-snooping.html" target="_blank" rel="noreferrer noopener">https://www.computerworld.com/article/1484722/here-s-how-to-opt-out-of-google-s-wi-fi-snooping.html</a><br /><a href="https://www.privacy.org.nz/publications/commissioner-inquiries/google-s-collection-of-wifi-information-during-street-view-filming/" target="_blank" rel="noreferrer noopener">https://www.privacy.org.nz/publications/commissioner-inquiries/google-s-collection-of-wifi-information-during-street-view-filming/</a><br />]]></itunes:summary><itunes:duration>556</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,wps; wifi; location; gps; nmap</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8994</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, May 23rd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-may-23rd-2024--60142999</link><description><![CDATA[NMAP Scanning Without Scanning - The ipinfo API<br /><a href="https://isc.sans.edu/diary/NMAP%20Scanning%20without%20Scanning%20%28Part%202%29%20-%20The%20ipinfo%20API/30948" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/NMAP%20Scanning%20without%20Scanning%20%28Part%202%29%20-%20The%20ipinfo%20API/30948</a><br /> Why Your WiFi Router Doubles As An Apple Airtag<br /><a href="https://krebsonsecurity.com/2024/05/why-your-wi-fi-router-doubles-as-an-apple-airtag/#more-67551" target="_blank" rel="noreferrer noopener">https://krebsonsecurity.com/2024/05/why-your-wi-fi-router-doubles-as-an-apple-airtag/#more-67551</a><br /><a href="https://account.microsoft.com/privacy/location-services-opt-out" target="_blank" rel="noreferrer noopener">https://account.microsoft.com/privacy/location-services-opt-out</a><br /><a href="https://answers.microsoft.com/en-us/windows/forum/all/wifi-sense-my-ssid-includes-optout-why-do-windows/1453142a-755a-476f-aa48-56d05b89e33c" target="_blank" rel="noreferrer noopener">https://answers.microsoft.com/en-us/windows/forum/all/wifi-sense-my-ssid-includes-optout-why-do-windows/1453142a-755a-476f-aa48-56d05b89e33c</a><br /><a href="https://www.computerworld.com/article/1484722/here-s-how-to-opt-out-of-google-s-wi-fi-snooping.html" target="_blank" rel="noreferrer noopener">https://www.computerworld.com/article/1484722/here-s-how-to-opt-out-of-google-s-wi-fi-snooping.html</a><br /><a href="https://www.privacy.org.nz/publications/commissioner-inquiries/google-s-collection-of-wifi-information-during-street-view-filming/" target="_blank" rel="noreferrer noopener">https://www.privacy.org.nz/publications/commissioner-inquiries/google-s-collection-of-wifi-information-during-street-view-filming/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8994.mp3</guid><pubDate>Thu, 23 May 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60142999/8994.mp3" length="8085426" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>NMAP Scanning Without Scanning - The ipinfo API
https://isc.sans.edu/diary/NMAP%20Scanning%20without%20Scanning%20%28Part%202%29%20-%20The%20ipinfo%20API/30948
 Why Your WiFi Router Doubles As An Apple Airtag...</itunes:subtitle><itunes:summary><![CDATA[NMAP Scanning Without Scanning - The ipinfo API<br /><a href="https://isc.sans.edu/diary/NMAP%20Scanning%20without%20Scanning%20%28Part%202%29%20-%20The%20ipinfo%20API/30948" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/NMAP%20Scanning%20without%20Scanning%20%28Part%202%29%20-%20The%20ipinfo%20API/30948</a><br /> Why Your WiFi Router Doubles As An Apple Airtag<br /><a href="https://krebsonsecurity.com/2024/05/why-your-wi-fi-router-doubles-as-an-apple-airtag/#more-67551" target="_blank" rel="noreferrer noopener">https://krebsonsecurity.com/2024/05/why-your-wi-fi-router-doubles-as-an-apple-airtag/#more-67551</a><br /><a href="https://account.microsoft.com/privacy/location-services-opt-out" target="_blank" rel="noreferrer noopener">https://account.microsoft.com/privacy/location-services-opt-out</a><br /><a href="https://answers.microsoft.com/en-us/windows/forum/all/wifi-sense-my-ssid-includes-optout-why-do-windows/1453142a-755a-476f-aa48-56d05b89e33c" target="_blank" rel="noreferrer noopener">https://answers.microsoft.com/en-us/windows/forum/all/wifi-sense-my-ssid-includes-optout-why-do-windows/1453142a-755a-476f-aa48-56d05b89e33c</a><br /><a href="https://www.computerworld.com/article/1484722/here-s-how-to-opt-out-of-google-s-wi-fi-snooping.html" target="_blank" rel="noreferrer noopener">https://www.computerworld.com/article/1484722/here-s-how-to-opt-out-of-google-s-wi-fi-snooping.html</a><br /><a href="https://www.privacy.org.nz/publications/commissioner-inquiries/google-s-collection-of-wifi-information-during-street-view-filming/" target="_blank" rel="noreferrer noopener">https://www.privacy.org.nz/publications/commissioner-inquiries/google-s-collection-of-wifi-information-during-street-view-filming/</a><br />]]></itunes:summary><itunes:duration>556</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,wps; wifi; location; gps; nmap</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8994</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, May 22nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-may-22nd-2024--62129366</link><description><![CDATA[Scanning without Scanning with nmap<br /><a href="https://isc.sans.edu/diary/Scanning%20without%20Scanning%20with%20NMAP%20%28APIs%20FTW%29/30944" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scanning%20without%20Scanning%20with%20NMAP%20%28APIs%20FTW%29/30944</a><br /> iTerm2 Vulnerablities<br /><a href="https://vin01.github.io/piptagole/escape-sequences/iterm2/hyper/url-handlers/code-execution/2024/05/21/arbitrary-url-schemes-terminal-emulators.html" target="_blank" rel="noreferrer noopener">https://vin01.github.io/piptagole/escape-sequences/iterm2/hyper/url-handlers/code-execution/2024/05/21/arbitrary-url-schemes-terminal-emulators.html</a><br /> GitHub Enterprise Vulnerablity CVE-2024-4985<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4985" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2024-4985</a><br /> BitBucket Pipelines Leaking Secrets<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/bitbucket-pipeline-leaking-secrets" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/bitbucket-pipeline-leaking-secrets</a><br /> Microsoft Recall Privacy<br /><a href="https://www.microsoft.com/en-us/windows/copilot-plus-pcs?r=1#faq1" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/windows/copilot-plus-pcs?r=1#faq1</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8992.mp3</guid><pubDate>Wed, 22 May 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129366/8992.mp3" length="5894458" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Scanning without Scanning with nmap
https://isc.sans.edu/diary/Scanning%20without%20Scanning%20with%20NMAP%20%28APIs%20FTW%29/30944
 iTerm2 Vulnerablities...</itunes:subtitle><itunes:summary><![CDATA[Scanning without Scanning with nmap<br /><a href="https://isc.sans.edu/diary/Scanning%20without%20Scanning%20with%20NMAP%20%28APIs%20FTW%29/30944" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scanning%20without%20Scanning%20with%20NMAP%20%28APIs%20FTW%29/30944</a><br /> iTerm2 Vulnerablities<br /><a href="https://vin01.github.io/piptagole/escape-sequences/iterm2/hyper/url-handlers/code-execution/2024/05/21/arbitrary-url-schemes-terminal-emulators.html" target="_blank" rel="noreferrer noopener">https://vin01.github.io/piptagole/escape-sequences/iterm2/hyper/url-handlers/code-execution/2024/05/21/arbitrary-url-schemes-terminal-emulators.html</a><br /> GitHub Enterprise Vulnerablity CVE-2024-4985<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4985" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2024-4985</a><br /> BitBucket Pipelines Leaking Secrets<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/bitbucket-pipeline-leaking-secrets" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/bitbucket-pipeline-leaking-secrets</a><br /> Microsoft Recall Privacy<br /><a href="https://www.microsoft.com/en-us/windows/copilot-plus-pcs?r=1#faq1" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/windows/copilot-plus-pcs?r=1#faq1</a><br />]]></itunes:summary><itunes:duration>399</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microsoft; recall; bitbucket; ,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8992</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, May 22nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-may-22nd-2024--60123388</link><description><![CDATA[Scanning without Scanning with nmap<br /><a href="https://isc.sans.edu/diary/Scanning%20without%20Scanning%20with%20NMAP%20%28APIs%20FTW%29/30944" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scanning%20without%20Scanning%20with%20NMAP%20%28APIs%20FTW%29/30944</a><br /> iTerm2 Vulnerablities<br /><a href="https://vin01.github.io/piptagole/escape-sequences/iterm2/hyper/url-handlers/code-execution/2024/05/21/arbitrary-url-schemes-terminal-emulators.html" target="_blank" rel="noreferrer noopener">https://vin01.github.io/piptagole/escape-sequences/iterm2/hyper/url-handlers/code-execution/2024/05/21/arbitrary-url-schemes-terminal-emulators.html</a><br /> GitHub Enterprise Vulnerablity CVE-2024-4985<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4985" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2024-4985</a><br /> BitBucket Pipelines Leaking Secrets<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/bitbucket-pipeline-leaking-secrets" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/bitbucket-pipeline-leaking-secrets</a><br /> Microsoft Recall Privacy<br /><a href="https://www.microsoft.com/en-us/windows/copilot-plus-pcs?r=1#faq1" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/windows/copilot-plus-pcs?r=1#faq1</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8992.mp3</guid><pubDate>Wed, 22 May 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60123388/8992.mp3" length="5894458" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Scanning without Scanning with nmap
https://isc.sans.edu/diary/Scanning%20without%20Scanning%20with%20NMAP%20%28APIs%20FTW%29/30944
 iTerm2 Vulnerablities...</itunes:subtitle><itunes:summary><![CDATA[Scanning without Scanning with nmap<br /><a href="https://isc.sans.edu/diary/Scanning%20without%20Scanning%20with%20NMAP%20%28APIs%20FTW%29/30944" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scanning%20without%20Scanning%20with%20NMAP%20%28APIs%20FTW%29/30944</a><br /> iTerm2 Vulnerablities<br /><a href="https://vin01.github.io/piptagole/escape-sequences/iterm2/hyper/url-handlers/code-execution/2024/05/21/arbitrary-url-schemes-terminal-emulators.html" target="_blank" rel="noreferrer noopener">https://vin01.github.io/piptagole/escape-sequences/iterm2/hyper/url-handlers/code-execution/2024/05/21/arbitrary-url-schemes-terminal-emulators.html</a><br /> GitHub Enterprise Vulnerablity CVE-2024-4985<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4985" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2024-4985</a><br /> BitBucket Pipelines Leaking Secrets<br /><a href="https://cloud.google.com/blog/topics/threat-intelligence/bitbucket-pipeline-leaking-secrets" target="_blank" rel="noreferrer noopener">https://cloud.google.com/blog/topics/threat-intelligence/bitbucket-pipeline-leaking-secrets</a><br /> Microsoft Recall Privacy<br /><a href="https://www.microsoft.com/en-us/windows/copilot-plus-pcs?r=1#faq1" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/windows/copilot-plus-pcs?r=1#faq1</a><br />]]></itunes:summary><itunes:duration>399</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microsoft; recall; bitbucket; ,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8992</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, May 21st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-may-21st-2024--62129396</link><description><![CDATA[Analyzing MSG Files<br /><a href="https://isc.sans.edu/diary/Analyzing%20MSG%20Files/30940" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analyzing%20MSG%20Files/30940</a><br /> Linguistic Lumberjack: Fluent Bit Vulnerability CVE-2024-4323<br /><a href="https://www.tenable.com/blog/linguistic-lumberjack-attacking-cloud-services-via-logging-endpoints-fluent-bit-cve-2024-4323" target="_blank" rel="noreferrer noopener">https://www.tenable.com/blog/linguistic-lumberjack-attacking-cloud-services-via-logging-endpoints-fluent-bit-cve-2024-4323</a><br /> Fortinet FortiSIEM Command Injection Deep-Dive CVE-2023-23992<br /><a href="https://www.horizon3.ai/attack-research/cve-2023-34992-fortinet-fortisiem-command-injection-deep-dive/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/cve-2023-34992-fortinet-fortisiem-command-injection-deep-dive/</a><br /> Git Vulnerability CVE-2024-32002 PoC<br /><a href="https://amalmurali.me/posts/git-rce/" target="_blank" rel="noreferrer noopener">https://amalmurali.me/posts/git-rce/</a><br /> Google Chrome CVE-2024-4947 PoC<br /><a href="https://buptsb.github.io/blog/post/CVE-2024-4947-%20v8%20incorrect%20AccessInfo%20for%20module%20namespace%20object%20causes%20Maglev%20type%20confusion.html" target="_blank" rel="noreferrer noopener">https://buptsb.github.io/blog/post/CVE-2024-4947-%20v8%20incorrect%20AccessInfo%20for%20module%20namespace%20object%20causes%20Maglev%20type%20confusion.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8990.mp3</guid><pubDate>Tue, 21 May 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129396/8990.mp3" length="5180096" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Analyzing MSG Files
https://isc.sans.edu/diary/Analyzing%20MSG%20Files/30940
 Linguistic Lumberjack: Fluent Bit Vulnerability CVE-2024-4323...</itunes:subtitle><itunes:summary><![CDATA[Analyzing MSG Files<br /><a href="https://isc.sans.edu/diary/Analyzing%20MSG%20Files/30940" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analyzing%20MSG%20Files/30940</a><br /> Linguistic Lumberjack: Fluent Bit Vulnerability CVE-2024-4323<br /><a href="https://www.tenable.com/blog/linguistic-lumberjack-attacking-cloud-services-via-logging-endpoints-fluent-bit-cve-2024-4323" target="_blank" rel="noreferrer noopener">https://www.tenable.com/blog/linguistic-lumberjack-attacking-cloud-services-via-logging-endpoints-fluent-bit-cve-2024-4323</a><br /> Fortinet FortiSIEM Command Injection Deep-Dive CVE-2023-23992<br /><a href="https://www.horizon3.ai/attack-research/cve-2023-34992-fortinet-fortisiem-command-injection-deep-dive/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/cve-2023-34992-fortinet-fortisiem-command-injection-deep-dive/</a><br /> Git Vulnerability CVE-2024-32002 PoC<br /><a href="https://amalmurali.me/posts/git-rce/" target="_blank" rel="noreferrer noopener">https://amalmurali.me/posts/git-rce/</a><br /> Google Chrome CVE-2024-4947 PoC<br /><a href="https://buptsb.github.io/blog/post/CVE-2024-4947-%20v8%20incorrect%20AccessInfo%20for%20module%20namespace%20object%20causes%20Maglev%20type%20confusion.html" target="_blank" rel="noreferrer noopener">https://buptsb.github.io/blog/post/CVE-2024-4947-%20v8%20incorrect%20AccessInfo%20for%20module%20namespace%20object%20causes%20Maglev%20type%20confusion.html</a><br />]]></itunes:summary><itunes:duration>348</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,msg; fluent bit; fortinet; for,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8990</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, May 21st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-may-21st-2024--60107509</link><description><![CDATA[Analyzing MSG Files<br /><a href="https://isc.sans.edu/diary/Analyzing%20MSG%20Files/30940" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analyzing%20MSG%20Files/30940</a><br /> Linguistic Lumberjack: Fluent Bit Vulnerability CVE-2024-4323<br /><a href="https://www.tenable.com/blog/linguistic-lumberjack-attacking-cloud-services-via-logging-endpoints-fluent-bit-cve-2024-4323" target="_blank" rel="noreferrer noopener">https://www.tenable.com/blog/linguistic-lumberjack-attacking-cloud-services-via-logging-endpoints-fluent-bit-cve-2024-4323</a><br /> Fortinet FortiSIEM Command Injection Deep-Dive CVE-2023-23992<br /><a href="https://www.horizon3.ai/attack-research/cve-2023-34992-fortinet-fortisiem-command-injection-deep-dive/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/cve-2023-34992-fortinet-fortisiem-command-injection-deep-dive/</a><br /> Git Vulnerability CVE-2024-32002 PoC<br /><a href="https://amalmurali.me/posts/git-rce/" target="_blank" rel="noreferrer noopener">https://amalmurali.me/posts/git-rce/</a><br /> Google Chrome CVE-2024-4947 PoC<br /><a href="https://buptsb.github.io/blog/post/CVE-2024-4947-%20v8%20incorrect%20AccessInfo%20for%20module%20namespace%20object%20causes%20Maglev%20type%20confusion.html" target="_blank" rel="noreferrer noopener">https://buptsb.github.io/blog/post/CVE-2024-4947-%20v8%20incorrect%20AccessInfo%20for%20module%20namespace%20object%20causes%20Maglev%20type%20confusion.html</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8990.mp3</guid><pubDate>Tue, 21 May 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60107509/8990.mp3" length="5180096" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Analyzing MSG Files
https://isc.sans.edu/diary/Analyzing%20MSG%20Files/30940
 Linguistic Lumberjack: Fluent Bit Vulnerability CVE-2024-4323...</itunes:subtitle><itunes:summary><![CDATA[Analyzing MSG Files<br /><a href="https://isc.sans.edu/diary/Analyzing%20MSG%20Files/30940" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analyzing%20MSG%20Files/30940</a><br /> Linguistic Lumberjack: Fluent Bit Vulnerability CVE-2024-4323<br /><a href="https://www.tenable.com/blog/linguistic-lumberjack-attacking-cloud-services-via-logging-endpoints-fluent-bit-cve-2024-4323" target="_blank" rel="noreferrer noopener">https://www.tenable.com/blog/linguistic-lumberjack-attacking-cloud-services-via-logging-endpoints-fluent-bit-cve-2024-4323</a><br /> Fortinet FortiSIEM Command Injection Deep-Dive CVE-2023-23992<br /><a href="https://www.horizon3.ai/attack-research/cve-2023-34992-fortinet-fortisiem-command-injection-deep-dive/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/cve-2023-34992-fortinet-fortisiem-command-injection-deep-dive/</a><br /> Git Vulnerability CVE-2024-32002 PoC<br /><a href="https://amalmurali.me/posts/git-rce/" target="_blank" rel="noreferrer noopener">https://amalmurali.me/posts/git-rce/</a><br /> Google Chrome CVE-2024-4947 PoC<br /><a href="https://buptsb.github.io/blog/post/CVE-2024-4947-%20v8%20incorrect%20AccessInfo%20for%20module%20namespace%20object%20causes%20Maglev%20type%20confusion.html" target="_blank" rel="noreferrer noopener">https://buptsb.github.io/blog/post/CVE-2024-4947-%20v8%20incorrect%20AccessInfo%20for%20module%20namespace%20object%20causes%20Maglev%20type%20confusion.html</a><br />]]></itunes:summary><itunes:duration>348</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,msg; fluent bit; fortinet; for,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8990</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, May 20th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-may-20th-2024--62129361</link><description><![CDATA[Another PDF Streams Example: Extracting JPEGs<br /><a href="https://isc.sans.edu/diary/Another%20PDF%20Streams%20Example%3A%20Extracting%20JPEGs/30924" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Another%20PDF%20Streams%20Example%3A%20Extracting%20JPEGs/30924</a><br /> QNAP QTS QNAPping At the Wheel<br /><a href="https://labs.watchtowr.com/qnap-qts-qnapping-at-the-wheel-cve-2024-27130-and-friends/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/qnap-qts-qnapping-at-the-wheel-cve-2024-27130-and-friends/</a><br /> May 2024 Security Update Problems with Windows 2019<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-1809-and-windows-server-2019#3299msgdesc" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-1809-and-windows-server-2019#3299msgdesc</a><br /> Dlink Vulnerabilities Exploited<br /><a href="https://www.cisa.gov/news-events/alerts/2024/05/16/cisa-adds-three-known-exploited-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2024/05/16/cisa-adds-three-known-exploited-vulnerabilities-catalog</a><br /> Ivanti PoC Exploit CVE 2024-22026<br /><a href="https://www.redlinecybersecurity.com/blog/exploiting-cve-2024-22026-rooting-ivanti-epmm-mobileiron-core" target="_blank" rel="noreferrer noopener">https://www.redlinecybersecurity.com/blog/exploiting-cve-2024-22026-rooting-ivanti-epmm-mobileiron-core</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8988.mp3</guid><pubDate>Mon, 20 May 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129361/8988.mp3" length="5662971" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Another PDF Streams Example: Extracting JPEGs
https://isc.sans.edu/diary/Another%20PDF%20Streams%20Example%3A%20Extracting%20JPEGs/30924
 QNAP QTS QNAPping At the Wheel...</itunes:subtitle><itunes:summary><![CDATA[Another PDF Streams Example: Extracting JPEGs<br /><a href="https://isc.sans.edu/diary/Another%20PDF%20Streams%20Example%3A%20Extracting%20JPEGs/30924" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Another%20PDF%20Streams%20Example%3A%20Extracting%20JPEGs/30924</a><br /> QNAP QTS QNAPping At the Wheel<br /><a href="https://labs.watchtowr.com/qnap-qts-qnapping-at-the-wheel-cve-2024-27130-and-friends/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/qnap-qts-qnapping-at-the-wheel-cve-2024-27130-and-friends/</a><br /> May 2024 Security Update Problems with Windows 2019<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-1809-and-windows-server-2019#3299msgdesc" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-1809-and-windows-server-2019#3299msgdesc</a><br /> Dlink Vulnerabilities Exploited<br /><a href="https://www.cisa.gov/news-events/alerts/2024/05/16/cisa-adds-three-known-exploited-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2024/05/16/cisa-adds-three-known-exploited-vulnerabilities-catalog</a><br /> Ivanti PoC Exploit CVE 2024-22026<br /><a href="https://www.redlinecybersecurity.com/blog/exploiting-cve-2024-22026-rooting-ivanti-epmm-mobileiron-core" target="_blank" rel="noreferrer noopener">https://www.redlinecybersecurity.com/blog/exploiting-cve-2024-22026-rooting-ivanti-epmm-mobileiron-core</a><br />]]></itunes:summary><itunes:duration>383</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,ivanti; poc; dlink; patch; win,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8988</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, May 20th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-may-20th-2024--60092975</link><description><![CDATA[Another PDF Streams Example: Extracting JPEGs<br /><a href="https://isc.sans.edu/diary/Another%20PDF%20Streams%20Example%3A%20Extracting%20JPEGs/30924" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Another%20PDF%20Streams%20Example%3A%20Extracting%20JPEGs/30924</a><br /> QNAP QTS QNAPping At the Wheel<br /><a href="https://labs.watchtowr.com/qnap-qts-qnapping-at-the-wheel-cve-2024-27130-and-friends/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/qnap-qts-qnapping-at-the-wheel-cve-2024-27130-and-friends/</a><br /> May 2024 Security Update Problems with Windows 2019<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-1809-and-windows-server-2019#3299msgdesc" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-1809-and-windows-server-2019#3299msgdesc</a><br /> Dlink Vulnerabilities Exploited<br /><a href="https://www.cisa.gov/news-events/alerts/2024/05/16/cisa-adds-three-known-exploited-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2024/05/16/cisa-adds-three-known-exploited-vulnerabilities-catalog</a><br /> Ivanti PoC Exploit CVE 2024-22026<br /><a href="https://www.redlinecybersecurity.com/blog/exploiting-cve-2024-22026-rooting-ivanti-epmm-mobileiron-core" target="_blank" rel="noreferrer noopener">https://www.redlinecybersecurity.com/blog/exploiting-cve-2024-22026-rooting-ivanti-epmm-mobileiron-core</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8988.mp3</guid><pubDate>Mon, 20 May 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60092975/8988.mp3" length="5662971" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Another PDF Streams Example: Extracting JPEGs
https://isc.sans.edu/diary/Another%20PDF%20Streams%20Example%3A%20Extracting%20JPEGs/30924
 QNAP QTS QNAPping At the Wheel...</itunes:subtitle><itunes:summary><![CDATA[Another PDF Streams Example: Extracting JPEGs<br /><a href="https://isc.sans.edu/diary/Another%20PDF%20Streams%20Example%3A%20Extracting%20JPEGs/30924" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Another%20PDF%20Streams%20Example%3A%20Extracting%20JPEGs/30924</a><br /> QNAP QTS QNAPping At the Wheel<br /><a href="https://labs.watchtowr.com/qnap-qts-qnapping-at-the-wheel-cve-2024-27130-and-friends/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/qnap-qts-qnapping-at-the-wheel-cve-2024-27130-and-friends/</a><br /> May 2024 Security Update Problems with Windows 2019<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-1809-and-windows-server-2019#3299msgdesc" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-1809-and-windows-server-2019#3299msgdesc</a><br /> Dlink Vulnerabilities Exploited<br /><a href="https://www.cisa.gov/news-events/alerts/2024/05/16/cisa-adds-three-known-exploited-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2024/05/16/cisa-adds-three-known-exploited-vulnerabilities-catalog</a><br /> Ivanti PoC Exploit CVE 2024-22026<br /><a href="https://www.redlinecybersecurity.com/blog/exploiting-cve-2024-22026-rooting-ivanti-epmm-mobileiron-core" target="_blank" rel="noreferrer noopener">https://www.redlinecybersecurity.com/blog/exploiting-cve-2024-22026-rooting-ivanti-epmm-mobileiron-core</a><br />]]></itunes:summary><itunes:duration>383</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,ivanti; poc; dlink; patch; win,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8988</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, May 17th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-may-17th-2024--62129383</link><description><![CDATA[Why yq? Adventurs in XML<br /><a href="https://isc.sans.edu/diary/Why%20yq%3F%20%20Adventures%20in%20XML/30930" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Why%20yq%3F%20%20Adventures%20in%20XML/30930</a><br /> Black Basta Uses Quick Assist<br /><a href="https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/</a><br /> Various Chrome 0-Day Vulnerabilities<br /><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html</a><br /> Android Theft Protection Improvement<br /><a href="https://blog.google/products/android/android-theft-protection/" target="_blank" rel="noreferrer noopener">https://blog.google/products/android/android-theft-protection/</a><br /> Critical Git Update<br /><a href="https://github.blog/2024-05-14-securing-git-addressing-5-new-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://github.blog/2024-05-14-securing-git-addressing-5-new-vulnerabilities/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8986.mp3</guid><pubDate>Fri, 17 May 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129383/8986.mp3" length="4808878" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Why yq? Adventurs in XML
https://isc.sans.edu/diary/Why%20yq%3F%20%20Adventures%20in%20XML/30930
 Black Basta Uses Quick Assist...</itunes:subtitle><itunes:summary><![CDATA[Why yq? Adventurs in XML<br /><a href="https://isc.sans.edu/diary/Why%20yq%3F%20%20Adventures%20in%20XML/30930" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Why%20yq%3F%20%20Adventures%20in%20XML/30930</a><br /> Black Basta Uses Quick Assist<br /><a href="https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/</a><br /> Various Chrome 0-Day Vulnerabilities<br /><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html</a><br /> Android Theft Protection Improvement<br /><a href="https://blog.google/products/android/android-theft-protection/" target="_blank" rel="noreferrer noopener">https://blog.google/products/android/android-theft-protection/</a><br /> Critical Git Update<br /><a href="https://github.blog/2024-05-14-securing-git-addressing-5-new-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://github.blog/2024-05-14-securing-git-addressing-5-new-vulnerabilities/</a><br />]]></itunes:summary><itunes:duration>322</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,git; android; chrome; quick as,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8986</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, May 17th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-may-17th-2024--60066414</link><description><![CDATA[Why yq? Adventurs in XML<br /><a href="https://isc.sans.edu/diary/Why%20yq%3F%20%20Adventures%20in%20XML/30930" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Why%20yq%3F%20%20Adventures%20in%20XML/30930</a><br /> Black Basta Uses Quick Assist<br /><a href="https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/</a><br /> Various Chrome 0-Day Vulnerabilities<br /><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html</a><br /> Android Theft Protection Improvement<br /><a href="https://blog.google/products/android/android-theft-protection/" target="_blank" rel="noreferrer noopener">https://blog.google/products/android/android-theft-protection/</a><br /> Critical Git Update<br /><a href="https://github.blog/2024-05-14-securing-git-addressing-5-new-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://github.blog/2024-05-14-securing-git-addressing-5-new-vulnerabilities/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8986.mp3</guid><pubDate>Fri, 17 May 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60066414/8986.mp3" length="4808878" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Why yq? Adventurs in XML
https://isc.sans.edu/diary/Why%20yq%3F%20%20Adventures%20in%20XML/30930
 Black Basta Uses Quick Assist...</itunes:subtitle><itunes:summary><![CDATA[Why yq? Adventurs in XML<br /><a href="https://isc.sans.edu/diary/Why%20yq%3F%20%20Adventures%20in%20XML/30930" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Why%20yq%3F%20%20Adventures%20in%20XML/30930</a><br /> Black Basta Uses Quick Assist<br /><a href="https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/</a><br /> Various Chrome 0-Day Vulnerabilities<br /><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html</a><br /> Android Theft Protection Improvement<br /><a href="https://blog.google/products/android/android-theft-protection/" target="_blank" rel="noreferrer noopener">https://blog.google/products/android/android-theft-protection/</a><br /> Critical Git Update<br /><a href="https://github.blog/2024-05-14-securing-git-addressing-5-new-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://github.blog/2024-05-14-securing-git-addressing-5-new-vulnerabilities/</a><br />]]></itunes:summary><itunes:duration>322</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,git; android; chrome; quick as,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8986</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, May 16th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-may-16th-2024--62129399</link><description><![CDATA[Got MFA? If not, now is the time!<br /><a href="https://isc.sans.edu/diary/Got%20MFA%3F%20%20If%20not%2C%20Now%20is%20the%20Time!/30926" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Got%20MFA%3F%20%20If%20not%2C%20Now%20is%20the%20Time!/30926</a><br /> SSID Confusion: Making Wi-Fi Clients Connect to the Wrong Network CVE-2023-52424<br /><a href="https://www.top10vpn.com/assets/2024/05/Top10VPN-x-Vanhoef-SSID-Confusion.pdf" target="_blank" rel="noreferrer noopener">https://www.top10vpn.com/assets/2024/05/Top10VPN-x-Vanhoef-SSID-Confusion.pdf</a><br /> FIDO2 MitM Session Hijacking<br /><a href="https://www.silverfort.com/blog/using-mitm-to-bypass-fido2/?web_view=true#but-first-some-background" target="_blank" rel="noreferrer noopener">https://www.silverfort.com/blog/using-mitm-to-bypass-fido2/?web_view=true#but-first-some-background</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8984.mp3</guid><pubDate>Thu, 16 May 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129399/8984.mp3" length="4947581" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Got MFA? If not, now is the time!
https://isc.sans.edu/diary/Got%20MFA%3F%20%20If%20not%2C%20Now%20is%20the%20Time!/30926
 SSID Confusion: Making Wi-Fi Clients Connect to the Wrong Network CVE-2023-52424...</itunes:subtitle><itunes:summary><![CDATA[Got MFA? If not, now is the time!<br /><a href="https://isc.sans.edu/diary/Got%20MFA%3F%20%20If%20not%2C%20Now%20is%20the%20Time!/30926" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Got%20MFA%3F%20%20If%20not%2C%20Now%20is%20the%20Time!/30926</a><br /> SSID Confusion: Making Wi-Fi Clients Connect to the Wrong Network CVE-2023-52424<br /><a href="https://www.top10vpn.com/assets/2024/05/Top10VPN-x-Vanhoef-SSID-Confusion.pdf" target="_blank" rel="noreferrer noopener">https://www.top10vpn.com/assets/2024/05/Top10VPN-x-Vanhoef-SSID-Confusion.pdf</a><br /> FIDO2 MitM Session Hijacking<br /><a href="https://www.silverfort.com/blog/using-mitm-to-bypass-fido2/?web_view=true#but-first-some-background" target="_blank" rel="noreferrer noopener">https://www.silverfort.com/blog/using-mitm-to-bypass-fido2/?web_view=true#but-first-some-background</a><br />]]></itunes:summary><itunes:duration>332</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,fido2; mitm; ssid; wifi; mfa;,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8984</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, May 16th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-may-16th-2024--60054161</link><description><![CDATA[Got MFA? If not, now is the time!<br /><a href="https://isc.sans.edu/diary/Got%20MFA%3F%20%20If%20not%2C%20Now%20is%20the%20Time!/30926" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Got%20MFA%3F%20%20If%20not%2C%20Now%20is%20the%20Time!/30926</a><br /> SSID Confusion: Making Wi-Fi Clients Connect to the Wrong Network CVE-2023-52424<br /><a href="https://www.top10vpn.com/assets/2024/05/Top10VPN-x-Vanhoef-SSID-Confusion.pdf" target="_blank" rel="noreferrer noopener">https://www.top10vpn.com/assets/2024/05/Top10VPN-x-Vanhoef-SSID-Confusion.pdf</a><br /> FIDO2 MitM Session Hijacking<br /><a href="https://www.silverfort.com/blog/using-mitm-to-bypass-fido2/?web_view=true#but-first-some-background" target="_blank" rel="noreferrer noopener">https://www.silverfort.com/blog/using-mitm-to-bypass-fido2/?web_view=true#but-first-some-background</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8984.mp3</guid><pubDate>Thu, 16 May 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60054161/8984.mp3" length="4947581" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Got MFA? If not, now is the time!
https://isc.sans.edu/diary/Got%20MFA%3F%20%20If%20not%2C%20Now%20is%20the%20Time!/30926
 SSID Confusion: Making Wi-Fi Clients Connect to the Wrong Network CVE-2023-52424...</itunes:subtitle><itunes:summary><![CDATA[Got MFA? If not, now is the time!<br /><a href="https://isc.sans.edu/diary/Got%20MFA%3F%20%20If%20not%2C%20Now%20is%20the%20Time!/30926" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Got%20MFA%3F%20%20If%20not%2C%20Now%20is%20the%20Time!/30926</a><br /> SSID Confusion: Making Wi-Fi Clients Connect to the Wrong Network CVE-2023-52424<br /><a href="https://www.top10vpn.com/assets/2024/05/Top10VPN-x-Vanhoef-SSID-Confusion.pdf" target="_blank" rel="noreferrer noopener">https://www.top10vpn.com/assets/2024/05/Top10VPN-x-Vanhoef-SSID-Confusion.pdf</a><br /> FIDO2 MitM Session Hijacking<br /><a href="https://www.silverfort.com/blog/using-mitm-to-bypass-fido2/?web_view=true#but-first-some-background" target="_blank" rel="noreferrer noopener">https://www.silverfort.com/blog/using-mitm-to-bypass-fido2/?web_view=true#but-first-some-background</a><br />]]></itunes:summary><itunes:duration>332</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,fido2; mitm; ssid; wifi; mfa;,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8984</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, May 15th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-may-15th-2024--62129412</link><description><![CDATA[Microsoft Patches<br /><a href="https://isc.sans.edu/diary/Microsoft%20May%202024%20Patch%20Tuesday/30920" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20May%202024%20Patch%20Tuesday/30920</a><br /> Detecting Bluetooth Trackers<br /><a href="https://security.googleblog.com/2024/05/google-and-apple-deliver-support-for.html" target="_blank" rel="noreferrer noopener">https://security.googleblog.com/2024/05/google-and-apple-deliver-support-for.html</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/products/acrobat/apsb24-29.html</a><br /> VMWare Updates<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24280" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24280</a><br /> Revoking Vulnerability Windows Boot Managers<br /><a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/revoking-vulnerable-windows-boot-managers/ba-p/4121735" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/windows-it-pro-blog/revoking-vulnerable-windows-boot-managers/ba-p/4121735</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8982.mp3</guid><pubDate>Wed, 15 May 2024 02:35:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129412/8982.mp3" length="6657544" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft Patches
https://isc.sans.edu/diary/Microsoft%20May%202024%20Patch%20Tuesday/30920
 Detecting Bluetooth Trackers
https://security.googleblog.com/2024/05/google-and-apple-deliver-support-for.html
 Adobe Patches...</itunes:subtitle><itunes:summary><![CDATA[Microsoft Patches<br /><a href="https://isc.sans.edu/diary/Microsoft%20May%202024%20Patch%20Tuesday/30920" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20May%202024%20Patch%20Tuesday/30920</a><br /> Detecting Bluetooth Trackers<br /><a href="https://security.googleblog.com/2024/05/google-and-apple-deliver-support-for.html" target="_blank" rel="noreferrer noopener">https://security.googleblog.com/2024/05/google-and-apple-deliver-support-for.html</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/products/acrobat/apsb24-29.html</a><br /> VMWare Updates<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24280" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24280</a><br /> Revoking Vulnerability Windows Boot Managers<br /><a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/revoking-vulnerable-windows-boot-managers/ba-p/4121735" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/windows-it-pro-blog/revoking-vulnerable-windows-boot-managers/ba-p/4121735</a><br />]]></itunes:summary><itunes:duration>454</itunes:duration><itunes:keywords>boot managers; windows; patche,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8982</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, May 15th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-may-15th-2024--60039587</link><description><![CDATA[Microsoft Patches<br /><a href="https://isc.sans.edu/diary/Microsoft%20May%202024%20Patch%20Tuesday/30920" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20May%202024%20Patch%20Tuesday/30920</a><br /> Detecting Bluetooth Trackers<br /><a href="https://security.googleblog.com/2024/05/google-and-apple-deliver-support-for.html" target="_blank" rel="noreferrer noopener">https://security.googleblog.com/2024/05/google-and-apple-deliver-support-for.html</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/products/acrobat/apsb24-29.html</a><br /> VMWare Updates<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24280" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24280</a><br /> Revoking Vulnerability Windows Boot Managers<br /><a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/revoking-vulnerable-windows-boot-managers/ba-p/4121735" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/windows-it-pro-blog/revoking-vulnerable-windows-boot-managers/ba-p/4121735</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8982.mp3</guid><pubDate>Wed, 15 May 2024 02:35:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60039587/8982.mp3" length="6657544" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft Patches
https://isc.sans.edu/diary/Microsoft%20May%202024%20Patch%20Tuesday/30920
 Detecting Bluetooth Trackers
https://security.googleblog.com/2024/05/google-and-apple-deliver-support-for.html
 Adobe Patches...</itunes:subtitle><itunes:summary><![CDATA[Microsoft Patches<br /><a href="https://isc.sans.edu/diary/Microsoft%20May%202024%20Patch%20Tuesday/30920" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20May%202024%20Patch%20Tuesday/30920</a><br /> Detecting Bluetooth Trackers<br /><a href="https://security.googleblog.com/2024/05/google-and-apple-deliver-support-for.html" target="_blank" rel="noreferrer noopener">https://security.googleblog.com/2024/05/google-and-apple-deliver-support-for.html</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/products/acrobat/apsb24-29.html</a><br /> VMWare Updates<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24280" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24280</a><br /> Revoking Vulnerability Windows Boot Managers<br /><a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/revoking-vulnerable-windows-boot-managers/ba-p/4121735" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/windows-it-pro-blog/revoking-vulnerable-windows-boot-managers/ba-p/4121735</a><br />]]></itunes:summary><itunes:duration>454</itunes:duration><itunes:keywords>boot managers; windows; patche,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8982</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, May 14th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-may-14th-2024--62129423</link><description><![CDATA[Apple Updates Everything<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20macOS%2C%20iOS%2C%20iPadOS%2C%20watchOS%2C%20tvOS%20updated./30916" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20macOS%2C%20iOS%2C%20iPadOS%2C%20watchOS%2C%20tvOS%20updated./30916</a><br /> Juniper OpenSSH Update<br /><a href="https://supportportal.juniper.net/s/article/2024-05-Reference-Advisory-Junos-OS-and-Junos-OS-Evolved-Multiple-CVEs-reported-in-OpenSSH?language=en_US" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/article/2024-05-Reference-Advisory-Junos-OS-and-Junos-OS-Evolved-Multiple-CVEs-reported-in-OpenSSH?language=en_US</a><br /> Malicious Go Binary Delivered via Steganography in PyPi<br /><a href="https://blog.phylum.io/malicious-go-binary-delivered-via-steganography-in-pypi/" target="_blank" rel="noreferrer noopener">https://blog.phylum.io/malicious-go-binary-delivered-via-steganography-in-pypi/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8980.mp3</guid><pubDate>Tue, 14 May 2024 02:35:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129423/8980.mp3" length="5570226" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Apple Updates Everything
https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20macOS%2C%20iOS%2C%20iPadOS%2C%20watchOS%2C%20tvOS%20updated./30916
 Juniper OpenSSH Update...</itunes:subtitle><itunes:summary><![CDATA[Apple Updates Everything<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20macOS%2C%20iOS%2C%20iPadOS%2C%20watchOS%2C%20tvOS%20updated./30916" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20macOS%2C%20iOS%2C%20iPadOS%2C%20watchOS%2C%20tvOS%20updated./30916</a><br /> Juniper OpenSSH Update<br /><a href="https://supportportal.juniper.net/s/article/2024-05-Reference-Advisory-Junos-OS-and-Junos-OS-Evolved-Multiple-CVEs-reported-in-OpenSSH?language=en_US" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/article/2024-05-Reference-Advisory-Junos-OS-and-Junos-OS-Evolved-Multiple-CVEs-reported-in-OpenSSH?language=en_US</a><br /> Malicious Go Binary Delivered via Steganography in PyPi<br /><a href="https://blog.phylum.io/malicious-go-binary-delivered-via-steganography-in-pypi/" target="_blank" rel="noreferrer noopener">https://blog.phylum.io/malicious-go-binary-delivered-via-steganography-in-pypi/</a><br />]]></itunes:summary><itunes:duration>376</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,go; pypi; openssh; apple,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8980</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, May 14th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-may-14th-2024--60016448</link><description><![CDATA[Apple Updates Everything<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20macOS%2C%20iOS%2C%20iPadOS%2C%20watchOS%2C%20tvOS%20updated./30916" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20macOS%2C%20iOS%2C%20iPadOS%2C%20watchOS%2C%20tvOS%20updated./30916</a><br /> Juniper OpenSSH Update<br /><a href="https://supportportal.juniper.net/s/article/2024-05-Reference-Advisory-Junos-OS-and-Junos-OS-Evolved-Multiple-CVEs-reported-in-OpenSSH?language=en_US" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/article/2024-05-Reference-Advisory-Junos-OS-and-Junos-OS-Evolved-Multiple-CVEs-reported-in-OpenSSH?language=en_US</a><br /> Malicious Go Binary Delivered via Steganography in PyPi<br /><a href="https://blog.phylum.io/malicious-go-binary-delivered-via-steganography-in-pypi/" target="_blank" rel="noreferrer noopener">https://blog.phylum.io/malicious-go-binary-delivered-via-steganography-in-pypi/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8980.mp3</guid><pubDate>Tue, 14 May 2024 02:35:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/60016448/8980.mp3" length="5570226" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Apple Updates Everything
https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20macOS%2C%20iOS%2C%20iPadOS%2C%20watchOS%2C%20tvOS%20updated./30916
 Juniper OpenSSH Update...</itunes:subtitle><itunes:summary><![CDATA[Apple Updates Everything<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20macOS%2C%20iOS%2C%20iPadOS%2C%20watchOS%2C%20tvOS%20updated./30916" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20macOS%2C%20iOS%2C%20iPadOS%2C%20watchOS%2C%20tvOS%20updated./30916</a><br /> Juniper OpenSSH Update<br /><a href="https://supportportal.juniper.net/s/article/2024-05-Reference-Advisory-Junos-OS-and-Junos-OS-Evolved-Multiple-CVEs-reported-in-OpenSSH?language=en_US" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/article/2024-05-Reference-Advisory-Junos-OS-and-Junos-OS-Evolved-Multiple-CVEs-reported-in-OpenSSH?language=en_US</a><br /> Malicious Go Binary Delivered via Steganography in PyPi<br /><a href="https://blog.phylum.io/malicious-go-binary-delivered-via-steganography-in-pypi/" target="_blank" rel="noreferrer noopener">https://blog.phylum.io/malicious-go-binary-delivered-via-steganography-in-pypi/</a><br />]]></itunes:summary><itunes:duration>376</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,go; pypi; openssh; apple,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8980</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, May 13th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-may-13th-2024--62129385</link><description><![CDATA[DNS Suffixes on Windows<br /><a href="https://isc.sans.edu/diary/DNS%20Suffixes%20on%20Windows/30912" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/DNS%20Suffixes%20on%20Windows/30912</a><br /> Black Basta Ransomware Advisory<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-131a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-131a</a><br /> Possible Exploitation of Arcserve Unified Data Protection Vuln<br /><a href="https://digital.nhs.uk/cyber-alerts/2024/cc-4487" target="_blank" rel="noreferrer noopener">https://digital.nhs.uk/cyber-alerts/2024/cc-4487</a><br /> Chrome Patches 0-Day<br /><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_9.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_9.html</a><br /> Solarwinds ARM Vulnerablities<br /><a href="https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-4_release_notes.htm" target="_blank" rel="noreferrer noopener">https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-4_release_notes.htm</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8978.mp3</guid><pubDate>Mon, 13 May 2024 03:00:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129385/8978.mp3" length="5006340" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>DNS Suffixes on Windows
https://isc.sans.edu/diary/DNS%20Suffixes%20on%20Windows/30912
 Black Basta Ransomware Advisory
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-131a
 Possible Exploitation of Arcserve Unified Data Protection Vuln...</itunes:subtitle><itunes:summary><![CDATA[DNS Suffixes on Windows<br /><a href="https://isc.sans.edu/diary/DNS%20Suffixes%20on%20Windows/30912" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/DNS%20Suffixes%20on%20Windows/30912</a><br /> Black Basta Ransomware Advisory<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-131a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-131a</a><br /> Possible Exploitation of Arcserve Unified Data Protection Vuln<br /><a href="https://digital.nhs.uk/cyber-alerts/2024/cc-4487" target="_blank" rel="noreferrer noopener">https://digital.nhs.uk/cyber-alerts/2024/cc-4487</a><br /> Chrome Patches 0-Day<br /><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_9.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_9.html</a><br /> Solarwinds ARM Vulnerablities<br /><a href="https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-4_release_notes.htm" target="_blank" rel="noreferrer noopener">https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-4_release_notes.htm</a><br />]]></itunes:summary><itunes:duration>336</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dns; suffix; windows; black ba,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8978</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, May 13th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-may-13th-2024--59998459</link><description><![CDATA[DNS Suffixes on Windows<br /><a href="https://isc.sans.edu/diary/DNS%20Suffixes%20on%20Windows/30912" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/DNS%20Suffixes%20on%20Windows/30912</a><br /> Black Basta Ransomware Advisory<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-131a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-131a</a><br /> Possible Exploitation of Arcserve Unified Data Protection Vuln<br /><a href="https://digital.nhs.uk/cyber-alerts/2024/cc-4487" target="_blank" rel="noreferrer noopener">https://digital.nhs.uk/cyber-alerts/2024/cc-4487</a><br /> Chrome Patches 0-Day<br /><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_9.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_9.html</a><br /> Solarwinds ARM Vulnerablities<br /><a href="https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-4_release_notes.htm" target="_blank" rel="noreferrer noopener">https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-4_release_notes.htm</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8978.mp3</guid><pubDate>Mon, 13 May 2024 03:00:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59998459/8978.mp3" length="5006340" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>DNS Suffixes on Windows
https://isc.sans.edu/diary/DNS%20Suffixes%20on%20Windows/30912
 Black Basta Ransomware Advisory
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-131a
 Possible Exploitation of Arcserve Unified Data Protection Vuln...</itunes:subtitle><itunes:summary><![CDATA[DNS Suffixes on Windows<br /><a href="https://isc.sans.edu/diary/DNS%20Suffixes%20on%20Windows/30912" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/DNS%20Suffixes%20on%20Windows/30912</a><br /> Black Basta Ransomware Advisory<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-131a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-131a</a><br /> Possible Exploitation of Arcserve Unified Data Protection Vuln<br /><a href="https://digital.nhs.uk/cyber-alerts/2024/cc-4487" target="_blank" rel="noreferrer noopener">https://digital.nhs.uk/cyber-alerts/2024/cc-4487</a><br /> Chrome Patches 0-Day<br /><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_9.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_9.html</a><br /> Solarwinds ARM Vulnerablities<br /><a href="https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-4_release_notes.htm" target="_blank" rel="noreferrer noopener">https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-4_release_notes.htm</a><br />]]></itunes:summary><itunes:duration>336</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dns; suffix; windows; black ba,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8978</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, May 10th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-may-10th-2024--62129379</link><description><![CDATA[Analyzing PDF Streams<br /><a href="https://isc.sans.edu/diary/Analyzing%20PDF%20Streams/30908" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analyzing%20PDF%20Streams/30908</a><br /> F5 Next Central Manager Vulnerabilities<br /><a href="https://eclypsium.com/blog/big-vulnerabilities-in-next-gen-big-ip/" target="_blank" rel="noreferrer noopener">https://eclypsium.com/blog/big-vulnerabilities-in-next-gen-big-ip/</a><br /> Veeam Patches<br /><a href="https://www.veeam.com/kb4441" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4441</a><br /><a href="https://www.veeam.com/kb4509" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4509</a><br /> Citrix Hypervisor Security Update CVE-2024-31497<br /><a href="https://support.citrix.com/article/CTX633416/citrix-hypervisor-security-update-for-cve202431497" target="_blank" rel="noreferrer noopener">https://support.citrix.com/article/CTX633416/citrix-hypervisor-security-update-for-cve202431497</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8976.mp3</guid><pubDate>Fri, 10 May 2024 03:05:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129379/8976.mp3" length="5255608" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Analyzing PDF Streams
https://isc.sans.edu/diary/Analyzing%20PDF%20Streams/30908
 F5 Next Central Manager Vulnerabilities
https://eclypsium.com/blog/big-vulnerabilities-in-next-gen-big-ip/
 Veeam Patches
https://www.veeam.com/kb4441...</itunes:subtitle><itunes:summary><![CDATA[Analyzing PDF Streams<br /><a href="https://isc.sans.edu/diary/Analyzing%20PDF%20Streams/30908" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analyzing%20PDF%20Streams/30908</a><br /> F5 Next Central Manager Vulnerabilities<br /><a href="https://eclypsium.com/blog/big-vulnerabilities-in-next-gen-big-ip/" target="_blank" rel="noreferrer noopener">https://eclypsium.com/blog/big-vulnerabilities-in-next-gen-big-ip/</a><br /> Veeam Patches<br /><a href="https://www.veeam.com/kb4441" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4441</a><br /><a href="https://www.veeam.com/kb4509" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4509</a><br /> Citrix Hypervisor Security Update CVE-2024-31497<br /><a href="https://support.citrix.com/article/CTX633416/citrix-hypervisor-security-update-for-cve202431497" target="_blank" rel="noreferrer noopener">https://support.citrix.com/article/CTX633416/citrix-hypervisor-security-update-for-cve202431497</a><br />]]></itunes:summary><itunes:duration>354</itunes:duration><itunes:keywords>business,citrix; hypervisor; veeam; f5;,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8976</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, May 10th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-may-10th-2024--59958554</link><description><![CDATA[Analyzing PDF Streams<br /><a href="https://isc.sans.edu/diary/Analyzing%20PDF%20Streams/30908" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analyzing%20PDF%20Streams/30908</a><br /> F5 Next Central Manager Vulnerabilities<br /><a href="https://eclypsium.com/blog/big-vulnerabilities-in-next-gen-big-ip/" target="_blank" rel="noreferrer noopener">https://eclypsium.com/blog/big-vulnerabilities-in-next-gen-big-ip/</a><br /> Veeam Patches<br /><a href="https://www.veeam.com/kb4441" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4441</a><br /><a href="https://www.veeam.com/kb4509" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4509</a><br /> Citrix Hypervisor Security Update CVE-2024-31497<br /><a href="https://support.citrix.com/article/CTX633416/citrix-hypervisor-security-update-for-cve202431497" target="_blank" rel="noreferrer noopener">https://support.citrix.com/article/CTX633416/citrix-hypervisor-security-update-for-cve202431497</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8976.mp3</guid><pubDate>Fri, 10 May 2024 03:05:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59958554/8976.mp3" length="5255608" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Analyzing PDF Streams
https://isc.sans.edu/diary/Analyzing%20PDF%20Streams/30908
 F5 Next Central Manager Vulnerabilities
https://eclypsium.com/blog/big-vulnerabilities-in-next-gen-big-ip/
 Veeam Patches
https://www.veeam.com/kb4441...</itunes:subtitle><itunes:summary><![CDATA[Analyzing PDF Streams<br /><a href="https://isc.sans.edu/diary/Analyzing%20PDF%20Streams/30908" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analyzing%20PDF%20Streams/30908</a><br /> F5 Next Central Manager Vulnerabilities<br /><a href="https://eclypsium.com/blog/big-vulnerabilities-in-next-gen-big-ip/" target="_blank" rel="noreferrer noopener">https://eclypsium.com/blog/big-vulnerabilities-in-next-gen-big-ip/</a><br /> Veeam Patches<br /><a href="https://www.veeam.com/kb4441" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4441</a><br /><a href="https://www.veeam.com/kb4509" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4509</a><br /> Citrix Hypervisor Security Update CVE-2024-31497<br /><a href="https://support.citrix.com/article/CTX633416/citrix-hypervisor-security-update-for-cve202431497" target="_blank" rel="noreferrer noopener">https://support.citrix.com/article/CTX633416/citrix-hypervisor-security-update-for-cve202431497</a><br />]]></itunes:summary><itunes:duration>354</itunes:duration><itunes:keywords>business,citrix; hypervisor; veeam; f5;,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8976</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, May 9th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-may-9th-2024--62129389</link><description><![CDATA[Analzying Synology Disks<br /><a href="https://isc.sans.edu/diary/Analyzing%20Synology%20Disks%20on%20Linux/30904" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analyzing%20Synology%20Disks%20on%20Linux/30904</a><br /> RSA Panel<br /><a href="https://www.rsaconference.com/usa/agenda/session/The%20Five%20Most%20Dangerous%20New%20Attack%20Techniques%20You%20Need%20to%20Know%20About" target="_blank" rel="noreferrer noopener">https://www.rsaconference.com/usa/agenda/session/The%20Five%20Most%20Dangerous%20New%20Attack%20Techniques%20You%20Need%20to%20Know%20About</a><br /> SANS.edu Research Journal<br /><a href="https://www.sans.edu/cyber-security-research" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-security-research</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8974.mp3</guid><pubDate>Thu, 09 May 2024 04:45:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129389/8974.mp3" length="5477992" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Analzying Synology Disks
https://isc.sans.edu/diary/Analyzing%20Synology%20Disks%20on%20Linux/30904
 RSA Panel
https://www.rsaconference.com/usa/agenda/session/The%20Five%20Most%20Dangerous%20New%20Attack%20Techniques%20You%20Need%20to%20Know%20About...</itunes:subtitle><itunes:summary><![CDATA[Analzying Synology Disks<br /><a href="https://isc.sans.edu/diary/Analyzing%20Synology%20Disks%20on%20Linux/30904" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analyzing%20Synology%20Disks%20on%20Linux/30904</a><br /> RSA Panel<br /><a href="https://www.rsaconference.com/usa/agenda/session/The%20Five%20Most%20Dangerous%20New%20Attack%20Techniques%20You%20Need%20to%20Know%20About" target="_blank" rel="noreferrer noopener">https://www.rsaconference.com/usa/agenda/session/The%20Five%20Most%20Dangerous%20New%20Attack%20Techniques%20You%20Need%20to%20Know%20About</a><br /> SANS.edu Research Journal<br /><a href="https://www.sans.edu/cyber-security-research" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-security-research</a><br />]]></itunes:summary><itunes:duration>370</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,sans.edu; research; journal; r,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8974</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, May 9th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-may-9th-2024--59938141</link><description><![CDATA[Analzying Synology Disks<br /><a href="https://isc.sans.edu/diary/Analyzing%20Synology%20Disks%20on%20Linux/30904" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analyzing%20Synology%20Disks%20on%20Linux/30904</a><br /> RSA Panel<br /><a href="https://www.rsaconference.com/usa/agenda/session/The%20Five%20Most%20Dangerous%20New%20Attack%20Techniques%20You%20Need%20to%20Know%20About" target="_blank" rel="noreferrer noopener">https://www.rsaconference.com/usa/agenda/session/The%20Five%20Most%20Dangerous%20New%20Attack%20Techniques%20You%20Need%20to%20Know%20About</a><br /> SANS.edu Research Journal<br /><a href="https://www.sans.edu/cyber-security-research" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-security-research</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8974.mp3</guid><pubDate>Thu, 09 May 2024 04:45:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59938141/8974.mp3" length="5477992" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Analzying Synology Disks
https://isc.sans.edu/diary/Analyzing%20Synology%20Disks%20on%20Linux/30904
 RSA Panel
https://www.rsaconference.com/usa/agenda/session/The%20Five%20Most%20Dangerous%20New%20Attack%20Techniques%20You%20Need%20to%20Know%20About...</itunes:subtitle><itunes:summary><![CDATA[Analzying Synology Disks<br /><a href="https://isc.sans.edu/diary/Analyzing%20Synology%20Disks%20on%20Linux/30904" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analyzing%20Synology%20Disks%20on%20Linux/30904</a><br /> RSA Panel<br /><a href="https://www.rsaconference.com/usa/agenda/session/The%20Five%20Most%20Dangerous%20New%20Attack%20Techniques%20You%20Need%20to%20Know%20About" target="_blank" rel="noreferrer noopener">https://www.rsaconference.com/usa/agenda/session/The%20Five%20Most%20Dangerous%20New%20Attack%20Techniques%20You%20Need%20to%20Know%20About</a><br /> SANS.edu Research Journal<br /><a href="https://www.sans.edu/cyber-security-research" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-security-research</a><br />]]></itunes:summary><itunes:duration>370</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,sans.edu; research; journal; r,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8974</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, May 8th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-may-8th-2024--62129368</link><description><![CDATA[Detecting XFinity/Comcast DNS Spoofing<br /><a href="https://isc.sans.edu/diary/Detecting%20XFinity%20Comcast%20DNS%20Spoofing/30898" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Detecting%20XFinity%20Comcast%20DNS%20Spoofing/30898</a><br /> Weblogic PoC CVE-2024-21006<br /><a href="https://pwnull.github.io/2024/oracle%20weblogic%20CVE-2024-21006%20Double-JNDInjection%20RCE%20analyze/" target="_blank" rel="noreferrer noopener">https://pwnull.github.io/2024/oracle%20weblogic%20CVE-2024-21006%20Double-JNDInjection%20RCE%20analyze/</a><br /><a href="https://github.com/momika233/CVE-2024-21006" target="_blank" rel="noreferrer noopener">https://github.com/momika233/CVE-2024-21006</a><br /> PDF.js React PDF Vulnerablity<br /><a href="https://securityonline.info/cve-2024-4367-cve-2024-34342-javascript-flaw-threatens-millions-of-pdf-js-and-react-pdf-users/" target="_blank" rel="noreferrer noopener">https://securityonline.info/cve-2024-4367-cve-2024-34342-javascript-flaw-threatens-millions-of-pdf-js-and-react-pdf-users/</a><br /> Tinyproxy Response <br /><a href="https://github.com/tinyproxy/tinyproxy/issues/533" target="_blank" rel="noreferrer noopener">https://github.com/tinyproxy/tinyproxy/issues/533</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8972.mp3</guid><pubDate>Wed, 08 May 2024 04:50:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129368/8972.mp3" length="7213077" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Detecting XFinity/Comcast DNS Spoofing
https://isc.sans.edu/diary/Detecting%20XFinity%20Comcast%20DNS%20Spoofing/30898
 Weblogic PoC CVE-2024-21006
https://pwnull.github.io/2024/oracle%20weblogic%20CVE-2024-21006%20Double-JNDInjection%20RCE%20analyze/...</itunes:subtitle><itunes:summary><![CDATA[Detecting XFinity/Comcast DNS Spoofing<br /><a href="https://isc.sans.edu/diary/Detecting%20XFinity%20Comcast%20DNS%20Spoofing/30898" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Detecting%20XFinity%20Comcast%20DNS%20Spoofing/30898</a><br /> Weblogic PoC CVE-2024-21006<br /><a href="https://pwnull.github.io/2024/oracle%20weblogic%20CVE-2024-21006%20Double-JNDInjection%20RCE%20analyze/" target="_blank" rel="noreferrer noopener">https://pwnull.github.io/2024/oracle%20weblogic%20CVE-2024-21006%20Double-JNDInjection%20RCE%20analyze/</a><br /><a href="https://github.com/momika233/CVE-2024-21006" target="_blank" rel="noreferrer noopener">https://github.com/momika233/CVE-2024-21006</a><br /> PDF.js React PDF Vulnerablity<br /><a href="https://securityonline.info/cve-2024-4367-cve-2024-34342-javascript-flaw-threatens-millions-of-pdf-js-and-react-pdf-users/" target="_blank" rel="noreferrer noopener">https://securityonline.info/cve-2024-4367-cve-2024-34342-javascript-flaw-threatens-millions-of-pdf-js-and-react-pdf-users/</a><br /> Tinyproxy Response <br /><a href="https://github.com/tinyproxy/tinyproxy/issues/533" target="_blank" rel="noreferrer noopener">https://github.com/tinyproxy/tinyproxy/issues/533</a><br />]]></itunes:summary><itunes:duration>494</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,tinyproxy; pdf.js; react; pdf;</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8972</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, May 8th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-may-8th-2024--59913848</link><description><![CDATA[Detecting XFinity/Comcast DNS Spoofing<br /><a href="https://isc.sans.edu/diary/Detecting%20XFinity%20Comcast%20DNS%20Spoofing/30898" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Detecting%20XFinity%20Comcast%20DNS%20Spoofing/30898</a><br /> Weblogic PoC CVE-2024-21006<br /><a href="https://pwnull.github.io/2024/oracle%20weblogic%20CVE-2024-21006%20Double-JNDInjection%20RCE%20analyze/" target="_blank" rel="noreferrer noopener">https://pwnull.github.io/2024/oracle%20weblogic%20CVE-2024-21006%20Double-JNDInjection%20RCE%20analyze/</a><br /><a href="https://github.com/momika233/CVE-2024-21006" target="_blank" rel="noreferrer noopener">https://github.com/momika233/CVE-2024-21006</a><br /> PDF.js React PDF Vulnerablity<br /><a href="https://securityonline.info/cve-2024-4367-cve-2024-34342-javascript-flaw-threatens-millions-of-pdf-js-and-react-pdf-users/" target="_blank" rel="noreferrer noopener">https://securityonline.info/cve-2024-4367-cve-2024-34342-javascript-flaw-threatens-millions-of-pdf-js-and-react-pdf-users/</a><br /> Tinyproxy Response <br /><a href="https://github.com/tinyproxy/tinyproxy/issues/533" target="_blank" rel="noreferrer noopener">https://github.com/tinyproxy/tinyproxy/issues/533</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8972.mp3</guid><pubDate>Wed, 08 May 2024 04:50:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59913848/8972.mp3" length="7213077" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Detecting XFinity/Comcast DNS Spoofing
https://isc.sans.edu/diary/Detecting%20XFinity%20Comcast%20DNS%20Spoofing/30898
 Weblogic PoC CVE-2024-21006
https://pwnull.github.io/2024/oracle%20weblogic%20CVE-2024-21006%20Double-JNDInjection%20RCE%20analyze/...</itunes:subtitle><itunes:summary><![CDATA[Detecting XFinity/Comcast DNS Spoofing<br /><a href="https://isc.sans.edu/diary/Detecting%20XFinity%20Comcast%20DNS%20Spoofing/30898" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Detecting%20XFinity%20Comcast%20DNS%20Spoofing/30898</a><br /> Weblogic PoC CVE-2024-21006<br /><a href="https://pwnull.github.io/2024/oracle%20weblogic%20CVE-2024-21006%20Double-JNDInjection%20RCE%20analyze/" target="_blank" rel="noreferrer noopener">https://pwnull.github.io/2024/oracle%20weblogic%20CVE-2024-21006%20Double-JNDInjection%20RCE%20analyze/</a><br /><a href="https://github.com/momika233/CVE-2024-21006" target="_blank" rel="noreferrer noopener">https://github.com/momika233/CVE-2024-21006</a><br /> PDF.js React PDF Vulnerablity<br /><a href="https://securityonline.info/cve-2024-4367-cve-2024-34342-javascript-flaw-threatens-millions-of-pdf-js-and-react-pdf-users/" target="_blank" rel="noreferrer noopener">https://securityonline.info/cve-2024-4367-cve-2024-34342-javascript-flaw-threatens-millions-of-pdf-js-and-react-pdf-users/</a><br /> Tinyproxy Response <br /><a href="https://github.com/tinyproxy/tinyproxy/issues/533" target="_blank" rel="noreferrer noopener">https://github.com/tinyproxy/tinyproxy/issues/533</a><br />]]></itunes:summary><itunes:duration>494</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,tinyproxy; pdf.js; react; pdf;</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8972</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, May 7th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-may-7th-2024--62129377</link><description><![CDATA[DHCP Based VPN Routing Leaks<br /><a href="https://www.leviathansecurity.com/blog/tunnelvision" target="_blank" rel="noreferrer noopener">https://www.leviathansecurity.com/blog/tunnelvision</a><br /> Mullvad VPN DNS Traffic Leak<br /><a href="https://mullvad.net/en/blog/dns-traffic-can-leak-outside-the-vpn-tunnel-on-android" target="_blank" rel="noreferrer noopener">https://mullvad.net/en/blog/dns-traffic-can-leak-outside-the-vpn-tunnel-on-android</a><br /> Tiny Proxy Vulnerability <br /><a href="https://talosintelligence.com/vulnerability_reports/TALOS-2023-1889" target="_blank" rel="noreferrer noopener">https://talosintelligence.com/vulnerability_reports/TALOS-2023-1889</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8970.mp3</guid><pubDate>Tue, 07 May 2024 05:30:06 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129377/8970.mp3" length="5729162" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>DHCP Based VPN Routing Leaks
https://www.leviathansecurity.com/blog/tunnelvision
 Mullvad VPN DNS Traffic Leak
https://mullvad.net/en/blog/dns-traffic-can-leak-outside-the-vpn-tunnel-on-android
 Tiny Proxy Vulnerability...</itunes:subtitle><itunes:summary><![CDATA[DHCP Based VPN Routing Leaks<br /><a href="https://www.leviathansecurity.com/blog/tunnelvision" target="_blank" rel="noreferrer noopener">https://www.leviathansecurity.com/blog/tunnelvision</a><br /> Mullvad VPN DNS Traffic Leak<br /><a href="https://mullvad.net/en/blog/dns-traffic-can-leak-outside-the-vpn-tunnel-on-android" target="_blank" rel="noreferrer noopener">https://mullvad.net/en/blog/dns-traffic-can-leak-outside-the-vpn-tunnel-on-android</a><br /> Tiny Proxy Vulnerability <br /><a href="https://talosintelligence.com/vulnerability_reports/TALOS-2023-1889" target="_blank" rel="noreferrer noopener">https://talosintelligence.com/vulnerability_reports/TALOS-2023-1889</a><br />]]></itunes:summary><itunes:duration>388</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,tiny proxy; vpn; mullvad; tunn</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8970</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, May 7th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-may-7th-2024--59891881</link><description><![CDATA[DHCP Based VPN Routing Leaks<br /><a href="https://www.leviathansecurity.com/blog/tunnelvision" target="_blank" rel="noreferrer noopener">https://www.leviathansecurity.com/blog/tunnelvision</a><br /> Mullvad VPN DNS Traffic Leak<br /><a href="https://mullvad.net/en/blog/dns-traffic-can-leak-outside-the-vpn-tunnel-on-android" target="_blank" rel="noreferrer noopener">https://mullvad.net/en/blog/dns-traffic-can-leak-outside-the-vpn-tunnel-on-android</a><br /> Tiny Proxy Vulnerability <br /><a href="https://talosintelligence.com/vulnerability_reports/TALOS-2023-1889" target="_blank" rel="noreferrer noopener">https://talosintelligence.com/vulnerability_reports/TALOS-2023-1889</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8970.mp3</guid><pubDate>Tue, 07 May 2024 05:30:06 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59891881/8970.mp3" length="5729162" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>DHCP Based VPN Routing Leaks
https://www.leviathansecurity.com/blog/tunnelvision
 Mullvad VPN DNS Traffic Leak
https://mullvad.net/en/blog/dns-traffic-can-leak-outside-the-vpn-tunnel-on-android
 Tiny Proxy Vulnerability...</itunes:subtitle><itunes:summary><![CDATA[DHCP Based VPN Routing Leaks<br /><a href="https://www.leviathansecurity.com/blog/tunnelvision" target="_blank" rel="noreferrer noopener">https://www.leviathansecurity.com/blog/tunnelvision</a><br /> Mullvad VPN DNS Traffic Leak<br /><a href="https://mullvad.net/en/blog/dns-traffic-can-leak-outside-the-vpn-tunnel-on-android" target="_blank" rel="noreferrer noopener">https://mullvad.net/en/blog/dns-traffic-can-leak-outside-the-vpn-tunnel-on-android</a><br /> Tiny Proxy Vulnerability <br /><a href="https://talosintelligence.com/vulnerability_reports/TALOS-2023-1889" target="_blank" rel="noreferrer noopener">https://talosintelligence.com/vulnerability_reports/TALOS-2023-1889</a><br />]]></itunes:summary><itunes:duration>388</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,tiny proxy; vpn; mullvad; tunn</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8970</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, May 6th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-may-6th-2024--62129397</link><description><![CDATA[DNS Debugging with nslookup<br /><a href="https://isc.sans.edu/diary/nslookups+Debug+Options/30894/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/nslookups+Debug+Options/30894/</a><br /> Microsoft Plans DNS Lockdown<br /><a href="https://techcommunity.microsoft.com/t5/networking-blog/announcing-zero-trust-dns-private-preview/ba-p/4110366" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/networking-blog/announcing-zero-trust-dns-private-preview/ba-p/4110366</a><br /> Microsoft Graph API Abuse<br /><a href="https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/graph-api-threats" target="_blank" rel="noreferrer noopener">https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/graph-api-threats</a><br /> SANSFIRE SEC522 Defending Web Applications<br /><a href="https://www.sans.org/cyber-security-training-events/sansfire-2024/" target="_blank" rel="noreferrer noopener">https://www.sans.org/cyber-security-training-events/sansfire-2024/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8968.mp3</guid><pubDate>Mon, 06 May 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129397/8968.mp3" length="4958836" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>DNS Debugging with nslookup
https://isc.sans.edu/diary/nslookups+Debug+Options/30894/
 Microsoft Plans DNS Lockdown
https://techcommunity.microsoft.com/t5/networking-blog/announcing-zero-trust-dns-private-preview/ba-p/4110366
 Microsoft Graph API...</itunes:subtitle><itunes:summary><![CDATA[DNS Debugging with nslookup<br /><a href="https://isc.sans.edu/diary/nslookups+Debug+Options/30894/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/nslookups+Debug+Options/30894/</a><br /> Microsoft Plans DNS Lockdown<br /><a href="https://techcommunity.microsoft.com/t5/networking-blog/announcing-zero-trust-dns-private-preview/ba-p/4110366" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/networking-blog/announcing-zero-trust-dns-private-preview/ba-p/4110366</a><br /> Microsoft Graph API Abuse<br /><a href="https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/graph-api-threats" target="_blank" rel="noreferrer noopener">https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/graph-api-threats</a><br /> SANSFIRE SEC522 Defending Web Applications<br /><a href="https://www.sans.org/cyber-security-training-events/sansfire-2024/" target="_blank" rel="noreferrer noopener">https://www.sans.org/cyber-security-training-events/sansfire-2024/</a><br />]]></itunes:summary><itunes:duration>333</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microsoft; graph; api; dns; ze,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8968</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, May 6th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-may-6th-2024--59864815</link><description><![CDATA[DNS Debugging with nslookup<br /><a href="https://isc.sans.edu/diary/nslookups+Debug+Options/30894/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/nslookups+Debug+Options/30894/</a><br /> Microsoft Plans DNS Lockdown<br /><a href="https://techcommunity.microsoft.com/t5/networking-blog/announcing-zero-trust-dns-private-preview/ba-p/4110366" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/networking-blog/announcing-zero-trust-dns-private-preview/ba-p/4110366</a><br /> Microsoft Graph API Abuse<br /><a href="https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/graph-api-threats" target="_blank" rel="noreferrer noopener">https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/graph-api-threats</a><br /> SANSFIRE SEC522 Defending Web Applications<br /><a href="https://www.sans.org/cyber-security-training-events/sansfire-2024/" target="_blank" rel="noreferrer noopener">https://www.sans.org/cyber-security-training-events/sansfire-2024/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8968.mp3</guid><pubDate>Mon, 06 May 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59864815/8968.mp3" length="4958836" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>DNS Debugging with nslookup
https://isc.sans.edu/diary/nslookups+Debug+Options/30894/
 Microsoft Plans DNS Lockdown
https://techcommunity.microsoft.com/t5/networking-blog/announcing-zero-trust-dns-private-preview/ba-p/4110366
 Microsoft Graph API...</itunes:subtitle><itunes:summary><![CDATA[DNS Debugging with nslookup<br /><a href="https://isc.sans.edu/diary/nslookups+Debug+Options/30894/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/nslookups+Debug+Options/30894/</a><br /> Microsoft Plans DNS Lockdown<br /><a href="https://techcommunity.microsoft.com/t5/networking-blog/announcing-zero-trust-dns-private-preview/ba-p/4110366" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/networking-blog/announcing-zero-trust-dns-private-preview/ba-p/4110366</a><br /> Microsoft Graph API Abuse<br /><a href="https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/graph-api-threats" target="_blank" rel="noreferrer noopener">https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/graph-api-threats</a><br /> SANSFIRE SEC522 Defending Web Applications<br /><a href="https://www.sans.org/cyber-security-training-events/sansfire-2024/" target="_blank" rel="noreferrer noopener">https://www.sans.org/cyber-security-training-events/sansfire-2024/</a><br />]]></itunes:summary><itunes:duration>333</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microsoft; graph; api; dns; ze,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8968</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, May 3rd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-may-3rd-2024--62129388</link><description><![CDATA[<a href="https://isc.sans.edu/diary/Scans%20Probing%20for%20LB-Link%20and%20Vinga%20WR-AC1200%20routers%20CVE-2023-24796/30890" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20Probing%20for%20LB-Link%20and%20Vinga%20WR-AC1200%20routers%20CVE-2023-24796/30890</a><br />  Scans Probing for LB-Link and Vinga WR-AC1200 routers CVE-2023-24796<br /> Buffer Overflow Vulnerabilities in ArubaOS<br /><a href="https://www.arubanetworks.com/support-services/security-bulletins/" target="_blank" rel="noreferrer noopener">https://www.arubanetworks.com/support-services/security-bulletins/</a><br /> The Cuttlefish Malware<br /><a href="https://blog.lumen.com/eight-arms-to-hold-you-the-cuttlefish-malware/" target="_blank" rel="noreferrer noopener">https://blog.lumen.com/eight-arms-to-hold-you-the-cuttlefish-malware/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8966.mp3</guid><pubDate>Fri, 03 May 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129388/8966.mp3" length="4975415" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>https://isc.sans.edu/diary/Scans%20Probing%20for%20LB-Link%20and%20Vinga%20WR-AC1200%20routers%20CVE-2023-24796/30890
  Scans Probing for LB-Link and Vinga WR-AC1200 routers CVE-2023-24796
 Buffer Overflow Vulnerabilities in ArubaOS...</itunes:subtitle><itunes:summary><![CDATA[<a href="https://isc.sans.edu/diary/Scans%20Probing%20for%20LB-Link%20and%20Vinga%20WR-AC1200%20routers%20CVE-2023-24796/30890" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20Probing%20for%20LB-Link%20and%20Vinga%20WR-AC1200%20routers%20CVE-2023-24796/30890</a><br />  Scans Probing for LB-Link and Vinga WR-AC1200 routers CVE-2023-24796<br /> Buffer Overflow Vulnerabilities in ArubaOS<br /><a href="https://www.arubanetworks.com/support-services/security-bulletins/" target="_blank" rel="noreferrer noopener">https://www.arubanetworks.com/support-services/security-bulletins/</a><br /> The Cuttlefish Malware<br /><a href="https://blog.lumen.com/eight-arms-to-hold-you-the-cuttlefish-malware/" target="_blank" rel="noreferrer noopener">https://blog.lumen.com/eight-arms-to-hold-you-the-cuttlefish-malware/</a><br />]]></itunes:summary><itunes:duration>334</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,routers; npm; cuddlefix; aruba,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8966</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, May 3rd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-may-3rd-2024--59790442</link><description><![CDATA[<a href="https://isc.sans.edu/diary/Scans%20Probing%20for%20LB-Link%20and%20Vinga%20WR-AC1200%20routers%20CVE-2023-24796/30890" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20Probing%20for%20LB-Link%20and%20Vinga%20WR-AC1200%20routers%20CVE-2023-24796/30890</a><br />  Scans Probing for LB-Link and Vinga WR-AC1200 routers CVE-2023-24796<br /> Buffer Overflow Vulnerabilities in ArubaOS<br /><a href="https://www.arubanetworks.com/support-services/security-bulletins/" target="_blank" rel="noreferrer noopener">https://www.arubanetworks.com/support-services/security-bulletins/</a><br /> The Cuttlefish Malware<br /><a href="https://blog.lumen.com/eight-arms-to-hold-you-the-cuttlefish-malware/" target="_blank" rel="noreferrer noopener">https://blog.lumen.com/eight-arms-to-hold-you-the-cuttlefish-malware/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8966.mp3</guid><pubDate>Fri, 03 May 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59790442/8966.mp3" length="4975415" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>https://isc.sans.edu/diary/Scans%20Probing%20for%20LB-Link%20and%20Vinga%20WR-AC1200%20routers%20CVE-2023-24796/30890
  Scans Probing for LB-Link and Vinga WR-AC1200 routers CVE-2023-24796
 Buffer Overflow Vulnerabilities in ArubaOS...</itunes:subtitle><itunes:summary><![CDATA[<a href="https://isc.sans.edu/diary/Scans%20Probing%20for%20LB-Link%20and%20Vinga%20WR-AC1200%20routers%20CVE-2023-24796/30890" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20Probing%20for%20LB-Link%20and%20Vinga%20WR-AC1200%20routers%20CVE-2023-24796/30890</a><br />  Scans Probing for LB-Link and Vinga WR-AC1200 routers CVE-2023-24796<br /> Buffer Overflow Vulnerabilities in ArubaOS<br /><a href="https://www.arubanetworks.com/support-services/security-bulletins/" target="_blank" rel="noreferrer noopener">https://www.arubanetworks.com/support-services/security-bulletins/</a><br /> The Cuttlefish Malware<br /><a href="https://blog.lumen.com/eight-arms-to-hold-you-the-cuttlefish-malware/" target="_blank" rel="noreferrer noopener">https://blog.lumen.com/eight-arms-to-hold-you-the-cuttlefish-malware/</a><br />]]></itunes:summary><itunes:duration>334</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,routers; npm; cuddlefix; aruba,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8966</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, May 2nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-may-2nd-2024--62129403</link><description><![CDATA[Linux Trojan - Xorddos with Filename eyshcjdmzg<br /><a href="https://isc.sans.edu/diary/Linux%20Trojan%20-%20Xorddos%20with%20Filename%20eyshcjdmzg/30880" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Linux%20Trojan%20-%20Xorddos%20with%20Filename%20eyshcjdmzg/30880</a><br /> AWS S3 Denial of Wallet Amplification Attack<br /><a href="https://medium.com/@maciej.pocwierz/how-an-empty-s3-bucket-can-make-your-aws-bill-explode-934a383cb8b1" target="_blank" rel="noreferrer noopener">https://medium.com/@maciej.pocwierz/how-an-empty-s3-bucket-can-make-your-aws-bill-explode-934a383cb8b1</a><br /><a href="https://blog.limbus-medtec.com/the-aws-s3-denial-of-wallet-amplification-attack-bc5a97cc041d" target="_blank" rel="noreferrer noopener">https://blog.limbus-medtec.com/the-aws-s3-denial-of-wallet-amplification-attack-bc5a97cc041d</a><br /> EU iOS Safari Allows User Tracking<br /><a href="https://www.mysk.blog/2024/04/28/safari-tracking/" target="_blank" rel="noreferrer noopener">https://www.mysk.blog/2024/04/28/safari-tracking/</a><br /> BentoML Critical Deserialization Vuln CVE-2024-2912<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2912" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2024-2912</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8964.mp3</guid><pubDate>Thu, 02 May 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129403/8964.mp3" length="6060626" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Linux Trojan - Xorddos with Filename eyshcjdmzg
https://isc.sans.edu/diary/Linux%20Trojan%20-%20Xorddos%20with%20Filename%20eyshcjdmzg/30880
 AWS S3 Denial of Wallet Amplification Attack...</itunes:subtitle><itunes:summary><![CDATA[Linux Trojan - Xorddos with Filename eyshcjdmzg<br /><a href="https://isc.sans.edu/diary/Linux%20Trojan%20-%20Xorddos%20with%20Filename%20eyshcjdmzg/30880" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Linux%20Trojan%20-%20Xorddos%20with%20Filename%20eyshcjdmzg/30880</a><br /> AWS S3 Denial of Wallet Amplification Attack<br /><a href="https://medium.com/@maciej.pocwierz/how-an-empty-s3-bucket-can-make-your-aws-bill-explode-934a383cb8b1" target="_blank" rel="noreferrer noopener">https://medium.com/@maciej.pocwierz/how-an-empty-s3-bucket-can-make-your-aws-bill-explode-934a383cb8b1</a><br /><a href="https://blog.limbus-medtec.com/the-aws-s3-denial-of-wallet-amplification-attack-bc5a97cc041d" target="_blank" rel="noreferrer noopener">https://blog.limbus-medtec.com/the-aws-s3-denial-of-wallet-amplification-attack-bc5a97cc041d</a><br /> EU iOS Safari Allows User Tracking<br /><a href="https://www.mysk.blog/2024/04/28/safari-tracking/" target="_blank" rel="noreferrer noopener">https://www.mysk.blog/2024/04/28/safari-tracking/</a><br /> BentoML Critical Deserialization Vuln CVE-2024-2912<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2912" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2024-2912</a><br />]]></itunes:summary><itunes:duration>411</itunes:duration><itunes:keywords>bentoml; ios; safari; tracking,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8964</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, May 2nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-may-2nd-2024--59761277</link><description><![CDATA[Linux Trojan - Xorddos with Filename eyshcjdmzg<br /><a href="https://isc.sans.edu/diary/Linux%20Trojan%20-%20Xorddos%20with%20Filename%20eyshcjdmzg/30880" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Linux%20Trojan%20-%20Xorddos%20with%20Filename%20eyshcjdmzg/30880</a><br /> AWS S3 Denial of Wallet Amplification Attack<br /><a href="https://medium.com/@maciej.pocwierz/how-an-empty-s3-bucket-can-make-your-aws-bill-explode-934a383cb8b1" target="_blank" rel="noreferrer noopener">https://medium.com/@maciej.pocwierz/how-an-empty-s3-bucket-can-make-your-aws-bill-explode-934a383cb8b1</a><br /><a href="https://blog.limbus-medtec.com/the-aws-s3-denial-of-wallet-amplification-attack-bc5a97cc041d" target="_blank" rel="noreferrer noopener">https://blog.limbus-medtec.com/the-aws-s3-denial-of-wallet-amplification-attack-bc5a97cc041d</a><br /> EU iOS Safari Allows User Tracking<br /><a href="https://www.mysk.blog/2024/04/28/safari-tracking/" target="_blank" rel="noreferrer noopener">https://www.mysk.blog/2024/04/28/safari-tracking/</a><br /> BentoML Critical Deserialization Vuln CVE-2024-2912<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2912" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2024-2912</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8964.mp3</guid><pubDate>Thu, 02 May 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59761277/8964.mp3" length="6060626" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Linux Trojan - Xorddos with Filename eyshcjdmzg
https://isc.sans.edu/diary/Linux%20Trojan%20-%20Xorddos%20with%20Filename%20eyshcjdmzg/30880
 AWS S3 Denial of Wallet Amplification Attack...</itunes:subtitle><itunes:summary><![CDATA[Linux Trojan - Xorddos with Filename eyshcjdmzg<br /><a href="https://isc.sans.edu/diary/Linux%20Trojan%20-%20Xorddos%20with%20Filename%20eyshcjdmzg/30880" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Linux%20Trojan%20-%20Xorddos%20with%20Filename%20eyshcjdmzg/30880</a><br /> AWS S3 Denial of Wallet Amplification Attack<br /><a href="https://medium.com/@maciej.pocwierz/how-an-empty-s3-bucket-can-make-your-aws-bill-explode-934a383cb8b1" target="_blank" rel="noreferrer noopener">https://medium.com/@maciej.pocwierz/how-an-empty-s3-bucket-can-make-your-aws-bill-explode-934a383cb8b1</a><br /><a href="https://blog.limbus-medtec.com/the-aws-s3-denial-of-wallet-amplification-attack-bc5a97cc041d" target="_blank" rel="noreferrer noopener">https://blog.limbus-medtec.com/the-aws-s3-denial-of-wallet-amplification-attack-bc5a97cc041d</a><br /> EU iOS Safari Allows User Tracking<br /><a href="https://www.mysk.blog/2024/04/28/safari-tracking/" target="_blank" rel="noreferrer noopener">https://www.mysk.blog/2024/04/28/safari-tracking/</a><br /> BentoML Critical Deserialization Vuln CVE-2024-2912<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2912" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2024-2912</a><br />]]></itunes:summary><itunes:duration>411</itunes:duration><itunes:keywords>bentoml; ios; safari; tracking,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8964</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, May 1st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-may-1st-2024--62129431</link><description><![CDATA[Another Day, Another NAS: Attacks against Zyxel NAS326 Devices CVE-2023-4473, CVE-2023-4474<br /><a href="https://isc.sans.edu/diary/Another%20Day%2C%20Another%20NAS%3A%20Attacks%20against%20Zyxel%20NAS326%20devices%20CVE-2023-4473%2C%20CVE-2023-4474/30884" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Another%20Day%2C%20Another%20NAS%3A%20Attacks%20against%20Zyxel%20NAS326%20devices%20CVE-2023-4473%2C%20CVE-2023-4474/30884</a><br /> R-Bitrary Code Execution: Vulnearbility in R's Deserialization<br /><a href="https://hiddenlayer.com/research/r-bitrary-code-execution/" target="_blank" rel="noreferrer noopener">https://hiddenlayer.com/research/r-bitrary-code-execution/</a><br /> Coordinated Docker Hub Attacks using Malicious Repositories<br /><a href="https://jfrog.com/blog/attacks-on-docker-with-millions-of-malicious-repositories-spread-malware-and-phishing-scams/" target="_blank" rel="noreferrer noopener">https://jfrog.com/blog/attacks-on-docker-with-millions-of-malicious-repositories-spread-malware-and-phishing-scams/</a><br /> NVMe-oF/TCP Vulnerabilities<br /><a href="https://www.cyberark.com/resources/threat-research-blog/your-nvme-had-been-syzed-fuzzing-nvme-of-tcp-driver-for-linux-with-syzkaller" target="_blank" rel="noreferrer noopener">https://www.cyberark.com/resources/threat-research-blog/your-nvme-had-been-syzed-fuzzing-nvme-of-tcp-driver-for-linux-with-syzkaller</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8962.mp3</guid><pubDate>Wed, 01 May 2024 10:15:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129431/8962.mp3" length="5885169" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Another Day, Another NAS: Attacks against Zyxel NAS326 Devices CVE-2023-4473, CVE-2023-4474
https://isc.sans.edu/diary/Another%20Day%2C%20Another%20NAS%3A%20Attacks%20against%20Zyxel%20NAS326%20devices%20CVE-2023-4473%2C%20CVE-2023-4474/30884...</itunes:subtitle><itunes:summary><![CDATA[Another Day, Another NAS: Attacks against Zyxel NAS326 Devices CVE-2023-4473, CVE-2023-4474<br /><a href="https://isc.sans.edu/diary/Another%20Day%2C%20Another%20NAS%3A%20Attacks%20against%20Zyxel%20NAS326%20devices%20CVE-2023-4473%2C%20CVE-2023-4474/30884" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Another%20Day%2C%20Another%20NAS%3A%20Attacks%20against%20Zyxel%20NAS326%20devices%20CVE-2023-4473%2C%20CVE-2023-4474/30884</a><br /> R-Bitrary Code Execution: Vulnearbility in R's Deserialization<br /><a href="https://hiddenlayer.com/research/r-bitrary-code-execution/" target="_blank" rel="noreferrer noopener">https://hiddenlayer.com/research/r-bitrary-code-execution/</a><br /> Coordinated Docker Hub Attacks using Malicious Repositories<br /><a href="https://jfrog.com/blog/attacks-on-docker-with-millions-of-malicious-repositories-spread-malware-and-phishing-scams/" target="_blank" rel="noreferrer noopener">https://jfrog.com/blog/attacks-on-docker-with-millions-of-malicious-repositories-spread-malware-and-phishing-scams/</a><br /> NVMe-oF/TCP Vulnerabilities<br /><a href="https://www.cyberark.com/resources/threat-research-blog/your-nvme-had-been-syzed-fuzzing-nvme-of-tcp-driver-for-linux-with-syzkaller" target="_blank" rel="noreferrer noopener">https://www.cyberark.com/resources/threat-research-blog/your-nvme-had-been-syzed-fuzzing-nvme-of-tcp-driver-for-linux-with-syzkaller</a><br />]]></itunes:summary><itunes:duration>399</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,nvme; tcp; docker; hub; malici,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8962</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, May 1st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-may-1st-2024--59748915</link><description><![CDATA[Another Day, Another NAS: Attacks against Zyxel NAS326 Devices CVE-2023-4473, CVE-2023-4474<br /><a href="https://isc.sans.edu/diary/Another%20Day%2C%20Another%20NAS%3A%20Attacks%20against%20Zyxel%20NAS326%20devices%20CVE-2023-4473%2C%20CVE-2023-4474/30884" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Another%20Day%2C%20Another%20NAS%3A%20Attacks%20against%20Zyxel%20NAS326%20devices%20CVE-2023-4473%2C%20CVE-2023-4474/30884</a><br /> R-Bitrary Code Execution: Vulnearbility in R's Deserialization<br /><a href="https://hiddenlayer.com/research/r-bitrary-code-execution/" target="_blank" rel="noreferrer noopener">https://hiddenlayer.com/research/r-bitrary-code-execution/</a><br /> Coordinated Docker Hub Attacks using Malicious Repositories<br /><a href="https://jfrog.com/blog/attacks-on-docker-with-millions-of-malicious-repositories-spread-malware-and-phishing-scams/" target="_blank" rel="noreferrer noopener">https://jfrog.com/blog/attacks-on-docker-with-millions-of-malicious-repositories-spread-malware-and-phishing-scams/</a><br /> NVMe-oF/TCP Vulnerabilities<br /><a href="https://www.cyberark.com/resources/threat-research-blog/your-nvme-had-been-syzed-fuzzing-nvme-of-tcp-driver-for-linux-with-syzkaller" target="_blank" rel="noreferrer noopener">https://www.cyberark.com/resources/threat-research-blog/your-nvme-had-been-syzed-fuzzing-nvme-of-tcp-driver-for-linux-with-syzkaller</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8962.mp3</guid><pubDate>Wed, 01 May 2024 10:15:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59748915/8962.mp3" length="5885169" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Another Day, Another NAS: Attacks against Zyxel NAS326 Devices CVE-2023-4473, CVE-2023-4474
https://isc.sans.edu/diary/Another%20Day%2C%20Another%20NAS%3A%20Attacks%20against%20Zyxel%20NAS326%20devices%20CVE-2023-4473%2C%20CVE-2023-4474/30884...</itunes:subtitle><itunes:summary><![CDATA[Another Day, Another NAS: Attacks against Zyxel NAS326 Devices CVE-2023-4473, CVE-2023-4474<br /><a href="https://isc.sans.edu/diary/Another%20Day%2C%20Another%20NAS%3A%20Attacks%20against%20Zyxel%20NAS326%20devices%20CVE-2023-4473%2C%20CVE-2023-4474/30884" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Another%20Day%2C%20Another%20NAS%3A%20Attacks%20against%20Zyxel%20NAS326%20devices%20CVE-2023-4473%2C%20CVE-2023-4474/30884</a><br /> R-Bitrary Code Execution: Vulnearbility in R's Deserialization<br /><a href="https://hiddenlayer.com/research/r-bitrary-code-execution/" target="_blank" rel="noreferrer noopener">https://hiddenlayer.com/research/r-bitrary-code-execution/</a><br /> Coordinated Docker Hub Attacks using Malicious Repositories<br /><a href="https://jfrog.com/blog/attacks-on-docker-with-millions-of-malicious-repositories-spread-malware-and-phishing-scams/" target="_blank" rel="noreferrer noopener">https://jfrog.com/blog/attacks-on-docker-with-millions-of-malicious-repositories-spread-malware-and-phishing-scams/</a><br /> NVMe-oF/TCP Vulnerabilities<br /><a href="https://www.cyberark.com/resources/threat-research-blog/your-nvme-had-been-syzed-fuzzing-nvme-of-tcp-driver-for-linux-with-syzkaller" target="_blank" rel="noreferrer noopener">https://www.cyberark.com/resources/threat-research-blog/your-nvme-had-been-syzed-fuzzing-nvme-of-tcp-driver-for-linux-with-syzkaller</a><br />]]></itunes:summary><itunes:duration>399</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,nvme; tcp; docker; hub; malici,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8962</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, April 30th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-april-30th-2024--62129362</link><description><![CDATA[DLink NAS Exploit Variation<br /><a href="https://www.qnap.com/en/security-advisory/qsa-24-09" target="_blank" rel="noreferrer noopener">https://www.qnap.com/en/security-advisory/qsa-24-09</a><br /> Muddling Meerkat DNS Abuse<br /><a href="https://blogs.infoblox.com/threat-intelligence/a-cunning-operator-muddling-meerkat-and-chinas-great-firewall/" target="_blank" rel="noreferrer noopener">https://blogs.infoblox.com/threat-intelligence/a-cunning-operator-muddling-meerkat-and-chinas-great-firewall/</a><br /> Android TV Data Leakage<br /><a href="https://www.youtube.com/watch?v=QiyBXXO8QpA" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=QiyBXXO8QpA</a><br /><a href="https://www.404media.co/android-tvs-can-expose-user-email-inboxes/" target="_blank" rel="noreferrer noopener">https://www.404media.co/android-tvs-can-expose-user-email-inboxes/</a><br /> SEC522: SANSFIRE<br /><a href="https://www.sans.org/cyber-security-courses/application-security-securing-web-apps-api-microservices/" target="_blank" rel="noreferrer noopener">https://www.sans.org/cyber-security-courses/application-security-securing-web-apps-api-microservices/</a><br /> SEC522 Demo (requires free account):<br /><a href="https://www.sans.org/ondemand/get-demo/316" target="_blank" rel="noreferrer noopener">https://www.sans.org/ondemand/get-demo/316</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8960.mp3</guid><pubDate>Tue, 30 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129362/8960.mp3" length="6118457" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>DLink NAS Exploit Variation
https://www.qnap.com/en/security-advisory/qsa-24-09
 Muddling Meerkat DNS Abuse
https://blogs.infoblox.com/threat-intelligence/a-cunning-operator-muddling-meerkat-and-chinas-great-firewall/
 Android TV Data Leakage...</itunes:subtitle><itunes:summary><![CDATA[DLink NAS Exploit Variation<br /><a href="https://www.qnap.com/en/security-advisory/qsa-24-09" target="_blank" rel="noreferrer noopener">https://www.qnap.com/en/security-advisory/qsa-24-09</a><br /> Muddling Meerkat DNS Abuse<br /><a href="https://blogs.infoblox.com/threat-intelligence/a-cunning-operator-muddling-meerkat-and-chinas-great-firewall/" target="_blank" rel="noreferrer noopener">https://blogs.infoblox.com/threat-intelligence/a-cunning-operator-muddling-meerkat-and-chinas-great-firewall/</a><br /> Android TV Data Leakage<br /><a href="https://www.youtube.com/watch?v=QiyBXXO8QpA" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=QiyBXXO8QpA</a><br /><a href="https://www.404media.co/android-tvs-can-expose-user-email-inboxes/" target="_blank" rel="noreferrer noopener">https://www.404media.co/android-tvs-can-expose-user-email-inboxes/</a><br /> SEC522: SANSFIRE<br /><a href="https://www.sans.org/cyber-security-courses/application-security-securing-web-apps-api-microservices/" target="_blank" rel="noreferrer noopener">https://www.sans.org/cyber-security-courses/application-security-securing-web-apps-api-microservices/</a><br /> SEC522 Demo (requires free account):<br /><a href="https://www.sans.org/ondemand/get-demo/316" target="_blank" rel="noreferrer noopener">https://www.sans.org/ondemand/get-demo/316</a><br />]]></itunes:summary><itunes:duration>415</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,sec522; sansfire; demo; androi,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8960</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, April 30th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-april-30th-2024--59716146</link><description><![CDATA[DLink NAS Exploit Variation<br /><a href="https://www.qnap.com/en/security-advisory/qsa-24-09" target="_blank" rel="noreferrer noopener">https://www.qnap.com/en/security-advisory/qsa-24-09</a><br /> Muddling Meerkat DNS Abuse<br /><a href="https://blogs.infoblox.com/threat-intelligence/a-cunning-operator-muddling-meerkat-and-chinas-great-firewall/" target="_blank" rel="noreferrer noopener">https://blogs.infoblox.com/threat-intelligence/a-cunning-operator-muddling-meerkat-and-chinas-great-firewall/</a><br /> Android TV Data Leakage<br /><a href="https://www.youtube.com/watch?v=QiyBXXO8QpA" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=QiyBXXO8QpA</a><br /><a href="https://www.404media.co/android-tvs-can-expose-user-email-inboxes/" target="_blank" rel="noreferrer noopener">https://www.404media.co/android-tvs-can-expose-user-email-inboxes/</a><br /> SEC522: SANSFIRE<br /><a href="https://www.sans.org/cyber-security-courses/application-security-securing-web-apps-api-microservices/" target="_blank" rel="noreferrer noopener">https://www.sans.org/cyber-security-courses/application-security-securing-web-apps-api-microservices/</a><br /> SEC522 Demo (requires free account):<br /><a href="https://www.sans.org/ondemand/get-demo/316" target="_blank" rel="noreferrer noopener">https://www.sans.org/ondemand/get-demo/316</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8960.mp3</guid><pubDate>Tue, 30 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59716146/8960.mp3" length="6118457" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>DLink NAS Exploit Variation
https://www.qnap.com/en/security-advisory/qsa-24-09
 Muddling Meerkat DNS Abuse
https://blogs.infoblox.com/threat-intelligence/a-cunning-operator-muddling-meerkat-and-chinas-great-firewall/
 Android TV Data Leakage...</itunes:subtitle><itunes:summary><![CDATA[DLink NAS Exploit Variation<br /><a href="https://www.qnap.com/en/security-advisory/qsa-24-09" target="_blank" rel="noreferrer noopener">https://www.qnap.com/en/security-advisory/qsa-24-09</a><br /> Muddling Meerkat DNS Abuse<br /><a href="https://blogs.infoblox.com/threat-intelligence/a-cunning-operator-muddling-meerkat-and-chinas-great-firewall/" target="_blank" rel="noreferrer noopener">https://blogs.infoblox.com/threat-intelligence/a-cunning-operator-muddling-meerkat-and-chinas-great-firewall/</a><br /> Android TV Data Leakage<br /><a href="https://www.youtube.com/watch?v=QiyBXXO8QpA" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=QiyBXXO8QpA</a><br /><a href="https://www.404media.co/android-tvs-can-expose-user-email-inboxes/" target="_blank" rel="noreferrer noopener">https://www.404media.co/android-tvs-can-expose-user-email-inboxes/</a><br /> SEC522: SANSFIRE<br /><a href="https://www.sans.org/cyber-security-courses/application-security-securing-web-apps-api-microservices/" target="_blank" rel="noreferrer noopener">https://www.sans.org/cyber-security-courses/application-security-securing-web-apps-api-microservices/</a><br /> SEC522 Demo (requires free account):<br /><a href="https://www.sans.org/ondemand/get-demo/316" target="_blank" rel="noreferrer noopener">https://www.sans.org/ondemand/get-demo/316</a><br />]]></itunes:summary><itunes:duration>415</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,sec522; sansfire; demo; androi,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8960</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, April 29th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-april-29th-2024--62129390</link><description><![CDATA[Okta warns of increase in credential stuffing<br /><a href="https://sec.okta.com/blockanonymizers" target="_blank" rel="noreferrer noopener">https://sec.okta.com/blockanonymizers</a><br /> Fake payment cards used by Police in Japan<br /><a href="https://twitter.com/vxunderground/status/1783522097425211887" target="_blank" rel="noreferrer noopener">https://twitter.com/vxunderground/status/1783522097425211887</a><br /> Phishing Campaigns Targeting USPS<br /><a href="https://www.akamai.com/blog/security-research/phishing-usps-malicious-domains-traffic-equal-to-legitimate-traffic" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/phishing-usps-malicious-domains-traffic-equal-to-legitimate-traffic</a><br /> Chrome 124 Breaks TLS Handshake<br /><a href="https://www.reddit.com/r/sysadmin/comments/1carvpd/chrome_124_breaks_tls_handshake/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/sysadmin/comments/1carvpd/chrome_124_breaks_tls_handshake/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8958.mp3</guid><pubDate>Mon, 29 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129390/8958.mp3" length="5852528" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Okta warns of increase in credential stuffing
https://sec.okta.com/blockanonymizers
 Fake payment cards used by Police in Japan
https://twitter.com/vxunderground/status/1783522097425211887
 Phishing Campaigns Targeting USPS...</itunes:subtitle><itunes:summary><![CDATA[Okta warns of increase in credential stuffing<br /><a href="https://sec.okta.com/blockanonymizers" target="_blank" rel="noreferrer noopener">https://sec.okta.com/blockanonymizers</a><br /> Fake payment cards used by Police in Japan<br /><a href="https://twitter.com/vxunderground/status/1783522097425211887" target="_blank" rel="noreferrer noopener">https://twitter.com/vxunderground/status/1783522097425211887</a><br /> Phishing Campaigns Targeting USPS<br /><a href="https://www.akamai.com/blog/security-research/phishing-usps-malicious-domains-traffic-equal-to-legitimate-traffic" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/phishing-usps-malicious-domains-traffic-equal-to-legitimate-traffic</a><br /> Chrome 124 Breaks TLS Handshake<br /><a href="https://www.reddit.com/r/sysadmin/comments/1carvpd/chrome_124_breaks_tls_handshake/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/sysadmin/comments/1carvpd/chrome_124_breaks_tls_handshake/</a><br />]]></itunes:summary><itunes:duration>396</itunes:duration><itunes:keywords>business,chrome; tls; phishing; usps; j,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8958</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, April 29th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-april-29th-2024--59691501</link><description><![CDATA[Okta warns of increase in credential stuffing<br /><a href="https://sec.okta.com/blockanonymizers" target="_blank" rel="noreferrer noopener">https://sec.okta.com/blockanonymizers</a><br /> Fake payment cards used by Police in Japan<br /><a href="https://twitter.com/vxunderground/status/1783522097425211887" target="_blank" rel="noreferrer noopener">https://twitter.com/vxunderground/status/1783522097425211887</a><br /> Phishing Campaigns Targeting USPS<br /><a href="https://www.akamai.com/blog/security-research/phishing-usps-malicious-domains-traffic-equal-to-legitimate-traffic" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/phishing-usps-malicious-domains-traffic-equal-to-legitimate-traffic</a><br /> Chrome 124 Breaks TLS Handshake<br /><a href="https://www.reddit.com/r/sysadmin/comments/1carvpd/chrome_124_breaks_tls_handshake/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/sysadmin/comments/1carvpd/chrome_124_breaks_tls_handshake/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8958.mp3</guid><pubDate>Mon, 29 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59691501/8958.mp3" length="5852528" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Okta warns of increase in credential stuffing
https://sec.okta.com/blockanonymizers
 Fake payment cards used by Police in Japan
https://twitter.com/vxunderground/status/1783522097425211887
 Phishing Campaigns Targeting USPS...</itunes:subtitle><itunes:summary><![CDATA[Okta warns of increase in credential stuffing<br /><a href="https://sec.okta.com/blockanonymizers" target="_blank" rel="noreferrer noopener">https://sec.okta.com/blockanonymizers</a><br /> Fake payment cards used by Police in Japan<br /><a href="https://twitter.com/vxunderground/status/1783522097425211887" target="_blank" rel="noreferrer noopener">https://twitter.com/vxunderground/status/1783522097425211887</a><br /> Phishing Campaigns Targeting USPS<br /><a href="https://www.akamai.com/blog/security-research/phishing-usps-malicious-domains-traffic-equal-to-legitimate-traffic" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/phishing-usps-malicious-domains-traffic-equal-to-legitimate-traffic</a><br /> Chrome 124 Breaks TLS Handshake<br /><a href="https://www.reddit.com/r/sysadmin/comments/1carvpd/chrome_124_breaks_tls_handshake/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/sysadmin/comments/1carvpd/chrome_124_breaks_tls_handshake/</a><br />]]></itunes:summary><itunes:duration>396</itunes:duration><itunes:keywords>business,chrome; tls; phishing; usps; j,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8958</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, April 26th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-april-26th-2024--62129391</link><description><![CDATA[Does it matter if iptables isn't running on my honeypot?<br /><a href="https://isc.sans.edu/forums/diary/Does%20it%20matter%20if%20iptables%20isn't%20running%20on%20my%20honeypot%3F/30862/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Does%20it%20matter%20if%20iptables%20isn't%20running%20on%20my%20honeypot%3F/30862/</a><br /> Unplugging PlugX: Singholing the PlugX USB worm botnet<br /><a href="https://blog.sekoia.io/unplugging-plugx-sinkholing-the-plugx-usb-worm-botnet/" target="_blank" rel="noreferrer noopener">https://blog.sekoia.io/unplugging-plugx-sinkholing-the-plugx-usb-worm-botnet/</a><br /> pfSense Updates<br /><a href="https://docs.netgate.com/advisories/index.html" target="_blank" rel="noreferrer noopener">https://docs.netgate.com/advisories/index.html</a><br /> GitLab Updates<br /><a href="https://about.gitlab.com/releases/2024/04/24/patch-release-gitlab-16-11-1-released/" target="_blank" rel="noreferrer noopener">https://about.gitlab.com/releases/2024/04/24/patch-release-gitlab-16-11-1-released/</a><br /> Matthew Alan Vorhees: Prevention Strategies for Modern Living Off the Land Usage<br /><a href="https://www.sans.edu/cyber-research/prevention-strategies-modern-living-off-land-usage/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/prevention-strategies-modern-living-off-land-usage/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8956.mp3</guid><pubDate>Fri, 26 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129391/8956.mp3" length="17501610" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Does it matter if iptables isn't running on my honeypot?
https://isc.sans.edu/forums/diary/Does%20it%20matter%20if%20iptables%20isn't%20running%20on%20my%20honeypot%3F/30862/
 Unplugging PlugX: Singholing the PlugX USB worm botnet...</itunes:subtitle><itunes:summary><![CDATA[Does it matter if iptables isn't running on my honeypot?<br /><a href="https://isc.sans.edu/forums/diary/Does%20it%20matter%20if%20iptables%20isn't%20running%20on%20my%20honeypot%3F/30862/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Does%20it%20matter%20if%20iptables%20isn't%20running%20on%20my%20honeypot%3F/30862/</a><br /> Unplugging PlugX: Singholing the PlugX USB worm botnet<br /><a href="https://blog.sekoia.io/unplugging-plugx-sinkholing-the-plugx-usb-worm-botnet/" target="_blank" rel="noreferrer noopener">https://blog.sekoia.io/unplugging-plugx-sinkholing-the-plugx-usb-worm-botnet/</a><br /> pfSense Updates<br /><a href="https://docs.netgate.com/advisories/index.html" target="_blank" rel="noreferrer noopener">https://docs.netgate.com/advisories/index.html</a><br /> GitLab Updates<br /><a href="https://about.gitlab.com/releases/2024/04/24/patch-release-gitlab-16-11-1-released/" target="_blank" rel="noreferrer noopener">https://about.gitlab.com/releases/2024/04/24/patch-release-gitlab-16-11-1-released/</a><br /> Matthew Alan Vorhees: Prevention Strategies for Modern Living Off the Land Usage<br /><a href="https://www.sans.edu/cyber-research/prevention-strategies-modern-living-off-land-usage/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/prevention-strategies-modern-living-off-land-usage/</a><br />]]></itunes:summary><itunes:duration>1228</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,sans.edu; research; gitlab; lo,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8956</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, April 26th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-april-26th-2024--59661324</link><description><![CDATA[Does it matter if iptables isn't running on my honeypot?<br /><a href="https://isc.sans.edu/forums/diary/Does%20it%20matter%20if%20iptables%20isn't%20running%20on%20my%20honeypot%3F/30862/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Does%20it%20matter%20if%20iptables%20isn't%20running%20on%20my%20honeypot%3F/30862/</a><br /> Unplugging PlugX: Singholing the PlugX USB worm botnet<br /><a href="https://blog.sekoia.io/unplugging-plugx-sinkholing-the-plugx-usb-worm-botnet/" target="_blank" rel="noreferrer noopener">https://blog.sekoia.io/unplugging-plugx-sinkholing-the-plugx-usb-worm-botnet/</a><br /> pfSense Updates<br /><a href="https://docs.netgate.com/advisories/index.html" target="_blank" rel="noreferrer noopener">https://docs.netgate.com/advisories/index.html</a><br /> GitLab Updates<br /><a href="https://about.gitlab.com/releases/2024/04/24/patch-release-gitlab-16-11-1-released/" target="_blank" rel="noreferrer noopener">https://about.gitlab.com/releases/2024/04/24/patch-release-gitlab-16-11-1-released/</a><br /> Matthew Alan Vorhees: Prevention Strategies for Modern Living Off the Land Usage<br /><a href="https://www.sans.edu/cyber-research/prevention-strategies-modern-living-off-land-usage/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/prevention-strategies-modern-living-off-land-usage/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8956.mp3</guid><pubDate>Fri, 26 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59661324/8956.mp3" length="17501610" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Does it matter if iptables isn't running on my honeypot?
https://isc.sans.edu/forums/diary/Does%20it%20matter%20if%20iptables%20isn't%20running%20on%20my%20honeypot%3F/30862/
 Unplugging PlugX: Singholing the PlugX USB worm botnet...</itunes:subtitle><itunes:summary><![CDATA[Does it matter if iptables isn't running on my honeypot?<br /><a href="https://isc.sans.edu/forums/diary/Does%20it%20matter%20if%20iptables%20isn't%20running%20on%20my%20honeypot%3F/30862/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Does%20it%20matter%20if%20iptables%20isn't%20running%20on%20my%20honeypot%3F/30862/</a><br /> Unplugging PlugX: Singholing the PlugX USB worm botnet<br /><a href="https://blog.sekoia.io/unplugging-plugx-sinkholing-the-plugx-usb-worm-botnet/" target="_blank" rel="noreferrer noopener">https://blog.sekoia.io/unplugging-plugx-sinkholing-the-plugx-usb-worm-botnet/</a><br /> pfSense Updates<br /><a href="https://docs.netgate.com/advisories/index.html" target="_blank" rel="noreferrer noopener">https://docs.netgate.com/advisories/index.html</a><br /> GitLab Updates<br /><a href="https://about.gitlab.com/releases/2024/04/24/patch-release-gitlab-16-11-1-released/" target="_blank" rel="noreferrer noopener">https://about.gitlab.com/releases/2024/04/24/patch-release-gitlab-16-11-1-released/</a><br /> Matthew Alan Vorhees: Prevention Strategies for Modern Living Off the Land Usage<br /><a href="https://www.sans.edu/cyber-research/prevention-strategies-modern-living-off-land-usage/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/prevention-strategies-modern-living-off-land-usage/</a><br />]]></itunes:summary><itunes:duration>1228</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,sans.edu; research; gitlab; lo,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8956</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, April 25th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-april-25th-2024--62129398</link><description><![CDATA[API Rug Pull - The NIST NVD Database and API<br /><a href="https://isc.sans.edu/diary/API%20Rug%20Pull%20-%20The%20NIST%20NVD%20Database%20and%20API%20%28Part%204%20of%203%29/30868" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/API%20Rug%20Pull%20-%20The%20NIST%20NVD%20Database%20and%20API%20%28Part%204%20of%203%29/30868</a><br /> Cisco Patches Vulnerabilities and Discovers Arcane Backdoor<br /><a href="https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/</a><br /> Vulnerabilities across keyboard apps reveal keystrokes to network eavesdroppers<br /><a href="https://citizenlab.ca/2024/04/vulnerabilities-across-keyboard-apps-reveal-keystrokes-to-network-eavesdroppers/" target="_blank" rel="noreferrer noopener">https://citizenlab.ca/2024/04/vulnerabilities-across-keyboard-apps-reveal-keystrokes-to-network-eavesdroppers/</a><br /> MySQL2: Dangers of User-Defined Database Connections<br /><a href="https://blog.slonser.info/posts/mysql2-attacker-configuration/" target="_blank" rel="noreferrer noopener">https://blog.slonser.info/posts/mysql2-attacker-configuration/</a><br /> Netgear Nighthawk Vulnerabilities<br /><a href="https://jvn.jp/en/vu/JVNVU91883072/" target="_blank" rel="noreferrer noopener">https://jvn.jp/en/vu/JVNVU91883072/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8954.mp3</guid><pubDate>Thu, 25 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129398/8954.mp3" length="5477300" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>API Rug Pull - The NIST NVD Database and API
https://isc.sans.edu/diary/API%20Rug%20Pull%20-%20The%20NIST%20NVD%20Database%20and%20API%20%28Part%204%20of%203%29/30868
 Cisco Patches Vulnerabilities and Discovers Arcane Backdoor...</itunes:subtitle><itunes:summary><![CDATA[API Rug Pull - The NIST NVD Database and API<br /><a href="https://isc.sans.edu/diary/API%20Rug%20Pull%20-%20The%20NIST%20NVD%20Database%20and%20API%20%28Part%204%20of%203%29/30868" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/API%20Rug%20Pull%20-%20The%20NIST%20NVD%20Database%20and%20API%20%28Part%204%20of%203%29/30868</a><br /> Cisco Patches Vulnerabilities and Discovers Arcane Backdoor<br /><a href="https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/</a><br /> Vulnerabilities across keyboard apps reveal keystrokes to network eavesdroppers<br /><a href="https://citizenlab.ca/2024/04/vulnerabilities-across-keyboard-apps-reveal-keystrokes-to-network-eavesdroppers/" target="_blank" rel="noreferrer noopener">https://citizenlab.ca/2024/04/vulnerabilities-across-keyboard-apps-reveal-keystrokes-to-network-eavesdroppers/</a><br /> MySQL2: Dangers of User-Defined Database Connections<br /><a href="https://blog.slonser.info/posts/mysql2-attacker-configuration/" target="_blank" rel="noreferrer noopener">https://blog.slonser.info/posts/mysql2-attacker-configuration/</a><br /> Netgear Nighthawk Vulnerabilities<br /><a href="https://jvn.jp/en/vu/JVNVU91883072/" target="_blank" rel="noreferrer noopener">https://jvn.jp/en/vu/JVNVU91883072/</a><br />]]></itunes:summary><itunes:duration>370</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,netgear; nighthawk; mysql2; no,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8954</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, April 25th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-april-25th-2024--59643252</link><description><![CDATA[API Rug Pull - The NIST NVD Database and API<br /><a href="https://isc.sans.edu/diary/API%20Rug%20Pull%20-%20The%20NIST%20NVD%20Database%20and%20API%20%28Part%204%20of%203%29/30868" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/API%20Rug%20Pull%20-%20The%20NIST%20NVD%20Database%20and%20API%20%28Part%204%20of%203%29/30868</a><br /> Cisco Patches Vulnerabilities and Discovers Arcane Backdoor<br /><a href="https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/</a><br /> Vulnerabilities across keyboard apps reveal keystrokes to network eavesdroppers<br /><a href="https://citizenlab.ca/2024/04/vulnerabilities-across-keyboard-apps-reveal-keystrokes-to-network-eavesdroppers/" target="_blank" rel="noreferrer noopener">https://citizenlab.ca/2024/04/vulnerabilities-across-keyboard-apps-reveal-keystrokes-to-network-eavesdroppers/</a><br /> MySQL2: Dangers of User-Defined Database Connections<br /><a href="https://blog.slonser.info/posts/mysql2-attacker-configuration/" target="_blank" rel="noreferrer noopener">https://blog.slonser.info/posts/mysql2-attacker-configuration/</a><br /> Netgear Nighthawk Vulnerabilities<br /><a href="https://jvn.jp/en/vu/JVNVU91883072/" target="_blank" rel="noreferrer noopener">https://jvn.jp/en/vu/JVNVU91883072/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8954.mp3</guid><pubDate>Thu, 25 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59643252/8954.mp3" length="5477300" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>API Rug Pull - The NIST NVD Database and API
https://isc.sans.edu/diary/API%20Rug%20Pull%20-%20The%20NIST%20NVD%20Database%20and%20API%20%28Part%204%20of%203%29/30868
 Cisco Patches Vulnerabilities and Discovers Arcane Backdoor...</itunes:subtitle><itunes:summary><![CDATA[API Rug Pull - The NIST NVD Database and API<br /><a href="https://isc.sans.edu/diary/API%20Rug%20Pull%20-%20The%20NIST%20NVD%20Database%20and%20API%20%28Part%204%20of%203%29/30868" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/API%20Rug%20Pull%20-%20The%20NIST%20NVD%20Database%20and%20API%20%28Part%204%20of%203%29/30868</a><br /> Cisco Patches Vulnerabilities and Discovers Arcane Backdoor<br /><a href="https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/</a><br /> Vulnerabilities across keyboard apps reveal keystrokes to network eavesdroppers<br /><a href="https://citizenlab.ca/2024/04/vulnerabilities-across-keyboard-apps-reveal-keystrokes-to-network-eavesdroppers/" target="_blank" rel="noreferrer noopener">https://citizenlab.ca/2024/04/vulnerabilities-across-keyboard-apps-reveal-keystrokes-to-network-eavesdroppers/</a><br /> MySQL2: Dangers of User-Defined Database Connections<br /><a href="https://blog.slonser.info/posts/mysql2-attacker-configuration/" target="_blank" rel="noreferrer noopener">https://blog.slonser.info/posts/mysql2-attacker-configuration/</a><br /> Netgear Nighthawk Vulnerabilities<br /><a href="https://jvn.jp/en/vu/JVNVU91883072/" target="_blank" rel="noreferrer noopener">https://jvn.jp/en/vu/JVNVU91883072/</a><br />]]></itunes:summary><itunes:duration>370</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,netgear; nighthawk; mysql2; no,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8954</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, April 24th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-april-24th-2024--62129410</link><description><![CDATA[Struts2 devmode Still a Problem Ten Years Later<br /><a href="https://isc.sans.edu/forums/diary/Struts%20%22devmode%22%3A%20Still%20a%20problem%20ten%20years%20later%3F/30866/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Struts%20%22devmode%22%3A%20Still%20a%20problem%20ten%20years%20later%3F/30866/</a><br /> Analyzing Forest Blizard's Custom Post-Compromise Tool for exploiting CVE-2022-38028<br /><a href="https://www.microsoft.com/en-us/security/blog/2024/04/22/analyzing-forest-blizzards-custom-post-compromise-tool-for-exploiting-cve-2022-38028-to-obtain-credentials/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2024/04/22/analyzing-forest-blizzards-custom-post-compromise-tool-for-exploiting-cve-2022-38028-to-obtain-credentials/</a><br /> April 2024 Exchange Server Hotfix Update<br /><a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/released-april-2024-exchange-server-hotfix-updates/ba-p/4120536" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/exchange-team-blog/released-april-2024-exchange-server-hotfix-updates/ba-p/4120536</a><br /> CVE-2024-2389: Command Injection Vulnerability in Progress Flowmon<br /><a href="https://rhinosecuritylabs.com/research/cve-2024-2389-in-progress-flowmon/" target="_blank" rel="noreferrer noopener">https://rhinosecuritylabs.com/research/cve-2024-2389-in-progress-flowmon/</a><br /> GuptiMiner: Hijacking Antivirus Updates for Distributing Backdoors and Casual Mining<br /><a href="https://decoded.avast.io/janrubin/guptiminer-hijacking-antivirus-updates-for-distributing-backdoors-and-casual-mining/" target="_blank" rel="noreferrer noopener">https://decoded.avast.io/janrubin/guptiminer-hijacking-antivirus-updates-for-distributing-backdoors-and-casual-mining/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8952.mp3</guid><pubDate>Wed, 24 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129410/8952.mp3" length="5657420" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Struts2 devmode Still a Problem Ten Years Later
https://isc.sans.edu/forums/diary/Struts%20%22devmode%22%3A%20Still%20a%20problem%20ten%20years%20later%3F/30866/
 Analyzing Forest Blizard's Custom Post-Compromise Tool for exploiting CVE-2022-38028...</itunes:subtitle><itunes:summary><![CDATA[Struts2 devmode Still a Problem Ten Years Later<br /><a href="https://isc.sans.edu/forums/diary/Struts%20%22devmode%22%3A%20Still%20a%20problem%20ten%20years%20later%3F/30866/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Struts%20%22devmode%22%3A%20Still%20a%20problem%20ten%20years%20later%3F/30866/</a><br /> Analyzing Forest Blizard's Custom Post-Compromise Tool for exploiting CVE-2022-38028<br /><a href="https://www.microsoft.com/en-us/security/blog/2024/04/22/analyzing-forest-blizzards-custom-post-compromise-tool-for-exploiting-cve-2022-38028-to-obtain-credentials/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2024/04/22/analyzing-forest-blizzards-custom-post-compromise-tool-for-exploiting-cve-2022-38028-to-obtain-credentials/</a><br /> April 2024 Exchange Server Hotfix Update<br /><a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/released-april-2024-exchange-server-hotfix-updates/ba-p/4120536" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/exchange-team-blog/released-april-2024-exchange-server-hotfix-updates/ba-p/4120536</a><br /> CVE-2024-2389: Command Injection Vulnerability in Progress Flowmon<br /><a href="https://rhinosecuritylabs.com/research/cve-2024-2389-in-progress-flowmon/" target="_blank" rel="noreferrer noopener">https://rhinosecuritylabs.com/research/cve-2024-2389-in-progress-flowmon/</a><br /> GuptiMiner: Hijacking Antivirus Updates for Distributing Backdoors and Casual Mining<br /><a href="https://decoded.avast.io/janrubin/guptiminer-hijacking-antivirus-updates-for-distributing-backdoors-and-casual-mining/" target="_blank" rel="noreferrer noopener">https://decoded.avast.io/janrubin/guptiminer-hijacking-antivirus-updates-for-distributing-backdoors-and-casual-mining/</a><br />]]></itunes:summary><itunes:duration>382</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,guptiminer; progress; flowmon;,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8952</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, April 24th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-april-24th-2024--59624597</link><description><![CDATA[Struts2 devmode Still a Problem Ten Years Later<br /><a href="https://isc.sans.edu/forums/diary/Struts%20%22devmode%22%3A%20Still%20a%20problem%20ten%20years%20later%3F/30866/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Struts%20%22devmode%22%3A%20Still%20a%20problem%20ten%20years%20later%3F/30866/</a><br /> Analyzing Forest Blizard's Custom Post-Compromise Tool for exploiting CVE-2022-38028<br /><a href="https://www.microsoft.com/en-us/security/blog/2024/04/22/analyzing-forest-blizzards-custom-post-compromise-tool-for-exploiting-cve-2022-38028-to-obtain-credentials/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2024/04/22/analyzing-forest-blizzards-custom-post-compromise-tool-for-exploiting-cve-2022-38028-to-obtain-credentials/</a><br /> April 2024 Exchange Server Hotfix Update<br /><a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/released-april-2024-exchange-server-hotfix-updates/ba-p/4120536" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/exchange-team-blog/released-april-2024-exchange-server-hotfix-updates/ba-p/4120536</a><br /> CVE-2024-2389: Command Injection Vulnerability in Progress Flowmon<br /><a href="https://rhinosecuritylabs.com/research/cve-2024-2389-in-progress-flowmon/" target="_blank" rel="noreferrer noopener">https://rhinosecuritylabs.com/research/cve-2024-2389-in-progress-flowmon/</a><br /> GuptiMiner: Hijacking Antivirus Updates for Distributing Backdoors and Casual Mining<br /><a href="https://decoded.avast.io/janrubin/guptiminer-hijacking-antivirus-updates-for-distributing-backdoors-and-casual-mining/" target="_blank" rel="noreferrer noopener">https://decoded.avast.io/janrubin/guptiminer-hijacking-antivirus-updates-for-distributing-backdoors-and-casual-mining/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8952.mp3</guid><pubDate>Wed, 24 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59624597/8952.mp3" length="5657420" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Struts2 devmode Still a Problem Ten Years Later
https://isc.sans.edu/forums/diary/Struts%20%22devmode%22%3A%20Still%20a%20problem%20ten%20years%20later%3F/30866/
 Analyzing Forest Blizard's Custom Post-Compromise Tool for exploiting CVE-2022-38028...</itunes:subtitle><itunes:summary><![CDATA[Struts2 devmode Still a Problem Ten Years Later<br /><a href="https://isc.sans.edu/forums/diary/Struts%20%22devmode%22%3A%20Still%20a%20problem%20ten%20years%20later%3F/30866/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Struts%20%22devmode%22%3A%20Still%20a%20problem%20ten%20years%20later%3F/30866/</a><br /> Analyzing Forest Blizard's Custom Post-Compromise Tool for exploiting CVE-2022-38028<br /><a href="https://www.microsoft.com/en-us/security/blog/2024/04/22/analyzing-forest-blizzards-custom-post-compromise-tool-for-exploiting-cve-2022-38028-to-obtain-credentials/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2024/04/22/analyzing-forest-blizzards-custom-post-compromise-tool-for-exploiting-cve-2022-38028-to-obtain-credentials/</a><br /> April 2024 Exchange Server Hotfix Update<br /><a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/released-april-2024-exchange-server-hotfix-updates/ba-p/4120536" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/exchange-team-blog/released-april-2024-exchange-server-hotfix-updates/ba-p/4120536</a><br /> CVE-2024-2389: Command Injection Vulnerability in Progress Flowmon<br /><a href="https://rhinosecuritylabs.com/research/cve-2024-2389-in-progress-flowmon/" target="_blank" rel="noreferrer noopener">https://rhinosecuritylabs.com/research/cve-2024-2389-in-progress-flowmon/</a><br /> GuptiMiner: Hijacking Antivirus Updates for Distributing Backdoors and Casual Mining<br /><a href="https://decoded.avast.io/janrubin/guptiminer-hijacking-antivirus-updates-for-distributing-backdoors-and-casual-mining/" target="_blank" rel="noreferrer noopener">https://decoded.avast.io/janrubin/guptiminer-hijacking-antivirus-updates-for-distributing-backdoors-and-casual-mining/</a><br />]]></itunes:summary><itunes:duration>382</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,guptiminer; progress; flowmon;,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8952</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, April 23rd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-april-23rd-2024--62129437</link><description><![CDATA[Number of Industrial Devices Accessible From Internet Up 30 Thousand over three years<br /><a href="https://isc.sans.edu/diary/It%20appears%20that%20the%20number%20of%20industrial%20devices%20accessible%20from%20the%20internet%20has%20risen%20by%2030%20thousand%20over%20the%20past%20three%20years/30860" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/It%20appears%20that%20the%20number%20of%20industrial%20devices%20accessible%20from%20the%20internet%20has%20risen%20by%2030%20thousand%20over%20the%20past%20three%20years/30860</a><br /> Evil XDR: Turning an XDR into an Offensive Tool<br /><a href="https://www.darkreading.com/application-security/evil-xdr-researcher-turns-palo-alto-software-into-perfect-malware" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/application-security/evil-xdr-researcher-turns-palo-alto-software-into-perfect-malware</a><br /> GitLab Comment Bug<br /><a href="https://www.bleepingcomputer.com/news/security/gitlab-affected-by-github-style-cdn-flaw-allowing-malware-hosting/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/gitlab-affected-by-github-style-cdn-flaw-allowing-malware-hosting/</a><br /> SEC522 Demo: <a href="https://www.sans.org/ondemand/get-demo/316" target="_blank" rel="noreferrer noopener">https://www.sans.org/ondemand/get-demo/316</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8950.mp3</guid><pubDate>Tue, 23 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129437/8950.mp3" length="5425120" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Number of Industrial Devices Accessible From Internet Up 30 Thousand over three years...</itunes:subtitle><itunes:summary><![CDATA[Number of Industrial Devices Accessible From Internet Up 30 Thousand over three years<br /><a href="https://isc.sans.edu/diary/It%20appears%20that%20the%20number%20of%20industrial%20devices%20accessible%20from%20the%20internet%20has%20risen%20by%2030%20thousand%20over%20the%20past%20three%20years/30860" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/It%20appears%20that%20the%20number%20of%20industrial%20devices%20accessible%20from%20the%20internet%20has%20risen%20by%2030%20thousand%20over%20the%20past%20three%20years/30860</a><br /> Evil XDR: Turning an XDR into an Offensive Tool<br /><a href="https://www.darkreading.com/application-security/evil-xdr-researcher-turns-palo-alto-software-into-perfect-malware" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/application-security/evil-xdr-researcher-turns-palo-alto-software-into-perfect-malware</a><br /> GitLab Comment Bug<br /><a href="https://www.bleepingcomputer.com/news/security/gitlab-affected-by-github-style-cdn-flaw-allowing-malware-hosting/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/gitlab-affected-by-github-style-cdn-flaw-allowing-malware-hosting/</a><br /> SEC522 Demo: <a href="https://www.sans.org/ondemand/get-demo/316" target="_blank" rel="noreferrer noopener">https://www.sans.org/ondemand/get-demo/316</a><br />]]></itunes:summary><itunes:duration>366</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,gitlab; xdr; evil xdr; ics,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8950</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, April 23rd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-april-23rd-2024--59605524</link><description><![CDATA[Number of Industrial Devices Accessible From Internet Up 30 Thousand over three years<br /><a href="https://isc.sans.edu/diary/It%20appears%20that%20the%20number%20of%20industrial%20devices%20accessible%20from%20the%20internet%20has%20risen%20by%2030%20thousand%20over%20the%20past%20three%20years/30860" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/It%20appears%20that%20the%20number%20of%20industrial%20devices%20accessible%20from%20the%20internet%20has%20risen%20by%2030%20thousand%20over%20the%20past%20three%20years/30860</a><br /> Evil XDR: Turning an XDR into an Offensive Tool<br /><a href="https://www.darkreading.com/application-security/evil-xdr-researcher-turns-palo-alto-software-into-perfect-malware" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/application-security/evil-xdr-researcher-turns-palo-alto-software-into-perfect-malware</a><br /> GitLab Comment Bug<br /><a href="https://www.bleepingcomputer.com/news/security/gitlab-affected-by-github-style-cdn-flaw-allowing-malware-hosting/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/gitlab-affected-by-github-style-cdn-flaw-allowing-malware-hosting/</a><br /> SEC522 Demo: <a href="https://www.sans.org/ondemand/get-demo/316" target="_blank" rel="noreferrer noopener">https://www.sans.org/ondemand/get-demo/316</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8950.mp3</guid><pubDate>Tue, 23 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59605524/8950.mp3" length="5425120" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Number of Industrial Devices Accessible From Internet Up 30 Thousand over three years...</itunes:subtitle><itunes:summary><![CDATA[Number of Industrial Devices Accessible From Internet Up 30 Thousand over three years<br /><a href="https://isc.sans.edu/diary/It%20appears%20that%20the%20number%20of%20industrial%20devices%20accessible%20from%20the%20internet%20has%20risen%20by%2030%20thousand%20over%20the%20past%20three%20years/30860" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/It%20appears%20that%20the%20number%20of%20industrial%20devices%20accessible%20from%20the%20internet%20has%20risen%20by%2030%20thousand%20over%20the%20past%20three%20years/30860</a><br /> Evil XDR: Turning an XDR into an Offensive Tool<br /><a href="https://www.darkreading.com/application-security/evil-xdr-researcher-turns-palo-alto-software-into-perfect-malware" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/application-security/evil-xdr-researcher-turns-palo-alto-software-into-perfect-malware</a><br /> GitLab Comment Bug<br /><a href="https://www.bleepingcomputer.com/news/security/gitlab-affected-by-github-style-cdn-flaw-allowing-malware-hosting/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/gitlab-affected-by-github-style-cdn-flaw-allowing-malware-hosting/</a><br /> SEC522 Demo: <a href="https://www.sans.org/ondemand/get-demo/316" target="_blank" rel="noreferrer noopener">https://www.sans.org/ondemand/get-demo/316</a><br />]]></itunes:summary><itunes:duration>366</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,gitlab; xdr; evil xdr; ics,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8950</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, April 22nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-april-22nd-2024--62129405</link><description><![CDATA[The CVE's They are A-Changing<br /><a href="https://isc.sans.edu/diary/The%20CVE%27s%20They%20are%20A-Changing!/30850" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20CVE%27s%20They%20are%20A-Changing!/30850</a><br /> CrushFTP 0-Day Vulnerability<br /><a href="https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update" target="_blank" rel="noreferrer noopener">https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update</a><br /><a href="https://www.reddit.com/r/crowdstrike/comments/1c88788/situational_awareness_20240419_crushftp_virtual/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/crowdstrike/comments/1c88788/situational_awareness_20240419_crushftp_virtual/</a><br /> GitHub Comment Bug Used to Distribute Malware<br /><a href="https://www.bleepingcomputer.com/news/security/github-comments-abused-to-push-malware-via-microsoft-repo-urls/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/github-comments-abused-to-push-malware-via-microsoft-repo-urls/</a><br /> YubiKey Manager Privilege Escalation<br /><a href="https://www.yubico.com/support/security-advisories/ysa-2024-01/" target="_blank" rel="noreferrer noopener">https://www.yubico.com/support/security-advisories/ysa-2024-01/</a><br /> Palo Alto Networks GlobalProtect Update<br /><a href="https://security.paloaltonetworks.com/CVE-2024-3400" target="_blank" rel="noreferrer noopener">https://security.paloaltonetworks.com/CVE-2024-3400</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8948.mp3</guid><pubDate>Mon, 22 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129405/8948.mp3" length="5011362" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>The CVE's They are A-Changing
https://isc.sans.edu/diary/The%20CVE%27s%20They%20are%20A-Changing!/30850
 CrushFTP 0-Day Vulnerability
https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update...</itunes:subtitle><itunes:summary><![CDATA[The CVE's They are A-Changing<br /><a href="https://isc.sans.edu/diary/The%20CVE%27s%20They%20are%20A-Changing!/30850" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20CVE%27s%20They%20are%20A-Changing!/30850</a><br /> CrushFTP 0-Day Vulnerability<br /><a href="https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update" target="_blank" rel="noreferrer noopener">https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update</a><br /><a href="https://www.reddit.com/r/crowdstrike/comments/1c88788/situational_awareness_20240419_crushftp_virtual/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/crowdstrike/comments/1c88788/situational_awareness_20240419_crushftp_virtual/</a><br /> GitHub Comment Bug Used to Distribute Malware<br /><a href="https://www.bleepingcomputer.com/news/security/github-comments-abused-to-push-malware-via-microsoft-repo-urls/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/github-comments-abused-to-push-malware-via-microsoft-repo-urls/</a><br /> YubiKey Manager Privilege Escalation<br /><a href="https://www.yubico.com/support/security-advisories/ysa-2024-01/" target="_blank" rel="noreferrer noopener">https://www.yubico.com/support/security-advisories/ysa-2024-01/</a><br /> Palo Alto Networks GlobalProtect Update<br /><a href="https://security.paloaltonetworks.com/CVE-2024-3400" target="_blank" rel="noreferrer noopener">https://security.paloaltonetworks.com/CVE-2024-3400</a><br />]]></itunes:summary><itunes:duration>336</itunes:duration><itunes:keywords>business,computer,cve; crushftp; github; yubikey,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8948</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, April 22nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-april-22nd-2024--59578439</link><description><![CDATA[The CVE's They are A-Changing<br /><a href="https://isc.sans.edu/diary/The%20CVE%27s%20They%20are%20A-Changing!/30850" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20CVE%27s%20They%20are%20A-Changing!/30850</a><br /> CrushFTP 0-Day Vulnerability<br /><a href="https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update" target="_blank" rel="noreferrer noopener">https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update</a><br /><a href="https://www.reddit.com/r/crowdstrike/comments/1c88788/situational_awareness_20240419_crushftp_virtual/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/crowdstrike/comments/1c88788/situational_awareness_20240419_crushftp_virtual/</a><br /> GitHub Comment Bug Used to Distribute Malware<br /><a href="https://www.bleepingcomputer.com/news/security/github-comments-abused-to-push-malware-via-microsoft-repo-urls/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/github-comments-abused-to-push-malware-via-microsoft-repo-urls/</a><br /> YubiKey Manager Privilege Escalation<br /><a href="https://www.yubico.com/support/security-advisories/ysa-2024-01/" target="_blank" rel="noreferrer noopener">https://www.yubico.com/support/security-advisories/ysa-2024-01/</a><br /> Palo Alto Networks GlobalProtect Update<br /><a href="https://security.paloaltonetworks.com/CVE-2024-3400" target="_blank" rel="noreferrer noopener">https://security.paloaltonetworks.com/CVE-2024-3400</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8948.mp3</guid><pubDate>Mon, 22 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59578439/8948.mp3" length="5011362" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>The CVE's They are A-Changing
https://isc.sans.edu/diary/The%20CVE%27s%20They%20are%20A-Changing!/30850
 CrushFTP 0-Day Vulnerability
https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update...</itunes:subtitle><itunes:summary><![CDATA[The CVE's They are A-Changing<br /><a href="https://isc.sans.edu/diary/The%20CVE%27s%20They%20are%20A-Changing!/30850" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20CVE%27s%20They%20are%20A-Changing!/30850</a><br /> CrushFTP 0-Day Vulnerability<br /><a href="https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update" target="_blank" rel="noreferrer noopener">https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update</a><br /><a href="https://www.reddit.com/r/crowdstrike/comments/1c88788/situational_awareness_20240419_crushftp_virtual/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/crowdstrike/comments/1c88788/situational_awareness_20240419_crushftp_virtual/</a><br /> GitHub Comment Bug Used to Distribute Malware<br /><a href="https://www.bleepingcomputer.com/news/security/github-comments-abused-to-push-malware-via-microsoft-repo-urls/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/github-comments-abused-to-push-malware-via-microsoft-repo-urls/</a><br /> YubiKey Manager Privilege Escalation<br /><a href="https://www.yubico.com/support/security-advisories/ysa-2024-01/" target="_blank" rel="noreferrer noopener">https://www.yubico.com/support/security-advisories/ysa-2024-01/</a><br /> Palo Alto Networks GlobalProtect Update<br /><a href="https://security.paloaltonetworks.com/CVE-2024-3400" target="_blank" rel="noreferrer noopener">https://security.paloaltonetworks.com/CVE-2024-3400</a><br />]]></itunes:summary><itunes:duration>336</itunes:duration><itunes:keywords>business,computer,cve; crushftp; github; yubikey,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8948</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, April 19th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-april-19th-2024--62129400</link><description><![CDATA[Delinea Secret Server Authn Authz Bypass<br /><a href="https://straightblast.medium.com/all-your-secrets-are-belong-to-us-a-delinea-secret-server-authn-authz-bypass-adc26c800ad3" target="_blank" rel="noreferrer noopener">https://straightblast.medium.com/all-your-secrets-are-belong-to-us-a-delinea-secret-server-authn-authz-bypass-adc26c800ad3</a><br /> Ivanti Avalanche Poc/Details<br /><a href="https://www.tenable.com/security/research/tra-2024-10" target="_blank" rel="noreferrer noopener">https://www.tenable.com/security/research/tra-2024-10</a><br /> Advanced Phishing Campaign<br /><a href="https://www.lookout.com/threat-intelligence/article/cryptochameleon-fcc-phishing-kit" target="_blank" rel="noreferrer noopener">https://www.lookout.com/threat-intelligence/article/cryptochameleon-fcc-phishing-kit</a><br /> Hashicorp go-getter update CVE-2024-3817<br /><a href="https://discuss.hashicorp.com/t/hcsec-2024-09-hashicorp-go-getter-vulnerable-to-argument-injection-when-fetching-remote-default-git-branches/66040" target="_blank" rel="noreferrer noopener">https://discuss.hashicorp.com/t/hcsec-2024-09-hashicorp-go-getter-vulnerable-to-argument-injection-when-fetching-remote-default-git-branches/66040</a><br /> OfflRouter Virus<br /><a href="https://blog.talosintelligence.com/offlrouter-virus-causes-upload-confidential-documents-to-virustotal/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/offlrouter-virus-causes-upload-confidential-documents-to-virustotal/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8946.mp3</guid><pubDate>Fri, 19 Apr 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129400/8946.mp3" length="4600797" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Delinea Secret Server Authn Authz Bypass
https://straightblast.medium.com/all-your-secrets-are-belong-to-us-a-delinea-secret-server-authn-authz-bypass-adc26c800ad3
 Ivanti Avalanche Poc/Details
https://www.tenable.com/security/research/tra-2024-10...</itunes:subtitle><itunes:summary><![CDATA[Delinea Secret Server Authn Authz Bypass<br /><a href="https://straightblast.medium.com/all-your-secrets-are-belong-to-us-a-delinea-secret-server-authn-authz-bypass-adc26c800ad3" target="_blank" rel="noreferrer noopener">https://straightblast.medium.com/all-your-secrets-are-belong-to-us-a-delinea-secret-server-authn-authz-bypass-adc26c800ad3</a><br /> Ivanti Avalanche Poc/Details<br /><a href="https://www.tenable.com/security/research/tra-2024-10" target="_blank" rel="noreferrer noopener">https://www.tenable.com/security/research/tra-2024-10</a><br /> Advanced Phishing Campaign<br /><a href="https://www.lookout.com/threat-intelligence/article/cryptochameleon-fcc-phishing-kit" target="_blank" rel="noreferrer noopener">https://www.lookout.com/threat-intelligence/article/cryptochameleon-fcc-phishing-kit</a><br /> Hashicorp go-getter update CVE-2024-3817<br /><a href="https://discuss.hashicorp.com/t/hcsec-2024-09-hashicorp-go-getter-vulnerable-to-argument-injection-when-fetching-remote-default-git-branches/66040" target="_blank" rel="noreferrer noopener">https://discuss.hashicorp.com/t/hcsec-2024-09-hashicorp-go-getter-vulnerable-to-argument-injection-when-fetching-remote-default-git-branches/66040</a><br /> OfflRouter Virus<br /><a href="https://blog.talosintelligence.com/offlrouter-virus-causes-upload-confidential-documents-to-virustotal/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/offlrouter-virus-causes-upload-confidential-documents-to-virustotal/</a><br />]]></itunes:summary><itunes:duration>307</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,offlrouter; ukraine; hashicorp,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8946</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, April 19th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-april-19th-2024--59541069</link><description><![CDATA[Delinea Secret Server Authn Authz Bypass<br /><a href="https://straightblast.medium.com/all-your-secrets-are-belong-to-us-a-delinea-secret-server-authn-authz-bypass-adc26c800ad3" target="_blank" rel="noreferrer noopener">https://straightblast.medium.com/all-your-secrets-are-belong-to-us-a-delinea-secret-server-authn-authz-bypass-adc26c800ad3</a><br /> Ivanti Avalanche Poc/Details<br /><a href="https://www.tenable.com/security/research/tra-2024-10" target="_blank" rel="noreferrer noopener">https://www.tenable.com/security/research/tra-2024-10</a><br /> Advanced Phishing Campaign<br /><a href="https://www.lookout.com/threat-intelligence/article/cryptochameleon-fcc-phishing-kit" target="_blank" rel="noreferrer noopener">https://www.lookout.com/threat-intelligence/article/cryptochameleon-fcc-phishing-kit</a><br /> Hashicorp go-getter update CVE-2024-3817<br /><a href="https://discuss.hashicorp.com/t/hcsec-2024-09-hashicorp-go-getter-vulnerable-to-argument-injection-when-fetching-remote-default-git-branches/66040" target="_blank" rel="noreferrer noopener">https://discuss.hashicorp.com/t/hcsec-2024-09-hashicorp-go-getter-vulnerable-to-argument-injection-when-fetching-remote-default-git-branches/66040</a><br /> OfflRouter Virus<br /><a href="https://blog.talosintelligence.com/offlrouter-virus-causes-upload-confidential-documents-to-virustotal/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/offlrouter-virus-causes-upload-confidential-documents-to-virustotal/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8946.mp3</guid><pubDate>Fri, 19 Apr 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59541069/8946.mp3" length="4600797" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Delinea Secret Server Authn Authz Bypass
https://straightblast.medium.com/all-your-secrets-are-belong-to-us-a-delinea-secret-server-authn-authz-bypass-adc26c800ad3
 Ivanti Avalanche Poc/Details
https://www.tenable.com/security/research/tra-2024-10...</itunes:subtitle><itunes:summary><![CDATA[Delinea Secret Server Authn Authz Bypass<br /><a href="https://straightblast.medium.com/all-your-secrets-are-belong-to-us-a-delinea-secret-server-authn-authz-bypass-adc26c800ad3" target="_blank" rel="noreferrer noopener">https://straightblast.medium.com/all-your-secrets-are-belong-to-us-a-delinea-secret-server-authn-authz-bypass-adc26c800ad3</a><br /> Ivanti Avalanche Poc/Details<br /><a href="https://www.tenable.com/security/research/tra-2024-10" target="_blank" rel="noreferrer noopener">https://www.tenable.com/security/research/tra-2024-10</a><br /> Advanced Phishing Campaign<br /><a href="https://www.lookout.com/threat-intelligence/article/cryptochameleon-fcc-phishing-kit" target="_blank" rel="noreferrer noopener">https://www.lookout.com/threat-intelligence/article/cryptochameleon-fcc-phishing-kit</a><br /> Hashicorp go-getter update CVE-2024-3817<br /><a href="https://discuss.hashicorp.com/t/hcsec-2024-09-hashicorp-go-getter-vulnerable-to-argument-injection-when-fetching-remote-default-git-branches/66040" target="_blank" rel="noreferrer noopener">https://discuss.hashicorp.com/t/hcsec-2024-09-hashicorp-go-getter-vulnerable-to-argument-injection-when-fetching-remote-default-git-branches/66040</a><br /> OfflRouter Virus<br /><a href="https://blog.talosintelligence.com/offlrouter-virus-causes-upload-confidential-documents-to-virustotal/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/offlrouter-virus-causes-upload-confidential-documents-to-virustotal/</a><br />]]></itunes:summary><itunes:duration>307</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,offlrouter; ukraine; hashicorp,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8946</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, April 18th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-april-18th-2024--62129408</link><description><![CDATA[Malicious PDF File As Delivery Mechanism<br /><a href="https://isc.sans.edu/diary/Malicious%20PDF%20File%20Used%20As%20Delivery%20Mechanism/30848" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Malicious%20PDF%20File%20Used%20As%20Delivery%20Mechanism/30848</a><br /> Updated Palo Alto Networks GlobalProtect Guidance<br /><a href="https://security.paloaltonetworks.com/CVE-2024-3400" target="_blank" rel="noreferrer noopener">https://security.paloaltonetworks.com/CVE-2024-3400</a><br /> Coordinated Social Engineering Takeovers of Open Source Projects;<br /><a href="https://openssf.org/blog/2024/04/15/open-source-security-openssf-and-openjs-foundations-issue-alert-for-social-engineering-takeovers-of-open-source-projects/" target="_blank" rel="noreferrer noopener">https://openssf.org/blog/2024/04/15/open-source-security-openssf-and-openjs-foundations-issue-alert-for-social-engineering-takeovers-of-open-source-projects/</a><br /> OpenMetaData Attacks<br /><a href="https://www.microsoft.com/en-us/security/blog/2024/04/17/attackers-exploiting-new-critical-openmetadata-vulnerabilities-on-kubernetes-clusters/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2024/04/17/attackers-exploiting-new-critical-openmetadata-vulnerabilities-on-kubernetes-clusters/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8944.mp3</guid><pubDate>Thu, 18 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129408/8944.mp3" length="4779531" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Malicious PDF File As Delivery Mechanism
https://isc.sans.edu/diary/Malicious%20PDF%20File%20Used%20As%20Delivery%20Mechanism/30848
 Updated Palo Alto Networks GlobalProtect Guidance
https://security.paloaltonetworks.com/CVE-2024-3400
 Coordinated...</itunes:subtitle><itunes:summary><![CDATA[Malicious PDF File As Delivery Mechanism<br /><a href="https://isc.sans.edu/diary/Malicious%20PDF%20File%20Used%20As%20Delivery%20Mechanism/30848" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Malicious%20PDF%20File%20Used%20As%20Delivery%20Mechanism/30848</a><br /> Updated Palo Alto Networks GlobalProtect Guidance<br /><a href="https://security.paloaltonetworks.com/CVE-2024-3400" target="_blank" rel="noreferrer noopener">https://security.paloaltonetworks.com/CVE-2024-3400</a><br /> Coordinated Social Engineering Takeovers of Open Source Projects;<br /><a href="https://openssf.org/blog/2024/04/15/open-source-security-openssf-and-openjs-foundations-issue-alert-for-social-engineering-takeovers-of-open-source-projects/" target="_blank" rel="noreferrer noopener">https://openssf.org/blog/2024/04/15/open-source-security-openssf-and-openjs-foundations-issue-alert-for-social-engineering-takeovers-of-open-source-projects/</a><br /> OpenMetaData Attacks<br /><a href="https://www.microsoft.com/en-us/security/blog/2024/04/17/attackers-exploiting-new-critical-openmetadata-vulnerabilities-on-kubernetes-clusters/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2024/04/17/attackers-exploiting-new-critical-openmetadata-vulnerabilities-on-kubernetes-clusters/</a><br />]]></itunes:summary><itunes:duration>320</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,openmetadata; social engineeri,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8944</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, April 18th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-april-18th-2024--59522820</link><description><![CDATA[Malicious PDF File As Delivery Mechanism<br /><a href="https://isc.sans.edu/diary/Malicious%20PDF%20File%20Used%20As%20Delivery%20Mechanism/30848" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Malicious%20PDF%20File%20Used%20As%20Delivery%20Mechanism/30848</a><br /> Updated Palo Alto Networks GlobalProtect Guidance<br /><a href="https://security.paloaltonetworks.com/CVE-2024-3400" target="_blank" rel="noreferrer noopener">https://security.paloaltonetworks.com/CVE-2024-3400</a><br /> Coordinated Social Engineering Takeovers of Open Source Projects;<br /><a href="https://openssf.org/blog/2024/04/15/open-source-security-openssf-and-openjs-foundations-issue-alert-for-social-engineering-takeovers-of-open-source-projects/" target="_blank" rel="noreferrer noopener">https://openssf.org/blog/2024/04/15/open-source-security-openssf-and-openjs-foundations-issue-alert-for-social-engineering-takeovers-of-open-source-projects/</a><br /> OpenMetaData Attacks<br /><a href="https://www.microsoft.com/en-us/security/blog/2024/04/17/attackers-exploiting-new-critical-openmetadata-vulnerabilities-on-kubernetes-clusters/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2024/04/17/attackers-exploiting-new-critical-openmetadata-vulnerabilities-on-kubernetes-clusters/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8944.mp3</guid><pubDate>Thu, 18 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59522820/8944.mp3" length="4779531" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Malicious PDF File As Delivery Mechanism
https://isc.sans.edu/diary/Malicious%20PDF%20File%20Used%20As%20Delivery%20Mechanism/30848
 Updated Palo Alto Networks GlobalProtect Guidance
https://security.paloaltonetworks.com/CVE-2024-3400
 Coordinated...</itunes:subtitle><itunes:summary><![CDATA[Malicious PDF File As Delivery Mechanism<br /><a href="https://isc.sans.edu/diary/Malicious%20PDF%20File%20Used%20As%20Delivery%20Mechanism/30848" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Malicious%20PDF%20File%20Used%20As%20Delivery%20Mechanism/30848</a><br /> Updated Palo Alto Networks GlobalProtect Guidance<br /><a href="https://security.paloaltonetworks.com/CVE-2024-3400" target="_blank" rel="noreferrer noopener">https://security.paloaltonetworks.com/CVE-2024-3400</a><br /> Coordinated Social Engineering Takeovers of Open Source Projects;<br /><a href="https://openssf.org/blog/2024/04/15/open-source-security-openssf-and-openjs-foundations-issue-alert-for-social-engineering-takeovers-of-open-source-projects/" target="_blank" rel="noreferrer noopener">https://openssf.org/blog/2024/04/15/open-source-security-openssf-and-openjs-foundations-issue-alert-for-social-engineering-takeovers-of-open-source-projects/</a><br /> OpenMetaData Attacks<br /><a href="https://www.microsoft.com/en-us/security/blog/2024/04/17/attackers-exploiting-new-critical-openmetadata-vulnerabilities-on-kubernetes-clusters/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2024/04/17/attackers-exploiting-new-critical-openmetadata-vulnerabilities-on-kubernetes-clusters/</a><br />]]></itunes:summary><itunes:duration>320</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,openmetadata; social engineeri,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8944</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, April 17th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-april-17th-2024--62129378</link><description><![CDATA[Palo Alto Networks GlobalProtect exploit public and widely exploited CVE-2024-3400<br /><a href="https://isc.sans.edu/forums/diary/Palo%20Alto%20Networks%20GlobalProtect%20exploit%20public%20and%20widely%20exploited%20CVE-2024-3400/30844/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Palo%20Alto%20Networks%20GlobalProtect%20exploit%20public%20and%20widely%20exploited%20CVE-2024-3400/30844/</a><br /> Putty Private Key Recovery<br /><a href="https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.html" target="_blank" rel="noreferrer noopener">https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.html</a><br /> Oracle Critical Patch Update<br /><a href="https://www.oracle.com/security-alerts/cpuapr2024.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpuapr2024.html</a><br /> Ivanti Avalanche MDM Patches<br /><a href="https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8942.mp3</guid><pubDate>Wed, 17 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129378/8942.mp3" length="4977956" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Palo Alto Networks GlobalProtect exploit public and widely exploited CVE-2024-3400
https://isc.sans.edu/forums/diary/Palo%20Alto%20Networks%20GlobalProtect%20exploit%20public%20and%20widely%20exploited%20CVE-2024-3400/30844/
 Putty Private Key...</itunes:subtitle><itunes:summary><![CDATA[Palo Alto Networks GlobalProtect exploit public and widely exploited CVE-2024-3400<br /><a href="https://isc.sans.edu/forums/diary/Palo%20Alto%20Networks%20GlobalProtect%20exploit%20public%20and%20widely%20exploited%20CVE-2024-3400/30844/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Palo%20Alto%20Networks%20GlobalProtect%20exploit%20public%20and%20widely%20exploited%20CVE-2024-3400/30844/</a><br /> Putty Private Key Recovery<br /><a href="https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.html" target="_blank" rel="noreferrer noopener">https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.html</a><br /> Oracle Critical Patch Update<br /><a href="https://www.oracle.com/security-alerts/cpuapr2024.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpuapr2024.html</a><br /> Ivanti Avalanche MDM Patches<br /><a href="https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US</a><br />]]></itunes:summary><itunes:duration>334</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,ivanti; avalanche; oracle; cpu,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8942</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, April 17th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-april-17th-2024--59496520</link><description><![CDATA[Palo Alto Networks GlobalProtect exploit public and widely exploited CVE-2024-3400<br /><a href="https://isc.sans.edu/forums/diary/Palo%20Alto%20Networks%20GlobalProtect%20exploit%20public%20and%20widely%20exploited%20CVE-2024-3400/30844/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Palo%20Alto%20Networks%20GlobalProtect%20exploit%20public%20and%20widely%20exploited%20CVE-2024-3400/30844/</a><br /> Putty Private Key Recovery<br /><a href="https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.html" target="_blank" rel="noreferrer noopener">https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.html</a><br /> Oracle Critical Patch Update<br /><a href="https://www.oracle.com/security-alerts/cpuapr2024.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpuapr2024.html</a><br /> Ivanti Avalanche MDM Patches<br /><a href="https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8942.mp3</guid><pubDate>Wed, 17 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59496520/8942.mp3" length="4977956" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Palo Alto Networks GlobalProtect exploit public and widely exploited CVE-2024-3400
https://isc.sans.edu/forums/diary/Palo%20Alto%20Networks%20GlobalProtect%20exploit%20public%20and%20widely%20exploited%20CVE-2024-3400/30844/
 Putty Private Key...</itunes:subtitle><itunes:summary><![CDATA[Palo Alto Networks GlobalProtect exploit public and widely exploited CVE-2024-3400<br /><a href="https://isc.sans.edu/forums/diary/Palo%20Alto%20Networks%20GlobalProtect%20exploit%20public%20and%20widely%20exploited%20CVE-2024-3400/30844/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Palo%20Alto%20Networks%20GlobalProtect%20exploit%20public%20and%20widely%20exploited%20CVE-2024-3400/30844/</a><br /> Putty Private Key Recovery<br /><a href="https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.html" target="_blank" rel="noreferrer noopener">https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.html</a><br /> Oracle Critical Patch Update<br /><a href="https://www.oracle.com/security-alerts/cpuapr2024.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpuapr2024.html</a><br /> Ivanti Avalanche MDM Patches<br /><a href="https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US</a><br />]]></itunes:summary><itunes:duration>334</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,ivanti; avalanche; oracle; cpu,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8942</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, April 16th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-april-16th-2024--62129415</link><description><![CDATA[Quick Palo Alto Networks Global Protect Vulnerablity Update CVE-2024-3400<br /><a href="https://isc.sans.edu/diary/30838" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/30838</a><br /> Delinea patches critical vulnerability in secret manager<br /><a href="https://trust.delinea.com/?tcuUid=17aaf4ef-ada9-46d5-bf97-abd3b07daae3" target="_blank" rel="noreferrer noopener">https://trust.delinea.com/?tcuUid=17aaf4ef-ada9-46d5-bf97-abd3b07daae3</a><br /> Lancom Windows Setup Assistant May Reset Password<br /><a href="https://www.lancom-systems.com/service-support/general-security-information" target="_blank" rel="noreferrer noopener">https://www.lancom-systems.com/service-support/general-security-information</a><br /> PHP Patches<br /><a href="https://seclists.org/oss-sec/2024/q2/113" target="_blank" rel="noreferrer noopener">https://seclists.org/oss-sec/2024/q2/113</a><br /> Duo SMS and VoiP Logs Leaked<br /><a href="https://app.securitymsp.cisco.com/e/es?e=2785&amp;eid=opguvrs&amp;elq=bd1c1886a59e40c09915b029a74be94e" target="_blank" rel="noreferrer noopener">https://app.securitymsp.cisco.com/e/es?e=2785&amp;eid=opguvrs&amp;elq=bd1c1886a59e40c09915b029a74be94e</a><br /> Lastpass Stops Deepfake Attack<br /><a href="https://blog.lastpass.com/posts/2024/04/attempted-audio-deepfake-call-targets-lastpass-employee" target="_blank" rel="noreferrer noopener">https://blog.lastpass.com/posts/2024/04/attempted-audio-deepfake-call-targets-lastpass-employee</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8940.mp3</guid><pubDate>Tue, 16 Apr 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129415/8940.mp3" length="5587860" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Quick Palo Alto Networks Global Protect Vulnerablity Update CVE-2024-3400
https://isc.sans.edu/diary/30838
 Delinea patches critical vulnerability in secret manager
https://trust.delinea.com/?tcuUid=17aaf4ef-ada9-46d5-bf97-abd3b07daae3
 Lancom Windows...</itunes:subtitle><itunes:summary><![CDATA[Quick Palo Alto Networks Global Protect Vulnerablity Update CVE-2024-3400<br /><a href="https://isc.sans.edu/diary/30838" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/30838</a><br /> Delinea patches critical vulnerability in secret manager<br /><a href="https://trust.delinea.com/?tcuUid=17aaf4ef-ada9-46d5-bf97-abd3b07daae3" target="_blank" rel="noreferrer noopener">https://trust.delinea.com/?tcuUid=17aaf4ef-ada9-46d5-bf97-abd3b07daae3</a><br /> Lancom Windows Setup Assistant May Reset Password<br /><a href="https://www.lancom-systems.com/service-support/general-security-information" target="_blank" rel="noreferrer noopener">https://www.lancom-systems.com/service-support/general-security-information</a><br /> PHP Patches<br /><a href="https://seclists.org/oss-sec/2024/q2/113" target="_blank" rel="noreferrer noopener">https://seclists.org/oss-sec/2024/q2/113</a><br /> Duo SMS and VoiP Logs Leaked<br /><a href="https://app.securitymsp.cisco.com/e/es?e=2785&amp;eid=opguvrs&amp;elq=bd1c1886a59e40c09915b029a74be94e" target="_blank" rel="noreferrer noopener">https://app.securitymsp.cisco.com/e/es?e=2785&amp;eid=opguvrs&amp;elq=bd1c1886a59e40c09915b029a74be94e</a><br /> Lastpass Stops Deepfake Attack<br /><a href="https://blog.lastpass.com/posts/2024/04/attempted-audio-deepfake-call-targets-lastpass-employee" target="_blank" rel="noreferrer noopener">https://blog.lastpass.com/posts/2024/04/attempted-audio-deepfake-call-targets-lastpass-employee</a><br />]]></itunes:summary><itunes:duration>377</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,delinea; secret manager; lanco,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8940</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, April 16th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-april-16th-2024--59481710</link><description><![CDATA[Quick Palo Alto Networks Global Protect Vulnerablity Update CVE-2024-3400<br /><a href="https://isc.sans.edu/diary/30838" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/30838</a><br /> Delinea patches critical vulnerability in secret manager<br /><a href="https://trust.delinea.com/?tcuUid=17aaf4ef-ada9-46d5-bf97-abd3b07daae3" target="_blank" rel="noreferrer noopener">https://trust.delinea.com/?tcuUid=17aaf4ef-ada9-46d5-bf97-abd3b07daae3</a><br /> Lancom Windows Setup Assistant May Reset Password<br /><a href="https://www.lancom-systems.com/service-support/general-security-information" target="_blank" rel="noreferrer noopener">https://www.lancom-systems.com/service-support/general-security-information</a><br /> PHP Patches<br /><a href="https://seclists.org/oss-sec/2024/q2/113" target="_blank" rel="noreferrer noopener">https://seclists.org/oss-sec/2024/q2/113</a><br /> Duo SMS and VoiP Logs Leaked<br /><a href="https://app.securitymsp.cisco.com/e/es?e=2785&amp;eid=opguvrs&amp;elq=bd1c1886a59e40c09915b029a74be94e" target="_blank" rel="noreferrer noopener">https://app.securitymsp.cisco.com/e/es?e=2785&amp;eid=opguvrs&amp;elq=bd1c1886a59e40c09915b029a74be94e</a><br /> Lastpass Stops Deepfake Attack<br /><a href="https://blog.lastpass.com/posts/2024/04/attempted-audio-deepfake-call-targets-lastpass-employee" target="_blank" rel="noreferrer noopener">https://blog.lastpass.com/posts/2024/04/attempted-audio-deepfake-call-targets-lastpass-employee</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8940.mp3</guid><pubDate>Tue, 16 Apr 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59481710/8940.mp3" length="5587860" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Quick Palo Alto Networks Global Protect Vulnerablity Update CVE-2024-3400
https://isc.sans.edu/diary/30838
 Delinea patches critical vulnerability in secret manager
https://trust.delinea.com/?tcuUid=17aaf4ef-ada9-46d5-bf97-abd3b07daae3
 Lancom Windows...</itunes:subtitle><itunes:summary><![CDATA[Quick Palo Alto Networks Global Protect Vulnerablity Update CVE-2024-3400<br /><a href="https://isc.sans.edu/diary/30838" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/30838</a><br /> Delinea patches critical vulnerability in secret manager<br /><a href="https://trust.delinea.com/?tcuUid=17aaf4ef-ada9-46d5-bf97-abd3b07daae3" target="_blank" rel="noreferrer noopener">https://trust.delinea.com/?tcuUid=17aaf4ef-ada9-46d5-bf97-abd3b07daae3</a><br /> Lancom Windows Setup Assistant May Reset Password<br /><a href="https://www.lancom-systems.com/service-support/general-security-information" target="_blank" rel="noreferrer noopener">https://www.lancom-systems.com/service-support/general-security-information</a><br /> PHP Patches<br /><a href="https://seclists.org/oss-sec/2024/q2/113" target="_blank" rel="noreferrer noopener">https://seclists.org/oss-sec/2024/q2/113</a><br /> Duo SMS and VoiP Logs Leaked<br /><a href="https://app.securitymsp.cisco.com/e/es?e=2785&amp;eid=opguvrs&amp;elq=bd1c1886a59e40c09915b029a74be94e" target="_blank" rel="noreferrer noopener">https://app.securitymsp.cisco.com/e/es?e=2785&amp;eid=opguvrs&amp;elq=bd1c1886a59e40c09915b029a74be94e</a><br /> Lastpass Stops Deepfake Attack<br /><a href="https://blog.lastpass.com/posts/2024/04/attempted-audio-deepfake-call-targets-lastpass-employee" target="_blank" rel="noreferrer noopener">https://blog.lastpass.com/posts/2024/04/attempted-audio-deepfake-call-targets-lastpass-employee</a><br />]]></itunes:summary><itunes:duration>377</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,delinea; secret manager; lanco,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8940</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Sunday, April 14th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-sunday-april-14th-2024--62129364</link><description><![CDATA[Palo Alto Networks GlobalProtect 0-Day CVE-2024-3400<br /><a href="https://security.paloaltonetworks.com/CVE-2024-3400" target="_blank" rel="noreferrer noopener">https://security.paloaltonetworks.com/CVE-2024-3400</a><br /><a href="https://www.volexity.com/blog/2024/04/12/zero-day-exploitation-of-unauthenticated-remote-code-execution-vulnerability-in-globalprotect-cve-2024-3400/#RespondingToCompromise" target="_blank" rel="noreferrer noopener">https://www.volexity.com/blog/2024/04/12/zero-day-exploitation-of-unauthenticated-remote-code-execution-vulnerability-in-globalprotect-cve-2024-3400/#RespondingToCompromise</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8938.mp3</guid><pubDate>Sat, 13 Apr 2024 19:58:48 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129364/8938.mp3" length="5079188" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Palo Alto Networks GlobalProtect 0-Day CVE-2024-3400
https://security.paloaltonetworks.com/CVE-2024-3400...</itunes:subtitle><itunes:summary><![CDATA[Palo Alto Networks GlobalProtect 0-Day CVE-2024-3400<br /><a href="https://security.paloaltonetworks.com/CVE-2024-3400" target="_blank" rel="noreferrer noopener">https://security.paloaltonetworks.com/CVE-2024-3400</a><br /><a href="https://www.volexity.com/blog/2024/04/12/zero-day-exploitation-of-unauthenticated-remote-code-execution-vulnerability-in-globalprotect-cve-2024-3400/#RespondingToCompromise" target="_blank" rel="noreferrer noopener">https://www.volexity.com/blog/2024/04/12/zero-day-exploitation-of-unauthenticated-remote-code-execution-vulnerability-in-globalprotect-cve-2024-3400/#RespondingToCompromise</a><br />]]></itunes:summary><itunes:duration>341</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,palo alto networks; pan; panos,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8938</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Sunday, April 14th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-sunday-april-14th-2024--59451428</link><description><![CDATA[Palo Alto Networks GlobalProtect 0-Day CVE-2024-3400<br /><a href="https://security.paloaltonetworks.com/CVE-2024-3400" target="_blank" rel="noreferrer noopener">https://security.paloaltonetworks.com/CVE-2024-3400</a><br /><a href="https://www.volexity.com/blog/2024/04/12/zero-day-exploitation-of-unauthenticated-remote-code-execution-vulnerability-in-globalprotect-cve-2024-3400/#RespondingToCompromise" target="_blank" rel="noreferrer noopener">https://www.volexity.com/blog/2024/04/12/zero-day-exploitation-of-unauthenticated-remote-code-execution-vulnerability-in-globalprotect-cve-2024-3400/#RespondingToCompromise</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8938.mp3</guid><pubDate>Sat, 13 Apr 2024 19:58:48 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59451428/8938.mp3" length="5079188" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Palo Alto Networks GlobalProtect 0-Day CVE-2024-3400
https://security.paloaltonetworks.com/CVE-2024-3400...</itunes:subtitle><itunes:summary><![CDATA[Palo Alto Networks GlobalProtect 0-Day CVE-2024-3400<br /><a href="https://security.paloaltonetworks.com/CVE-2024-3400" target="_blank" rel="noreferrer noopener">https://security.paloaltonetworks.com/CVE-2024-3400</a><br /><a href="https://www.volexity.com/blog/2024/04/12/zero-day-exploitation-of-unauthenticated-remote-code-execution-vulnerability-in-globalprotect-cve-2024-3400/#RespondingToCompromise" target="_blank" rel="noreferrer noopener">https://www.volexity.com/blog/2024/04/12/zero-day-exploitation-of-unauthenticated-remote-code-execution-vulnerability-in-globalprotect-cve-2024-3400/#RespondingToCompromise</a><br />]]></itunes:summary><itunes:duration>341</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,palo alto networks; pan; panos,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8938</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, April 12th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-april-12th-2024--62129413</link><description><![CDATA[BatBadBut: You can't securely execute commands on Windows<br /><a href="https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows/" target="_blank" rel="noreferrer noopener">https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows/</a><br /> FortiClient Linux Remote Code Execution<br /><a href="https://www.fortiguard.com/psirt/FG-IR-23-087" target="_blank" rel="noreferrer noopener">https://www.fortiguard.com/psirt/FG-IR-23-087</a><br /> Apple Threat Notifications and Protecting Against Mercenary Spyware<br /><a href="https://support.apple.com/en-us/102174" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/102174</a><br /> New Technique to Trick Developers Detected in an Open Source Supply Chain Attack<br /><a href="https://checkmarx.com/blog/new-technique-to-trick-developers-detected-in-an-open-source-supply-chain-attack/" target="_blank" rel="noreferrer noopener">https://checkmarx.com/blog/new-technique-to-trick-developers-detected-in-an-open-source-supply-chain-attack/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8936.mp3</guid><pubDate>Fri, 12 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129413/8936.mp3" length="5509514" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>BatBadBut: You can't securely execute commands on Windows
https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows/
 FortiClient Linux Remote Code Execution
https://www.fortiguard.com/psirt/FG-IR-23-087
 Apple Threat...</itunes:subtitle><itunes:summary><![CDATA[BatBadBut: You can't securely execute commands on Windows<br /><a href="https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows/" target="_blank" rel="noreferrer noopener">https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows/</a><br /> FortiClient Linux Remote Code Execution<br /><a href="https://www.fortiguard.com/psirt/FG-IR-23-087" target="_blank" rel="noreferrer noopener">https://www.fortiguard.com/psirt/FG-IR-23-087</a><br /> Apple Threat Notifications and Protecting Against Mercenary Spyware<br /><a href="https://support.apple.com/en-us/102174" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/102174</a><br /> New Technique to Trick Developers Detected in an Open Source Supply Chain Attack<br /><a href="https://checkmarx.com/blog/new-technique-to-trick-developers-detected-in-an-open-source-supply-chain-attack/" target="_blank" rel="noreferrer noopener">https://checkmarx.com/blog/new-technique-to-trick-developers-detected-in-an-open-source-supply-chain-attack/</a><br />]]></itunes:summary><itunes:duration>372</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,github; supply chain; search; ,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8936</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, April 12th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-april-12th-2024--59429884</link><description><![CDATA[BatBadBut: You can't securely execute commands on Windows<br /><a href="https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows/" target="_blank" rel="noreferrer noopener">https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows/</a><br /> FortiClient Linux Remote Code Execution<br /><a href="https://www.fortiguard.com/psirt/FG-IR-23-087" target="_blank" rel="noreferrer noopener">https://www.fortiguard.com/psirt/FG-IR-23-087</a><br /> Apple Threat Notifications and Protecting Against Mercenary Spyware<br /><a href="https://support.apple.com/en-us/102174" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/102174</a><br /> New Technique to Trick Developers Detected in an Open Source Supply Chain Attack<br /><a href="https://checkmarx.com/blog/new-technique-to-trick-developers-detected-in-an-open-source-supply-chain-attack/" target="_blank" rel="noreferrer noopener">https://checkmarx.com/blog/new-technique-to-trick-developers-detected-in-an-open-source-supply-chain-attack/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8936.mp3</guid><pubDate>Fri, 12 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59429884/8936.mp3" length="5509514" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>BatBadBut: You can't securely execute commands on Windows
https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows/
 FortiClient Linux Remote Code Execution
https://www.fortiguard.com/psirt/FG-IR-23-087
 Apple Threat...</itunes:subtitle><itunes:summary><![CDATA[BatBadBut: You can't securely execute commands on Windows<br /><a href="https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows/" target="_blank" rel="noreferrer noopener">https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows/</a><br /> FortiClient Linux Remote Code Execution<br /><a href="https://www.fortiguard.com/psirt/FG-IR-23-087" target="_blank" rel="noreferrer noopener">https://www.fortiguard.com/psirt/FG-IR-23-087</a><br /> Apple Threat Notifications and Protecting Against Mercenary Spyware<br /><a href="https://support.apple.com/en-us/102174" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/102174</a><br /> New Technique to Trick Developers Detected in an Open Source Supply Chain Attack<br /><a href="https://checkmarx.com/blog/new-technique-to-trick-developers-detected-in-an-open-source-supply-chain-attack/" target="_blank" rel="noreferrer noopener">https://checkmarx.com/blog/new-technique-to-trick-developers-detected-in-an-open-source-supply-chain-attack/</a><br />]]></itunes:summary><itunes:duration>372</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,github; supply chain; search; ,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8936</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, April 11th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-april-11th-2024--62129381</link><description><![CDATA[Rust Command API code execution vulnerability CVE-2024-24576<br /><a href="https://blog.rust-lang.org/2024/04/09/cve-2024-24576.html" target="_blank" rel="noreferrer noopener">https://blog.rust-lang.org/2024/04/09/cve-2024-24576.html</a> <br /> Adobe Updates: Magento Adobe Commerce CVE-2024-20759 CVE-2024-20758<br /><a href="https://helpx.adobe.com/security/products/magento/apsb24-18.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/products/magento/apsb24-18.html</a><br /><a href="https://helpx.adobe.com/security.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security.html</a><br /> Fortinet FortiOS And FortiProxy Vulnerability CVE-2023-41677<br /><a href="https://www.fortiguard.com/psirt/FG-IR-23-493" target="_blank" rel="noreferrer noopener">https://www.fortiguard.com/psirt/FG-IR-23-493</a><br /> Smoke and Screen Mirrors Signed Backdoor CVE-2024-26234 <br /><a href="https://news.sophos.com/en-us/2024/04/09/smoke-and-screen-mirrors-a-strange-signed-backdoor/" target="_blank" rel="noreferrer noopener">https://news.sophos.com/en-us/2024/04/09/smoke-and-screen-mirrors-a-strange-signed-backdoor/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8934.mp3</guid><pubDate>Thu, 11 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129381/8934.mp3" length="5329921" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Rust Command API code execution vulnerability CVE-2024-24576
https://blog.rust-lang.org/2024/04/09/cve-2024-24576.html 
 Adobe Updates: Magento Adobe Commerce CVE-2024-20759 CVE-2024-20758...</itunes:subtitle><itunes:summary><![CDATA[Rust Command API code execution vulnerability CVE-2024-24576<br /><a href="https://blog.rust-lang.org/2024/04/09/cve-2024-24576.html" target="_blank" rel="noreferrer noopener">https://blog.rust-lang.org/2024/04/09/cve-2024-24576.html</a> <br /> Adobe Updates: Magento Adobe Commerce CVE-2024-20759 CVE-2024-20758<br /><a href="https://helpx.adobe.com/security/products/magento/apsb24-18.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/products/magento/apsb24-18.html</a><br /><a href="https://helpx.adobe.com/security.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security.html</a><br /> Fortinet FortiOS And FortiProxy Vulnerability CVE-2023-41677<br /><a href="https://www.fortiguard.com/psirt/FG-IR-23-493" target="_blank" rel="noreferrer noopener">https://www.fortiguard.com/psirt/FG-IR-23-493</a><br /> Smoke and Screen Mirrors Signed Backdoor CVE-2024-26234 <br /><a href="https://news.sophos.com/en-us/2024/04/09/smoke-and-screen-mirrors-a-strange-signed-backdoor/" target="_blank" rel="noreferrer noopener">https://news.sophos.com/en-us/2024/04/09/smoke-and-screen-mirrors-a-strange-signed-backdoor/</a><br />]]></itunes:summary><itunes:duration>359</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,driver; backdoor; fortinet; fo,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8934</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, April 11th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-april-11th-2024--59409697</link><description><![CDATA[Rust Command API code execution vulnerability CVE-2024-24576<br /><a href="https://blog.rust-lang.org/2024/04/09/cve-2024-24576.html" target="_blank" rel="noreferrer noopener">https://blog.rust-lang.org/2024/04/09/cve-2024-24576.html</a> <br /> Adobe Updates: Magento Adobe Commerce CVE-2024-20759 CVE-2024-20758<br /><a href="https://helpx.adobe.com/security/products/magento/apsb24-18.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/products/magento/apsb24-18.html</a><br /><a href="https://helpx.adobe.com/security.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security.html</a><br /> Fortinet FortiOS And FortiProxy Vulnerability CVE-2023-41677<br /><a href="https://www.fortiguard.com/psirt/FG-IR-23-493" target="_blank" rel="noreferrer noopener">https://www.fortiguard.com/psirt/FG-IR-23-493</a><br /> Smoke and Screen Mirrors Signed Backdoor CVE-2024-26234 <br /><a href="https://news.sophos.com/en-us/2024/04/09/smoke-and-screen-mirrors-a-strange-signed-backdoor/" target="_blank" rel="noreferrer noopener">https://news.sophos.com/en-us/2024/04/09/smoke-and-screen-mirrors-a-strange-signed-backdoor/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8934.mp3</guid><pubDate>Thu, 11 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59409697/8934.mp3" length="5329921" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Rust Command API code execution vulnerability CVE-2024-24576
https://blog.rust-lang.org/2024/04/09/cve-2024-24576.html 
 Adobe Updates: Magento Adobe Commerce CVE-2024-20759 CVE-2024-20758...</itunes:subtitle><itunes:summary><![CDATA[Rust Command API code execution vulnerability CVE-2024-24576<br /><a href="https://blog.rust-lang.org/2024/04/09/cve-2024-24576.html" target="_blank" rel="noreferrer noopener">https://blog.rust-lang.org/2024/04/09/cve-2024-24576.html</a> <br /> Adobe Updates: Magento Adobe Commerce CVE-2024-20759 CVE-2024-20758<br /><a href="https://helpx.adobe.com/security/products/magento/apsb24-18.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/products/magento/apsb24-18.html</a><br /><a href="https://helpx.adobe.com/security.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security.html</a><br /> Fortinet FortiOS And FortiProxy Vulnerability CVE-2023-41677<br /><a href="https://www.fortiguard.com/psirt/FG-IR-23-493" target="_blank" rel="noreferrer noopener">https://www.fortiguard.com/psirt/FG-IR-23-493</a><br /> Smoke and Screen Mirrors Signed Backdoor CVE-2024-26234 <br /><a href="https://news.sophos.com/en-us/2024/04/09/smoke-and-screen-mirrors-a-strange-signed-backdoor/" target="_blank" rel="noreferrer noopener">https://news.sophos.com/en-us/2024/04/09/smoke-and-screen-mirrors-a-strange-signed-backdoor/</a><br />]]></itunes:summary><itunes:duration>359</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,driver; backdoor; fortinet; fo,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8934</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, April 10th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-april-10th-2024--62129418</link><description><![CDATA[Microsoft Patches<br /><a href="https://isc.sans.edu/forums/diary/April%202024%20Microsoft%20Patch%20Tuesday%20Summary/30822/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/April%202024%20Microsoft%20Patch%20Tuesday%20Summary/30822/</a><br /> D-Link NAS Backdoor<br /><a href="https://github.com/netsecfish/dlink" target="_blank" rel="noreferrer noopener">https://github.com/netsecfish/dlink</a><br /> LG SmartTV Vulnerabilities<br /><a href="https://www.bitdefender.com/blog/labs/vulnerabilities-identified-in-lg-webos/" target="_blank" rel="noreferrer noopener">https://www.bitdefender.com/blog/labs/vulnerabilities-identified-in-lg-webos/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8932.mp3</guid><pubDate>Wed, 10 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129418/8932.mp3" length="5778164" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft Patches
https://isc.sans.edu/forums/diary/April%202024%20Microsoft%20Patch%20Tuesday%20Summary/30822/
 D-Link NAS Backdoor
https://github.com/netsecfish/dlink
 LG SmartTV Vulnerabilities...</itunes:subtitle><itunes:summary><![CDATA[Microsoft Patches<br /><a href="https://isc.sans.edu/forums/diary/April%202024%20Microsoft%20Patch%20Tuesday%20Summary/30822/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/April%202024%20Microsoft%20Patch%20Tuesday%20Summary/30822/</a><br /> D-Link NAS Backdoor<br /><a href="https://github.com/netsecfish/dlink" target="_blank" rel="noreferrer noopener">https://github.com/netsecfish/dlink</a><br /> LG SmartTV Vulnerabilities<br /><a href="https://www.bitdefender.com/blog/labs/vulnerabilities-identified-in-lg-webos/" target="_blank" rel="noreferrer noopener">https://www.bitdefender.com/blog/labs/vulnerabilities-identified-in-lg-webos/</a><br />]]></itunes:summary><itunes:duration>391</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,lg; smarttv; d-link; nas; back,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8932</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, April 10th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-april-10th-2024--59381945</link><description><![CDATA[Microsoft Patches<br /><a href="https://isc.sans.edu/forums/diary/April%202024%20Microsoft%20Patch%20Tuesday%20Summary/30822/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/April%202024%20Microsoft%20Patch%20Tuesday%20Summary/30822/</a><br /> D-Link NAS Backdoor<br /><a href="https://github.com/netsecfish/dlink" target="_blank" rel="noreferrer noopener">https://github.com/netsecfish/dlink</a><br /> LG SmartTV Vulnerabilities<br /><a href="https://www.bitdefender.com/blog/labs/vulnerabilities-identified-in-lg-webos/" target="_blank" rel="noreferrer noopener">https://www.bitdefender.com/blog/labs/vulnerabilities-identified-in-lg-webos/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8932.mp3</guid><pubDate>Wed, 10 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59381945/8932.mp3" length="5778164" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft Patches
https://isc.sans.edu/forums/diary/April%202024%20Microsoft%20Patch%20Tuesday%20Summary/30822/
 D-Link NAS Backdoor
https://github.com/netsecfish/dlink
 LG SmartTV Vulnerabilities...</itunes:subtitle><itunes:summary><![CDATA[Microsoft Patches<br /><a href="https://isc.sans.edu/forums/diary/April%202024%20Microsoft%20Patch%20Tuesday%20Summary/30822/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/April%202024%20Microsoft%20Patch%20Tuesday%20Summary/30822/</a><br /> D-Link NAS Backdoor<br /><a href="https://github.com/netsecfish/dlink" target="_blank" rel="noreferrer noopener">https://github.com/netsecfish/dlink</a><br /> LG SmartTV Vulnerabilities<br /><a href="https://www.bitdefender.com/blog/labs/vulnerabilities-identified-in-lg-webos/" target="_blank" rel="noreferrer noopener">https://www.bitdefender.com/blog/labs/vulnerabilities-identified-in-lg-webos/</a><br />]]></itunes:summary><itunes:duration>391</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,lg; smarttv; d-link; nas; back,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8932</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, April 9th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-april-9th-2024--62129447</link><description><![CDATA[A Use Case for Adding Threat Hunting to Your Security Operations Team.<br /><a href="https://isc.sans.edu/diary/30816" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/30816</a><br /> Notepad++ Parasite Site<br /><a href="https://notepad-plus-plus.org/news/help-to-take-down-parasite-site/" target="_blank" rel="noreferrer noopener">https://notepad-plus-plus.org/news/help-to-take-down-parasite-site/</a><br /> Hugging Face Pickle File Vulnerablities<br /><a href="https://huggingface.co/blog/hugging-face-wiz-security-blog" target="_blank" rel="noreferrer noopener">https://huggingface.co/blog/hugging-face-wiz-security-blog</a><br /> Google Considers V8 Sandbox no longer experimental<br /><a href="https://v8.dev/blog/sandbox" target="_blank" rel="noreferrer noopener">https://v8.dev/blog/sandbox</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8930.mp3</guid><pubDate>Tue, 09 Apr 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129447/8930.mp3" length="5332082" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>A Use Case for Adding Threat Hunting to Your Security Operations Team.
https://isc.sans.edu/diary/30816
 Notepad++ Parasite Site
https://notepad-plus-plus.org/news/help-to-take-down-parasite-site/
 Hugging Face Pickle File Vulnerablities...</itunes:subtitle><itunes:summary><![CDATA[A Use Case for Adding Threat Hunting to Your Security Operations Team.<br /><a href="https://isc.sans.edu/diary/30816" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/30816</a><br /> Notepad++ Parasite Site<br /><a href="https://notepad-plus-plus.org/news/help-to-take-down-parasite-site/" target="_blank" rel="noreferrer noopener">https://notepad-plus-plus.org/news/help-to-take-down-parasite-site/</a><br /> Hugging Face Pickle File Vulnerablities<br /><a href="https://huggingface.co/blog/hugging-face-wiz-security-blog" target="_blank" rel="noreferrer noopener">https://huggingface.co/blog/hugging-face-wiz-security-blog</a><br /> Google Considers V8 Sandbox no longer experimental<br /><a href="https://v8.dev/blog/sandbox" target="_blank" rel="noreferrer noopener">https://v8.dev/blog/sandbox</a><br />]]></itunes:summary><itunes:duration>359</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,v8; google; hugging face; pick</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8930</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, April 9th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-april-9th-2024--59358649</link><description><![CDATA[A Use Case for Adding Threat Hunting to Your Security Operations Team.<br /><a href="https://isc.sans.edu/diary/30816" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/30816</a><br /> Notepad++ Parasite Site<br /><a href="https://notepad-plus-plus.org/news/help-to-take-down-parasite-site/" target="_blank" rel="noreferrer noopener">https://notepad-plus-plus.org/news/help-to-take-down-parasite-site/</a><br /> Hugging Face Pickle File Vulnerablities<br /><a href="https://huggingface.co/blog/hugging-face-wiz-security-blog" target="_blank" rel="noreferrer noopener">https://huggingface.co/blog/hugging-face-wiz-security-blog</a><br /> Google Considers V8 Sandbox no longer experimental<br /><a href="https://v8.dev/blog/sandbox" target="_blank" rel="noreferrer noopener">https://v8.dev/blog/sandbox</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8930.mp3</guid><pubDate>Tue, 09 Apr 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59358649/8930.mp3" length="5332082" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>A Use Case for Adding Threat Hunting to Your Security Operations Team.
https://isc.sans.edu/diary/30816
 Notepad++ Parasite Site
https://notepad-plus-plus.org/news/help-to-take-down-parasite-site/
 Hugging Face Pickle File Vulnerablities...</itunes:subtitle><itunes:summary><![CDATA[A Use Case for Adding Threat Hunting to Your Security Operations Team.<br /><a href="https://isc.sans.edu/diary/30816" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/30816</a><br /> Notepad++ Parasite Site<br /><a href="https://notepad-plus-plus.org/news/help-to-take-down-parasite-site/" target="_blank" rel="noreferrer noopener">https://notepad-plus-plus.org/news/help-to-take-down-parasite-site/</a><br /> Hugging Face Pickle File Vulnerablities<br /><a href="https://huggingface.co/blog/hugging-face-wiz-security-blog" target="_blank" rel="noreferrer noopener">https://huggingface.co/blog/hugging-face-wiz-security-blog</a><br /> Google Considers V8 Sandbox no longer experimental<br /><a href="https://v8.dev/blog/sandbox" target="_blank" rel="noreferrer noopener">https://v8.dev/blog/sandbox</a><br />]]></itunes:summary><itunes:duration>359</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,v8; google; hugging face; pick</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8930</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, April 8th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-april-8th-2024--62129422</link><description><![CDATA[Heartbleed 10th Anniversary<br /><a href="https://heartbleed.com/" target="_blank" rel="noreferrer noopener">https://heartbleed.com/</a><br /> Possible Libarchive Backdoor Vulnerability<br /><a href="https://github.com/libarchive/libarchive/pull/1609" target="_blank" rel="noreferrer noopener">https://github.com/libarchive/libarchive/pull/1609</a><br /> Magento XML Backdoor<br /><a href="https://sansec.io/research/magento-xml-backdoor" target="_blank" rel="noreferrer noopener">https://sansec.io/research/magento-xml-backdoor</a><br /> Google Public DNS's approach to fight against cache poisoning attacks<br /><a href="https://security.googleblog.com/2024/03/google-public-dnss-approach-to-fight.html" target="_blank" rel="noreferrer noopener">https://security.googleblog.com/2024/03/google-public-dnss-approach-to-fight.html</a><br /> Remote code execution (RCE)vulnerability in Brocade Fabric OS (CVE-2023-3454)<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/23215" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/23215</a><br /> SANS London April Evening Talk<br /><a href="https://sans.zoom.us/webinar/register/WN_ZLLnQKCCQCywLGm-CM4xQg#/registration" target="_blank" rel="noreferrer noopener">https://sans.zoom.us/webinar/register/WN_ZLLnQKCCQCywLGm-CM4xQg#/registration</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8928.mp3</guid><pubDate>Mon, 08 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129422/8928.mp3" length="4917328" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Heartbleed 10th Anniversary
https://heartbleed.com/
 Possible Libarchive Backdoor Vulnerability
https://github.com/libarchive/libarchive/pull/1609
 Magento XML Backdoor
https://sansec.io/research/magento-xml-backdoor
 Google Public DNS's approach to...</itunes:subtitle><itunes:summary><![CDATA[Heartbleed 10th Anniversary<br /><a href="https://heartbleed.com/" target="_blank" rel="noreferrer noopener">https://heartbleed.com/</a><br /> Possible Libarchive Backdoor Vulnerability<br /><a href="https://github.com/libarchive/libarchive/pull/1609" target="_blank" rel="noreferrer noopener">https://github.com/libarchive/libarchive/pull/1609</a><br /> Magento XML Backdoor<br /><a href="https://sansec.io/research/magento-xml-backdoor" target="_blank" rel="noreferrer noopener">https://sansec.io/research/magento-xml-backdoor</a><br /> Google Public DNS's approach to fight against cache poisoning attacks<br /><a href="https://security.googleblog.com/2024/03/google-public-dnss-approach-to-fight.html" target="_blank" rel="noreferrer noopener">https://security.googleblog.com/2024/03/google-public-dnss-approach-to-fight.html</a><br /> Remote code execution (RCE)vulnerability in Brocade Fabric OS (CVE-2023-3454)<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/23215" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/23215</a><br /> SANS London April Evening Talk<br /><a href="https://sans.zoom.us/webinar/register/WN_ZLLnQKCCQCywLGm-CM4xQg#/registration" target="_blank" rel="noreferrer noopener">https://sans.zoom.us/webinar/register/WN_ZLLnQKCCQCywLGm-CM4xQg#/registration</a><br />]]></itunes:summary><itunes:duration>330</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,heartbleed; xz-utils; magento;,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8928</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, April 8th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-april-8th-2024--59337954</link><description><![CDATA[Heartbleed 10th Anniversary<br /><a href="https://heartbleed.com/" target="_blank" rel="noreferrer noopener">https://heartbleed.com/</a><br /> Possible Libarchive Backdoor Vulnerability<br /><a href="https://github.com/libarchive/libarchive/pull/1609" target="_blank" rel="noreferrer noopener">https://github.com/libarchive/libarchive/pull/1609</a><br /> Magento XML Backdoor<br /><a href="https://sansec.io/research/magento-xml-backdoor" target="_blank" rel="noreferrer noopener">https://sansec.io/research/magento-xml-backdoor</a><br /> Google Public DNS's approach to fight against cache poisoning attacks<br /><a href="https://security.googleblog.com/2024/03/google-public-dnss-approach-to-fight.html" target="_blank" rel="noreferrer noopener">https://security.googleblog.com/2024/03/google-public-dnss-approach-to-fight.html</a><br /> Remote code execution (RCE)vulnerability in Brocade Fabric OS (CVE-2023-3454)<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/23215" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/23215</a><br /> SANS London April Evening Talk<br /><a href="https://sans.zoom.us/webinar/register/WN_ZLLnQKCCQCywLGm-CM4xQg#/registration" target="_blank" rel="noreferrer noopener">https://sans.zoom.us/webinar/register/WN_ZLLnQKCCQCywLGm-CM4xQg#/registration</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8928.mp3</guid><pubDate>Mon, 08 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59337954/8928.mp3" length="4917328" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Heartbleed 10th Anniversary
https://heartbleed.com/
 Possible Libarchive Backdoor Vulnerability
https://github.com/libarchive/libarchive/pull/1609
 Magento XML Backdoor
https://sansec.io/research/magento-xml-backdoor
 Google Public DNS's approach to...</itunes:subtitle><itunes:summary><![CDATA[Heartbleed 10th Anniversary<br /><a href="https://heartbleed.com/" target="_blank" rel="noreferrer noopener">https://heartbleed.com/</a><br /> Possible Libarchive Backdoor Vulnerability<br /><a href="https://github.com/libarchive/libarchive/pull/1609" target="_blank" rel="noreferrer noopener">https://github.com/libarchive/libarchive/pull/1609</a><br /> Magento XML Backdoor<br /><a href="https://sansec.io/research/magento-xml-backdoor" target="_blank" rel="noreferrer noopener">https://sansec.io/research/magento-xml-backdoor</a><br /> Google Public DNS's approach to fight against cache poisoning attacks<br /><a href="https://security.googleblog.com/2024/03/google-public-dnss-approach-to-fight.html" target="_blank" rel="noreferrer noopener">https://security.googleblog.com/2024/03/google-public-dnss-approach-to-fight.html</a><br /> Remote code execution (RCE)vulnerability in Brocade Fabric OS (CVE-2023-3454)<br /><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/23215" target="_blank" rel="noreferrer noopener">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/23215</a><br /> SANS London April Evening Talk<br /><a href="https://sans.zoom.us/webinar/register/WN_ZLLnQKCCQCywLGm-CM4xQg#/registration" target="_blank" rel="noreferrer noopener">https://sans.zoom.us/webinar/register/WN_ZLLnQKCCQCywLGm-CM4xQg#/registration</a><br />]]></itunes:summary><itunes:duration>330</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,heartbleed; xz-utils; magento;,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8928</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, April 5th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-april-5th-2024--62129414</link><description><![CDATA[Slicing up DoNex with Binary Ninja<br /><a href="https://isc.sans.edu/diary/Slicing%20up%20DoNex%20with%20Binary%20Ninja/30812" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Slicing%20up%20DoNex%20with%20Binary%20Ninja/30812</a><br /> HTTP/2 Continuation Flood<br /><a href="https://nowotarski.info/http2-continuation-flood-technical-details/" target="_blank" rel="noreferrer noopener">https://nowotarski.info/http2-continuation-flood-technical-details/</a><br /> Dangers of CSS in HTML Email<br /><a href="https://lutrasecurity.com/en/articles/kobold-letters/" target="_blank" rel="noreferrer noopener">https://lutrasecurity.com/en/articles/kobold-letters/</a><br /> Dan Mazzella: Infostealers in Automotive Headunits<br /><a href="https://www.sans.edu/cyber-research/exploring-infostealer-malware-techniques-automotive-head-units/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/exploring-infostealer-malware-techniques-automotive-head-units/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8926.mp3</guid><pubDate>Fri, 05 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129414/8926.mp3" length="13068938" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Slicing up DoNex with Binary Ninja
https://isc.sans.edu/diary/Slicing%20up%20DoNex%20with%20Binary%20Ninja/30812
 HTTP/2 Continuation Flood
https://nowotarski.info/http2-continuation-flood-technical-details/
 Dangers of CSS in HTML Email...</itunes:subtitle><itunes:summary><![CDATA[Slicing up DoNex with Binary Ninja<br /><a href="https://isc.sans.edu/diary/Slicing%20up%20DoNex%20with%20Binary%20Ninja/30812" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Slicing%20up%20DoNex%20with%20Binary%20Ninja/30812</a><br /> HTTP/2 Continuation Flood<br /><a href="https://nowotarski.info/http2-continuation-flood-technical-details/" target="_blank" rel="noreferrer noopener">https://nowotarski.info/http2-continuation-flood-technical-details/</a><br /> Dangers of CSS in HTML Email<br /><a href="https://lutrasecurity.com/en/articles/kobold-letters/" target="_blank" rel="noreferrer noopener">https://lutrasecurity.com/en/articles/kobold-letters/</a><br /> Dan Mazzella: Infostealers in Automotive Headunits<br /><a href="https://www.sans.edu/cyber-research/exploring-infostealer-malware-techniques-automotive-head-units/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/exploring-infostealer-malware-techniques-automotive-head-units/</a><br />]]></itunes:summary><itunes:duration>912</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,donex; binary ninja; http2; cs,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8926</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, April 5th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-april-5th-2024--59302085</link><description><![CDATA[Slicing up DoNex with Binary Ninja<br /><a href="https://isc.sans.edu/diary/Slicing%20up%20DoNex%20with%20Binary%20Ninja/30812" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Slicing%20up%20DoNex%20with%20Binary%20Ninja/30812</a><br /> HTTP/2 Continuation Flood<br /><a href="https://nowotarski.info/http2-continuation-flood-technical-details/" target="_blank" rel="noreferrer noopener">https://nowotarski.info/http2-continuation-flood-technical-details/</a><br /> Dangers of CSS in HTML Email<br /><a href="https://lutrasecurity.com/en/articles/kobold-letters/" target="_blank" rel="noreferrer noopener">https://lutrasecurity.com/en/articles/kobold-letters/</a><br /> Dan Mazella: Infostealers in Automotive Headunits<br /><a href="https://www.sans.edu/cyber-research/exploring-infostealer-malware-techniques-automotive-head-units/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/exploring-infostealer-malware-techniques-automotive-head-units/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8926.mp3</guid><pubDate>Fri, 05 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59302085/8926.mp3" length="13068938" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Slicing up DoNex with Binary Ninja
https://isc.sans.edu/diary/Slicing%20up%20DoNex%20with%20Binary%20Ninja/30812
 HTTP/2 Continuation Flood
https://nowotarski.info/http2-continuation-flood-technical-details/
 Dangers of CSS in HTML Email...</itunes:subtitle><itunes:summary><![CDATA[Slicing up DoNex with Binary Ninja<br /><a href="https://isc.sans.edu/diary/Slicing%20up%20DoNex%20with%20Binary%20Ninja/30812" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Slicing%20up%20DoNex%20with%20Binary%20Ninja/30812</a><br /> HTTP/2 Continuation Flood<br /><a href="https://nowotarski.info/http2-continuation-flood-technical-details/" target="_blank" rel="noreferrer noopener">https://nowotarski.info/http2-continuation-flood-technical-details/</a><br /> Dangers of CSS in HTML Email<br /><a href="https://lutrasecurity.com/en/articles/kobold-letters/" target="_blank" rel="noreferrer noopener">https://lutrasecurity.com/en/articles/kobold-letters/</a><br /> Dan Mazella: Infostealers in Automotive Headunits<br /><a href="https://www.sans.edu/cyber-research/exploring-infostealer-malware-techniques-automotive-head-units/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/exploring-infostealer-malware-techniques-automotive-head-units/</a><br />]]></itunes:summary><itunes:duration>912</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,donex; binary ninja; http2; cs,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8926</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, April 4th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-april-4th-2024--62129365</link><description><![CDATA[Playing with xzbot: Some things you can learn from SSH traffic<br /><a href="https://isc.sans.edu/forums/diary/Some%20things%20you%20can%20learn%20from%20SSH%20traffic/30808/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Some%20things%20you%20can%20learn%20from%20SSH%20traffic/30808/</a><br /> Google Proposes Device Bound Session Credentials (DBSC)<br /><a href="https://blog.chromium.org/2024/04/fighting-cookie-theft-using-device.html" target="_blank" rel="noreferrer noopener">https://blog.chromium.org/2024/04/fighting-cookie-theft-using-device.html</a><br /><br /> Four More Ivanti Vulnerabilities<br /><a href="https://forums.ivanti.com/s/article/SA-CVE-2024-21894-Heap-Overflow-CVE-2024-22052-Null-Pointer-Dereference-CVE-2024-22053-Heap-Overflow-and-CVE-2024-22023-XML-entity-expansion-or-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/SA-CVE-2024-21894-Heap-Overflow-CVE-2024-22052-Null-Pointer-Dereference-CVE-2024-22053-Heap-Overflow-and-CVE-2024-22023-XML-entity-expansion-or-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US</a><br /> Google Pixel Zero Day<br /><a href="https://source.android.com/docs/security/bulletin/pixel/2024-04-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/pixel/2024-04-01</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8924.mp3</guid><pubDate>Thu, 04 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129365/8924.mp3" length="5380070" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Playing with xzbot: Some things you can learn from SSH traffic
https://isc.sans.edu/forums/diary/Some%20things%20you%20can%20learn%20from%20SSH%20traffic/30808/
 Google Proposes Device Bound Session Credentials (DBSC)...</itunes:subtitle><itunes:summary><![CDATA[Playing with xzbot: Some things you can learn from SSH traffic<br /><a href="https://isc.sans.edu/forums/diary/Some%20things%20you%20can%20learn%20from%20SSH%20traffic/30808/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Some%20things%20you%20can%20learn%20from%20SSH%20traffic/30808/</a><br /> Google Proposes Device Bound Session Credentials (DBSC)<br /><a href="https://blog.chromium.org/2024/04/fighting-cookie-theft-using-device.html" target="_blank" rel="noreferrer noopener">https://blog.chromium.org/2024/04/fighting-cookie-theft-using-device.html</a><br /><br /> Four More Ivanti Vulnerabilities<br /><a href="https://forums.ivanti.com/s/article/SA-CVE-2024-21894-Heap-Overflow-CVE-2024-22052-Null-Pointer-Dereference-CVE-2024-22053-Heap-Overflow-and-CVE-2024-22023-XML-entity-expansion-or-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/SA-CVE-2024-21894-Heap-Overflow-CVE-2024-22052-Null-Pointer-Dereference-CVE-2024-22053-Heap-Overflow-and-CVE-2024-22023-XML-entity-expansion-or-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US</a><br /> Google Pixel Zero Day<br /><a href="https://source.android.com/docs/security/bulletin/pixel/2024-04-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/pixel/2024-04-01</a><br />]]></itunes:summary><itunes:duration>363</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,google; pixel; cookies; sessio,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8924</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, April 4th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-april-4th-2024--59287000</link><description><![CDATA[Playing with xzbot: Some things you can learn from SSH traffic<br /><a href="https://isc.sans.edu/forums/diary/Some%20things%20you%20can%20learn%20from%20SSH%20traffic/30808/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Some%20things%20you%20can%20learn%20from%20SSH%20traffic/30808/</a><br /> Google Proposes Device Bound Session Credentials (DBSC)<br /><a href="https://blog.chromium.org/2024/04/fighting-cookie-theft-using-device.html" target="_blank" rel="noreferrer noopener">https://blog.chromium.org/2024/04/fighting-cookie-theft-using-device.html</a><br /><br /> Four More Ivanti Vulnerabilities<br /><a href="https://forums.ivanti.com/s/article/SA-CVE-2024-21894-Heap-Overflow-CVE-2024-22052-Null-Pointer-Dereference-CVE-2024-22053-Heap-Overflow-and-CVE-2024-22023-XML-entity-expansion-or-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/SA-CVE-2024-21894-Heap-Overflow-CVE-2024-22052-Null-Pointer-Dereference-CVE-2024-22053-Heap-Overflow-and-CVE-2024-22023-XML-entity-expansion-or-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US</a><br /> Google Pixel Zero Day<br /><a href="https://source.android.com/docs/security/bulletin/pixel/2024-04-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/pixel/2024-04-01</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8924.mp3</guid><pubDate>Thu, 04 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59287000/8924.mp3" length="5380070" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Playing with xzbot: Some things you can learn from SSH traffic
https://isc.sans.edu/forums/diary/Some%20things%20you%20can%20learn%20from%20SSH%20traffic/30808/
 Google Proposes Device Bound Session Credentials (DBSC)...</itunes:subtitle><itunes:summary><![CDATA[Playing with xzbot: Some things you can learn from SSH traffic<br /><a href="https://isc.sans.edu/forums/diary/Some%20things%20you%20can%20learn%20from%20SSH%20traffic/30808/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Some%20things%20you%20can%20learn%20from%20SSH%20traffic/30808/</a><br /> Google Proposes Device Bound Session Credentials (DBSC)<br /><a href="https://blog.chromium.org/2024/04/fighting-cookie-theft-using-device.html" target="_blank" rel="noreferrer noopener">https://blog.chromium.org/2024/04/fighting-cookie-theft-using-device.html</a><br /><br /> Four More Ivanti Vulnerabilities<br /><a href="https://forums.ivanti.com/s/article/SA-CVE-2024-21894-Heap-Overflow-CVE-2024-22052-Null-Pointer-Dereference-CVE-2024-22053-Heap-Overflow-and-CVE-2024-22023-XML-entity-expansion-or-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/SA-CVE-2024-21894-Heap-Overflow-CVE-2024-22052-Null-Pointer-Dereference-CVE-2024-22053-Heap-Overflow-and-CVE-2024-22023-XML-entity-expansion-or-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US</a><br /> Google Pixel Zero Day<br /><a href="https://source.android.com/docs/security/bulletin/pixel/2024-04-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/pixel/2024-04-01</a><br />]]></itunes:summary><itunes:duration>363</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,google; pixel; cookies; sessio,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8924</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, April 3rd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-april-3rd-2024--62129367</link><description><![CDATA[Chrome Incognito Mode Settlement<br /><a href="https://www.wired.com/story/google-chrome-incognito-mode-data-deletion-settlement/" target="_blank" rel="noreferrer noopener">https://www.wired.com/story/google-chrome-incognito-mode-data-deletion-settlement/</a><br /> Google E-Mail Sender Guidelines FAQ<br /><a href="https://support.google.com/a/answer/14229414?hl=en&amp;fl=1&amp;sjid=2270464422796374445-NC" target="_blank" rel="noreferrer noopener">https://support.google.com/a/answer/14229414?hl=en&amp;fl=1&amp;sjid=2270464422796374445-NC</a><br /> Cisco Updates and VPN Best Practices<br /><a href="https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221806-password-spray-attacks-impacting-custome.html" target="_blank" rel="noreferrer noopener">https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221806-password-spray-attacks-impacting-custome.html</a><br /><a href="https://sec.cloudapps.cisco.com/security/center/publicationListing.x" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/publicationListing.x</a><br /> Apache Pulsar Vulnerability<br /><a href="https://pulsar.apache.org/security/CVE-2024-29834/" target="_blank" rel="noreferrer noopener">https://pulsar.apache.org/security/CVE-2024-29834/</a><br /> Progress Flowmon Network Monitoring Tool Vulnerability CVE-2024-2389<br /><a href="https://support.kemptechnologies.com/hc/en-us/articles/24878235038733-CVE-2024-2389-Flowmon-critical-security-vulnerability" target="_blank" rel="noreferrer noopener">https://support.kemptechnologies.com/hc/en-us/articles/24878235038733-CVE-2024-2389-Flowmon-critical-security-vulnerability</a><br /> Wait Just an Infosec Episode with Bojan Zdrnja: Thursday April 4th 2024 10:00 EDST<br /><a href="https://isc.sans.edu/j/xzutils" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/j/xzutils</a> (link will redirect once episode is live)<br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8922.mp3</guid><pubDate>Wed, 03 Apr 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129367/8922.mp3" length="5061444" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Chrome Incognito Mode Settlement
https://www.wired.com/story/google-chrome-incognito-mode-data-deletion-settlement/
 Google E-Mail Sender Guidelines FAQ
https://support.google.com/a/answer/14229414?hl=en&amp;amp;fl=1&amp;amp;sjid=2270464422796374445-NC
 Cisco...</itunes:subtitle><itunes:summary><![CDATA[Chrome Incognito Mode Settlement<br /><a href="https://www.wired.com/story/google-chrome-incognito-mode-data-deletion-settlement/" target="_blank" rel="noreferrer noopener">https://www.wired.com/story/google-chrome-incognito-mode-data-deletion-settlement/</a><br /> Google E-Mail Sender Guidelines FAQ<br /><a href="https://support.google.com/a/answer/14229414?hl=en&amp;fl=1&amp;sjid=2270464422796374445-NC" target="_blank" rel="noreferrer noopener">https://support.google.com/a/answer/14229414?hl=en&amp;fl=1&amp;sjid=2270464422796374445-NC</a><br /> Cisco Updates and VPN Best Practices<br /><a href="https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221806-password-spray-attacks-impacting-custome.html" target="_blank" rel="noreferrer noopener">https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221806-password-spray-attacks-impacting-custome.html</a><br /><a href="https://sec.cloudapps.cisco.com/security/center/publicationListing.x" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/publicationListing.x</a><br /> Apache Pulsar Vulnerability<br /><a href="https://pulsar.apache.org/security/CVE-2024-29834/" target="_blank" rel="noreferrer noopener">https://pulsar.apache.org/security/CVE-2024-29834/</a><br /> Progress Flowmon Network Monitoring Tool Vulnerability CVE-2024-2389<br /><a href="https://support.kemptechnologies.com/hc/en-us/articles/24878235038733-CVE-2024-2389-Flowmon-critical-security-vulnerability" target="_blank" rel="noreferrer noopener">https://support.kemptechnologies.com/hc/en-us/articles/24878235038733-CVE-2024-2389-Flowmon-critical-security-vulnerability</a><br /> Wait Just an Infosec Episode with Bojan Zdrnja: Thursday April 4th 2024 10:00 EDST<br /><a href="https://isc.sans.edu/j/xzutils" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/j/xzutils</a> (link will redirect once episode is live)<br />]]></itunes:summary><itunes:duration>340</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,progress; flowmon; apache; pul,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8922</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, April 3rd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-april-3rd-2024--59270586</link><description><![CDATA[Chrome Incognito Mode Settlement<br /><a href="https://www.wired.com/story/google-chrome-incognito-mode-data-deletion-settlement/" target="_blank" rel="noreferrer noopener">https://www.wired.com/story/google-chrome-incognito-mode-data-deletion-settlement/</a><br /> Google E-Mail Sender Guidelines FAQ<br /><a href="https://support.google.com/a/answer/14229414?hl=en&amp;fl=1&amp;sjid=2270464422796374445-NC" target="_blank" rel="noreferrer noopener">https://support.google.com/a/answer/14229414?hl=en&amp;fl=1&amp;sjid=2270464422796374445-NC</a><br /> Cisco Updates and VPN Best Practices<br /><a href="https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221806-password-spray-attacks-impacting-custome.html" target="_blank" rel="noreferrer noopener">https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221806-password-spray-attacks-impacting-custome.html</a><br /><a href="https://sec.cloudapps.cisco.com/security/center/publicationListing.x" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/publicationListing.x</a><br /> Apache Pulsar Vulnerability<br /><a href="https://pulsar.apache.org/security/CVE-2024-29834/" target="_blank" rel="noreferrer noopener">https://pulsar.apache.org/security/CVE-2024-29834/</a><br /> Progress Flowmon Network Monitoring Tool Vulnerability CVE-2024-2389<br /><a href="https://support.kemptechnologies.com/hc/en-us/articles/24878235038733-CVE-2024-2389-Flowmon-critical-security-vulnerability" target="_blank" rel="noreferrer noopener">https://support.kemptechnologies.com/hc/en-us/articles/24878235038733-CVE-2024-2389-Flowmon-critical-security-vulnerability</a><br /> Wait Just an Infosec Episode with Bojan Zdrnja: Thursday April 4th 2024 10:00 EDST<br /><a href="https://isc.sans.edu/j/xzutils" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/j/xzutils</a> (link will redirect once episode is live)<br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8922.mp3</guid><pubDate>Wed, 03 Apr 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59270586/8922.mp3" length="5061444" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Chrome Incognito Mode Settlement
https://www.wired.com/story/google-chrome-incognito-mode-data-deletion-settlement/
 Google E-Mail Sender Guidelines FAQ
https://support.google.com/a/answer/14229414?hl=en&amp;amp;fl=1&amp;amp;sjid=2270464422796374445-NC
 Cisco...</itunes:subtitle><itunes:summary><![CDATA[Chrome Incognito Mode Settlement<br /><a href="https://www.wired.com/story/google-chrome-incognito-mode-data-deletion-settlement/" target="_blank" rel="noreferrer noopener">https://www.wired.com/story/google-chrome-incognito-mode-data-deletion-settlement/</a><br /> Google E-Mail Sender Guidelines FAQ<br /><a href="https://support.google.com/a/answer/14229414?hl=en&amp;fl=1&amp;sjid=2270464422796374445-NC" target="_blank" rel="noreferrer noopener">https://support.google.com/a/answer/14229414?hl=en&amp;fl=1&amp;sjid=2270464422796374445-NC</a><br /> Cisco Updates and VPN Best Practices<br /><a href="https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221806-password-spray-attacks-impacting-custome.html" target="_blank" rel="noreferrer noopener">https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221806-password-spray-attacks-impacting-custome.html</a><br /><a href="https://sec.cloudapps.cisco.com/security/center/publicationListing.x" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/publicationListing.x</a><br /> Apache Pulsar Vulnerability<br /><a href="https://pulsar.apache.org/security/CVE-2024-29834/" target="_blank" rel="noreferrer noopener">https://pulsar.apache.org/security/CVE-2024-29834/</a><br /> Progress Flowmon Network Monitoring Tool Vulnerability CVE-2024-2389<br /><a href="https://support.kemptechnologies.com/hc/en-us/articles/24878235038733-CVE-2024-2389-Flowmon-critical-security-vulnerability" target="_blank" rel="noreferrer noopener">https://support.kemptechnologies.com/hc/en-us/articles/24878235038733-CVE-2024-2389-Flowmon-critical-security-vulnerability</a><br /> Wait Just an Infosec Episode with Bojan Zdrnja: Thursday April 4th 2024 10:00 EDST<br /><a href="https://isc.sans.edu/j/xzutils" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/j/xzutils</a> (link will redirect once episode is live)<br />]]></itunes:summary><itunes:duration>340</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,progress; flowmon; apache; pul,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8922</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, April 2nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-april-2nd-2024--62129429</link><description><![CDATA[The amazingly scary xz sshd backdoor<br /><a href="https://isc.sans.edu/diary/The%20amazingly%20scary%20xz%20sshd%20backdoor/30802" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20amazingly%20scary%20xz%20sshd%20backdoor/30802</a><br /> The xz-utils backdoor in security advisories by national CSIRTs<br /><a href="https://isc.sans.edu/diary/The+xzutils+backdoor+in+security+advisories+by+national+CSIRTs/30800" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The+xzutils+backdoor+in+security+advisories+by+national+CSIRTs/30800</a><br /> Checking CSV Files<br /><a href="https://isc.sans.edu/diary/Checking%20CSV%20Files/30796" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Checking%20CSV%20Files/30796</a><br /> Infostealers Pose Threat to macOS<br /><a href="https://www.jamf.com/blog/infostealers-pose-threat-to-macos/" target="_blank" rel="noreferrer noopener">https://www.jamf.com/blog/infostealers-pose-threat-to-macos/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8920.mp3</guid><pubDate>Tue, 02 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129429/8920.mp3" length="6315950" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>The amazingly scary xz sshd backdoor
https://isc.sans.edu/diary/The%20amazingly%20scary%20xz%20sshd%20backdoor/30802
 The xz-utils backdoor in security advisories by national CSIRTs...</itunes:subtitle><itunes:summary><![CDATA[The amazingly scary xz sshd backdoor<br /><a href="https://isc.sans.edu/diary/The%20amazingly%20scary%20xz%20sshd%20backdoor/30802" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20amazingly%20scary%20xz%20sshd%20backdoor/30802</a><br /> The xz-utils backdoor in security advisories by national CSIRTs<br /><a href="https://isc.sans.edu/diary/The+xzutils+backdoor+in+security+advisories+by+national+CSIRTs/30800" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The+xzutils+backdoor+in+security+advisories+by+national+CSIRTs/30800</a><br /> Checking CSV Files<br /><a href="https://isc.sans.edu/diary/Checking%20CSV%20Files/30796" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Checking%20CSV%20Files/30796</a><br /> Infostealers Pose Threat to macOS<br /><a href="https://www.jamf.com/blog/infostealers-pose-threat-to-macos/" target="_blank" rel="noreferrer noopener">https://www.jamf.com/blog/infostealers-pose-threat-to-macos/</a><br />]]></itunes:summary><itunes:duration>430</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,infostealers; macos; cvs; xz-u,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8920</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, April 2nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-april-2nd-2024--59255854</link><description><![CDATA[The amazingly scary xz sshd backdoor<br /><a href="https://isc.sans.edu/diary/The%20amazingly%20scary%20xz%20sshd%20backdoor/30802" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20amazingly%20scary%20xz%20sshd%20backdoor/30802</a><br /> The xz-utils backdoor in security advisories by national CSIRTs<br /><a href="https://isc.sans.edu/diary/The+xzutils+backdoor+in+security+advisories+by+national+CSIRTs/30800" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The+xzutils+backdoor+in+security+advisories+by+national+CSIRTs/30800</a><br /> Checking CSV Files<br /><a href="https://isc.sans.edu/diary/Checking%20CSV%20Files/30796" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Checking%20CSV%20Files/30796</a><br /> Infostealers Pose Threat to macOS<br /><a href="https://www.jamf.com/blog/infostealers-pose-threat-to-macos/" target="_blank" rel="noreferrer noopener">https://www.jamf.com/blog/infostealers-pose-threat-to-macos/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8920.mp3</guid><pubDate>Tue, 02 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59255854/8920.mp3" length="6315950" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>The amazingly scary xz sshd backdoor
https://isc.sans.edu/diary/The%20amazingly%20scary%20xz%20sshd%20backdoor/30802
 The xz-utils backdoor in security advisories by national CSIRTs...</itunes:subtitle><itunes:summary><![CDATA[The amazingly scary xz sshd backdoor<br /><a href="https://isc.sans.edu/diary/The%20amazingly%20scary%20xz%20sshd%20backdoor/30802" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20amazingly%20scary%20xz%20sshd%20backdoor/30802</a><br /> The xz-utils backdoor in security advisories by national CSIRTs<br /><a href="https://isc.sans.edu/diary/The+xzutils+backdoor+in+security+advisories+by+national+CSIRTs/30800" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The+xzutils+backdoor+in+security+advisories+by+national+CSIRTs/30800</a><br /> Checking CSV Files<br /><a href="https://isc.sans.edu/diary/Checking%20CSV%20Files/30796" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Checking%20CSV%20Files/30796</a><br /> Infostealers Pose Threat to macOS<br /><a href="https://www.jamf.com/blog/infostealers-pose-threat-to-macos/" target="_blank" rel="noreferrer noopener">https://www.jamf.com/blog/infostealers-pose-threat-to-macos/</a><br />]]></itunes:summary><itunes:duration>430</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,infostealers; macos; cvs; xz-u,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8920</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, April 1st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-april-1st-2024--62129434</link><description><![CDATA[xz-utils Backdoor CVE-2024-3094<br /><a href="https://www.openwall.com/lists/oss-security/2024/03/29/4" target="_blank" rel="noreferrer noopener">https://www.openwall.com/lists/oss-security/2024/03/29/4</a><br /><a href="https://tukaani.org/xz-backdoor/" target="_blank" rel="noreferrer noopener">https://tukaani.org/xz-backdoor/</a><br /><a href="https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27" target="_blank" rel="noreferrer noopener">https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27</a><br /> Backdoor reverse analysis<br /><a href="https://bsky.app/profile/did:plc:x2nsupeeo52oznrmplwapppl/post/3kowjkx2njy2b" target="_blank" rel="noreferrer noopener">https://bsky.app/profile/did:plc:x2nsupeeo52oznrmplwapppl/post/3kowjkx2njy2b</a><br /> YARA Rule<br /><a href="https://github.com/byinarie/CVE-2024-3094-info/blob/main/CVE-2024-3094.yar" target="_blank" rel="noreferrer noopener">https://github.com/byinarie/CVE-2024-3094-info/blob/main/CVE-2024-3094.yar</a><br /> Social Engineering Attempts to Include Backdoor in Distros<br /><a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067708" target="_blank" rel="noreferrer noopener">https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067708</a><br /><a href="https://news.ycombinator.com/item?id=39866275" target="_blank" rel="noreferrer noopener">https://news.ycombinator.com/item?id=39866275</a><br /> Github Repo (now disabled)<br /><a href="https://github.com/tukaani-project/xz" target="_blank" rel="noreferrer noopener">https://github.com/tukaani-project/xz</a><br /> Statements from Distributions<br /><a href="https://www.kali.org/blog/about-the-xz-backdoor/" target="_blank" rel="noreferrer noopener">https://www.kali.org/blog/about-the-xz-backdoor/</a><br /><a href="https://archlinux.org/news/the-xz-package-has-been-backdoored/" target="_blank" rel="noreferrer noopener">https://archlinux.org/news/the-xz-package-has-been-backdoored/</a><br /><a href="https://access.redhat.com/security/cve/CVE-2024-3094" target="_blank" rel="noreferrer noopener">https://access.redhat.com/security/cve/CVE-2024-3094</a><br /><a href="https://bugs.gentoo.org/928134" target="_blank" rel="noreferrer noopener">https://bugs.gentoo.org/928134</a><br /><a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024" target="_blank" rel="noreferrer noopener">https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024</a><br /><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8918.mp3</guid><pubDate>Mon, 01 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129434/8918.mp3" length="6709262" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>xz-utils Backdoor CVE-2024-3094
https://www.openwall.com/lists/oss-security/2024/03/29/4
https://tukaani.org/xz-backdoor/
https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27
 Backdoor reverse analysis...</itunes:subtitle><itunes:summary><![CDATA[xz-utils Backdoor CVE-2024-3094<br /><a href="https://www.openwall.com/lists/oss-security/2024/03/29/4" target="_blank" rel="noreferrer noopener">https://www.openwall.com/lists/oss-security/2024/03/29/4</a><br /><a href="https://tukaani.org/xz-backdoor/" target="_blank" rel="noreferrer noopener">https://tukaani.org/xz-backdoor/</a><br /><a href="https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27" target="_blank" rel="noreferrer noopener">https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27</a><br /> Backdoor reverse analysis<br /><a href="https://bsky.app/profile/did:plc:x2nsupeeo52oznrmplwapppl/post/3kowjkx2njy2b" target="_blank" rel="noreferrer noopener">https://bsky.app/profile/did:plc:x2nsupeeo52oznrmplwapppl/post/3kowjkx2njy2b</a><br /> YARA Rule<br /><a href="https://github.com/byinarie/CVE-2024-3094-info/blob/main/CVE-2024-3094.yar" target="_blank" rel="noreferrer noopener">https://github.com/byinarie/CVE-2024-3094-info/blob/main/CVE-2024-3094.yar</a><br /> Social Engineering Attempts to Include Backdoor in Distros<br /><a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067708" target="_blank" rel="noreferrer noopener">https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067708</a><br /><a href="https://news.ycombinator.com/item?id=39866275" target="_blank" rel="noreferrer noopener">https://news.ycombinator.com/item?id=39866275</a><br /> Github Repo (now disabled)<br /><a href="https://github.com/tukaani-project/xz" target="_blank" rel="noreferrer noopener">https://github.com/tukaani-project/xz</a><br /> Statements from Distributions<br /><a href="https://www.kali.org/blog/about-the-xz-backdoor/" target="_blank" rel="noreferrer noopener">https://www.kali.org/blog/about-the-xz-backdoor/</a><br /><a href="https://archlinux.org/news/the-xz-package-has-been-backdoored/" target="_blank" rel="noreferrer noopener">https://archlinux.org/news/the-xz-package-has-been-backdoored/</a><br /><a href="https://access.redhat.com/security/cve/CVE-2024-3094" target="_blank" rel="noreferrer noopener">https://access.redhat.com/security/cve/CVE-2024-3094</a><br /><a href="https://bugs.gentoo.org/928134" target="_blank" rel="noreferrer noopener">https://bugs.gentoo.org/928134</a><br /><a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024" target="_blank" rel="noreferrer noopener">https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024</a><br /><br />]]></itunes:summary><itunes:duration>458</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,xz-utils; backdoor; xz</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8918</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, April 1st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-april-1st-2024--59242969</link><description><![CDATA[xz-utils Backdoor CVE-2024-3094<br /><a href="https://www.openwall.com/lists/oss-security/2024/03/29/4" target="_blank" rel="noreferrer noopener">https://www.openwall.com/lists/oss-security/2024/03/29/4</a><br /><a href="https://tukaani.org/xz-backdoor/" target="_blank" rel="noreferrer noopener">https://tukaani.org/xz-backdoor/</a><br /><a href="https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27" target="_blank" rel="noreferrer noopener">https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27</a><br /> Backdoor reverse analysis<br /><a href="https://bsky.app/profile/did:plc:x2nsupeeo52oznrmplwapppl/post/3kowjkx2njy2b" target="_blank" rel="noreferrer noopener">https://bsky.app/profile/did:plc:x2nsupeeo52oznrmplwapppl/post/3kowjkx2njy2b</a><br /> YARA Rule<br /><a href="https://github.com/byinarie/CVE-2024-3094-info/blob/main/CVE-2024-3094.yar" target="_blank" rel="noreferrer noopener">https://github.com/byinarie/CVE-2024-3094-info/blob/main/CVE-2024-3094.yar</a><br /> Social Engineering Attempts to Include Backdoor in Distros<br /><a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067708" target="_blank" rel="noreferrer noopener">https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067708</a><br /><a href="https://news.ycombinator.com/item?id=39866275" target="_blank" rel="noreferrer noopener">https://news.ycombinator.com/item?id=39866275</a><br /> Github Repo (now disabled)<br /><a href="https://github.com/tukaani-project/xz" target="_blank" rel="noreferrer noopener">https://github.com/tukaani-project/xz</a><br /> Statements from Distributions<br /><a href="https://www.kali.org/blog/about-the-xz-backdoor/" target="_blank" rel="noreferrer noopener">https://www.kali.org/blog/about-the-xz-backdoor/</a><br /><a href="https://archlinux.org/news/the-xz-package-has-been-backdoored/" target="_blank" rel="noreferrer noopener">https://archlinux.org/news/the-xz-package-has-been-backdoored/</a><br /><a href="https://access.redhat.com/security/cve/CVE-2024-3094" target="_blank" rel="noreferrer noopener">https://access.redhat.com/security/cve/CVE-2024-3094</a><br /><a href="https://bugs.gentoo.org/928134" target="_blank" rel="noreferrer noopener">https://bugs.gentoo.org/928134</a><br /><a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024" target="_blank" rel="noreferrer noopener">https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024</a><br /><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8918.mp3</guid><pubDate>Mon, 01 Apr 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59242969/8918.mp3" length="6709262" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>xz-utils Backdoor CVE-2024-3094
https://www.openwall.com/lists/oss-security/2024/03/29/4
https://tukaani.org/xz-backdoor/
https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27
 Backdoor reverse analysis...</itunes:subtitle><itunes:summary><![CDATA[xz-utils Backdoor CVE-2024-3094<br /><a href="https://www.openwall.com/lists/oss-security/2024/03/29/4" target="_blank" rel="noreferrer noopener">https://www.openwall.com/lists/oss-security/2024/03/29/4</a><br /><a href="https://tukaani.org/xz-backdoor/" target="_blank" rel="noreferrer noopener">https://tukaani.org/xz-backdoor/</a><br /><a href="https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27" target="_blank" rel="noreferrer noopener">https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27</a><br /> Backdoor reverse analysis<br /><a href="https://bsky.app/profile/did:plc:x2nsupeeo52oznrmplwapppl/post/3kowjkx2njy2b" target="_blank" rel="noreferrer noopener">https://bsky.app/profile/did:plc:x2nsupeeo52oznrmplwapppl/post/3kowjkx2njy2b</a><br /> YARA Rule<br /><a href="https://github.com/byinarie/CVE-2024-3094-info/blob/main/CVE-2024-3094.yar" target="_blank" rel="noreferrer noopener">https://github.com/byinarie/CVE-2024-3094-info/blob/main/CVE-2024-3094.yar</a><br /> Social Engineering Attempts to Include Backdoor in Distros<br /><a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067708" target="_blank" rel="noreferrer noopener">https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067708</a><br /><a href="https://news.ycombinator.com/item?id=39866275" target="_blank" rel="noreferrer noopener">https://news.ycombinator.com/item?id=39866275</a><br /> Github Repo (now disabled)<br /><a href="https://github.com/tukaani-project/xz" target="_blank" rel="noreferrer noopener">https://github.com/tukaani-project/xz</a><br /> Statements from Distributions<br /><a href="https://www.kali.org/blog/about-the-xz-backdoor/" target="_blank" rel="noreferrer noopener">https://www.kali.org/blog/about-the-xz-backdoor/</a><br /><a href="https://archlinux.org/news/the-xz-package-has-been-backdoored/" target="_blank" rel="noreferrer noopener">https://archlinux.org/news/the-xz-package-has-been-backdoored/</a><br /><a href="https://access.redhat.com/security/cve/CVE-2024-3094" target="_blank" rel="noreferrer noopener">https://access.redhat.com/security/cve/CVE-2024-3094</a><br /><a href="https://bugs.gentoo.org/928134" target="_blank" rel="noreferrer noopener">https://bugs.gentoo.org/928134</a><br /><a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024" target="_blank" rel="noreferrer noopener">https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024</a><br /><br />]]></itunes:summary><itunes:duration>458</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,xz-utils; backdoor; xz</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8918</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, March 29th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-march-29th-2024--62129406</link><description><![CDATA[From JavaScript to AsyncRAT<br /><a href="https://isc.sans.edu/diary/From%20JavaScript%20to%20AsyncRAT/30788" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/From%20JavaScript%20to%20AsyncRAT/30788</a><br /> TeamCity Patches<br /><a href="https://www.jetbrains.com/privacy-security/issues-fixed/?product=TeamCity&amp;version=2024.03" target="_blank" rel="noreferrer noopener">https://www.jetbrains.com/privacy-security/issues-fixed/?product=TeamCity&amp;version=2024.03</a><br /> Okta Verify for Windows Auto-update Arbitrary Code Execution CVE-2024-0980<br /><a href="https://trust.okta.com/security-advisories/okta-verify-windows-auto-update-arbitrary-code-execution-cve-2024-0980/" target="_blank" rel="noreferrer noopener">https://trust.okta.com/security-advisories/okta-verify-windows-auto-update-arbitrary-code-execution-cve-2024-0980/</a><br /> Google Zero Day Report<br /><a href="https://storage.googleapis.com/gweb-uniblog-publish-prod/documents/Year_in_Review_of_ZeroDays.pdf" target="_blank" rel="noreferrer noopener">https://storage.googleapis.com/gweb-uniblog-publish-prod/documents/Year_in_Review_of_ZeroDays.pdf</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8916.mp3</guid><pubDate>Fri, 29 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129406/8916.mp3" length="5016585" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>From JavaScript to AsyncRAT
https://isc.sans.edu/diary/From%20JavaScript%20to%20AsyncRAT/30788
 TeamCity Patches
https://www.jetbrains.com/privacy-security/issues-fixed/?product=TeamCity&amp;amp;version=2024.03
 Okta Verify for Windows Auto-update...</itunes:subtitle><itunes:summary><![CDATA[From JavaScript to AsyncRAT<br /><a href="https://isc.sans.edu/diary/From%20JavaScript%20to%20AsyncRAT/30788" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/From%20JavaScript%20to%20AsyncRAT/30788</a><br /> TeamCity Patches<br /><a href="https://www.jetbrains.com/privacy-security/issues-fixed/?product=TeamCity&amp;version=2024.03" target="_blank" rel="noreferrer noopener">https://www.jetbrains.com/privacy-security/issues-fixed/?product=TeamCity&amp;version=2024.03</a><br /> Okta Verify for Windows Auto-update Arbitrary Code Execution CVE-2024-0980<br /><a href="https://trust.okta.com/security-advisories/okta-verify-windows-auto-update-arbitrary-code-execution-cve-2024-0980/" target="_blank" rel="noreferrer noopener">https://trust.okta.com/security-advisories/okta-verify-windows-auto-update-arbitrary-code-execution-cve-2024-0980/</a><br /> Google Zero Day Report<br /><a href="https://storage.googleapis.com/gweb-uniblog-publish-prod/documents/Year_in_Review_of_ZeroDays.pdf" target="_blank" rel="noreferrer noopener">https://storage.googleapis.com/gweb-uniblog-publish-prod/documents/Year_in_Review_of_ZeroDays.pdf</a><br />]]></itunes:summary><itunes:duration>337</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,google; zero day; okta; teamci,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8916</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, March 29th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-march-29th-2024--59214780</link><description><![CDATA[From JavaScript to AsyncRAT<br /><a href="https://isc.sans.edu/diary/From%20JavaScript%20to%20AsyncRAT/30788" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/From%20JavaScript%20to%20AsyncRAT/30788</a><br /> TeamCity Patches<br /><a href="https://www.jetbrains.com/privacy-security/issues-fixed/?product=TeamCity&amp;version=2024.03" target="_blank" rel="noreferrer noopener">https://www.jetbrains.com/privacy-security/issues-fixed/?product=TeamCity&amp;version=2024.03</a><br /> Okta Verify for Windows Auto-update Arbitrary Code Execution CVE-2024-0980<br /><a href="https://trust.okta.com/security-advisories/okta-verify-windows-auto-update-arbitrary-code-execution-cve-2024-0980/" target="_blank" rel="noreferrer noopener">https://trust.okta.com/security-advisories/okta-verify-windows-auto-update-arbitrary-code-execution-cve-2024-0980/</a><br /> Google Zero Day Report<br /><a href="https://storage.googleapis.com/gweb-uniblog-publish-prod/documents/Year_in_Review_of_ZeroDays.pdf" target="_blank" rel="noreferrer noopener">https://storage.googleapis.com/gweb-uniblog-publish-prod/documents/Year_in_Review_of_ZeroDays.pdf</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8916.mp3</guid><pubDate>Fri, 29 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59214780/8916.mp3" length="5016585" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>From JavaScript to AsyncRAT
https://isc.sans.edu/diary/From%20JavaScript%20to%20AsyncRAT/30788
 TeamCity Patches
https://www.jetbrains.com/privacy-security/issues-fixed/?product=TeamCity&amp;amp;version=2024.03
 Okta Verify for Windows Auto-update...</itunes:subtitle><itunes:summary><![CDATA[From JavaScript to AsyncRAT<br /><a href="https://isc.sans.edu/diary/From%20JavaScript%20to%20AsyncRAT/30788" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/From%20JavaScript%20to%20AsyncRAT/30788</a><br /> TeamCity Patches<br /><a href="https://www.jetbrains.com/privacy-security/issues-fixed/?product=TeamCity&amp;version=2024.03" target="_blank" rel="noreferrer noopener">https://www.jetbrains.com/privacy-security/issues-fixed/?product=TeamCity&amp;version=2024.03</a><br /> Okta Verify for Windows Auto-update Arbitrary Code Execution CVE-2024-0980<br /><a href="https://trust.okta.com/security-advisories/okta-verify-windows-auto-update-arbitrary-code-execution-cve-2024-0980/" target="_blank" rel="noreferrer noopener">https://trust.okta.com/security-advisories/okta-verify-windows-auto-update-arbitrary-code-execution-cve-2024-0980/</a><br /> Google Zero Day Report<br /><a href="https://storage.googleapis.com/gweb-uniblog-publish-prod/documents/Year_in_Review_of_ZeroDays.pdf" target="_blank" rel="noreferrer noopener">https://storage.googleapis.com/gweb-uniblog-publish-prod/documents/Year_in_Review_of_ZeroDays.pdf</a><br />]]></itunes:summary><itunes:duration>337</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,google; zero day; okta; teamci,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8916</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, March 28th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-march-28th-2024--62129419</link><description><![CDATA[Scans for Apache OfBiz<br /><a href="https://isc.sans.edu/diary/Scans%20for%20Apache%20OfBiz/30784" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20Apache%20OfBiz/30784</a><br /> Wall-Escape (CVE-2024-28085)<br /><a href="https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txt" target="_blank" rel="noreferrer noopener">https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txt</a><br /> Recent "MFA Bombing" Attacks Targeting Apple Users<br /><a href="https://krebsonsecurity.com/2024/03/recent-mfa-bombing-attacks-targeting-apple-users/" target="_blank" rel="noreferrer noopener">https://krebsonsecurity.com/2024/03/recent-mfa-bombing-attacks-targeting-apple-users/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8914.mp3</guid><pubDate>Thu, 28 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129419/8914.mp3" length="4792897" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Scans for Apache OfBiz
https://isc.sans.edu/diary/Scans%20for%20Apache%20OfBiz/30784
 Wall-Escape (CVE-2024-28085)
https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txt
 Recent "MFA Bombing" Attacks Targeting Apple Users...</itunes:subtitle><itunes:summary><![CDATA[Scans for Apache OfBiz<br /><a href="https://isc.sans.edu/diary/Scans%20for%20Apache%20OfBiz/30784" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20Apache%20OfBiz/30784</a><br /> Wall-Escape (CVE-2024-28085)<br /><a href="https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txt" target="_blank" rel="noreferrer noopener">https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txt</a><br /> Recent "MFA Bombing" Attacks Targeting Apple Users<br /><a href="https://krebsonsecurity.com/2024/03/recent-mfa-bombing-attacks-targeting-apple-users/" target="_blank" rel="noreferrer noopener">https://krebsonsecurity.com/2024/03/recent-mfa-bombing-attacks-targeting-apple-users/</a><br />]]></itunes:summary><itunes:duration>321</itunes:duration><itunes:keywords>apple; mfa; bombing; wall; esc,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8914</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, March 28th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-march-28th-2024--59203068</link><description><![CDATA[Scans for Apache OfBiz<br /><a href="https://isc.sans.edu/diary/Scans%20for%20Apache%20OfBiz/30784" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20Apache%20OfBiz/30784</a><br /> Wall-Escape (CVE-2024-28085)<br /><a href="https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txt" target="_blank" rel="noreferrer noopener">https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txt</a><br /> Recent "MFA Bombing" Attacks Targeting Apple Users<br /><a href="https://krebsonsecurity.com/2024/03/recent-mfa-bombing-attacks-targeting-apple-users/" target="_blank" rel="noreferrer noopener">https://krebsonsecurity.com/2024/03/recent-mfa-bombing-attacks-targeting-apple-users/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8914.mp3</guid><pubDate>Thu, 28 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59203068/8914.mp3" length="4792897" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Scans for Apache OfBiz
https://isc.sans.edu/diary/Scans%20for%20Apache%20OfBiz/30784
 Wall-Escape (CVE-2024-28085)
https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txt
 Recent "MFA Bombing" Attacks Targeting Apple Users...</itunes:subtitle><itunes:summary><![CDATA[Scans for Apache OfBiz<br /><a href="https://isc.sans.edu/diary/Scans%20for%20Apache%20OfBiz/30784" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20Apache%20OfBiz/30784</a><br /> Wall-Escape (CVE-2024-28085)<br /><a href="https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txt" target="_blank" rel="noreferrer noopener">https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txt</a><br /> Recent "MFA Bombing" Attacks Targeting Apple Users<br /><a href="https://krebsonsecurity.com/2024/03/recent-mfa-bombing-attacks-targeting-apple-users/" target="_blank" rel="noreferrer noopener">https://krebsonsecurity.com/2024/03/recent-mfa-bombing-attacks-targeting-apple-users/</a><br />]]></itunes:summary><itunes:duration>321</itunes:duration><itunes:keywords>apple; mfa; bombing; wall; esc,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8914</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, March 27th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-march-27th-2024--62129449</link><description><![CDATA[New tool: linux-pkgs.sh<br /><a href="https://isc.sans.edu/forums/diary/New%20tool%3A%20linux-pkgs.sh/30774/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/New%20tool%3A%20linux-pkgs.sh/30774/</a><br /> Suspicious NuGet package grabs data from industrial systems<br /><a href="https://www.reversinglabs.com/blog/suspicious-nuget-package-grabs-data-from-industrial-systems" target="_blank" rel="noreferrer noopener">https://www.reversinglabs.com/blog/suspicious-nuget-package-grabs-data-from-industrial-systems</a><br /> Preventing Cross Service UDP Loops in QUIC<br /><a href="https://bughunters.google.com/blog/5960150648750080/preventing-cross-service-udp-loops-in-quic" target="_blank" rel="noreferrer noopener">https://bughunters.google.com/blog/5960150648750080/preventing-cross-service-udp-loops-in-quic</a><br /> ShadowRay Attacks AI Workloads Actively Exploited in the Wild<br /><a href="https://www.oligo.security/blog/shadowray-attack-ai-workloads-actively-exploited-in-the-wild" target="_blank" rel="noreferrer noopener">https://www.oligo.security/blog/shadowray-attack-ai-workloads-actively-exploited-in-the-wild</a><br /> TheMoon Malware Infects 6,000 ASUS Routers in 72 Hours for Proxy Service<br /><a href="https://www.bleepingcomputer.com/news/security/themoon-malware-infects-6-000-asus-routers-in-72-hours-for-proxy-service/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/themoon-malware-infects-6-000-asus-routers-in-72-hours-for-proxy-service/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8912.mp3</guid><pubDate>Wed, 27 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129449/8912.mp3" length="5185050" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>New tool: linux-pkgs.sh
https://isc.sans.edu/forums/diary/New%20tool%3A%20linux-pkgs.sh/30774/
 Suspicious NuGet package grabs data from industrial systems
https://www.reversinglabs.com/blog/suspicious-nuget-package-grabs-data-from-industrial-systems...</itunes:subtitle><itunes:summary><![CDATA[New tool: linux-pkgs.sh<br /><a href="https://isc.sans.edu/forums/diary/New%20tool%3A%20linux-pkgs.sh/30774/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/New%20tool%3A%20linux-pkgs.sh/30774/</a><br /> Suspicious NuGet package grabs data from industrial systems<br /><a href="https://www.reversinglabs.com/blog/suspicious-nuget-package-grabs-data-from-industrial-systems" target="_blank" rel="noreferrer noopener">https://www.reversinglabs.com/blog/suspicious-nuget-package-grabs-data-from-industrial-systems</a><br /> Preventing Cross Service UDP Loops in QUIC<br /><a href="https://bughunters.google.com/blog/5960150648750080/preventing-cross-service-udp-loops-in-quic" target="_blank" rel="noreferrer noopener">https://bughunters.google.com/blog/5960150648750080/preventing-cross-service-udp-loops-in-quic</a><br /> ShadowRay Attacks AI Workloads Actively Exploited in the Wild<br /><a href="https://www.oligo.security/blog/shadowray-attack-ai-workloads-actively-exploited-in-the-wild" target="_blank" rel="noreferrer noopener">https://www.oligo.security/blog/shadowray-attack-ai-workloads-actively-exploited-in-the-wild</a><br /> TheMoon Malware Infects 6,000 ASUS Routers in 72 Hours for Proxy Service<br /><a href="https://www.bleepingcomputer.com/news/security/themoon-malware-infects-6-000-asus-routers-in-72-hours-for-proxy-service/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/themoon-malware-infects-6-000-asus-routers-in-72-hours-for-proxy-service/</a><br />]]></itunes:summary><itunes:duration>349</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,linux packages; themoon; asus;,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8912</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, March 27th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-march-27th-2024--59190372</link><description><![CDATA[New tool: linux-pkgs.sh<br /><a href="https://isc.sans.edu/forums/diary/New%20tool%3A%20linux-pkgs.sh/30774/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/New%20tool%3A%20linux-pkgs.sh/30774/</a><br /> Suspicious NuGet package grabs data from industrial systems<br /><a href="https://www.reversinglabs.com/blog/suspicious-nuget-package-grabs-data-from-industrial-systems" target="_blank" rel="noreferrer noopener">https://www.reversinglabs.com/blog/suspicious-nuget-package-grabs-data-from-industrial-systems</a><br /> Preventing Cross Service UDP Loops in QUIC<br /><a href="https://bughunters.google.com/blog/5960150648750080/preventing-cross-service-udp-loops-in-quic" target="_blank" rel="noreferrer noopener">https://bughunters.google.com/blog/5960150648750080/preventing-cross-service-udp-loops-in-quic</a><br /> ShadowRay Attacks AI Workloads Actively Exploited in the Wild<br /><a href="https://www.oligo.security/blog/shadowray-attack-ai-workloads-actively-exploited-in-the-wild" target="_blank" rel="noreferrer noopener">https://www.oligo.security/blog/shadowray-attack-ai-workloads-actively-exploited-in-the-wild</a><br /> TheMoon Malware Infects 6,000 ASUS Routers in 72 Hours for Proxy Service<br /><a href="https://www.bleepingcomputer.com/news/security/themoon-malware-infects-6-000-asus-routers-in-72-hours-for-proxy-service/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/themoon-malware-infects-6-000-asus-routers-in-72-hours-for-proxy-service/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8912.mp3</guid><pubDate>Wed, 27 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59190372/8912.mp3" length="5185050" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>New tool: linux-pkgs.sh
https://isc.sans.edu/forums/diary/New%20tool%3A%20linux-pkgs.sh/30774/
 Suspicious NuGet package grabs data from industrial systems
https://www.reversinglabs.com/blog/suspicious-nuget-package-grabs-data-from-industrial-systems...</itunes:subtitle><itunes:summary><![CDATA[New tool: linux-pkgs.sh<br /><a href="https://isc.sans.edu/forums/diary/New%20tool%3A%20linux-pkgs.sh/30774/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/New%20tool%3A%20linux-pkgs.sh/30774/</a><br /> Suspicious NuGet package grabs data from industrial systems<br /><a href="https://www.reversinglabs.com/blog/suspicious-nuget-package-grabs-data-from-industrial-systems" target="_blank" rel="noreferrer noopener">https://www.reversinglabs.com/blog/suspicious-nuget-package-grabs-data-from-industrial-systems</a><br /> Preventing Cross Service UDP Loops in QUIC<br /><a href="https://bughunters.google.com/blog/5960150648750080/preventing-cross-service-udp-loops-in-quic" target="_blank" rel="noreferrer noopener">https://bughunters.google.com/blog/5960150648750080/preventing-cross-service-udp-loops-in-quic</a><br /> ShadowRay Attacks AI Workloads Actively Exploited in the Wild<br /><a href="https://www.oligo.security/blog/shadowray-attack-ai-workloads-actively-exploited-in-the-wild" target="_blank" rel="noreferrer noopener">https://www.oligo.security/blog/shadowray-attack-ai-workloads-actively-exploited-in-the-wild</a><br /> TheMoon Malware Infects 6,000 ASUS Routers in 72 Hours for Proxy Service<br /><a href="https://www.bleepingcomputer.com/news/security/themoon-malware-infects-6-000-asus-routers-in-72-hours-for-proxy-service/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/themoon-malware-infects-6-000-asus-routers-in-72-hours-for-proxy-service/</a><br />]]></itunes:summary><itunes:duration>349</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,linux packages; themoon; asus;,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8912</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, March 26th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-march-26th-2024--62129382</link><description><![CDATA[Tool updates: le-hex-to-ip.py and sigs.py<br /><a href="https://isc.sans.edu/diary/Tool%20updates%3A%20le-hex-to-ip.py%20and%20sigs.py/30772" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Tool%20updates%3A%20le-hex-to-ip.py%20and%20sigs.py/30772</a><br /> Apple Updates for MacOS, iOS/iPadOS, visionOS;<br /><a href="https://isc.sans.edu/diary/Apple%20Updates%20for%20MacOS%2C%20iOS%20iPadOS%20and%20visionOS/30778" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Updates%20for%20MacOS%2C%20iOS%20iPadOS%20and%20visionOS/30778</a><br /> Fake Python Infrastructure<br /><a href="https://checkmarx.com/blog/over-170k-users-affected-by-attack-using-fake-python-infrastructure/" target="_blank" rel="noreferrer noopener">https://checkmarx.com/blog/over-170k-users-affected-by-attack-using-fake-python-infrastructure/</a><br /> OpenVPN Update<br /><a href="https://openvpn.net/community-downloads/" target="_blank" rel="noreferrer noopener">https://openvpn.net/community-downloads/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8910.mp3</guid><pubDate>Tue, 26 Mar 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129382/8910.mp3" length="5375517" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Tool updates: le-hex-to-ip.py and sigs.py
https://isc.sans.edu/diary/Tool%20updates%3A%20le-hex-to-ip.py%20and%20sigs.py/30772
 Apple Updates for MacOS, iOS/iPadOS, visionOS;...</itunes:subtitle><itunes:summary><![CDATA[Tool updates: le-hex-to-ip.py and sigs.py<br /><a href="https://isc.sans.edu/diary/Tool%20updates%3A%20le-hex-to-ip.py%20and%20sigs.py/30772" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Tool%20updates%3A%20le-hex-to-ip.py%20and%20sigs.py/30772</a><br /> Apple Updates for MacOS, iOS/iPadOS, visionOS;<br /><a href="https://isc.sans.edu/diary/Apple%20Updates%20for%20MacOS%2C%20iOS%20iPadOS%20and%20visionOS/30778" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Updates%20for%20MacOS%2C%20iOS%20iPadOS%20and%20visionOS/30778</a><br /> Fake Python Infrastructure<br /><a href="https://checkmarx.com/blog/over-170k-users-affected-by-attack-using-fake-python-infrastructure/" target="_blank" rel="noreferrer noopener">https://checkmarx.com/blog/over-170k-users-affected-by-attack-using-fake-python-infrastructure/</a><br /> OpenVPN Update<br /><a href="https://openvpn.net/community-downloads/" target="_blank" rel="noreferrer noopener">https://openvpn.net/community-downloads/</a><br />]]></itunes:summary><itunes:duration>362</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,openvpn; python; apple; macos;,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8910</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, March 26th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-march-26th-2024--59175019</link><description><![CDATA[Tool updates: le-hex-to-ip.py and sigs.py<br /><a href="https://isc.sans.edu/diary/Tool%20updates%3A%20le-hex-to-ip.py%20and%20sigs.py/30772" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Tool%20updates%3A%20le-hex-to-ip.py%20and%20sigs.py/30772</a><br /> Apple Updates for MacOS, iOS/iPadOS, visionOS;<br /><a href="https://isc.sans.edu/diary/Apple%20Updates%20for%20MacOS%2C%20iOS%20iPadOS%20and%20visionOS/30778" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Updates%20for%20MacOS%2C%20iOS%20iPadOS%20and%20visionOS/30778</a><br /> Fake Python Infrastructure<br /><a href="https://checkmarx.com/blog/over-170k-users-affected-by-attack-using-fake-python-infrastructure/" target="_blank" rel="noreferrer noopener">https://checkmarx.com/blog/over-170k-users-affected-by-attack-using-fake-python-infrastructure/</a><br /> OpenVPN Update<br /><a href="https://openvpn.net/community-downloads/" target="_blank" rel="noreferrer noopener">https://openvpn.net/community-downloads/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8910.mp3</guid><pubDate>Tue, 26 Mar 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59175019/8910.mp3" length="5375517" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Tool updates: le-hex-to-ip.py and sigs.py
https://isc.sans.edu/diary/Tool%20updates%3A%20le-hex-to-ip.py%20and%20sigs.py/30772
 Apple Updates for MacOS, iOS/iPadOS, visionOS;...</itunes:subtitle><itunes:summary><![CDATA[Tool updates: le-hex-to-ip.py and sigs.py<br /><a href="https://isc.sans.edu/diary/Tool%20updates%3A%20le-hex-to-ip.py%20and%20sigs.py/30772" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Tool%20updates%3A%20le-hex-to-ip.py%20and%20sigs.py/30772</a><br /> Apple Updates for MacOS, iOS/iPadOS, visionOS;<br /><a href="https://isc.sans.edu/diary/Apple%20Updates%20for%20MacOS%2C%20iOS%20iPadOS%20and%20visionOS/30778" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Updates%20for%20MacOS%2C%20iOS%20iPadOS%20and%20visionOS/30778</a><br /> Fake Python Infrastructure<br /><a href="https://checkmarx.com/blog/over-170k-users-affected-by-attack-using-fake-python-infrastructure/" target="_blank" rel="noreferrer noopener">https://checkmarx.com/blog/over-170k-users-affected-by-attack-using-fake-python-infrastructure/</a><br /> OpenVPN Update<br /><a href="https://openvpn.net/community-downloads/" target="_blank" rel="noreferrer noopener">https://openvpn.net/community-downloads/</a><br />]]></itunes:summary><itunes:duration>362</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,openvpn; python; apple; macos;,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8910</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, March 25th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-march-25th-2024--62129452</link><description><![CDATA[1768.py's Experimental Mode<br /><a href="https://isc.sans.edu/diary/1768.py%27s%20Experimental%20Mode/30770" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/1768.py%27s%20Experimental%20Mode/30770</a><br /> CISCP Advisory on Application-Layer Loop DoS<br /><a href="https://docs.google.com/document/d/1KByZzrdwQhrXGPPCf9tUzERZyRzg0xOpGbWoDURZxTI/edit" target="_blank" rel="noreferrer noopener">https://docs.google.com/document/d/1KByZzrdwQhrXGPPCf9tUzERZyRzg0xOpGbWoDURZxTI/edit</a><br /> Fixes for Windows Server LSASS Memory Leak<br /><a href="https://www.catalog.update.microsoft.com/Search.aspx?q=2024-03%20Cumulative%20Update" target="_blank" rel="noreferrer noopener">https://www.catalog.update.microsoft.com/Search.aspx?q=2024-03%20Cumulative%20Update</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8908.mp3</guid><pubDate>Mon, 25 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129452/8908.mp3" length="4943916" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>1768.py's Experimental Mode
https://isc.sans.edu/diary/1768.py%27s%20Experimental%20Mode/30770
 CISCP Advisory on Application-Layer Loop DoS
https://docs.google.com/document/d/1KByZzrdwQhrXGPPCf9tUzERZyRzg0xOpGbWoDURZxTI/edit
 Fixes for Windows Server...</itunes:subtitle><itunes:summary><![CDATA[1768.py's Experimental Mode<br /><a href="https://isc.sans.edu/diary/1768.py%27s%20Experimental%20Mode/30770" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/1768.py%27s%20Experimental%20Mode/30770</a><br /> CISCP Advisory on Application-Layer Loop DoS<br /><a href="https://docs.google.com/document/d/1KByZzrdwQhrXGPPCf9tUzERZyRzg0xOpGbWoDURZxTI/edit" target="_blank" rel="noreferrer noopener">https://docs.google.com/document/d/1KByZzrdwQhrXGPPCf9tUzERZyRzg0xOpGbWoDURZxTI/edit</a><br /> Fixes for Windows Server LSASS Memory Leak<br /><a href="https://www.catalog.update.microsoft.com/Search.aspx?q=2024-03%20Cumulative%20Update" target="_blank" rel="noreferrer noopener">https://www.catalog.update.microsoft.com/Search.aspx?q=2024-03%20Cumulative%20Update</a><br />]]></itunes:summary><itunes:duration>332</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,lsass; windows; server; ciscp;,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8908</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, March 25th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-march-25th-2024--59159628</link><description><![CDATA[1768.py's Experimental Mode<br /><a href="https://isc.sans.edu/diary/1768.py%27s%20Experimental%20Mode/30770" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/1768.py%27s%20Experimental%20Mode/30770</a><br /> CISCP Advisory on Application-Layer Loop DoS<br /><a href="https://docs.google.com/document/d/1KByZzrdwQhrXGPPCf9tUzERZyRzg0xOpGbWoDURZxTI/edit" target="_blank" rel="noreferrer noopener">https://docs.google.com/document/d/1KByZzrdwQhrXGPPCf9tUzERZyRzg0xOpGbWoDURZxTI/edit</a><br /> Fixes for Windows Server LSASS Memory Leak<br /><a href="https://www.catalog.update.microsoft.com/Search.aspx?q=2024-03%20Cumulative%20Update" target="_blank" rel="noreferrer noopener">https://www.catalog.update.microsoft.com/Search.aspx?q=2024-03%20Cumulative%20Update</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8908.mp3</guid><pubDate>Mon, 25 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59159628/8908.mp3" length="4943916" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>1768.py's Experimental Mode
https://isc.sans.edu/diary/1768.py%27s%20Experimental%20Mode/30770
 CISCP Advisory on Application-Layer Loop DoS
https://docs.google.com/document/d/1KByZzrdwQhrXGPPCf9tUzERZyRzg0xOpGbWoDURZxTI/edit
 Fixes for Windows Server...</itunes:subtitle><itunes:summary><![CDATA[1768.py's Experimental Mode<br /><a href="https://isc.sans.edu/diary/1768.py%27s%20Experimental%20Mode/30770" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/1768.py%27s%20Experimental%20Mode/30770</a><br /> CISCP Advisory on Application-Layer Loop DoS<br /><a href="https://docs.google.com/document/d/1KByZzrdwQhrXGPPCf9tUzERZyRzg0xOpGbWoDURZxTI/edit" target="_blank" rel="noreferrer noopener">https://docs.google.com/document/d/1KByZzrdwQhrXGPPCf9tUzERZyRzg0xOpGbWoDURZxTI/edit</a><br /> Fixes for Windows Server LSASS Memory Leak<br /><a href="https://www.catalog.update.microsoft.com/Search.aspx?q=2024-03%20Cumulative%20Update" target="_blank" rel="noreferrer noopener">https://www.catalog.update.microsoft.com/Search.aspx?q=2024-03%20Cumulative%20Update</a><br />]]></itunes:summary><itunes:duration>332</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,lsass; windows; server; ciscp;,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8908</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, March 22nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-march-22nd-2024--62129371</link><description><![CDATA[Geofeed<br /><a href="https://isc.sans.edu/forums/diary/Whois%20%22geofeed%22%20Data/30766/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Whois%20%22geofeed%22%20Data/30766/</a><br /> Apple Updates<br /><a href="https://support.apple.com/en-us/HT201222" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/HT201222</a><br /> Apple Bug<br /><a href="https://gofetch.fail/" target="_blank" rel="noreferrer noopener">https://gofetch.fail/</a><br /> GitHub Copilot AutoFix<br /><a href="https://github.blog/2024-03-20-found-means-fixed-introducing-code-scanning-autofix-powered-by-github-copilot-and-codeql/" target="_blank" rel="noreferrer noopener">https://github.blog/2024-03-20-found-means-fixed-introducing-code-scanning-autofix-powered-by-github-copilot-and-codeql/</a><br /> Fortinet PoC<br /><a href="https://www.horizon3.ai/attack-research/attack-blogs/cve-2023-48788-fortinet-forticlientems-sql-injection-deep-dive/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/attack-blogs/cve-2023-48788-fortinet-forticlientems-sql-injection-deep-dive/</a><br /> Ivanti Standalone Sentry<br /><a href="https://forums.ivanti.com/s/article/KB-CVE-2023-41724-Remote-Code-Execution-for-Ivanti-Standalone-Sentry?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/KB-CVE-2023-41724-Remote-Code-Execution-for-Ivanti-Standalone-Sentry?language=en_US</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8906.mp3</guid><pubDate>Fri, 22 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129371/8906.mp3" length="5686958" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Geofeed
https://isc.sans.edu/forums/diary/Whois%20%22geofeed%22%20Data/30766/
 Apple Updates
https://support.apple.com/en-us/HT201222
 Apple Bug
https://gofetch.fail/
 GitHub Copilot AutoFix...</itunes:subtitle><itunes:summary><![CDATA[Geofeed<br /><a href="https://isc.sans.edu/forums/diary/Whois%20%22geofeed%22%20Data/30766/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Whois%20%22geofeed%22%20Data/30766/</a><br /> Apple Updates<br /><a href="https://support.apple.com/en-us/HT201222" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/HT201222</a><br /> Apple Bug<br /><a href="https://gofetch.fail/" target="_blank" rel="noreferrer noopener">https://gofetch.fail/</a><br /> GitHub Copilot AutoFix<br /><a href="https://github.blog/2024-03-20-found-means-fixed-introducing-code-scanning-autofix-powered-by-github-copilot-and-codeql/" target="_blank" rel="noreferrer noopener">https://github.blog/2024-03-20-found-means-fixed-introducing-code-scanning-autofix-powered-by-github-copilot-and-codeql/</a><br /> Fortinet PoC<br /><a href="https://www.horizon3.ai/attack-research/attack-blogs/cve-2023-48788-fortinet-forticlientems-sql-injection-deep-dive/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/attack-blogs/cve-2023-48788-fortinet-forticlientems-sql-injection-deep-dive/</a><br /> Ivanti Standalone Sentry<br /><a href="https://forums.ivanti.com/s/article/KB-CVE-2023-41724-Remote-Code-Execution-for-Ivanti-Standalone-Sentry?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/KB-CVE-2023-41724-Remote-Code-Execution-for-Ivanti-Standalone-Sentry?language=en_US</a><br />]]></itunes:summary><itunes:duration>385</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,geofeed; apple; apple bug; git,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8906</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, March 22nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-march-22nd-2024--59132981</link><description><![CDATA[Geofeed<br /><a href="https://isc.sans.edu/forums/diary/Whois%20%22geofeed%22%20Data/30766/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Whois%20%22geofeed%22%20Data/30766/</a><br /> Apple Updates<br /><a href="https://support.apple.com/en-us/HT201222" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/HT201222</a><br /> Apple Bug<br /><a href="https://gofetch.fail/" target="_blank" rel="noreferrer noopener">https://gofetch.fail/</a><br /> GitHub Copilot AutoFix<br /><a href="https://github.blog/2024-03-20-found-means-fixed-introducing-code-scanning-autofix-powered-by-github-copilot-and-codeql/" target="_blank" rel="noreferrer noopener">https://github.blog/2024-03-20-found-means-fixed-introducing-code-scanning-autofix-powered-by-github-copilot-and-codeql/</a><br /> Fortinet PoC<br /><a href="https://www.horizon3.ai/attack-research/attack-blogs/cve-2023-48788-fortinet-forticlientems-sql-injection-deep-dive/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/attack-blogs/cve-2023-48788-fortinet-forticlientems-sql-injection-deep-dive/</a><br /> Ivanti Standalone Sentry<br /><a href="https://forums.ivanti.com/s/article/KB-CVE-2023-41724-Remote-Code-Execution-for-Ivanti-Standalone-Sentry?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/KB-CVE-2023-41724-Remote-Code-Execution-for-Ivanti-Standalone-Sentry?language=en_US</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8906.mp3</guid><pubDate>Fri, 22 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59132981/8906.mp3" length="5686958" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Geofeed
https://isc.sans.edu/forums/diary/Whois%20%22geofeed%22%20Data/30766/
 Apple Updates
https://support.apple.com/en-us/HT201222
 Apple Bug
https://gofetch.fail/
 GitHub Copilot AutoFix...</itunes:subtitle><itunes:summary><![CDATA[Geofeed<br /><a href="https://isc.sans.edu/forums/diary/Whois%20%22geofeed%22%20Data/30766/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Whois%20%22geofeed%22%20Data/30766/</a><br /> Apple Updates<br /><a href="https://support.apple.com/en-us/HT201222" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/HT201222</a><br /> Apple Bug<br /><a href="https://gofetch.fail/" target="_blank" rel="noreferrer noopener">https://gofetch.fail/</a><br /> GitHub Copilot AutoFix<br /><a href="https://github.blog/2024-03-20-found-means-fixed-introducing-code-scanning-autofix-powered-by-github-copilot-and-codeql/" target="_blank" rel="noreferrer noopener">https://github.blog/2024-03-20-found-means-fixed-introducing-code-scanning-autofix-powered-by-github-copilot-and-codeql/</a><br /> Fortinet PoC<br /><a href="https://www.horizon3.ai/attack-research/attack-blogs/cve-2023-48788-fortinet-forticlientems-sql-injection-deep-dive/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/attack-blogs/cve-2023-48788-fortinet-forticlientems-sql-injection-deep-dive/</a><br /> Ivanti Standalone Sentry<br /><a href="https://forums.ivanti.com/s/article/KB-CVE-2023-41724-Remote-Code-Execution-for-Ivanti-Standalone-Sentry?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/KB-CVE-2023-41724-Remote-Code-Execution-for-Ivanti-Standalone-Sentry?language=en_US</a><br />]]></itunes:summary><itunes:duration>385</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,geofeed; apple; apple bug; git,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8906</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, March 21st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-march-21st-2024--62129466</link><description><![CDATA[Scans for the Fortinet FortiOS CVE-2024-21762 Vulnerability<br /><a href="https://isc.sans.edu/diary/Scans%20for%20Fortinet%20FortiOS%20and%20the%20CVE-2024-21762%20vulnerability/30762" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20Fortinet%20FortiOS%20and%20the%20CVE-2024-21762%20vulnerability/30762</a><br /> Microsoft Reminder: It is Tax Season (at least in the US)<br /><a href="https://www.theregister.com/2024/03/20/its_tax_season_and_scammers/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2024/03/20/its_tax_season_and_scammers/</a><br /> Abusing DHCP Administrators Group for Privilege Escalation in Windows Domains;<br /><a href="https://www.akamai.com/blog/security-research/abusing-dhcp-administrators-group-for-privilege-escalation-in-windows-domains" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/abusing-dhcp-administrators-group-for-privilege-escalation-in-windows-domains</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8904.mp3</guid><pubDate>Thu, 21 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129466/8904.mp3" length="5293351" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Scans for the Fortinet FortiOS CVE-2024-21762 Vulnerability
https://isc.sans.edu/diary/Scans%20for%20Fortinet%20FortiOS%20and%20the%20CVE-2024-21762%20vulnerability/30762
 Microsoft Reminder: It is Tax Season (at least in the US)...</itunes:subtitle><itunes:summary><![CDATA[Scans for the Fortinet FortiOS CVE-2024-21762 Vulnerability<br /><a href="https://isc.sans.edu/diary/Scans%20for%20Fortinet%20FortiOS%20and%20the%20CVE-2024-21762%20vulnerability/30762" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20Fortinet%20FortiOS%20and%20the%20CVE-2024-21762%20vulnerability/30762</a><br /> Microsoft Reminder: It is Tax Season (at least in the US)<br /><a href="https://www.theregister.com/2024/03/20/its_tax_season_and_scammers/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2024/03/20/its_tax_season_and_scammers/</a><br /> Abusing DHCP Administrators Group for Privilege Escalation in Windows Domains;<br /><a href="https://www.akamai.com/blog/security-research/abusing-dhcp-administrators-group-for-privilege-escalation-in-windows-domains" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/abusing-dhcp-administrators-group-for-privilege-escalation-in-windows-domains</a><br />]]></itunes:summary><itunes:duration>356</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dhcp; administrators; windows;,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8904</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, March 21st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-march-21st-2024--59121496</link><description><![CDATA[Scans for the Fortinet FortiOS CVE-2024-21762 Vulnerability<br /><a href="https://isc.sans.edu/diary/Scans%20for%20Fortinet%20FortiOS%20and%20the%20CVE-2024-21762%20vulnerability/30762" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20Fortinet%20FortiOS%20and%20the%20CVE-2024-21762%20vulnerability/30762</a><br /> Microsoft Reminder: It is Tax Season (at least in the US)<br /><a href="https://www.theregister.com/2024/03/20/its_tax_season_and_scammers/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2024/03/20/its_tax_season_and_scammers/</a><br /> Abusing DHCP Administrators Group for Privilege Escalation in Windows Domains;<br /><a href="https://www.akamai.com/blog/security-research/abusing-dhcp-administrators-group-for-privilege-escalation-in-windows-domains" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/abusing-dhcp-administrators-group-for-privilege-escalation-in-windows-domains</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8904.mp3</guid><pubDate>Thu, 21 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59121496/8904.mp3" length="5293351" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Scans for the Fortinet FortiOS CVE-2024-21762 Vulnerability
https://isc.sans.edu/diary/Scans%20for%20Fortinet%20FortiOS%20and%20the%20CVE-2024-21762%20vulnerability/30762
 Microsoft Reminder: It is Tax Season (at least in the US)...</itunes:subtitle><itunes:summary><![CDATA[Scans for the Fortinet FortiOS CVE-2024-21762 Vulnerability<br /><a href="https://isc.sans.edu/diary/Scans%20for%20Fortinet%20FortiOS%20and%20the%20CVE-2024-21762%20vulnerability/30762" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20Fortinet%20FortiOS%20and%20the%20CVE-2024-21762%20vulnerability/30762</a><br /> Microsoft Reminder: It is Tax Season (at least in the US)<br /><a href="https://www.theregister.com/2024/03/20/its_tax_season_and_scammers/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2024/03/20/its_tax_season_and_scammers/</a><br /> Abusing DHCP Administrators Group for Privilege Escalation in Windows Domains;<br /><a href="https://www.akamai.com/blog/security-research/abusing-dhcp-administrators-group-for-privilege-escalation-in-windows-domains" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/abusing-dhcp-administrators-group-for-privilege-escalation-in-windows-domains</a><br />]]></itunes:summary><itunes:duration>356</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dhcp; administrators; windows;,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8904</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, March 20th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-march-20th-2024--62129372</link><description><![CDATA[Attacker Hunting Firewalls<br /><a href="https://isc.sans.edu/diary/Attacker%20Hunting%20Firewalls/30758" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Attacker%20Hunting%20Firewalls/30758</a><br /> Fortigate Vulnerability Exploit Available<br /><a href="https://github.com/h4x0r-dz/CVE-2024-21762" target="_blank" rel="noreferrer noopener">https://github.com/h4x0r-dz/CVE-2024-21762</a><br /> IC3 Annual Report 2023<br /><a href="https://www.ic3.gov/Media/PDF/AnnualReport/2023_IC3Report.pdf" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/Media/PDF/AnnualReport/2023_IC3Report.pdf</a><br /> Issues with macOS 14.4 Update<br /><a href="https://www.macrumors.com/2024/03/18/do-not-update-macos-sonoma-14-4/" target="_blank" rel="noreferrer noopener">https://www.macrumors.com/2024/03/18/do-not-update-macos-sonoma-14-4/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8902.mp3</guid><pubDate>Wed, 20 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129372/8902.mp3" length="4859729" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Attacker Hunting Firewalls
https://isc.sans.edu/diary/Attacker%20Hunting%20Firewalls/30758
 Fortigate Vulnerability Exploit Available
https://github.com/h4x0r-dz/CVE-2024-21762
 IC3 Annual Report 2023...</itunes:subtitle><itunes:summary><![CDATA[Attacker Hunting Firewalls<br /><a href="https://isc.sans.edu/diary/Attacker%20Hunting%20Firewalls/30758" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Attacker%20Hunting%20Firewalls/30758</a><br /> Fortigate Vulnerability Exploit Available<br /><a href="https://github.com/h4x0r-dz/CVE-2024-21762" target="_blank" rel="noreferrer noopener">https://github.com/h4x0r-dz/CVE-2024-21762</a><br /> IC3 Annual Report 2023<br /><a href="https://www.ic3.gov/Media/PDF/AnnualReport/2023_IC3Report.pdf" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/Media/PDF/AnnualReport/2023_IC3Report.pdf</a><br /> Issues with macOS 14.4 Update<br /><a href="https://www.macrumors.com/2024/03/18/do-not-update-macos-sonoma-14-4/" target="_blank" rel="noreferrer noopener">https://www.macrumors.com/2024/03/18/do-not-update-macos-sonoma-14-4/</a><br />]]></itunes:summary><itunes:duration>326</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,macos; ic3; fortigate; firewal,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8902</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, March 20th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-march-20th-2024--59107322</link><description><![CDATA[Attacker Hunting Firewalls<br /><a href="https://isc.sans.edu/diary/Attacker%20Hunting%20Firewalls/30758" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Attacker%20Hunting%20Firewalls/30758</a><br /> Fortigate Vulnerability Exploit Available<br /><a href="https://github.com/h4x0r-dz/CVE-2024-21762" target="_blank" rel="noreferrer noopener">https://github.com/h4x0r-dz/CVE-2024-21762</a><br /> IC3 Annual Report 2023<br /><a href="https://www.ic3.gov/Media/PDF/AnnualReport/2023_IC3Report.pdf" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/Media/PDF/AnnualReport/2023_IC3Report.pdf</a><br /> Issues with macOS 14.4 Update<br /><a href="https://www.macrumors.com/2024/03/18/do-not-update-macos-sonoma-14-4/" target="_blank" rel="noreferrer noopener">https://www.macrumors.com/2024/03/18/do-not-update-macos-sonoma-14-4/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8902.mp3</guid><pubDate>Wed, 20 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59107322/8902.mp3" length="4859729" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Attacker Hunting Firewalls
https://isc.sans.edu/diary/Attacker%20Hunting%20Firewalls/30758
 Fortigate Vulnerability Exploit Available
https://github.com/h4x0r-dz/CVE-2024-21762
 IC3 Annual Report 2023...</itunes:subtitle><itunes:summary><![CDATA[Attacker Hunting Firewalls<br /><a href="https://isc.sans.edu/diary/Attacker%20Hunting%20Firewalls/30758" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Attacker%20Hunting%20Firewalls/30758</a><br /> Fortigate Vulnerability Exploit Available<br /><a href="https://github.com/h4x0r-dz/CVE-2024-21762" target="_blank" rel="noreferrer noopener">https://github.com/h4x0r-dz/CVE-2024-21762</a><br /> IC3 Annual Report 2023<br /><a href="https://www.ic3.gov/Media/PDF/AnnualReport/2023_IC3Report.pdf" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/Media/PDF/AnnualReport/2023_IC3Report.pdf</a><br /> Issues with macOS 14.4 Update<br /><a href="https://www.macrumors.com/2024/03/18/do-not-update-macos-sonoma-14-4/" target="_blank" rel="noreferrer noopener">https://www.macrumors.com/2024/03/18/do-not-update-macos-sonoma-14-4/</a><br />]]></itunes:summary><itunes:duration>326</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,macos; ic3; fortigate; firewal,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8902</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, March 19th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-march-19th-2024--62129386</link><description><![CDATA[Microsoft announced deprecation of 1024 bit RSA Keys<br /><a href="https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features#deprecated-features" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features#deprecated-features</a><br /> Chrome Real-Time Safe Browsing Protection<br /><a href="https://blog.google/products/chrome/google-chrome-safe-browsing-real-time/" target="_blank" rel="noreferrer noopener">https://blog.google/products/chrome/google-chrome-safe-browsing-real-time/</a><br /> Fortra FileCatalyst Vulnerability CVE-2024-25153<br /><a href="https://www.fortra.com/security/advisory/fi-2024-002" target="_blank" rel="noreferrer noopener">https://www.fortra.com/security/advisory/fi-2024-002</a><br /> Spring Security CVE-2024-22257<br /><a href="https://spring.io/security/cve-2024-22257/" target="_blank" rel="noreferrer noopener">https://spring.io/security/cve-2024-22257/</a><br /> TrendNet TWEW-827DRU Router Vulnerability CVE-2024-28353 CVE-2024-28354<br /><a href="https://warp-desk-89d.notion.site/TEW-827DRU-5c40fb20572148f0b00f329d69273791" target="_blank" rel="noreferrer noopener">https://warp-desk-89d.notion.site/TEW-827DRU-5c40fb20572148f0b00f329d69273791</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8900.mp3</guid><pubDate>Tue, 19 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129386/8900.mp3" length="4835457" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft announced deprecation of 1024 bit RSA Keys
https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features#deprecated-features
 Chrome Real-Time Safe Browsing Protection...</itunes:subtitle><itunes:summary><![CDATA[Microsoft announced deprecation of 1024 bit RSA Keys<br /><a href="https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features#deprecated-features" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features#deprecated-features</a><br /> Chrome Real-Time Safe Browsing Protection<br /><a href="https://blog.google/products/chrome/google-chrome-safe-browsing-real-time/" target="_blank" rel="noreferrer noopener">https://blog.google/products/chrome/google-chrome-safe-browsing-real-time/</a><br /> Fortra FileCatalyst Vulnerability CVE-2024-25153<br /><a href="https://www.fortra.com/security/advisory/fi-2024-002" target="_blank" rel="noreferrer noopener">https://www.fortra.com/security/advisory/fi-2024-002</a><br /> Spring Security CVE-2024-22257<br /><a href="https://spring.io/security/cve-2024-22257/" target="_blank" rel="noreferrer noopener">https://spring.io/security/cve-2024-22257/</a><br /> TrendNet TWEW-827DRU Router Vulnerability CVE-2024-28353 CVE-2024-28354<br /><a href="https://warp-desk-89d.notion.site/TEW-827DRU-5c40fb20572148f0b00f329d69273791" target="_blank" rel="noreferrer noopener">https://warp-desk-89d.notion.site/TEW-827DRU-5c40fb20572148f0b00f329d69273791</a><br />]]></itunes:summary><itunes:duration>324</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,trendnet; spring; security; ch</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8900</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, March 19th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-march-19th-2024--59095558</link><description><![CDATA[Microsoft announced deprecation of 1024 bit RSA Keys<br /><a href="https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features#deprecated-features" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features#deprecated-features</a><br /> Chrome Real-Time Safe Browsing Protection<br /><a href="https://blog.google/products/chrome/google-chrome-safe-browsing-real-time/" target="_blank" rel="noreferrer noopener">https://blog.google/products/chrome/google-chrome-safe-browsing-real-time/</a><br /> Fortra FileCatalyst Vulnerability CVE-2024-25153<br /><a href="https://www.fortra.com/security/advisory/fi-2024-002" target="_blank" rel="noreferrer noopener">https://www.fortra.com/security/advisory/fi-2024-002</a><br /> Spring Security CVE-2024-22257<br /><a href="https://spring.io/security/cve-2024-22257/" target="_blank" rel="noreferrer noopener">https://spring.io/security/cve-2024-22257/</a><br /> TrendNet TWEW-827DRU Router Vulnerability CVE-2024-28353 CVE-2024-28354<br /><a href="https://warp-desk-89d.notion.site/TEW-827DRU-5c40fb20572148f0b00f329d69273791" target="_blank" rel="noreferrer noopener">https://warp-desk-89d.notion.site/TEW-827DRU-5c40fb20572148f0b00f329d69273791</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8900.mp3</guid><pubDate>Tue, 19 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59095558/8900.mp3" length="4835457" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft announced deprecation of 1024 bit RSA Keys
https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features#deprecated-features
 Chrome Real-Time Safe Browsing Protection...</itunes:subtitle><itunes:summary><![CDATA[Microsoft announced deprecation of 1024 bit RSA Keys<br /><a href="https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features#deprecated-features" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features#deprecated-features</a><br /> Chrome Real-Time Safe Browsing Protection<br /><a href="https://blog.google/products/chrome/google-chrome-safe-browsing-real-time/" target="_blank" rel="noreferrer noopener">https://blog.google/products/chrome/google-chrome-safe-browsing-real-time/</a><br /> Fortra FileCatalyst Vulnerability CVE-2024-25153<br /><a href="https://www.fortra.com/security/advisory/fi-2024-002" target="_blank" rel="noreferrer noopener">https://www.fortra.com/security/advisory/fi-2024-002</a><br /> Spring Security CVE-2024-22257<br /><a href="https://spring.io/security/cve-2024-22257/" target="_blank" rel="noreferrer noopener">https://spring.io/security/cve-2024-22257/</a><br /> TrendNet TWEW-827DRU Router Vulnerability CVE-2024-28353 CVE-2024-28354<br /><a href="https://warp-desk-89d.notion.site/TEW-827DRU-5c40fb20572148f0b00f329d69273791" target="_blank" rel="noreferrer noopener">https://warp-desk-89d.notion.site/TEW-827DRU-5c40fb20572148f0b00f329d69273791</a><br />]]></itunes:summary><itunes:duration>324</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,trendnet; spring; security; ch</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8900</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, March 18th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-march-18th-2024--62129469</link><description><![CDATA[5GHoul Revisted: Thress Months Later<br /><a href="https://isc.sans.edu/diary/5Ghoul%20Revisited%3A%20Three%20Months%20Later/30746" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/5Ghoul%20Revisited%3A%20Three%20Months%20Later/30746</a><br /> Obfuscated Hexadecimal Payload<br /><a href="https://isc.sans.edu/diary/Obfuscated%20Hexadecimal%20Payload/30750" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Obfuscated%20Hexadecimal%20Payload/30750</a><br /> ChatGPT Related OAUTH Issues<br /><a href="https://salt.security/blog/security-flaws-within-chatgpt-extensions-allowed-access-to-accounts-on-third-party-websites-and-sensitive-data?utm_source=social&amp;utm_medium=reddit" target="_blank" rel="noreferrer noopener">https://salt.security/blog/security-flaws-within-chatgpt-extensions-allowed-access-to-accounts-on-third-party-websites-and-sensitive-data?utm_source=social&amp;utm_medium=reddit</a><br /> RedCanary Threat Detection Report<br /><a href="https://redcanary.com/threat-detection-report/" target="_blank" rel="noreferrer noopener">https://redcanary.com/threat-detection-report/</a><br /> CRL/OCSP Changes<br /><a href="https://github.com/cabforum/servercert/blob/main/docs/BR.md" target="_blank" rel="noreferrer noopener">https://github.com/cabforum/servercert/blob/main/docs/BR.md</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8898.mp3</guid><pubDate>Mon, 18 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129469/8898.mp3" length="5900024" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>5GHoul Revisted: Thress Months Later
https://isc.sans.edu/diary/5Ghoul%20Revisited%3A%20Three%20Months%20Later/30746
 Obfuscated Hexadecimal Payload
https://isc.sans.edu/diary/Obfuscated%20Hexadecimal%20Payload/30750
 ChatGPT Related OAUTH Issues...</itunes:subtitle><itunes:summary><![CDATA[5GHoul Revisted: Thress Months Later<br /><a href="https://isc.sans.edu/diary/5Ghoul%20Revisited%3A%20Three%20Months%20Later/30746" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/5Ghoul%20Revisited%3A%20Three%20Months%20Later/30746</a><br /> Obfuscated Hexadecimal Payload<br /><a href="https://isc.sans.edu/diary/Obfuscated%20Hexadecimal%20Payload/30750" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Obfuscated%20Hexadecimal%20Payload/30750</a><br /> ChatGPT Related OAUTH Issues<br /><a href="https://salt.security/blog/security-flaws-within-chatgpt-extensions-allowed-access-to-accounts-on-third-party-websites-and-sensitive-data?utm_source=social&amp;utm_medium=reddit" target="_blank" rel="noreferrer noopener">https://salt.security/blog/security-flaws-within-chatgpt-extensions-allowed-access-to-accounts-on-third-party-websites-and-sensitive-data?utm_source=social&amp;utm_medium=reddit</a><br /> RedCanary Threat Detection Report<br /><a href="https://redcanary.com/threat-detection-report/" target="_blank" rel="noreferrer noopener">https://redcanary.com/threat-detection-report/</a><br /> CRL/OCSP Changes<br /><a href="https://github.com/cabforum/servercert/blob/main/docs/BR.md" target="_blank" rel="noreferrer noopener">https://github.com/cabforum/servercert/blob/main/docs/BR.md</a><br />]]></itunes:summary><itunes:duration>400</itunes:duration><itunes:keywords>business,computer,crl; ocsp; cab forum; revocati,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8898</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, March 18th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-march-18th-2024--59082413</link><description><![CDATA[5GHoul Revisted: Thress Months Later<br /><a href="https://isc.sans.edu/diary/5Ghoul%20Revisited%3A%20Three%20Months%20Later/30746" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/5Ghoul%20Revisited%3A%20Three%20Months%20Later/30746</a><br /> Obfuscated Hexadecimal Payload<br /><a href="https://isc.sans.edu/diary/Obfuscated%20Hexadecimal%20Payload/30750" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Obfuscated%20Hexadecimal%20Payload/30750</a><br /> ChatGPT Related OAUTH Issues<br /><a href="https://salt.security/blog/security-flaws-within-chatgpt-extensions-allowed-access-to-accounts-on-third-party-websites-and-sensitive-data?utm_source=social&amp;utm_medium=reddit" target="_blank" rel="noreferrer noopener">https://salt.security/blog/security-flaws-within-chatgpt-extensions-allowed-access-to-accounts-on-third-party-websites-and-sensitive-data?utm_source=social&amp;utm_medium=reddit</a><br /> RedCanary Threat Detection Report<br /><a href="https://redcanary.com/threat-detection-report/" target="_blank" rel="noreferrer noopener">https://redcanary.com/threat-detection-report/</a><br /> CRL/OCSP Changes<br /><a href="https://github.com/cabforum/servercert/blob/main/docs/BR.md" target="_blank" rel="noreferrer noopener">https://github.com/cabforum/servercert/blob/main/docs/BR.md</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8898.mp3</guid><pubDate>Mon, 18 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59082413/8898.mp3" length="5900024" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>5GHoul Revisted: Thress Months Later
https://isc.sans.edu/diary/5Ghoul%20Revisited%3A%20Three%20Months%20Later/30746
 Obfuscated Hexadecimal Payload
https://isc.sans.edu/diary/Obfuscated%20Hexadecimal%20Payload/30750
 ChatGPT Related OAUTH Issues...</itunes:subtitle><itunes:summary><![CDATA[5GHoul Revisted: Thress Months Later<br /><a href="https://isc.sans.edu/diary/5Ghoul%20Revisited%3A%20Three%20Months%20Later/30746" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/5Ghoul%20Revisited%3A%20Three%20Months%20Later/30746</a><br /> Obfuscated Hexadecimal Payload<br /><a href="https://isc.sans.edu/diary/Obfuscated%20Hexadecimal%20Payload/30750" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Obfuscated%20Hexadecimal%20Payload/30750</a><br /> ChatGPT Related OAUTH Issues<br /><a href="https://salt.security/blog/security-flaws-within-chatgpt-extensions-allowed-access-to-accounts-on-third-party-websites-and-sensitive-data?utm_source=social&amp;utm_medium=reddit" target="_blank" rel="noreferrer noopener">https://salt.security/blog/security-flaws-within-chatgpt-extensions-allowed-access-to-accounts-on-third-party-websites-and-sensitive-data?utm_source=social&amp;utm_medium=reddit</a><br /> RedCanary Threat Detection Report<br /><a href="https://redcanary.com/threat-detection-report/" target="_blank" rel="noreferrer noopener">https://redcanary.com/threat-detection-report/</a><br /> CRL/OCSP Changes<br /><a href="https://github.com/cabforum/servercert/blob/main/docs/BR.md" target="_blank" rel="noreferrer noopener">https://github.com/cabforum/servercert/blob/main/docs/BR.md</a><br />]]></itunes:summary><itunes:duration>400</itunes:duration><itunes:keywords>business,computer,crl; ocsp; cab forum; revocati,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8898</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, March 15th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-march-15th-2024--62129470</link><description><![CDATA[Increase in the number of phishing messages pointing to IPFS and to R2 buckets<br /><a href="https://isc.sans.edu/diary/Increase%20in%20the%20number%20of%20phishing%20messages%20pointing%20to%20IPFS%20and%20to%20R2%20buckets/30744" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Increase%20in%20the%20number%20of%20phishing%20messages%20pointing%20to%20IPFS%20and%20to%20R2%20buckets/30744</a><br /> Fortinet New Vulnerabilities<br /><a href="https://www.horizon3.ai/attack-research/attack-blogs/fortiwlm-the-almost-story-for-the-forti-forty/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/attack-blogs/fortiwlm-the-almost-story-for-the-forti-forty/</a><br /> Fortinet Updates<br /><a href="https://www.helpnetsecurity.com/2024/03/14/cve-2023-48788-poc/" target="_blank" rel="noreferrer noopener">https://www.helpnetsecurity.com/2024/03/14/cve-2023-48788-poc/</a><br /> Arcserve UDP Vulnerability and PoC<br /><a href="https://www.tenable.com/security/research/tra-2024-07" target="_blank" rel="noreferrer noopener">https://www.tenable.com/security/research/tra-2024-07</a><br /> Michael Holcomb: Mode Matters: Monitoring PLCs for Detecting Potential ICS/OT Incidents<br /><a href="https://www.sans.edu/cyber-research/mode-matters-monitoring-plcs-for-detecting-potential-ics-ot-incidents/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/mode-matters-monitoring-plcs-for-detecting-potential-ics-ot-incidents/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8896.mp3</guid><pubDate>Fri, 15 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129470/8896.mp3" length="17631870" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Increase in the number of phishing messages pointing to IPFS and to R2 buckets
https://isc.sans.edu/diary/Increase%20in%20the%20number%20of%20phishing%20messages%20pointing%20to%20IPFS%20and%20to%20R2%20buckets/30744
 Fortinet New Vulnerabilities...</itunes:subtitle><itunes:summary><![CDATA[Increase in the number of phishing messages pointing to IPFS and to R2 buckets<br /><a href="https://isc.sans.edu/diary/Increase%20in%20the%20number%20of%20phishing%20messages%20pointing%20to%20IPFS%20and%20to%20R2%20buckets/30744" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Increase%20in%20the%20number%20of%20phishing%20messages%20pointing%20to%20IPFS%20and%20to%20R2%20buckets/30744</a><br /> Fortinet New Vulnerabilities<br /><a href="https://www.horizon3.ai/attack-research/attack-blogs/fortiwlm-the-almost-story-for-the-forti-forty/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/attack-blogs/fortiwlm-the-almost-story-for-the-forti-forty/</a><br /> Fortinet Updates<br /><a href="https://www.helpnetsecurity.com/2024/03/14/cve-2023-48788-poc/" target="_blank" rel="noreferrer noopener">https://www.helpnetsecurity.com/2024/03/14/cve-2023-48788-poc/</a><br /> Arcserve UDP Vulnerability and PoC<br /><a href="https://www.tenable.com/security/research/tra-2024-07" target="_blank" rel="noreferrer noopener">https://www.tenable.com/security/research/tra-2024-07</a><br /> Michael Holcomb: Mode Matters: Monitoring PLCs for Detecting Potential ICS/OT Incidents<br /><a href="https://www.sans.edu/cyber-research/mode-matters-monitoring-plcs-for-detecting-potential-ics-ot-incidents/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/mode-matters-monitoring-plcs-for-detecting-potential-ics-ot-incidents/</a><br />]]></itunes:summary><itunes:duration>1238</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,holcomb; sans.edu; ics; plc; m,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8896</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, March 15th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-march-15th-2024--59051818</link><description><![CDATA[Increase in the number of phishing messages pointing to IPFS and to R2 buckets<br /><a href="https://isc.sans.edu/diary/Increase%20in%20the%20number%20of%20phishing%20messages%20pointing%20to%20IPFS%20and%20to%20R2%20buckets/30744" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Increase%20in%20the%20number%20of%20phishing%20messages%20pointing%20to%20IPFS%20and%20to%20R2%20buckets/30744</a><br /> Fortinet New Vulnerabilities<br /><a href="https://www.horizon3.ai/attack-research/attack-blogs/fortiwlm-the-almost-story-for-the-forti-forty/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/attack-blogs/fortiwlm-the-almost-story-for-the-forti-forty/</a><br /> Fortinet Updates<br /><a href="https://www.helpnetsecurity.com/2024/03/14/cve-2023-48788-poc/" target="_blank" rel="noreferrer noopener">https://www.helpnetsecurity.com/2024/03/14/cve-2023-48788-poc/</a><br /> Arcserve UDP Vulnerability and PoC<br /><a href="https://www.tenable.com/security/research/tra-2024-07" target="_blank" rel="noreferrer noopener">https://www.tenable.com/security/research/tra-2024-07</a><br /> Michael Holcomb: Mode Matters: Monitoring PLCs for Detecting Potential ICS/OT Incidents<br /><a href="https://www.sans.edu/cyber-research/mode-matters-monitoring-plcs-for-detecting-potential-ics-ot-incidents/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/mode-matters-monitoring-plcs-for-detecting-potential-ics-ot-incidents/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8896.mp3</guid><pubDate>Fri, 15 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59051818/8896.mp3" length="17631870" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Increase in the number of phishing messages pointing to IPFS and to R2 buckets
https://isc.sans.edu/diary/Increase%20in%20the%20number%20of%20phishing%20messages%20pointing%20to%20IPFS%20and%20to%20R2%20buckets/30744
 Fortinet New Vulnerabilities...</itunes:subtitle><itunes:summary><![CDATA[Increase in the number of phishing messages pointing to IPFS and to R2 buckets<br /><a href="https://isc.sans.edu/diary/Increase%20in%20the%20number%20of%20phishing%20messages%20pointing%20to%20IPFS%20and%20to%20R2%20buckets/30744" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Increase%20in%20the%20number%20of%20phishing%20messages%20pointing%20to%20IPFS%20and%20to%20R2%20buckets/30744</a><br /> Fortinet New Vulnerabilities<br /><a href="https://www.horizon3.ai/attack-research/attack-blogs/fortiwlm-the-almost-story-for-the-forti-forty/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/attack-research/attack-blogs/fortiwlm-the-almost-story-for-the-forti-forty/</a><br /> Fortinet Updates<br /><a href="https://www.helpnetsecurity.com/2024/03/14/cve-2023-48788-poc/" target="_blank" rel="noreferrer noopener">https://www.helpnetsecurity.com/2024/03/14/cve-2023-48788-poc/</a><br /> Arcserve UDP Vulnerability and PoC<br /><a href="https://www.tenable.com/security/research/tra-2024-07" target="_blank" rel="noreferrer noopener">https://www.tenable.com/security/research/tra-2024-07</a><br /> Michael Holcomb: Mode Matters: Monitoring PLCs for Detecting Potential ICS/OT Incidents<br /><a href="https://www.sans.edu/cyber-research/mode-matters-monitoring-plcs-for-detecting-potential-ics-ot-incidents/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/mode-matters-monitoring-plcs-for-detecting-potential-ics-ot-incidents/</a><br />]]></itunes:summary><itunes:duration>1238</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,holcomb; sans.edu; ics; plc; m,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8896</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, March 14th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-march-14th-2024--62129417</link><description><![CDATA[Using ChatGPT to Deofuscate Malicious Scripts<br /><a href="https://isc.sans.edu/diary/Using%20ChatGPT%20to%20Deobfuscate%20Malicious%20Scripts/30740" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Using%20ChatGPT%20to%20Deobfuscate%20Malicious%20Scripts/30740</a><br /> Critical Fortinet Vulnerabilities<br /><a href="https://fortiguard.fortinet.com/psirt" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt</a><br /> Adobe Security Bulletins<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> Kubernetes Local Volumes Command Injection Vulnerability<br /><a href="https://www.akamai.com/blog/security-research/kubernetes-local-volumes-command-injection-vulnerability-rce-system-privileges" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/kubernetes-local-volumes-command-injection-vulnerability-rce-system-privileges</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8894.mp3</guid><pubDate>Thu, 14 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129417/8894.mp3" length="4897930" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Using ChatGPT to Deofuscate Malicious Scripts
https://isc.sans.edu/diary/Using%20ChatGPT%20to%20Deobfuscate%20Malicious%20Scripts/30740
 Critical Fortinet Vulnerabilities
https://fortiguard.fortinet.com/psirt
 Adobe Security Bulletins...</itunes:subtitle><itunes:summary><![CDATA[Using ChatGPT to Deofuscate Malicious Scripts<br /><a href="https://isc.sans.edu/diary/Using%20ChatGPT%20to%20Deobfuscate%20Malicious%20Scripts/30740" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Using%20ChatGPT%20to%20Deobfuscate%20Malicious%20Scripts/30740</a><br /> Critical Fortinet Vulnerabilities<br /><a href="https://fortiguard.fortinet.com/psirt" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt</a><br /> Adobe Security Bulletins<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> Kubernetes Local Volumes Command Injection Vulnerability<br /><a href="https://www.akamai.com/blog/security-research/kubernetes-local-volumes-command-injection-vulnerability-rce-system-privileges" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/kubernetes-local-volumes-command-injection-vulnerability-rce-system-privileges</a><br />]]></itunes:summary><itunes:duration>328</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,kubernetes; adobe; fortinet; c,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8894</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, March 14th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-march-14th-2024--59038746</link><description><![CDATA[Using ChatGPT to Deofuscate Malicious Scripts<br /><a href="https://isc.sans.edu/diary/Using%20ChatGPT%20to%20Deobfuscate%20Malicious%20Scripts/30740" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Using%20ChatGPT%20to%20Deobfuscate%20Malicious%20Scripts/30740</a><br /> Critical Fortinet Vulnerabilities<br /><a href="https://fortiguard.fortinet.com/psirt" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt</a><br /> Adobe Security Bulletins<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> Kubernetes Local Volumes Command Injection Vulnerability<br /><a href="https://www.akamai.com/blog/security-research/kubernetes-local-volumes-command-injection-vulnerability-rce-system-privileges" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/kubernetes-local-volumes-command-injection-vulnerability-rce-system-privileges</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8894.mp3</guid><pubDate>Thu, 14 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59038746/8894.mp3" length="4897930" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Using ChatGPT to Deofuscate Malicious Scripts
https://isc.sans.edu/diary/Using%20ChatGPT%20to%20Deobfuscate%20Malicious%20Scripts/30740
 Critical Fortinet Vulnerabilities
https://fortiguard.fortinet.com/psirt
 Adobe Security Bulletins...</itunes:subtitle><itunes:summary><![CDATA[Using ChatGPT to Deofuscate Malicious Scripts<br /><a href="https://isc.sans.edu/diary/Using%20ChatGPT%20to%20Deobfuscate%20Malicious%20Scripts/30740" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Using%20ChatGPT%20to%20Deobfuscate%20Malicious%20Scripts/30740</a><br /> Critical Fortinet Vulnerabilities<br /><a href="https://fortiguard.fortinet.com/psirt" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt</a><br /> Adobe Security Bulletins<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> Kubernetes Local Volumes Command Injection Vulnerability<br /><a href="https://www.akamai.com/blog/security-research/kubernetes-local-volumes-command-injection-vulnerability-rce-system-privileges" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/kubernetes-local-volumes-command-injection-vulnerability-rce-system-privileges</a><br />]]></itunes:summary><itunes:duration>328</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,kubernetes; adobe; fortinet; c,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8894</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, March 13th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-march-13th-2024--62129402</link><description><![CDATA[Microsoft Patch Tuesday March 2024<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20March%202024/30736" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20March%202024/30736</a><br /> Death Knell of NVD<br /><a href="https://resilientcyber.substack.com/p/death-knell-of-the-nvd" target="_blank" rel="noreferrer noopener">https://resilientcyber.substack.com/p/death-knell-of-the-nvd</a><br /> Unrestricted file upload vulnerability in ManageEngine Desktop Central<br /><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/unrestricted-file-upload-vulnerability-manageengine-desktop-central" target="_blank" rel="noreferrer noopener">https://www.incibe.es/en/incibe-cert/notices/aviso/unrestricted-file-upload-vulnerability-manageengine-desktop-central</a><br /> Siemens Fire Protection System Updates<br /><a href="https://cert-portal.siemens.com/productcert/html/ssa-225840.html" target="_blank" rel="noreferrer noopener">https://cert-portal.siemens.com/productcert/html/ssa-225840.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8892.mp3</guid><pubDate>Wed, 13 Mar 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129402/8892.mp3" length="5055247" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft Patch Tuesday March 2024
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20March%202024/30736
 Death Knell of NVD
https://resilientcyber.substack.com/p/death-knell-of-the-nvd
 Unrestricted file upload vulnerability in ManageEngine...</itunes:subtitle><itunes:summary><![CDATA[Microsoft Patch Tuesday March 2024<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20March%202024/30736" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20March%202024/30736</a><br /> Death Knell of NVD<br /><a href="https://resilientcyber.substack.com/p/death-knell-of-the-nvd" target="_blank" rel="noreferrer noopener">https://resilientcyber.substack.com/p/death-knell-of-the-nvd</a><br /> Unrestricted file upload vulnerability in ManageEngine Desktop Central<br /><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/unrestricted-file-upload-vulnerability-manageengine-desktop-central" target="_blank" rel="noreferrer noopener">https://www.incibe.es/en/incibe-cert/notices/aviso/unrestricted-file-upload-vulnerability-manageengine-desktop-central</a><br /> Siemens Fire Protection System Updates<br /><a href="https://cert-portal.siemens.com/productcert/html/ssa-225840.html" target="_blank" rel="noreferrer noopener">https://cert-portal.siemens.com/productcert/html/ssa-225840.html</a><br />]]></itunes:summary><itunes:duration>339</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,siemens; manageengine; nvd; ni</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8892</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, March 13th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-march-13th-2024--59027946</link><description><![CDATA[Microsoft Patch Tuesday March 2024<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20March%202024/30736" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20March%202024/30736</a><br /> Death Knell of NVD<br /><a href="https://resilientcyber.substack.com/p/death-knell-of-the-nvd" target="_blank" rel="noreferrer noopener">https://resilientcyber.substack.com/p/death-knell-of-the-nvd</a><br /> Unrestricted file upload vulnerability in ManageEngine Desktop Central<br /><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/unrestricted-file-upload-vulnerability-manageengine-desktop-central" target="_blank" rel="noreferrer noopener">https://www.incibe.es/en/incibe-cert/notices/aviso/unrestricted-file-upload-vulnerability-manageengine-desktop-central</a><br /> Siemens Fire Protection System Updates<br /><a href="https://cert-portal.siemens.com/productcert/html/ssa-225840.html" target="_blank" rel="noreferrer noopener">https://cert-portal.siemens.com/productcert/html/ssa-225840.html</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8892.mp3</guid><pubDate>Wed, 13 Mar 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59027946/8892.mp3" length="5055247" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft Patch Tuesday March 2024
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20March%202024/30736
 Death Knell of NVD
https://resilientcyber.substack.com/p/death-knell-of-the-nvd
 Unrestricted file upload vulnerability in ManageEngine...</itunes:subtitle><itunes:summary><![CDATA[Microsoft Patch Tuesday March 2024<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20March%202024/30736" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20March%202024/30736</a><br /> Death Knell of NVD<br /><a href="https://resilientcyber.substack.com/p/death-knell-of-the-nvd" target="_blank" rel="noreferrer noopener">https://resilientcyber.substack.com/p/death-knell-of-the-nvd</a><br /> Unrestricted file upload vulnerability in ManageEngine Desktop Central<br /><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/unrestricted-file-upload-vulnerability-manageengine-desktop-central" target="_blank" rel="noreferrer noopener">https://www.incibe.es/en/incibe-cert/notices/aviso/unrestricted-file-upload-vulnerability-manageengine-desktop-central</a><br /> Siemens Fire Protection System Updates<br /><a href="https://cert-portal.siemens.com/productcert/html/ssa-225840.html" target="_blank" rel="noreferrer noopener">https://cert-portal.siemens.com/productcert/html/ssa-225840.html</a><br />]]></itunes:summary><itunes:duration>339</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,siemens; manageengine; nvd; ni</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8892</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, March 12th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-march-12th-2024--62129404</link><description><![CDATA[What happens when you accidentially leak your AWS API Keys<br /><a href="https://isc.sans.edu/diary/What%20happens%20when%20you%20accidentally%20leak%20your%20AWS%20API%20keys%3F%20%5BGuest%20Diary%5D/30730" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20happens%20when%20you%20accidentally%20leak%20your%20AWS%20API%20keys%3F%20%5BGuest%20Diary%5D/30730</a><br /> How Crypto Imposters are using Calendly to infect Macs with Malware<br /><a href="https://cyberguy.com/news/how-crypto-imposters-are-using-calendly-to-infect-macs-with-malware/" target="_blank" rel="noreferrer noopener">https://cyberguy.com/news/how-crypto-imposters-are-using-calendly-to-infect-macs-with-malware/</a><br /><a href="https://krebsonsecurity.com/2024/02/calendar-meeting-links-used-to-spread-mac-malware/" target="_blank" rel="noreferrer noopener">https://krebsonsecurity.com/2024/02/calendar-meeting-links-used-to-spread-mac-malware/</a><br /> Misconfiguration Manager: Overlooked and Overprivileged<br /><a href="https://posts.specterops.io/misconfiguration-manager-overlooked-and-overprivileged-70983b8f350d" target="_blank" rel="noreferrer noopener">https://posts.specterops.io/misconfiguration-manager-overlooked-and-overprivileged-70983b8f350d</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8890.mp3</guid><pubDate>Tue, 12 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129404/8890.mp3" length="5586149" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>What happens when you accidentially leak your AWS API Keys
https://isc.sans.edu/diary/What%20happens%20when%20you%20accidentally%20leak%20your%20AWS%20API%20keys%3F%20%5BGuest%20Diary%5D/30730
 How Crypto Imposters are using Calendly to infect Macs...</itunes:subtitle><itunes:summary><![CDATA[What happens when you accidentially leak your AWS API Keys<br /><a href="https://isc.sans.edu/diary/What%20happens%20when%20you%20accidentally%20leak%20your%20AWS%20API%20keys%3F%20%5BGuest%20Diary%5D/30730" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20happens%20when%20you%20accidentally%20leak%20your%20AWS%20API%20keys%3F%20%5BGuest%20Diary%5D/30730</a><br /> How Crypto Imposters are using Calendly to infect Macs with Malware<br /><a href="https://cyberguy.com/news/how-crypto-imposters-are-using-calendly-to-infect-macs-with-malware/" target="_blank" rel="noreferrer noopener">https://cyberguy.com/news/how-crypto-imposters-are-using-calendly-to-infect-macs-with-malware/</a><br /><a href="https://krebsonsecurity.com/2024/02/calendar-meeting-links-used-to-spread-mac-malware/" target="_blank" rel="noreferrer noopener">https://krebsonsecurity.com/2024/02/calendar-meeting-links-used-to-spread-mac-malware/</a><br /> Misconfiguration Manager: Overlooked and Overprivileged<br /><a href="https://posts.specterops.io/misconfiguration-manager-overlooked-and-overprivileged-70983b8f350d" target="_blank" rel="noreferrer noopener">https://posts.specterops.io/misconfiguration-manager-overlooked-and-overprivileged-70983b8f350d</a><br />]]></itunes:summary><itunes:duration>377</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,misconfiguration; configuratio,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8890</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, March 12th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-march-12th-2024--59010867</link><description><![CDATA[What happens when you accidentially leak your AWS API Keys<br /><a href="https://isc.sans.edu/diary/What%20happens%20when%20you%20accidentally%20leak%20your%20AWS%20API%20keys%3F%20%5BGuest%20Diary%5D/30730" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20happens%20when%20you%20accidentally%20leak%20your%20AWS%20API%20keys%3F%20%5BGuest%20Diary%5D/30730</a><br /> How Crypto Imposters are using Calendly to infect Macs with Malware<br /><a href="https://cyberguy.com/news/how-crypto-imposters-are-using-calendly-to-infect-macs-with-malware/" target="_blank" rel="noreferrer noopener">https://cyberguy.com/news/how-crypto-imposters-are-using-calendly-to-infect-macs-with-malware/</a><br /><a href="https://krebsonsecurity.com/2024/02/calendar-meeting-links-used-to-spread-mac-malware/" target="_blank" rel="noreferrer noopener">https://krebsonsecurity.com/2024/02/calendar-meeting-links-used-to-spread-mac-malware/</a><br /> Misconfiguration Manager: Overlooked and Overprivileged<br /><a href="https://posts.specterops.io/misconfiguration-manager-overlooked-and-overprivileged-70983b8f350d" target="_blank" rel="noreferrer noopener">https://posts.specterops.io/misconfiguration-manager-overlooked-and-overprivileged-70983b8f350d</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8890.mp3</guid><pubDate>Tue, 12 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/59010867/8890.mp3" length="5586149" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>What happens when you accidentially leak your AWS API Keys
https://isc.sans.edu/diary/What%20happens%20when%20you%20accidentally%20leak%20your%20AWS%20API%20keys%3F%20%5BGuest%20Diary%5D/30730
 How Crypto Imposters are using Calendly to infect Macs...</itunes:subtitle><itunes:summary><![CDATA[What happens when you accidentially leak your AWS API Keys<br /><a href="https://isc.sans.edu/diary/What%20happens%20when%20you%20accidentally%20leak%20your%20AWS%20API%20keys%3F%20%5BGuest%20Diary%5D/30730" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20happens%20when%20you%20accidentally%20leak%20your%20AWS%20API%20keys%3F%20%5BGuest%20Diary%5D/30730</a><br /> How Crypto Imposters are using Calendly to infect Macs with Malware<br /><a href="https://cyberguy.com/news/how-crypto-imposters-are-using-calendly-to-infect-macs-with-malware/" target="_blank" rel="noreferrer noopener">https://cyberguy.com/news/how-crypto-imposters-are-using-calendly-to-infect-macs-with-malware/</a><br /><a href="https://krebsonsecurity.com/2024/02/calendar-meeting-links-used-to-spread-mac-malware/" target="_blank" rel="noreferrer noopener">https://krebsonsecurity.com/2024/02/calendar-meeting-links-used-to-spread-mac-malware/</a><br /> Misconfiguration Manager: Overlooked and Overprivileged<br /><a href="https://posts.specterops.io/misconfiguration-manager-overlooked-and-overprivileged-70983b8f350d" target="_blank" rel="noreferrer noopener">https://posts.specterops.io/misconfiguration-manager-overlooked-and-overprivileged-70983b8f350d</a><br />]]></itunes:summary><itunes:duration>377</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,misconfiguration; configuratio,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8890</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, March 11th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-march-11th-2024--62129471</link><description><![CDATA[Attack Wrangles Thousands of Web Users into a Password Cracking Botnet<br /><a href="https://arstechnica.com/security/2024/03/attack-wrangles-thousands-of-web-users-into-a-password-cracking-botnet" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2024/03/attack-wrangles-thousands-of-web-users-into-a-password-cracking-botnet</a><br /> Cisco VPN Client Vuln<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-secure-client-crlf-W43V4G7" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-secure-client-crlf-W43V4G7</a><br /> Fortinet Vulnerability Exploited<br /><a href="https://bishopfox.com/blog/cve-2024-21762-vulnerability-scanner-for-fortigate-firewalls" target="_blank" rel="noreferrer noopener">https://bishopfox.com/blog/cve-2024-21762-vulnerability-scanner-for-fortigate-firewalls</a><br /> pgAdmin Path Traversal<br /><a href="https://www.shielder.com/advisories/pgadmin-path-traversal_leads_to_unsafe_deserialization_and_rce/" target="_blank" rel="noreferrer noopener">https://www.shielder.com/advisories/pgadmin-path-traversal_leads_to_unsafe_deserialization_and_rce/</a><br /> Font Vulnerabilities<br /><a href="https://www.canva.dev/blog/engineering/fonts-are-still-a-helvetica-of-a-problem/" target="_blank" rel="noreferrer noopener">https://www.canva.dev/blog/engineering/fonts-are-still-a-helvetica-of-a-problem/</a><br /><br /> QNAP Flaws<br /><a href="https://securityonline.info/cve-2024-21899-cvss-9-8-critical-qnap-flaw-opens-door-to-hackers/" target="_blank" rel="noreferrer noopener">https://securityonline.info/cve-2024-21899-cvss-9-8-critical-qnap-flaw-opens-door-to-hackers/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8888.mp3</guid><pubDate>Mon, 11 Mar 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129471/8888.mp3" length="6430576" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Attack Wrangles Thousands of Web Users into a Password Cracking Botnet
https://arstechnica.com/security/2024/03/attack-wrangles-thousands-of-web-users-into-a-password-cracking-botnet
 Cisco VPN Client Vuln...</itunes:subtitle><itunes:summary><![CDATA[Attack Wrangles Thousands of Web Users into a Password Cracking Botnet<br /><a href="https://arstechnica.com/security/2024/03/attack-wrangles-thousands-of-web-users-into-a-password-cracking-botnet" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2024/03/attack-wrangles-thousands-of-web-users-into-a-password-cracking-botnet</a><br /> Cisco VPN Client Vuln<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-secure-client-crlf-W43V4G7" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-secure-client-crlf-W43V4G7</a><br /> Fortinet Vulnerability Exploited<br /><a href="https://bishopfox.com/blog/cve-2024-21762-vulnerability-scanner-for-fortigate-firewalls" target="_blank" rel="noreferrer noopener">https://bishopfox.com/blog/cve-2024-21762-vulnerability-scanner-for-fortigate-firewalls</a><br /> pgAdmin Path Traversal<br /><a href="https://www.shielder.com/advisories/pgadmin-path-traversal_leads_to_unsafe_deserialization_and_rce/" target="_blank" rel="noreferrer noopener">https://www.shielder.com/advisories/pgadmin-path-traversal_leads_to_unsafe_deserialization_and_rce/</a><br /> Font Vulnerabilities<br /><a href="https://www.canva.dev/blog/engineering/fonts-are-still-a-helvetica-of-a-problem/" target="_blank" rel="noreferrer noopener">https://www.canva.dev/blog/engineering/fonts-are-still-a-helvetica-of-a-problem/</a><br /><br /> QNAP Flaws<br /><a href="https://securityonline.info/cve-2024-21899-cvss-9-8-critical-qnap-flaw-opens-door-to-hackers/" target="_blank" rel="noreferrer noopener">https://securityonline.info/cve-2024-21899-cvss-9-8-critical-qnap-flaw-opens-door-to-hackers/</a><br />]]></itunes:summary><itunes:duration>438</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,qnap; fonts; canva; pgadmin; f,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8888</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, March 11th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-march-11th-2024--58995049</link><description><![CDATA[Attack Wrangles Thousands of Web Users into a Password Cracking Botnet<br /><a href="https://arstechnica.com/security/2024/03/attack-wrangles-thousands-of-web-users-into-a-password-cracking-botnet" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2024/03/attack-wrangles-thousands-of-web-users-into-a-password-cracking-botnet</a><br /> Cisco VPN Client Vuln<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-secure-client-crlf-W43V4G7" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-secure-client-crlf-W43V4G7</a><br /> Fortinet Vulnerability Exploited<br /><a href="https://bishopfox.com/blog/cve-2024-21762-vulnerability-scanner-for-fortigate-firewalls" target="_blank" rel="noreferrer noopener">https://bishopfox.com/blog/cve-2024-21762-vulnerability-scanner-for-fortigate-firewalls</a><br /> pgAdmin Path Traversal<br /><a href="https://www.shielder.com/advisories/pgadmin-path-traversal_leads_to_unsafe_deserialization_and_rce/" target="_blank" rel="noreferrer noopener">https://www.shielder.com/advisories/pgadmin-path-traversal_leads_to_unsafe_deserialization_and_rce/</a><br /> Font Vulnerabilities<br /><a href="https://www.canva.dev/blog/engineering/fonts-are-still-a-helvetica-of-a-problem/" target="_blank" rel="noreferrer noopener">https://www.canva.dev/blog/engineering/fonts-are-still-a-helvetica-of-a-problem/</a><br /><br /> QNAP Flaws<br /><a href="https://securityonline.info/cve-2024-21899-cvss-9-8-critical-qnap-flaw-opens-door-to-hackers/" target="_blank" rel="noreferrer noopener">https://securityonline.info/cve-2024-21899-cvss-9-8-critical-qnap-flaw-opens-door-to-hackers/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8888.mp3</guid><pubDate>Mon, 11 Mar 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58995049/8888.mp3" length="6430576" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Attack Wrangles Thousands of Web Users into a Password Cracking Botnet
https://arstechnica.com/security/2024/03/attack-wrangles-thousands-of-web-users-into-a-password-cracking-botnet
 Cisco VPN Client Vuln...</itunes:subtitle><itunes:summary><![CDATA[Attack Wrangles Thousands of Web Users into a Password Cracking Botnet<br /><a href="https://arstechnica.com/security/2024/03/attack-wrangles-thousands-of-web-users-into-a-password-cracking-botnet" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2024/03/attack-wrangles-thousands-of-web-users-into-a-password-cracking-botnet</a><br /> Cisco VPN Client Vuln<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-secure-client-crlf-W43V4G7" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-secure-client-crlf-W43V4G7</a><br /> Fortinet Vulnerability Exploited<br /><a href="https://bishopfox.com/blog/cve-2024-21762-vulnerability-scanner-for-fortigate-firewalls" target="_blank" rel="noreferrer noopener">https://bishopfox.com/blog/cve-2024-21762-vulnerability-scanner-for-fortigate-firewalls</a><br /> pgAdmin Path Traversal<br /><a href="https://www.shielder.com/advisories/pgadmin-path-traversal_leads_to_unsafe_deserialization_and_rce/" target="_blank" rel="noreferrer noopener">https://www.shielder.com/advisories/pgadmin-path-traversal_leads_to_unsafe_deserialization_and_rce/</a><br /> Font Vulnerabilities<br /><a href="https://www.canva.dev/blog/engineering/fonts-are-still-a-helvetica-of-a-problem/" target="_blank" rel="noreferrer noopener">https://www.canva.dev/blog/engineering/fonts-are-still-a-helvetica-of-a-problem/</a><br /><br /> QNAP Flaws<br /><a href="https://securityonline.info/cve-2024-21899-cvss-9-8-critical-qnap-flaw-opens-door-to-hackers/" target="_blank" rel="noreferrer noopener">https://securityonline.info/cve-2024-21899-cvss-9-8-critical-qnap-flaw-opens-door-to-hackers/</a><br />]]></itunes:summary><itunes:duration>438</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,qnap; fonts; canva; pgadmin; f,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8888</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, March 8th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-march-8th-2024--62129472</link><description><![CDATA[AWS Deploymnet Risks - Configuration and Credential File Targeting<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20AWS%20Deployment%20Risks%20-%20Configuration%20and%20Credential%20File%20Targeting/30722" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20AWS%20Deployment%20Risks%20-%20Configuration%20and%20Credential%20File%20Targeting/30722</a><br /> Apple Updates<br /><a href="https://isc.sans.edu/diary/MacOS%20Patches%20%28and%20Safari%2C%20TVOS%2C%20VisionOS%2C%20WatchOS%29/30726" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/MacOS%20Patches%20%28and%20Safari%2C%20TVOS%2C%20VisionOS%2C%20WatchOS%29/30726</a><br /> NSA/CISA Secure Cloud Guides<br /><a href="https://media.defense.gov/2024/Mar/07/2003407866/-1/-1/0/CSI-CloudTop10-Identity-Access-Management.PDF" target="_blank" rel="noreferrer noopener">https://media.defense.gov/2024/Mar/07/2003407866/-1/-1/0/CSI-CloudTop10-Identity-Access-Management.PDF</a><br /><a href="https://media.defense.gov/2024/Mar/07/2003407858/-1/-1/0/CSI-CloudTop10-Key-Management.PDF" target="_blank" rel="noreferrer noopener">https://media.defense.gov/2024/Mar/07/2003407858/-1/-1/0/CSI-CloudTop10-Key-Management.PDF</a><br /><a href="https://media.defense.gov/2024/Mar/07/2003407859/-1/-1/0/CSI-CloudTop10-Managed-Service-Providers.PDF" target="_blank" rel="noreferrer noopener">https://media.defense.gov/2024/Mar/07/2003407859/-1/-1/0/CSI-CloudTop10-Managed-Service-Providers.PDF</a><br /><a href="https://media.defense.gov/2024/Mar/07/2003407862/-1/-1/0/CSI-CloudTop10-Secure-Data.PDF" target="_blank" rel="noreferrer noopener">https://media.defense.gov/2024/Mar/07/2003407862/-1/-1/0/CSI-CloudTop10-Secure-Data.PDF</a><br /><a href="https://media.defense.gov/2024/Mar/07/2003407861/-1/-1/0/CSI-CloudTop10-Network-Segmentation.PDF" target="_blank" rel="noreferrer noopener">https://media.defense.gov/2024/Mar/07/2003407861/-1/-1/0/CSI-CloudTop10-Network-Segmentation.PDF</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8886.mp3</guid><pubDate>Fri, 08 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129472/8886.mp3" length="4688309" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>AWS Deploymnet Risks - Configuration and Credential File Targeting
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20AWS%20Deployment%20Risks%20-%20Configuration%20and%20Credential%20File%20Targeting/30722
 Apple Updates...</itunes:subtitle><itunes:summary><![CDATA[AWS Deploymnet Risks - Configuration and Credential File Targeting<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20AWS%20Deployment%20Risks%20-%20Configuration%20and%20Credential%20File%20Targeting/30722" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20AWS%20Deployment%20Risks%20-%20Configuration%20and%20Credential%20File%20Targeting/30722</a><br /> Apple Updates<br /><a href="https://isc.sans.edu/diary/MacOS%20Patches%20%28and%20Safari%2C%20TVOS%2C%20VisionOS%2C%20WatchOS%29/30726" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/MacOS%20Patches%20%28and%20Safari%2C%20TVOS%2C%20VisionOS%2C%20WatchOS%29/30726</a><br /> NSA/CISA Secure Cloud Guides<br /><a href="https://media.defense.gov/2024/Mar/07/2003407866/-1/-1/0/CSI-CloudTop10-Identity-Access-Management.PDF" target="_blank" rel="noreferrer noopener">https://media.defense.gov/2024/Mar/07/2003407866/-1/-1/0/CSI-CloudTop10-Identity-Access-Management.PDF</a><br /><a href="https://media.defense.gov/2024/Mar/07/2003407858/-1/-1/0/CSI-CloudTop10-Key-Management.PDF" target="_blank" rel="noreferrer noopener">https://media.defense.gov/2024/Mar/07/2003407858/-1/-1/0/CSI-CloudTop10-Key-Management.PDF</a><br /><a href="https://media.defense.gov/2024/Mar/07/2003407859/-1/-1/0/CSI-CloudTop10-Managed-Service-Providers.PDF" target="_blank" rel="noreferrer noopener">https://media.defense.gov/2024/Mar/07/2003407859/-1/-1/0/CSI-CloudTop10-Managed-Service-Providers.PDF</a><br /><a href="https://media.defense.gov/2024/Mar/07/2003407862/-1/-1/0/CSI-CloudTop10-Secure-Data.PDF" target="_blank" rel="noreferrer noopener">https://media.defense.gov/2024/Mar/07/2003407862/-1/-1/0/CSI-CloudTop10-Secure-Data.PDF</a><br /><a href="https://media.defense.gov/2024/Mar/07/2003407861/-1/-1/0/CSI-CloudTop10-Network-Segmentation.PDF" target="_blank" rel="noreferrer noopener">https://media.defense.gov/2024/Mar/07/2003407861/-1/-1/0/CSI-CloudTop10-Network-Segmentation.PDF</a><br />]]></itunes:summary><itunes:duration>313</itunes:duration><itunes:keywords>apple,aws,azure,business,cisa,cloud,computer,cyber,cybersecurity,daily,hacking,honeypot,infosec,internet,it,network,news,nsa,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8886</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, March 8th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-march-8th-2024--58966712</link><description><![CDATA[AWS Deploymnet Risks - Configuration and Credential File Targeting<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20AWS%20Deployment%20Risks%20-%20Configuration%20and%20Credential%20File%20Targeting/30722" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20AWS%20Deployment%20Risks%20-%20Configuration%20and%20Credential%20File%20Targeting/30722</a><br /> Apple Updates<br /><a href="https://isc.sans.edu/diary/MacOS%20Patches%20%28and%20Safari%2C%20TVOS%2C%20VisionOS%2C%20WatchOS%29/30726" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/MacOS%20Patches%20%28and%20Safari%2C%20TVOS%2C%20VisionOS%2C%20WatchOS%29/30726</a><br /> NSA/CISA Secure Cloud Guides<br /><a href="https://media.defense.gov/2024/Mar/07/2003407866/-1/-1/0/CSI-CloudTop10-Identity-Access-Management.PDF" target="_blank" rel="noreferrer noopener">https://media.defense.gov/2024/Mar/07/2003407866/-1/-1/0/CSI-CloudTop10-Identity-Access-Management.PDF</a><br /><a href="https://media.defense.gov/2024/Mar/07/2003407858/-1/-1/0/CSI-CloudTop10-Key-Management.PDF" target="_blank" rel="noreferrer noopener">https://media.defense.gov/2024/Mar/07/2003407858/-1/-1/0/CSI-CloudTop10-Key-Management.PDF</a><br /><a href="https://media.defense.gov/2024/Mar/07/2003407859/-1/-1/0/CSI-CloudTop10-Managed-Service-Providers.PDF" target="_blank" rel="noreferrer noopener">https://media.defense.gov/2024/Mar/07/2003407859/-1/-1/0/CSI-CloudTop10-Managed-Service-Providers.PDF</a><br /><a href="https://media.defense.gov/2024/Mar/07/2003407862/-1/-1/0/CSI-CloudTop10-Secure-Data.PDF" target="_blank" rel="noreferrer noopener">https://media.defense.gov/2024/Mar/07/2003407862/-1/-1/0/CSI-CloudTop10-Secure-Data.PDF</a><br /><a href="https://media.defense.gov/2024/Mar/07/2003407861/-1/-1/0/CSI-CloudTop10-Network-Segmentation.PDF" target="_blank" rel="noreferrer noopener">https://media.defense.gov/2024/Mar/07/2003407861/-1/-1/0/CSI-CloudTop10-Network-Segmentation.PDF</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8886.mp3</guid><pubDate>Fri, 08 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58966712/8886.mp3" length="4688309" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>AWS Deploymnet Risks - Configuration and Credential File Targeting
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20AWS%20Deployment%20Risks%20-%20Configuration%20and%20Credential%20File%20Targeting/30722
 Apple Updates...</itunes:subtitle><itunes:summary><![CDATA[AWS Deploymnet Risks - Configuration and Credential File Targeting<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20AWS%20Deployment%20Risks%20-%20Configuration%20and%20Credential%20File%20Targeting/30722" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20AWS%20Deployment%20Risks%20-%20Configuration%20and%20Credential%20File%20Targeting/30722</a><br /> Apple Updates<br /><a href="https://isc.sans.edu/diary/MacOS%20Patches%20%28and%20Safari%2C%20TVOS%2C%20VisionOS%2C%20WatchOS%29/30726" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/MacOS%20Patches%20%28and%20Safari%2C%20TVOS%2C%20VisionOS%2C%20WatchOS%29/30726</a><br /> NSA/CISA Secure Cloud Guides<br /><a href="https://media.defense.gov/2024/Mar/07/2003407866/-1/-1/0/CSI-CloudTop10-Identity-Access-Management.PDF" target="_blank" rel="noreferrer noopener">https://media.defense.gov/2024/Mar/07/2003407866/-1/-1/0/CSI-CloudTop10-Identity-Access-Management.PDF</a><br /><a href="https://media.defense.gov/2024/Mar/07/2003407858/-1/-1/0/CSI-CloudTop10-Key-Management.PDF" target="_blank" rel="noreferrer noopener">https://media.defense.gov/2024/Mar/07/2003407858/-1/-1/0/CSI-CloudTop10-Key-Management.PDF</a><br /><a href="https://media.defense.gov/2024/Mar/07/2003407859/-1/-1/0/CSI-CloudTop10-Managed-Service-Providers.PDF" target="_blank" rel="noreferrer noopener">https://media.defense.gov/2024/Mar/07/2003407859/-1/-1/0/CSI-CloudTop10-Managed-Service-Providers.PDF</a><br /><a href="https://media.defense.gov/2024/Mar/07/2003407862/-1/-1/0/CSI-CloudTop10-Secure-Data.PDF" target="_blank" rel="noreferrer noopener">https://media.defense.gov/2024/Mar/07/2003407862/-1/-1/0/CSI-CloudTop10-Secure-Data.PDF</a><br /><a href="https://media.defense.gov/2024/Mar/07/2003407861/-1/-1/0/CSI-CloudTop10-Network-Segmentation.PDF" target="_blank" rel="noreferrer noopener">https://media.defense.gov/2024/Mar/07/2003407861/-1/-1/0/CSI-CloudTop10-Network-Segmentation.PDF</a><br />]]></itunes:summary><itunes:duration>313</itunes:duration><itunes:keywords>apple,aws,azure,business,cisa,cloud,computer,cyber,cybersecurity,daily,hacking,honeypot,infosec,internet,it,network,news,nsa,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8886</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, March 7th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-march-7th-2024--62129438</link><description><![CDATA[Scanning and Abusing the QUIC Protocol<br /><a href="https://isc.sans.edu/diary/Scanning%20and%20abusing%20the%20QUIC%20protocol/30720" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scanning%20and%20abusing%20the%20QUIC%20protocol/30720</a><br /> Google Chrome Update<br /><a href="https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop.html</a><br /> Spinning YARN<br /><a href="https://www.cadosecurity.com/spinning-yarn-a-new-linux-malware-campaign-targets-docker-apache-hadoop-redis-and-confluence/" target="_blank" rel="noreferrer noopener">https://www.cadosecurity.com/spinning-yarn-a-new-linux-malware-campaign-targets-docker-apache-hadoop-redis-and-confluence/</a><br /> Teamcity Exploited<br /><a href="https://twitter.com/leak_ix/status/1765460190621581347" target="_blank" rel="noreferrer noopener">https://twitter.com/leak_ix/status/1765460190621581347</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8884.mp3</guid><pubDate>Thu, 07 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129438/8884.mp3" length="5439389" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Scanning and Abusing the QUIC Protocol
https://isc.sans.edu/diary/Scanning%20and%20abusing%20the%20QUIC%20protocol/30720
 Google Chrome Update
https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop.html
 Spinning YARN...</itunes:subtitle><itunes:summary><![CDATA[Scanning and Abusing the QUIC Protocol<br /><a href="https://isc.sans.edu/diary/Scanning%20and%20abusing%20the%20QUIC%20protocol/30720" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scanning%20and%20abusing%20the%20QUIC%20protocol/30720</a><br /> Google Chrome Update<br /><a href="https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop.html</a><br /> Spinning YARN<br /><a href="https://www.cadosecurity.com/spinning-yarn-a-new-linux-malware-campaign-targets-docker-apache-hadoop-redis-and-confluence/" target="_blank" rel="noreferrer noopener">https://www.cadosecurity.com/spinning-yarn-a-new-linux-malware-campaign-targets-docker-apache-hadoop-redis-and-confluence/</a><br /> Teamcity Exploited<br /><a href="https://twitter.com/leak_ix/status/1765460190621581347" target="_blank" rel="noreferrer noopener">https://twitter.com/leak_ix/status/1765460190621581347</a><br />]]></itunes:summary><itunes:duration>367</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,teamcity; yarn; hadoop; chrome</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8884</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, March 7th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-march-7th-2024--58953607</link><description><![CDATA[Scanning and Abusing the QUIC Protocol<br /><a href="https://isc.sans.edu/diary/Scanning%20and%20abusing%20the%20QUIC%20protocol/30720" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scanning%20and%20abusing%20the%20QUIC%20protocol/30720</a><br /> Google Chrome Update<br /><a href="https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop.html</a><br /> Spinning YARN<br /><a href="https://www.cadosecurity.com/spinning-yarn-a-new-linux-malware-campaign-targets-docker-apache-hadoop-redis-and-confluence/" target="_blank" rel="noreferrer noopener">https://www.cadosecurity.com/spinning-yarn-a-new-linux-malware-campaign-targets-docker-apache-hadoop-redis-and-confluence/</a><br /> Teamcity Exploited<br /><a href="https://twitter.com/leak_ix/status/1765460190621581347" target="_blank" rel="noreferrer noopener">https://twitter.com/leak_ix/status/1765460190621581347</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8884.mp3</guid><pubDate>Thu, 07 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58953607/8884.mp3" length="5439389" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Scanning and Abusing the QUIC Protocol
https://isc.sans.edu/diary/Scanning%20and%20abusing%20the%20QUIC%20protocol/30720
 Google Chrome Update
https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop.html
 Spinning YARN...</itunes:subtitle><itunes:summary><![CDATA[Scanning and Abusing the QUIC Protocol<br /><a href="https://isc.sans.edu/diary/Scanning%20and%20abusing%20the%20QUIC%20protocol/30720" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scanning%20and%20abusing%20the%20QUIC%20protocol/30720</a><br /> Google Chrome Update<br /><a href="https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop.html</a><br /> Spinning YARN<br /><a href="https://www.cadosecurity.com/spinning-yarn-a-new-linux-malware-campaign-targets-docker-apache-hadoop-redis-and-confluence/" target="_blank" rel="noreferrer noopener">https://www.cadosecurity.com/spinning-yarn-a-new-linux-malware-campaign-targets-docker-apache-hadoop-redis-and-confluence/</a><br /> Teamcity Exploited<br /><a href="https://twitter.com/leak_ix/status/1765460190621581347" target="_blank" rel="noreferrer noopener">https://twitter.com/leak_ix/status/1765460190621581347</a><br />]]></itunes:summary><itunes:duration>367</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,teamcity; yarn; hadoop; chrome</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8884</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, March 6th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-march-6th-2024--62129421</link><description><![CDATA[iOS/iPadOS Updates with Zero Day Fixes<br /><a href="https://isc.sans.edu/diary/Apple%20Releases%20iOS%20iPadOS%20Updates%20with%20Zero%20Day%20Fixes./30716" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Releases%20iOS%20iPadOS%20Updates%20with%20Zero%20Day%20Fixes./30716</a><br /> Why Your Firewall Will Kill You<br /><a href="https://isc.sans.edu/diary/Why+Your+Firewall+Will+Kill+You/30714/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Why+Your+Firewall+Will+Kill+You/30714/</a><br /> QEMU Tunnel<br /><a href="https://securelist.com/network-tunneling-with-qemu/111803/" target="_blank" rel="noreferrer noopener">https://securelist.com/network-tunneling-with-qemu/111803/</a><br /> VMware Vulnerabilities Patched<br /><a href="https://www.vmware.com/security/advisories/VMSA-2024-0006.html" target="_blank" rel="noreferrer noopener">https://www.vmware.com/security/advisories/VMSA-2024-0006.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8882.mp3</guid><pubDate>Wed, 06 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129421/8882.mp3" length="5909665" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>iOS/iPadOS Updates with Zero Day Fixes
https://isc.sans.edu/diary/Apple%20Releases%20iOS%20iPadOS%20Updates%20with%20Zero%20Day%20Fixes./30716
 Why Your Firewall Will Kill You
https://isc.sans.edu/diary/Why+Your+Firewall+Will+Kill+You/30714/
 QEMU...</itunes:subtitle><itunes:summary><![CDATA[iOS/iPadOS Updates with Zero Day Fixes<br /><a href="https://isc.sans.edu/diary/Apple%20Releases%20iOS%20iPadOS%20Updates%20with%20Zero%20Day%20Fixes./30716" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Releases%20iOS%20iPadOS%20Updates%20with%20Zero%20Day%20Fixes./30716</a><br /> Why Your Firewall Will Kill You<br /><a href="https://isc.sans.edu/diary/Why+Your+Firewall+Will+Kill+You/30714/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Why+Your+Firewall+Will+Kill+You/30714/</a><br /> QEMU Tunnel<br /><a href="https://securelist.com/network-tunneling-with-qemu/111803/" target="_blank" rel="noreferrer noopener">https://securelist.com/network-tunneling-with-qemu/111803/</a><br /> VMware Vulnerabilities Patched<br /><a href="https://www.vmware.com/security/advisories/VMSA-2024-0006.html" target="_blank" rel="noreferrer noopener">https://www.vmware.com/security/advisories/VMSA-2024-0006.html</a><br />]]></itunes:summary><itunes:duration>401</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,vmware; qemu; tunnel; firewall</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8882</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, March 6th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-march-6th-2024--58938365</link><description><![CDATA[iOS/iPadOS Updates with Zero Day Fixes<br /><a href="https://isc.sans.edu/diary/Apple%20Releases%20iOS%20iPadOS%20Updates%20with%20Zero%20Day%20Fixes./30716" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Releases%20iOS%20iPadOS%20Updates%20with%20Zero%20Day%20Fixes./30716</a><br /> Why Your Firewall Will Kill You<br /><a href="https://isc.sans.edu/diary/Why+Your+Firewall+Will+Kill+You/30714/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Why+Your+Firewall+Will+Kill+You/30714/</a><br /> QEMU Tunnel<br /><a href="https://securelist.com/network-tunneling-with-qemu/111803/" target="_blank" rel="noreferrer noopener">https://securelist.com/network-tunneling-with-qemu/111803/</a><br /> VMware Vulnerabilities Patched<br /><a href="https://www.vmware.com/security/advisories/VMSA-2024-0006.html" target="_blank" rel="noreferrer noopener">https://www.vmware.com/security/advisories/VMSA-2024-0006.html</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8882.mp3</guid><pubDate>Wed, 06 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58938365/8882.mp3" length="5909665" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>iOS/iPadOS Updates with Zero Day Fixes
https://isc.sans.edu/diary/Apple%20Releases%20iOS%20iPadOS%20Updates%20with%20Zero%20Day%20Fixes./30716
 Why Your Firewall Will Kill You
https://isc.sans.edu/diary/Why+Your+Firewall+Will+Kill+You/30714/
 QEMU...</itunes:subtitle><itunes:summary><![CDATA[iOS/iPadOS Updates with Zero Day Fixes<br /><a href="https://isc.sans.edu/diary/Apple%20Releases%20iOS%20iPadOS%20Updates%20with%20Zero%20Day%20Fixes./30716" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Releases%20iOS%20iPadOS%20Updates%20with%20Zero%20Day%20Fixes./30716</a><br /> Why Your Firewall Will Kill You<br /><a href="https://isc.sans.edu/diary/Why+Your+Firewall+Will+Kill+You/30714/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Why+Your+Firewall+Will+Kill+You/30714/</a><br /> QEMU Tunnel<br /><a href="https://securelist.com/network-tunneling-with-qemu/111803/" target="_blank" rel="noreferrer noopener">https://securelist.com/network-tunneling-with-qemu/111803/</a><br /> VMware Vulnerabilities Patched<br /><a href="https://www.vmware.com/security/advisories/VMSA-2024-0006.html" target="_blank" rel="noreferrer noopener">https://www.vmware.com/security/advisories/VMSA-2024-0006.html</a><br />]]></itunes:summary><itunes:duration>401</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,vmware; qemu; tunnel; firewall</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8882</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, March 5th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-march-5th-2024--62129474</link><description><![CDATA[Capturing DShield Packets with a LAN Tap<br /><a href="https://isc.sans.edu/diary/Capturing%20DShield%20Packets%20with%20a%20LAN%20Tap%20%5BGuest%20Diary%5D/30708" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Capturing%20DShield%20Packets%20with%20a%20LAN%20Tap%20%5BGuest%20Diary%5D/30708</a><br /> Additional Critical Security Issues Affecting Teamcity<br /><a href="https://blog.jetbrains.com/teamcity/2024/03/additional-critical-security-issues-affecting-teamcity-on-premises-cve-2024-27198-and-cve-2024-27199-update-to-2023-11-4-now/" target="_blank" rel="noreferrer noopener">https://blog.jetbrains.com/teamcity/2024/03/additional-critical-security-issues-affecting-teamcity-on-premises-cve-2024-27198-and-cve-2024-27199-update-to-2023-11-4-now/</a><br /> GitHub Push Protection Now On By Default<br /><a href="https://github.blog/2024-02-29-keeping-secrets-out-of-public-repositories/" target="_blank" rel="noreferrer noopener">https://github.blog/2024-02-29-keeping-secrets-out-of-public-repositories/</a><br /> Android Updates<br /><a href="https://source.android.com/docs/security/bulletin/2024-03-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2024-03-01</a><br /> Linksys E-2000 Vulnerablity<br /><a href="https://warp-desk-89d.notion.site/Linksys-E-2000-efcd532d8dcf4710a4af13fca131a5b8" target="_blank" rel="noreferrer noopener">https://warp-desk-89d.notion.site/Linksys-E-2000-efcd532d8dcf4710a4af13fca131a5b8</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8880.mp3</guid><pubDate>Tue, 05 Mar 2024 02:15:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129474/8880.mp3" length="5071737" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Capturing DShield Packets with a LAN Tap
https://isc.sans.edu/diary/Capturing%20DShield%20Packets%20with%20a%20LAN%20Tap%20%5BGuest%20Diary%5D/30708
 Additional Critical Security Issues Affecting Teamcity...</itunes:subtitle><itunes:summary><![CDATA[Capturing DShield Packets with a LAN Tap<br /><a href="https://isc.sans.edu/diary/Capturing%20DShield%20Packets%20with%20a%20LAN%20Tap%20%5BGuest%20Diary%5D/30708" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Capturing%20DShield%20Packets%20with%20a%20LAN%20Tap%20%5BGuest%20Diary%5D/30708</a><br /> Additional Critical Security Issues Affecting Teamcity<br /><a href="https://blog.jetbrains.com/teamcity/2024/03/additional-critical-security-issues-affecting-teamcity-on-premises-cve-2024-27198-and-cve-2024-27199-update-to-2023-11-4-now/" target="_blank" rel="noreferrer noopener">https://blog.jetbrains.com/teamcity/2024/03/additional-critical-security-issues-affecting-teamcity-on-premises-cve-2024-27198-and-cve-2024-27199-update-to-2023-11-4-now/</a><br /> GitHub Push Protection Now On By Default<br /><a href="https://github.blog/2024-02-29-keeping-secrets-out-of-public-repositories/" target="_blank" rel="noreferrer noopener">https://github.blog/2024-02-29-keeping-secrets-out-of-public-repositories/</a><br /> Android Updates<br /><a href="https://source.android.com/docs/security/bulletin/2024-03-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2024-03-01</a><br /> Linksys E-2000 Vulnerablity<br /><a href="https://warp-desk-89d.notion.site/Linksys-E-2000-efcd532d8dcf4710a4af13fca131a5b8" target="_blank" rel="noreferrer noopener">https://warp-desk-89d.notion.site/Linksys-E-2000-efcd532d8dcf4710a4af13fca131a5b8</a><br />]]></itunes:summary><itunes:duration>341</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,linksys; android; github; tap;,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8880</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, March 5th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-march-5th-2024--58927397</link><description><![CDATA[Capturing DShield Packets with a LAN Tap<br /><a href="https://isc.sans.edu/diary/Capturing%20DShield%20Packets%20with%20a%20LAN%20Tap%20%5BGuest%20Diary%5D/30708" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Capturing%20DShield%20Packets%20with%20a%20LAN%20Tap%20%5BGuest%20Diary%5D/30708</a><br /> Additional Critical Security Issues Affecting Teamcity<br /><a href="https://blog.jetbrains.com/teamcity/2024/03/additional-critical-security-issues-affecting-teamcity-on-premises-cve-2024-27198-and-cve-2024-27199-update-to-2023-11-4-now/" target="_blank" rel="noreferrer noopener">https://blog.jetbrains.com/teamcity/2024/03/additional-critical-security-issues-affecting-teamcity-on-premises-cve-2024-27198-and-cve-2024-27199-update-to-2023-11-4-now/</a><br /> GitHub Push Protection Now On By Default<br /><a href="https://github.blog/2024-02-29-keeping-secrets-out-of-public-repositories/" target="_blank" rel="noreferrer noopener">https://github.blog/2024-02-29-keeping-secrets-out-of-public-repositories/</a><br /> Android Updates<br /><a href="https://source.android.com/docs/security/bulletin/2024-03-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2024-03-01</a><br /> Linksys E-2000 Vulnerablity<br /><a href="https://warp-desk-89d.notion.site/Linksys-E-2000-efcd532d8dcf4710a4af13fca131a5b8" target="_blank" rel="noreferrer noopener">https://warp-desk-89d.notion.site/Linksys-E-2000-efcd532d8dcf4710a4af13fca131a5b8</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8880.mp3</guid><pubDate>Tue, 05 Mar 2024 02:15:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58927397/8880.mp3" length="5071737" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Capturing DShield Packets with a LAN Tap
https://isc.sans.edu/diary/Capturing%20DShield%20Packets%20with%20a%20LAN%20Tap%20%5BGuest%20Diary%5D/30708
 Additional Critical Security Issues Affecting Teamcity...</itunes:subtitle><itunes:summary><![CDATA[Capturing DShield Packets with a LAN Tap<br /><a href="https://isc.sans.edu/diary/Capturing%20DShield%20Packets%20with%20a%20LAN%20Tap%20%5BGuest%20Diary%5D/30708" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Capturing%20DShield%20Packets%20with%20a%20LAN%20Tap%20%5BGuest%20Diary%5D/30708</a><br /> Additional Critical Security Issues Affecting Teamcity<br /><a href="https://blog.jetbrains.com/teamcity/2024/03/additional-critical-security-issues-affecting-teamcity-on-premises-cve-2024-27198-and-cve-2024-27199-update-to-2023-11-4-now/" target="_blank" rel="noreferrer noopener">https://blog.jetbrains.com/teamcity/2024/03/additional-critical-security-issues-affecting-teamcity-on-premises-cve-2024-27198-and-cve-2024-27199-update-to-2023-11-4-now/</a><br /> GitHub Push Protection Now On By Default<br /><a href="https://github.blog/2024-02-29-keeping-secrets-out-of-public-repositories/" target="_blank" rel="noreferrer noopener">https://github.blog/2024-02-29-keeping-secrets-out-of-public-repositories/</a><br /> Android Updates<br /><a href="https://source.android.com/docs/security/bulletin/2024-03-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2024-03-01</a><br /> Linksys E-2000 Vulnerablity<br /><a href="https://warp-desk-89d.notion.site/Linksys-E-2000-efcd532d8dcf4710a4af13fca131a5b8" target="_blank" rel="noreferrer noopener">https://warp-desk-89d.notion.site/Linksys-E-2000-efcd532d8dcf4710a4af13fca131a5b8</a><br />]]></itunes:summary><itunes:duration>341</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,linksys; android; github; tap;,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8880</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, March 4th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-march-4th-2024--62129430</link><description><![CDATA[Scanning for Confluence CVE-2022-26134<br /><a href="https://isc.sans.edu/diary/Scanning%20for%20Confluence%20CVE-2022-26134/30704" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scanning%20for%20Confluence%20CVE-2022-26134/30704</a><br /> Exploiting CSP Wildcards for Google Domains<br /><a href="https://attackshipsonfi.re/p/exploiting-csp-wildcards-for-google" target="_blank" rel="noreferrer noopener">https://attackshipsonfi.re/p/exploiting-csp-wildcards-for-google</a><br /> Silver SAML: Golden SAML in the Cloud<br /><a href="https://www.semperis.com/blog/meet-silver-saml/" target="_blank" rel="noreferrer noopener">https://www.semperis.com/blog/meet-silver-saml/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8878.mp3</guid><pubDate>Mon, 04 Mar 2024 02:00:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129430/8878.mp3" length="4900425" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Scanning for Confluence CVE-2022-26134
https://isc.sans.edu/diary/Scanning%20for%20Confluence%20CVE-2022-26134/30704
 Exploiting CSP Wildcards for Google Domains
https://attackshipsonfi.re/p/exploiting-csp-wildcards-for-google
 Silver SAML: Golden...</itunes:subtitle><itunes:summary><![CDATA[Scanning for Confluence CVE-2022-26134<br /><a href="https://isc.sans.edu/diary/Scanning%20for%20Confluence%20CVE-2022-26134/30704" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scanning%20for%20Confluence%20CVE-2022-26134/30704</a><br /> Exploiting CSP Wildcards for Google Domains<br /><a href="https://attackshipsonfi.re/p/exploiting-csp-wildcards-for-google" target="_blank" rel="noreferrer noopener">https://attackshipsonfi.re/p/exploiting-csp-wildcards-for-google</a><br /> Silver SAML: Golden SAML in the Cloud<br /><a href="https://www.semperis.com/blog/meet-silver-saml/" target="_blank" rel="noreferrer noopener">https://www.semperis.com/blog/meet-silver-saml/</a><br />]]></itunes:summary><itunes:duration>328</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,saml; csp; confluence; cve-202,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8878</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, March 4th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-march-4th-2024--58912643</link><description><![CDATA[Scanning for Confluence CVE-2022-26134<br /><a href="https://isc.sans.edu/diary/Scanning%20for%20Confluence%20CVE-2022-26134/30704" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scanning%20for%20Confluence%20CVE-2022-26134/30704</a><br /> Exploiting CSP Wildcards for Google Domains<br /><a href="https://attackshipsonfi.re/p/exploiting-csp-wildcards-for-google" target="_blank" rel="noreferrer noopener">https://attackshipsonfi.re/p/exploiting-csp-wildcards-for-google</a><br /> Silver SAML: Golden SAML in the Cloud<br /><a href="https://www.semperis.com/blog/meet-silver-saml/" target="_blank" rel="noreferrer noopener">https://www.semperis.com/blog/meet-silver-saml/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8878.mp3</guid><pubDate>Mon, 04 Mar 2024 02:00:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58912643/8878.mp3" length="4900425" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Scanning for Confluence CVE-2022-26134
https://isc.sans.edu/diary/Scanning%20for%20Confluence%20CVE-2022-26134/30704
 Exploiting CSP Wildcards for Google Domains
https://attackshipsonfi.re/p/exploiting-csp-wildcards-for-google
 Silver SAML: Golden...</itunes:subtitle><itunes:summary><![CDATA[Scanning for Confluence CVE-2022-26134<br /><a href="https://isc.sans.edu/diary/Scanning%20for%20Confluence%20CVE-2022-26134/30704" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scanning%20for%20Confluence%20CVE-2022-26134/30704</a><br /> Exploiting CSP Wildcards for Google Domains<br /><a href="https://attackshipsonfi.re/p/exploiting-csp-wildcards-for-google" target="_blank" rel="noreferrer noopener">https://attackshipsonfi.re/p/exploiting-csp-wildcards-for-google</a><br /> Silver SAML: Golden SAML in the Cloud<br /><a href="https://www.semperis.com/blog/meet-silver-saml/" target="_blank" rel="noreferrer noopener">https://www.semperis.com/blog/meet-silver-saml/</a><br />]]></itunes:summary><itunes:duration>328</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,saml; csp; confluence; cve-202,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8878</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, March 1st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-march-1st-2024--62129440</link><description><![CDATA[Dissecting DarkGate: Module Malware Delivery and Persistence as a Service<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Dissecting%20DarkGate%3A%20Modular%20Malware%20Delivery%20and%20Persistence%20as%20a%20Service./30700" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Dissecting%20DarkGate%3A%20Modular%20Malware%20Delivery%20and%20Persistence%20as%20a%20Service./30700</a><br /> Ivanti Incident Response Update<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060b" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060b</a><br /> Github Flooded with Infected Repos<br /><a href="https://apiiro.com/blog/malicious-code-campaign-github-repo-confusion-attack" target="_blank" rel="noreferrer noopener">https://apiiro.com/blog/malicious-code-campaign-github-repo-confusion-attack</a><br /> Security Flaws in NoName Doorbell Cameras<br /><a href="https://www.consumerreports.org/home-garden/home-security-cameras/video-doorbells-sold-by-major-retailers-have-security-flaws-a2579288796/" target="_blank" rel="noreferrer noopener">https://www.consumerreports.org/home-garden/home-security-cameras/video-doorbells-sold-by-major-retailers-have-security-flaws-a2579288796/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8876.mp3</guid><pubDate>Fri, 01 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129440/8876.mp3" length="5730506" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Dissecting DarkGate: Module Malware Delivery and Persistence as a Service
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Dissecting%20DarkGate%3A%20Modular%20Malware%20Delivery%20and%20Persistence%20as%20a%20Service./30700
 Ivanti Incident Response...</itunes:subtitle><itunes:summary><![CDATA[Dissecting DarkGate: Module Malware Delivery and Persistence as a Service<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Dissecting%20DarkGate%3A%20Modular%20Malware%20Delivery%20and%20Persistence%20as%20a%20Service./30700" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Dissecting%20DarkGate%3A%20Modular%20Malware%20Delivery%20and%20Persistence%20as%20a%20Service./30700</a><br /> Ivanti Incident Response Update<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060b" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060b</a><br /> Github Flooded with Infected Repos<br /><a href="https://apiiro.com/blog/malicious-code-campaign-github-repo-confusion-attack" target="_blank" rel="noreferrer noopener">https://apiiro.com/blog/malicious-code-campaign-github-repo-confusion-attack</a><br /> Security Flaws in NoName Doorbell Cameras<br /><a href="https://www.consumerreports.org/home-garden/home-security-cameras/video-doorbells-sold-by-major-retailers-have-security-flaws-a2579288796/" target="_blank" rel="noreferrer noopener">https://www.consumerreports.org/home-garden/home-security-cameras/video-doorbells-sold-by-major-retailers-have-security-flaws-a2579288796/</a><br />]]></itunes:summary><itunes:duration>388</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,doorbells; github; repos; floo,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8876</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, March 1st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-march-1st-2024--58883559</link><description><![CDATA[Dissecting DarkGate: Module Malware Delivery and Persistence as a Service<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Dissecting%20DarkGate%3A%20Modular%20Malware%20Delivery%20and%20Persistence%20as%20a%20Service./30700" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Dissecting%20DarkGate%3A%20Modular%20Malware%20Delivery%20and%20Persistence%20as%20a%20Service./30700</a><br /> Ivanti Incident Response Update<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060b" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060b</a><br /> Github Flooded with Infected Repos<br /><a href="https://apiiro.com/blog/malicious-code-campaign-github-repo-confusion-attack" target="_blank" rel="noreferrer noopener">https://apiiro.com/blog/malicious-code-campaign-github-repo-confusion-attack</a><br /> Security Flaws in NoName Doorbell Cameras<br /><a href="https://www.consumerreports.org/home-garden/home-security-cameras/video-doorbells-sold-by-major-retailers-have-security-flaws-a2579288796/" target="_blank" rel="noreferrer noopener">https://www.consumerreports.org/home-garden/home-security-cameras/video-doorbells-sold-by-major-retailers-have-security-flaws-a2579288796/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8876.mp3</guid><pubDate>Fri, 01 Mar 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58883559/8876.mp3" length="5730506" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Dissecting DarkGate: Module Malware Delivery and Persistence as a Service
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Dissecting%20DarkGate%3A%20Modular%20Malware%20Delivery%20and%20Persistence%20as%20a%20Service./30700
 Ivanti Incident Response...</itunes:subtitle><itunes:summary><![CDATA[Dissecting DarkGate: Module Malware Delivery and Persistence as a Service<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Dissecting%20DarkGate%3A%20Modular%20Malware%20Delivery%20and%20Persistence%20as%20a%20Service./30700" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Dissecting%20DarkGate%3A%20Modular%20Malware%20Delivery%20and%20Persistence%20as%20a%20Service./30700</a><br /> Ivanti Incident Response Update<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060b" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060b</a><br /> Github Flooded with Infected Repos<br /><a href="https://apiiro.com/blog/malicious-code-campaign-github-repo-confusion-attack" target="_blank" rel="noreferrer noopener">https://apiiro.com/blog/malicious-code-campaign-github-repo-confusion-attack</a><br /> Security Flaws in NoName Doorbell Cameras<br /><a href="https://www.consumerreports.org/home-garden/home-security-cameras/video-doorbells-sold-by-major-retailers-have-security-flaws-a2579288796/" target="_blank" rel="noreferrer noopener">https://www.consumerreports.org/home-garden/home-security-cameras/video-doorbells-sold-by-major-retailers-have-security-flaws-a2579288796/</a><br />]]></itunes:summary><itunes:duration>388</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,doorbells; github; repos; floo,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8876</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, February 29th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-february-29th-2024--62129475</link><description><![CDATA[Exploit Attempts for Unknown Password Reset Vulnerability<br /><a href="https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Unknown%20Password%20Reset%20Vulnerability/30698" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Unknown%20Password%20Reset%20Vulnerability/30698</a><br /> StopRansomware: Updated ALPHV Blackcat Advisory<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-353a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-353a</a><br /> GlobalBlock Service To Prevent Trademark abuse<br /><a href="https://www.bleepingcomputer.com/news/technology/registrars-can-now-block-all-domains-that-resemble-brand-names/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/technology/registrars-can-now-block-all-domains-that-resemble-brand-names/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8874.mp3</guid><pubDate>Thu, 29 Feb 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129475/8874.mp3" length="5032633" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Exploit Attempts for Unknown Password Reset Vulnerability
https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Unknown%20Password%20Reset%20Vulnerability/30698
 StopRansomware: Updated ALPHV Blackcat Advisory...</itunes:subtitle><itunes:summary><![CDATA[Exploit Attempts for Unknown Password Reset Vulnerability<br /><a href="https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Unknown%20Password%20Reset%20Vulnerability/30698" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Unknown%20Password%20Reset%20Vulnerability/30698</a><br /> StopRansomware: Updated ALPHV Blackcat Advisory<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-353a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-353a</a><br /> GlobalBlock Service To Prevent Trademark abuse<br /><a href="https://www.bleepingcomputer.com/news/technology/registrars-can-now-block-all-domains-that-resemble-brand-names/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/technology/registrars-can-now-block-all-domains-that-resemble-brand-names/</a><br />]]></itunes:summary><itunes:duration>338</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,globalblock; trademark; regist,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8874</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, February 29th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-february-29th-2024--58871970</link><description><![CDATA[Exploit Attempts for Unknown Password Reset Vulnerability<br /><a href="https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Unknown%20Password%20Reset%20Vulnerability/30698" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Unknown%20Password%20Reset%20Vulnerability/30698</a><br /> StopRansomware: Updated ALPHV Blackcat Advisory<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-353a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-353a</a><br /> GlobalBlock Service To Prevent Trademark abuse<br /><a href="https://www.bleepingcomputer.com/news/technology/registrars-can-now-block-all-domains-that-resemble-brand-names/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/technology/registrars-can-now-block-all-domains-that-resemble-brand-names/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8874.mp3</guid><pubDate>Thu, 29 Feb 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58871970/8874.mp3" length="5032633" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Exploit Attempts for Unknown Password Reset Vulnerability
https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Unknown%20Password%20Reset%20Vulnerability/30698
 StopRansomware: Updated ALPHV Blackcat Advisory...</itunes:subtitle><itunes:summary><![CDATA[Exploit Attempts for Unknown Password Reset Vulnerability<br /><a href="https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Unknown%20Password%20Reset%20Vulnerability/30698" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Unknown%20Password%20Reset%20Vulnerability/30698</a><br /> StopRansomware: Updated ALPHV Blackcat Advisory<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-353a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-353a</a><br /> GlobalBlock Service To Prevent Trademark abuse<br /><a href="https://www.bleepingcomputer.com/news/technology/registrars-can-now-block-all-domains-that-resemble-brand-names/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/technology/registrars-can-now-block-all-domains-that-resemble-brand-names/</a><br />]]></itunes:summary><itunes:duration>338</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,globalblock; trademark; regist,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8874</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, February 28th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-february-28th-2024--62129450</link><description><![CDATA[Take Downs and the Rest of Us: Do they matter?<br /><a href="https://isc.sans.edu/diary/Take%20Downs%20and%20the%20Rest%20of%20Us%3A%20Do%20they%20matter%3F/30694" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Take%20Downs%20and%20the%20Rest%20of%20Us%3A%20Do%20they%20matter%3F/30694</a><br /> Joint Cybersecurity Advisory<br /><a href="https://www.ic3.gov/Media/News/2024/240227.pdf" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/Media/News/2024/240227.pdf</a><br /> SVR Cyber Actors Adapt Tactics for Initial Cloud Access<br /><a href="https://www.ncsc.gov.uk/news/svr-cyber-actors-adapt-tactics-for-initial-cloud-access" target="_blank" rel="noreferrer noopener">https://www.ncsc.gov.uk/news/svr-cyber-actors-adapt-tactics-for-initial-cloud-access</a><br /> Data Scientists Targeted by Malicious Hugging Face ML Models with Silent Backdoor<br /><a href="https://jfrog.com/blog/data-scientists-targeted-by-malicious-hugging-face-ml-models-with-silent-backdoor/" target="_blank" rel="noreferrer noopener">https://jfrog.com/blog/data-scientists-targeted-by-malicious-hugging-face-ml-models-with-silent-backdoor/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8872.mp3</guid><pubDate>Wed, 28 Feb 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129450/8872.mp3" length="5530850" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Take Downs and the Rest of Us: Do they matter?
https://isc.sans.edu/diary/Take%20Downs%20and%20the%20Rest%20of%20Us%3A%20Do%20they%20matter%3F/30694
 Joint Cybersecurity Advisory
https://www.ic3.gov/Media/News/2024/240227.pdf
 SVR Cyber Actors Adapt...</itunes:subtitle><itunes:summary><![CDATA[Take Downs and the Rest of Us: Do they matter?<br /><a href="https://isc.sans.edu/diary/Take%20Downs%20and%20the%20Rest%20of%20Us%3A%20Do%20they%20matter%3F/30694" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Take%20Downs%20and%20the%20Rest%20of%20Us%3A%20Do%20they%20matter%3F/30694</a><br /> Joint Cybersecurity Advisory<br /><a href="https://www.ic3.gov/Media/News/2024/240227.pdf" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/Media/News/2024/240227.pdf</a><br /> SVR Cyber Actors Adapt Tactics for Initial Cloud Access<br /><a href="https://www.ncsc.gov.uk/news/svr-cyber-actors-adapt-tactics-for-initial-cloud-access" target="_blank" rel="noreferrer noopener">https://www.ncsc.gov.uk/news/svr-cyber-actors-adapt-tactics-for-initial-cloud-access</a><br /> Data Scientists Targeted by Malicious Hugging Face ML Models with Silent Backdoor<br /><a href="https://jfrog.com/blog/data-scientists-targeted-by-malicious-hugging-face-ml-models-with-silent-backdoor/" target="_blank" rel="noreferrer noopener">https://jfrog.com/blog/data-scientists-targeted-by-malicious-hugging-face-ml-models-with-silent-backdoor/</a><br />]]></itunes:summary><itunes:duration>373</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,machine learning; ml; backdoor,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8872</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, February 28th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-february-28th-2024--58858609</link><description><![CDATA[Take Downs and the Rest of Us: Do they matter?<br /><a href="https://isc.sans.edu/diary/Take%20Downs%20and%20the%20Rest%20of%20Us%3A%20Do%20they%20matter%3F/30694" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Take%20Downs%20and%20the%20Rest%20of%20Us%3A%20Do%20they%20matter%3F/30694</a><br /> Joint Cybersecurity Advisory<br /><a href="https://www.ic3.gov/Media/News/2024/240227.pdf" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/Media/News/2024/240227.pdf</a><br /> SVR Cyber Actors Adapt Tactics for Initial Cloud Access<br /><a href="https://www.ncsc.gov.uk/news/svr-cyber-actors-adapt-tactics-for-initial-cloud-access" target="_blank" rel="noreferrer noopener">https://www.ncsc.gov.uk/news/svr-cyber-actors-adapt-tactics-for-initial-cloud-access</a><br /> Data Scientists Targeted by Malicious Hugging Face ML Models with Silent Backdoor<br /><a href="https://jfrog.com/blog/data-scientists-targeted-by-malicious-hugging-face-ml-models-with-silent-backdoor/" target="_blank" rel="noreferrer noopener">https://jfrog.com/blog/data-scientists-targeted-by-malicious-hugging-face-ml-models-with-silent-backdoor/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8872.mp3</guid><pubDate>Wed, 28 Feb 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58858609/8872.mp3" length="5530850" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Take Downs and the Rest of Us: Do they matter?
https://isc.sans.edu/diary/Take%20Downs%20and%20the%20Rest%20of%20Us%3A%20Do%20they%20matter%3F/30694
 Joint Cybersecurity Advisory
https://www.ic3.gov/Media/News/2024/240227.pdf
 SVR Cyber Actors Adapt...</itunes:subtitle><itunes:summary><![CDATA[Take Downs and the Rest of Us: Do they matter?<br /><a href="https://isc.sans.edu/diary/Take%20Downs%20and%20the%20Rest%20of%20Us%3A%20Do%20they%20matter%3F/30694" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Take%20Downs%20and%20the%20Rest%20of%20Us%3A%20Do%20they%20matter%3F/30694</a><br /> Joint Cybersecurity Advisory<br /><a href="https://www.ic3.gov/Media/News/2024/240227.pdf" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/Media/News/2024/240227.pdf</a><br /> SVR Cyber Actors Adapt Tactics for Initial Cloud Access<br /><a href="https://www.ncsc.gov.uk/news/svr-cyber-actors-adapt-tactics-for-initial-cloud-access" target="_blank" rel="noreferrer noopener">https://www.ncsc.gov.uk/news/svr-cyber-actors-adapt-tactics-for-initial-cloud-access</a><br /> Data Scientists Targeted by Malicious Hugging Face ML Models with Silent Backdoor<br /><a href="https://jfrog.com/blog/data-scientists-targeted-by-malicious-hugging-face-ml-models-with-silent-backdoor/" target="_blank" rel="noreferrer noopener">https://jfrog.com/blog/data-scientists-targeted-by-malicious-hugging-face-ml-models-with-silent-backdoor/</a><br />]]></itunes:summary><itunes:duration>373</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,machine learning; ml; backdoor,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8872</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, February 27th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-february-27th-2024--62129426</link><description><![CDATA[Utilizing the VirusTotal API to Query Files Uploaded to the DShield Honeypot<br /><a href="https://isc.sans.edu/diary/Utilizing%20the%20VirusTotal%20API%20to%20Query%20Files%20Uploaded%20to%20DShield%20Honeypot%20%5BGuest%20Diary%5D/30688" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Utilizing%20the%20VirusTotal%20API%20to%20Query%20Files%20Uploaded%20to%20DShield%20Honeypot%20%5BGuest%20Diary%5D/30688</a><br /> New WiFi Authentication Vulnerabilities Discovered<br /><a href="https://www.top10vpn.com/research/wifi-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://www.top10vpn.com/research/wifi-vulnerabilities/</a><br /> Subdomain Takeover Spam<br /><a href="https://labs.guard.io/subdomailing-thousands-of-hijacked-major-brand-subdomains-found-bombarding-users-with-millions-a5e5fb892935" target="_blank" rel="noreferrer noopener">https://labs.guard.io/subdomailing-thousands-of-hijacked-major-brand-subdomains-found-bombarding-users-with-millions-a5e5fb892935</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8870.mp3</guid><pubDate>Tue, 27 Feb 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129426/8870.mp3" length="5642700" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Utilizing the VirusTotal API to Query Files Uploaded to the DShield Honeypot
https://isc.sans.edu/diary/Utilizing%20the%20VirusTotal%20API%20to%20Query%20Files%20Uploaded%20to%20DShield%20Honeypot%20%5BGuest%20Diary%5D/30688
 New WiFi Authentication...</itunes:subtitle><itunes:summary><![CDATA[Utilizing the VirusTotal API to Query Files Uploaded to the DShield Honeypot<br /><a href="https://isc.sans.edu/diary/Utilizing%20the%20VirusTotal%20API%20to%20Query%20Files%20Uploaded%20to%20DShield%20Honeypot%20%5BGuest%20Diary%5D/30688" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Utilizing%20the%20VirusTotal%20API%20to%20Query%20Files%20Uploaded%20to%20DShield%20Honeypot%20%5BGuest%20Diary%5D/30688</a><br /> New WiFi Authentication Vulnerabilities Discovered<br /><a href="https://www.top10vpn.com/research/wifi-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://www.top10vpn.com/research/wifi-vulnerabilities/</a><br /> Subdomain Takeover Spam<br /><a href="https://labs.guard.io/subdomailing-thousands-of-hijacked-major-brand-subdomains-found-bombarding-users-with-millions-a5e5fb892935" target="_blank" rel="noreferrer noopener">https://labs.guard.io/subdomailing-thousands-of-hijacked-major-brand-subdomains-found-bombarding-users-with-millions-a5e5fb892935</a><br />]]></itunes:summary><itunes:duration>381</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,subdomain; spam; malspam; wifi</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8870</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, February 27th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-february-27th-2024--58842338</link><description><![CDATA[Utilizing the VirusTotal API to Query Files Uploaded to the DShield Honeypot<br /><a href="https://isc.sans.edu/diary/Utilizing%20the%20VirusTotal%20API%20to%20Query%20Files%20Uploaded%20to%20DShield%20Honeypot%20%5BGuest%20Diary%5D/30688" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Utilizing%20the%20VirusTotal%20API%20to%20Query%20Files%20Uploaded%20to%20DShield%20Honeypot%20%5BGuest%20Diary%5D/30688</a><br /> New WiFi Authentication Vulnerabilities Discovered<br /><a href="https://www.top10vpn.com/research/wifi-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://www.top10vpn.com/research/wifi-vulnerabilities/</a><br /> Subdomain Takeover Spam<br /><a href="https://labs.guard.io/subdomailing-thousands-of-hijacked-major-brand-subdomains-found-bombarding-users-with-millions-a5e5fb892935" target="_blank" rel="noreferrer noopener">https://labs.guard.io/subdomailing-thousands-of-hijacked-major-brand-subdomains-found-bombarding-users-with-millions-a5e5fb892935</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8870.mp3</guid><pubDate>Tue, 27 Feb 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58842338/8870.mp3" length="5642700" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Utilizing the VirusTotal API to Query Files Uploaded to the DShield Honeypot
https://isc.sans.edu/diary/Utilizing%20the%20VirusTotal%20API%20to%20Query%20Files%20Uploaded%20to%20DShield%20Honeypot%20%5BGuest%20Diary%5D/30688
 New WiFi Authentication...</itunes:subtitle><itunes:summary><![CDATA[Utilizing the VirusTotal API to Query Files Uploaded to the DShield Honeypot<br /><a href="https://isc.sans.edu/diary/Utilizing%20the%20VirusTotal%20API%20to%20Query%20Files%20Uploaded%20to%20DShield%20Honeypot%20%5BGuest%20Diary%5D/30688" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Utilizing%20the%20VirusTotal%20API%20to%20Query%20Files%20Uploaded%20to%20DShield%20Honeypot%20%5BGuest%20Diary%5D/30688</a><br /> New WiFi Authentication Vulnerabilities Discovered<br /><a href="https://www.top10vpn.com/research/wifi-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://www.top10vpn.com/research/wifi-vulnerabilities/</a><br /> Subdomain Takeover Spam<br /><a href="https://labs.guard.io/subdomailing-thousands-of-hijacked-major-brand-subdomains-found-bombarding-users-with-millions-a5e5fb892935" target="_blank" rel="noreferrer noopener">https://labs.guard.io/subdomailing-thousands-of-hijacked-major-brand-subdomains-found-bombarding-users-with-millions-a5e5fb892935</a><br />]]></itunes:summary><itunes:duration>381</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,subdomain; spam; malspam; wifi</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8870</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, February 26th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-february-26th-2024--62129373</link><description><![CDATA[Update MGLNDD * Scans<br /><a href="https://isc.sans.edu/forums/diary/Update%3A%20MGLNDD_*%20Scans/30686/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Update%3A%20MGLNDD_*%20Scans/30686/</a><br /> Simple Anti-Sandbox Technique: Where's the Mouse<br /><a href="https://isc.sans.edu/diary/Simple%20Anti-Sandbox%20Technique%3A%20Where%27s%20The%20Mouse%3F/30684" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Simple%20Anti-Sandbox%20Technique%3A%20Where%27s%20The%20Mouse%3F/30684</a><br /> Security Vulnerabilities in Apex Code Could Leak Salesforce Data<br /><a href="https://www.varonis.com/blog/apex-code-vulnerabilities" target="_blank" rel="noreferrer noopener">https://www.varonis.com/blog/apex-code-vulnerabilities</a><br /> IBM Operation Decision Manager Exploit CVE-2024-22319 CVE-2024-22320<br /><a href="https://labs.watchtowr.com/double-k-o-rce-in-ibm-operation-decision-manager/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/double-k-o-rce-in-ibm-operation-decision-manager/</a><br /> Linux Kernel TLS Vulnerability CVE-2024-26582<br /><a href="https://lore.kernel.org/linux-cve-announce/2024022139-spruce-prelude-c358@gregkh/" target="_blank" rel="noreferrer noopener">https://lore.kernel.org/linux-cve-announce/2024022139-spruce-prelude-c358@gregkh/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8868.mp3</guid><pubDate>Mon, 26 Feb 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129373/8868.mp3" length="5176029" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Update MGLNDD * Scans
https://isc.sans.edu/forums/diary/Update%3A%20MGLNDD_*%20Scans/30686/
 Simple Anti-Sandbox Technique: Where's the Mouse
https://isc.sans.edu/diary/Simple%20Anti-Sandbox%20Technique%3A%20Where%27s%20The%20Mouse%3F/30684
 Security...</itunes:subtitle><itunes:summary><![CDATA[Update MGLNDD * Scans<br /><a href="https://isc.sans.edu/forums/diary/Update%3A%20MGLNDD_*%20Scans/30686/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Update%3A%20MGLNDD_*%20Scans/30686/</a><br /> Simple Anti-Sandbox Technique: Where's the Mouse<br /><a href="https://isc.sans.edu/diary/Simple%20Anti-Sandbox%20Technique%3A%20Where%27s%20The%20Mouse%3F/30684" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Simple%20Anti-Sandbox%20Technique%3A%20Where%27s%20The%20Mouse%3F/30684</a><br /> Security Vulnerabilities in Apex Code Could Leak Salesforce Data<br /><a href="https://www.varonis.com/blog/apex-code-vulnerabilities" target="_blank" rel="noreferrer noopener">https://www.varonis.com/blog/apex-code-vulnerabilities</a><br /> IBM Operation Decision Manager Exploit CVE-2024-22319 CVE-2024-22320<br /><a href="https://labs.watchtowr.com/double-k-o-rce-in-ibm-operation-decision-manager/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/double-k-o-rce-in-ibm-operation-decision-manager/</a><br /> Linux Kernel TLS Vulnerability CVE-2024-26582<br /><a href="https://lore.kernel.org/linux-cve-announce/2024022139-spruce-prelude-c358@gregkh/" target="_blank" rel="noreferrer noopener">https://lore.kernel.org/linux-cve-announce/2024022139-spruce-prelude-c358@gregkh/</a><br />]]></itunes:summary><itunes:duration>348</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,linux; tls; ibm; odm; exploit;,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8868</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, February 26th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-february-26th-2024--58820277</link><description><![CDATA[Update MGLNDD * Scans<br /><a href="https://isc.sans.edu/forums/diary/Update%3A%20MGLNDD_*%20Scans/30686/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Update%3A%20MGLNDD_*%20Scans/30686/</a><br /> Simple Anti-Sandbox Technique: Where's the Mouse<br /><a href="https://isc.sans.edu/diary/Simple%20Anti-Sandbox%20Technique%3A%20Where%27s%20The%20Mouse%3F/30684" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Simple%20Anti-Sandbox%20Technique%3A%20Where%27s%20The%20Mouse%3F/30684</a><br /> Security Vulnerabilities in Apex Code Could Leak Salesforce Data<br /><a href="https://www.varonis.com/blog/apex-code-vulnerabilities" target="_blank" rel="noreferrer noopener">https://www.varonis.com/blog/apex-code-vulnerabilities</a><br /> IBM Operation Decision Manager Exploit CVE-2024-22319 CVE-2024-22320<br /><a href="https://labs.watchtowr.com/double-k-o-rce-in-ibm-operation-decision-manager/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/double-k-o-rce-in-ibm-operation-decision-manager/</a><br /> Linux Kernel TLS Vulnerability CVE-2024-26582<br /><a href="https://lore.kernel.org/linux-cve-announce/2024022139-spruce-prelude-c358@gregkh/" target="_blank" rel="noreferrer noopener">https://lore.kernel.org/linux-cve-announce/2024022139-spruce-prelude-c358@gregkh/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8868.mp3</guid><pubDate>Mon, 26 Feb 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58820277/8868.mp3" length="5176029" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Update MGLNDD * Scans
https://isc.sans.edu/forums/diary/Update%3A%20MGLNDD_*%20Scans/30686/
 Simple Anti-Sandbox Technique: Where's the Mouse
https://isc.sans.edu/diary/Simple%20Anti-Sandbox%20Technique%3A%20Where%27s%20The%20Mouse%3F/30684
 Security...</itunes:subtitle><itunes:summary><![CDATA[Update MGLNDD * Scans<br /><a href="https://isc.sans.edu/forums/diary/Update%3A%20MGLNDD_*%20Scans/30686/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Update%3A%20MGLNDD_*%20Scans/30686/</a><br /> Simple Anti-Sandbox Technique: Where's the Mouse<br /><a href="https://isc.sans.edu/diary/Simple%20Anti-Sandbox%20Technique%3A%20Where%27s%20The%20Mouse%3F/30684" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Simple%20Anti-Sandbox%20Technique%3A%20Where%27s%20The%20Mouse%3F/30684</a><br /> Security Vulnerabilities in Apex Code Could Leak Salesforce Data<br /><a href="https://www.varonis.com/blog/apex-code-vulnerabilities" target="_blank" rel="noreferrer noopener">https://www.varonis.com/blog/apex-code-vulnerabilities</a><br /> IBM Operation Decision Manager Exploit CVE-2024-22319 CVE-2024-22320<br /><a href="https://labs.watchtowr.com/double-k-o-rce-in-ibm-operation-decision-manager/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/double-k-o-rce-in-ibm-operation-decision-manager/</a><br /> Linux Kernel TLS Vulnerability CVE-2024-26582<br /><a href="https://lore.kernel.org/linux-cve-announce/2024022139-spruce-prelude-c358@gregkh/" target="_blank" rel="noreferrer noopener">https://lore.kernel.org/linux-cve-announce/2024022139-spruce-prelude-c358@gregkh/</a><br />]]></itunes:summary><itunes:duration>348</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,linux; tls; ibm; odm; exploit;,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8868</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, February 23rd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-february-23rd-2024--62129477</link><description><![CDATA[Friend, Foe or Something In Between<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Friend%2C%20foe%20or%20something%20in%20between%3F%20The%20grey%20area%20of%20%27security%20research%27/30670" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Friend%2C%20foe%20or%20something%20in%20between%3F%20The%20grey%20area%20of%20%27security%20research%27/30670</a><br /> Large AT&amp;T Wireless Network Outage <br /><a href="https://isc.sans.edu/diary/Large%20AT%26T%20Wireless%20Network%20Outage%20%23att%20%23outage/30680" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Large%20AT%26T%20Wireless%20Network%20Outage%20%23att%20%23outage/30680</a><br /> Connect Wise Screenconnect Userd by LockBit<br /><a href="https://www.bleepingcomputer.com/news/security/screenconnect-servers-hacked-in-lockbit-ransomware-attacks/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/screenconnect-servers-hacked-in-lockbit-ransomware-attacks/</a><br /> SSH Snake Abused in the Wild<br /><a href="https://github.com/MegaManSec/SSH-Snake" target="_blank" rel="noreferrer noopener">https://github.com/MegaManSec/SSH-Snake</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8866.mp3</guid><pubDate>Fri, 23 Feb 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129477/8866.mp3" length="5216417" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Friend, Foe or Something In Between
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Friend%2C%20foe%20or%20something%20in%20between%3F%20The%20grey%20area%20of%20%27security%20research%27/30670
 Large AT&amp;amp;T Wireless Network Outage...</itunes:subtitle><itunes:summary><![CDATA[Friend, Foe or Something In Between<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Friend%2C%20foe%20or%20something%20in%20between%3F%20The%20grey%20area%20of%20%27security%20research%27/30670" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Friend%2C%20foe%20or%20something%20in%20between%3F%20The%20grey%20area%20of%20%27security%20research%27/30670</a><br /> Large AT&amp;T Wireless Network Outage <br /><a href="https://isc.sans.edu/diary/Large%20AT%26T%20Wireless%20Network%20Outage%20%23att%20%23outage/30680" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Large%20AT%26T%20Wireless%20Network%20Outage%20%23att%20%23outage/30680</a><br /> Connect Wise Screenconnect Userd by LockBit<br /><a href="https://www.bleepingcomputer.com/news/security/screenconnect-servers-hacked-in-lockbit-ransomware-attacks/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/screenconnect-servers-hacked-in-lockbit-ransomware-attacks/</a><br /> SSH Snake Abused in the Wild<br /><a href="https://github.com/MegaManSec/SSH-Snake" target="_blank" rel="noreferrer noopener">https://github.com/MegaManSec/SSH-Snake</a><br />]]></itunes:summary><itunes:duration>351</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,ssh snake; ssh; connectwise; s</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8866</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, February 23rd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-february-23rd-2024--58792028</link><description><![CDATA[Friend, Foe or Something In Between<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Friend%2C%20foe%20or%20something%20in%20between%3F%20The%20grey%20area%20of%20%27security%20research%27/30670" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Friend%2C%20foe%20or%20something%20in%20between%3F%20The%20grey%20area%20of%20%27security%20research%27/30670</a><br /> Large AT&amp;T Wireless Network Outage <br /><a href="https://isc.sans.edu/diary/Large%20AT%26T%20Wireless%20Network%20Outage%20%23att%20%23outage/30680" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Large%20AT%26T%20Wireless%20Network%20Outage%20%23att%20%23outage/30680</a><br /> Connect Wise Screenconnect Userd by LockBit<br /><a href="https://www.bleepingcomputer.com/news/security/screenconnect-servers-hacked-in-lockbit-ransomware-attacks/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/screenconnect-servers-hacked-in-lockbit-ransomware-attacks/</a><br /> SSH Snake Abused in the Wild<br /><a href="https://github.com/MegaManSec/SSH-Snake" target="_blank" rel="noreferrer noopener">https://github.com/MegaManSec/SSH-Snake</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8866.mp3</guid><pubDate>Fri, 23 Feb 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58792028/8866.mp3" length="5216417" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Friend, Foe or Something In Between
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Friend%2C%20foe%20or%20something%20in%20between%3F%20The%20grey%20area%20of%20%27security%20research%27/30670
 Large AT&amp;amp;T Wireless Network Outage...</itunes:subtitle><itunes:summary><![CDATA[Friend, Foe or Something In Between<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Friend%2C%20foe%20or%20something%20in%20between%3F%20The%20grey%20area%20of%20%27security%20research%27/30670" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Friend%2C%20foe%20or%20something%20in%20between%3F%20The%20grey%20area%20of%20%27security%20research%27/30670</a><br /> Large AT&amp;T Wireless Network Outage <br /><a href="https://isc.sans.edu/diary/Large%20AT%26T%20Wireless%20Network%20Outage%20%23att%20%23outage/30680" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Large%20AT%26T%20Wireless%20Network%20Outage%20%23att%20%23outage/30680</a><br /> Connect Wise Screenconnect Userd by LockBit<br /><a href="https://www.bleepingcomputer.com/news/security/screenconnect-servers-hacked-in-lockbit-ransomware-attacks/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/screenconnect-servers-hacked-in-lockbit-ransomware-attacks/</a><br /> SSH Snake Abused in the Wild<br /><a href="https://github.com/MegaManSec/SSH-Snake" target="_blank" rel="noreferrer noopener">https://github.com/MegaManSec/SSH-Snake</a><br />]]></itunes:summary><itunes:duration>351</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,ssh snake; ssh; connectwise; s</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8866</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, February 22nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-february-22nd-2024--62129432</link><description><![CDATA[Phishing Pages Hosted on Archive.org<br /><a href="https://isc.sans.edu/forums/diary/Phishing%20pages%20hosted%20on%20archive.org/30676/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Phishing%20pages%20hosted%20on%20archive.org/30676/</a><br /> ScreenConnect Authentication Bypass Exploit CVE-2024-1709 CVE-2024-1708)<br /><a href="https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass" target="_blank" rel="noreferrer noopener">https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass</a><br /> iMessage with PQ3<br /><a href="https://security.apple.com/blog/imessage-pq3/" target="_blank" rel="noreferrer noopener">https://security.apple.com/blog/imessage-pq3/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8864.mp3</guid><pubDate>Thu, 22 Feb 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129432/8864.mp3" length="5789777" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Phishing Pages Hosted on Archive.org
https://isc.sans.edu/forums/diary/Phishing%20pages%20hosted%20on%20archive.org/30676/
 ScreenConnect Authentication Bypass Exploit CVE-2024-1709 CVE-2024-1708)...</itunes:subtitle><itunes:summary><![CDATA[Phishing Pages Hosted on Archive.org<br /><a href="https://isc.sans.edu/forums/diary/Phishing%20pages%20hosted%20on%20archive.org/30676/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Phishing%20pages%20hosted%20on%20archive.org/30676/</a><br /> ScreenConnect Authentication Bypass Exploit CVE-2024-1709 CVE-2024-1708)<br /><a href="https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass" target="_blank" rel="noreferrer noopener">https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass</a><br /> iMessage with PQ3<br /><a href="https://security.apple.com/blog/imessage-pq3/" target="_blank" rel="noreferrer noopener">https://security.apple.com/blog/imessage-pq3/</a><br />]]></itunes:summary><itunes:duration>392</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,imessage; pq3; screenconnect; ,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8864</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, February 22nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-february-22nd-2024--58775696</link><description><![CDATA[Phishing Pages Hosted on Archive.org<br /><a href="https://isc.sans.edu/forums/diary/Phishing%20pages%20hosted%20on%20archive.org/30676/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Phishing%20pages%20hosted%20on%20archive.org/30676/</a><br /> ScreenConnect Authentication Bypass Exploit CVE-2024-1709 CVE-2024-1708)<br /><a href="https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass" target="_blank" rel="noreferrer noopener">https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass</a><br /> iMessage with PQ3<br /><a href="https://security.apple.com/blog/imessage-pq3/" target="_blank" rel="noreferrer noopener">https://security.apple.com/blog/imessage-pq3/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8864.mp3</guid><pubDate>Thu, 22 Feb 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58775696/8864.mp3" length="5789777" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Phishing Pages Hosted on Archive.org
https://isc.sans.edu/forums/diary/Phishing%20pages%20hosted%20on%20archive.org/30676/
 ScreenConnect Authentication Bypass Exploit CVE-2024-1709 CVE-2024-1708)...</itunes:subtitle><itunes:summary><![CDATA[Phishing Pages Hosted on Archive.org<br /><a href="https://isc.sans.edu/forums/diary/Phishing%20pages%20hosted%20on%20archive.org/30676/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Phishing%20pages%20hosted%20on%20archive.org/30676/</a><br /> ScreenConnect Authentication Bypass Exploit CVE-2024-1709 CVE-2024-1708)<br /><a href="https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass" target="_blank" rel="noreferrer noopener">https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass</a><br /> iMessage with PQ3<br /><a href="https://security.apple.com/blog/imessage-pq3/" target="_blank" rel="noreferrer noopener">https://security.apple.com/blog/imessage-pq3/</a><br />]]></itunes:summary><itunes:duration>392</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,imessage; pq3; screenconnect; ,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8864</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, February 21st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-february-21st-2024--62129455</link><description><![CDATA[Python InfoStealer Wtih Dynamic Sandbox Detection<br /><a href="https://isc.sans.edu/diary/Python%20InfoStealer%20With%20Dynamic%20Sandbox%20Detection/30668" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Python%20InfoStealer%20With%20Dynamic%20Sandbox%20Detection/30668</a><br /> Connectwise Screenconnect Vulnerabilities<br /><a href="https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8" target="_blank" rel="noreferrer noopener">https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8</a><br /> Remove VMWare Enhanced Authentication Plugin (EAP)  VE-2024-22245 CVE-2024-22250<br /><a href="https://kb.vmware.com/s/article/96442" target="_blank" rel="noreferrer noopener">https://kb.vmware.com/s/article/96442</a><br /> Voltage Noise to Manipulate Wireless Chargers<br /><a href="https://arxiv.org/pdf/2402.11423.pdf" target="_blank" rel="noreferrer noopener">https://arxiv.org/pdf/2402.11423.pdf</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8862.mp3</guid><pubDate>Wed, 21 Feb 2024 02:45:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129455/8862.mp3" length="5639353" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Python InfoStealer Wtih Dynamic Sandbox Detection
https://isc.sans.edu/diary/Python%20InfoStealer%20With%20Dynamic%20Sandbox%20Detection/30668
 Connectwise Screenconnect Vulnerabilities...</itunes:subtitle><itunes:summary><![CDATA[Python InfoStealer Wtih Dynamic Sandbox Detection<br /><a href="https://isc.sans.edu/diary/Python%20InfoStealer%20With%20Dynamic%20Sandbox%20Detection/30668" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Python%20InfoStealer%20With%20Dynamic%20Sandbox%20Detection/30668</a><br /> Connectwise Screenconnect Vulnerabilities<br /><a href="https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8" target="_blank" rel="noreferrer noopener">https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8</a><br /> Remove VMWare Enhanced Authentication Plugin (EAP)  VE-2024-22245 CVE-2024-22250<br /><a href="https://kb.vmware.com/s/article/96442" target="_blank" rel="noreferrer noopener">https://kb.vmware.com/s/article/96442</a><br /> Voltage Noise to Manipulate Wireless Chargers<br /><a href="https://arxiv.org/pdf/2402.11423.pdf" target="_blank" rel="noreferrer noopener">https://arxiv.org/pdf/2402.11423.pdf</a><br />]]></itunes:summary><itunes:duration>381</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,voltage; voltschemer; qi; wire</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8862</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, February 21st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-february-21st-2024--58759017</link><description><![CDATA[Old Mirai New Exploits<br /><a href="https://isc.sans.edu/diary/Mirai-Mirai%20On%20The%20Wall...%20%5BGuest%20Diary%5D/30658" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Mirai-Mirai%20On%20The%20Wall...%20%5BGuest%20Diary%5D/30658</a><br /> KeyTrap PoC Exploit<br /><a href="https://github.com/knqyf263/CVE-2023-50387" target="_blank" rel="noreferrer noopener">https://github.com/knqyf263/CVE-2023-50387</a><br /> Google Open Sources Magika File ID System<br /><a href="https://opensource.googleblog.com/2024/02/magika-ai-powered-fast-and-efficient-file-type-identification.html" target="_blank" rel="noreferrer noopener">https://opensource.googleblog.com/2024/02/magika-ai-powered-fast-and-efficient-file-type-identification.html</a><br /> Exploiting Unsynchronised Clocks<br /><a href="https://attackshipsonfi.re/p/exploiting-unsynchonised-clocks" target="_blank" rel="noreferrer noopener">https://attackshipsonfi.re/p/exploiting-unsynchonised-clocks</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8862.mp3</guid><pubDate>Wed, 21 Feb 2024 02:10:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58759017/8862.mp3" length="4962529" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Old Mirai New Exploits
https://isc.sans.edu/diary/Mirai-Mirai%20On%20The%20Wall...%20%5BGuest%20Diary%5D/30658
 KeyTrap PoC Exploit
https://github.com/knqyf263/CVE-2023-50387
 Google Open Sources Magika File ID System...</itunes:subtitle><itunes:summary><![CDATA[Old Mirai New Exploits<br /><a href="https://isc.sans.edu/diary/Mirai-Mirai%20On%20The%20Wall...%20%5BGuest%20Diary%5D/30658" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Mirai-Mirai%20On%20The%20Wall...%20%5BGuest%20Diary%5D/30658</a><br /> KeyTrap PoC Exploit<br /><a href="https://github.com/knqyf263/CVE-2023-50387" target="_blank" rel="noreferrer noopener">https://github.com/knqyf263/CVE-2023-50387</a><br /> Google Open Sources Magika File ID System<br /><a href="https://opensource.googleblog.com/2024/02/magika-ai-powered-fast-and-efficient-file-type-identification.html" target="_blank" rel="noreferrer noopener">https://opensource.googleblog.com/2024/02/magika-ai-powered-fast-and-efficient-file-type-identification.html</a><br /> Exploiting Unsynchronised Clocks<br /><a href="https://attackshipsonfi.re/p/exploiting-unsynchonised-clocks" target="_blank" rel="noreferrer noopener">https://attackshipsonfi.re/p/exploiting-unsynchonised-clocks</a><br />]]></itunes:summary><itunes:duration>333</itunes:duration><itunes:keywords>business,clocks; ntp; caching; google; ,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8862</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, February 20th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-february-20th-2024--62129407</link><description><![CDATA[Old Mirai New Exploits<br /><a href="https://isc.sans.edu/diary/Mirai-Mirai%20On%20The%20Wall...%20%5BGuest%20Diary%5D/30658" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Mirai-Mirai%20On%20The%20Wall...%20%5BGuest%20Diary%5D/30658</a><br /> KeyTrap PoC Exploit<br /><a href="https://github.com/knqyf263/CVE-2023-50387" target="_blank" rel="noreferrer noopener">https://github.com/knqyf263/CVE-2023-50387</a><br /> Google Open Sources Magika File ID System<br /><a href="https://opensource.googleblog.com/2024/02/magika-ai-powered-fast-and-efficient-file-type-identification.html" target="_blank" rel="noreferrer noopener">https://opensource.googleblog.com/2024/02/magika-ai-powered-fast-and-efficient-file-type-identification.html</a><br /> Exploiting Unsynchronised Clocks<br /><a href="https://attackshipsonfi.re/p/exploiting-unsynchonised-clocks" target="_blank" rel="noreferrer noopener">https://attackshipsonfi.re/p/exploiting-unsynchonised-clocks</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8860.mp3</guid><pubDate>Tue, 20 Feb 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129407/8860.mp3" length="4962521" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Old Mirai New Exploits
https://isc.sans.edu/diary/Mirai-Mirai%20On%20The%20Wall...%20%5BGuest%20Diary%5D/30658
 KeyTrap PoC Exploit
https://github.com/knqyf263/CVE-2023-50387
 Google Open Sources Magika File ID System...</itunes:subtitle><itunes:summary><![CDATA[Old Mirai New Exploits<br /><a href="https://isc.sans.edu/diary/Mirai-Mirai%20On%20The%20Wall...%20%5BGuest%20Diary%5D/30658" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Mirai-Mirai%20On%20The%20Wall...%20%5BGuest%20Diary%5D/30658</a><br /> KeyTrap PoC Exploit<br /><a href="https://github.com/knqyf263/CVE-2023-50387" target="_blank" rel="noreferrer noopener">https://github.com/knqyf263/CVE-2023-50387</a><br /> Google Open Sources Magika File ID System<br /><a href="https://opensource.googleblog.com/2024/02/magika-ai-powered-fast-and-efficient-file-type-identification.html" target="_blank" rel="noreferrer noopener">https://opensource.googleblog.com/2024/02/magika-ai-powered-fast-and-efficient-file-type-identification.html</a><br /> Exploiting Unsynchronised Clocks<br /><a href="https://attackshipsonfi.re/p/exploiting-unsynchonised-clocks" target="_blank" rel="noreferrer noopener">https://attackshipsonfi.re/p/exploiting-unsynchonised-clocks</a><br />]]></itunes:summary><itunes:duration>333</itunes:duration><itunes:keywords>business,clocks; ntp; caching; google; ,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8860</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, February 20th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-february-20th-2024--58746472</link><description><![CDATA[Old Mirai New Exploits<br /><a href="https://isc.sans.edu/diary/Mirai-Mirai%20On%20The%20Wall...%20%5BGuest%20Diary%5D/30658" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Mirai-Mirai%20On%20The%20Wall...%20%5BGuest%20Diary%5D/30658</a><br /> KeyTrap PoC Exploit<br /><a href="https://github.com/knqyf263/CVE-2023-50387" target="_blank" rel="noreferrer noopener">https://github.com/knqyf263/CVE-2023-50387</a><br /> Google Open Sources Magika File ID System<br /><a href="https://opensource.googleblog.com/2024/02/magika-ai-powered-fast-and-efficient-file-type-identification.html" target="_blank" rel="noreferrer noopener">https://opensource.googleblog.com/2024/02/magika-ai-powered-fast-and-efficient-file-type-identification.html</a><br /> Exploiting Unsynchronised Clocks<br /><a href="https://attackshipsonfi.re/p/exploiting-unsynchonised-clocks" target="_blank" rel="noreferrer noopener">https://attackshipsonfi.re/p/exploiting-unsynchonised-clocks</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8860.mp3</guid><pubDate>Tue, 20 Feb 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58746472/8860.mp3" length="4962521" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Old Mirai New Exploits
https://isc.sans.edu/diary/Mirai-Mirai%20On%20The%20Wall...%20%5BGuest%20Diary%5D/30658
 KeyTrap PoC Exploit
https://github.com/knqyf263/CVE-2023-50387
 Google Open Sources Magika File ID System...</itunes:subtitle><itunes:summary><![CDATA[Old Mirai New Exploits<br /><a href="https://isc.sans.edu/diary/Mirai-Mirai%20On%20The%20Wall...%20%5BGuest%20Diary%5D/30658" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Mirai-Mirai%20On%20The%20Wall...%20%5BGuest%20Diary%5D/30658</a><br /> KeyTrap PoC Exploit<br /><a href="https://github.com/knqyf263/CVE-2023-50387" target="_blank" rel="noreferrer noopener">https://github.com/knqyf263/CVE-2023-50387</a><br /> Google Open Sources Magika File ID System<br /><a href="https://opensource.googleblog.com/2024/02/magika-ai-powered-fast-and-efficient-file-type-identification.html" target="_blank" rel="noreferrer noopener">https://opensource.googleblog.com/2024/02/magika-ai-powered-fast-and-efficient-file-type-identification.html</a><br /> Exploiting Unsynchronised Clocks<br /><a href="https://attackshipsonfi.re/p/exploiting-unsynchonised-clocks" target="_blank" rel="noreferrer noopener">https://attackshipsonfi.re/p/exploiting-unsynchonised-clocks</a><br />]]></itunes:summary><itunes:duration>333</itunes:duration><itunes:keywords>business,clocks; ntp; caching; google; ,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8860</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, February 19th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-february-19th-2024--62129409</link><description><![CDATA[SolarWinds Security Advisories<br /><a href="https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-3_release_notes.htm" target="_blank" rel="noreferrer noopener">https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-3_release_notes.htm</a><br /> Google Chrome Adds Private Network Checks<br /><a href="https://chromestatus.com/feature/4869685172764672" target="_blank" rel="noreferrer noopener">https://chromestatus.com/feature/4869685172764672</a><br /> Gold Factory iOS Trojan<br /><a href="https://www.group-ib.com/blog/goldfactory-ios-trojan/" target="_blank" rel="noreferrer noopener">https://www.group-ib.com/blog/goldfactory-ios-trojan/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8858.mp3</guid><pubDate>Mon, 19 Feb 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129409/8858.mp3" length="6726175" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>SolarWinds Security Advisories
https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-3_release_notes.htm
 Google Chrome Adds Private Network Checks
https://chromestatus.com/feature/4869685172764672
 Gold Factory...</itunes:subtitle><itunes:summary><![CDATA[SolarWinds Security Advisories<br /><a href="https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-3_release_notes.htm" target="_blank" rel="noreferrer noopener">https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-3_release_notes.htm</a><br /> Google Chrome Adds Private Network Checks<br /><a href="https://chromestatus.com/feature/4869685172764672" target="_blank" rel="noreferrer noopener">https://chromestatus.com/feature/4869685172764672</a><br /> Gold Factory iOS Trojan<br /><a href="https://www.group-ib.com/blog/goldfactory-ios-trojan/" target="_blank" rel="noreferrer noopener">https://www.group-ib.com/blog/goldfactory-ios-trojan/</a><br />]]></itunes:summary><itunes:duration>459</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,goldfactory; ios; trojan; chro,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8858</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, February 19th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-february-19th-2024--58730557</link><description><![CDATA[SolarWinds Security Advisories<br /><a href="https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-3_release_notes.htm" target="_blank" rel="noreferrer noopener">https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-3_release_notes.htm</a><br /> Google Chrome Adds Private Network Checks<br /><a href="https://chromestatus.com/feature/4869685172764672" target="_blank" rel="noreferrer noopener">https://chromestatus.com/feature/4869685172764672</a><br /> Gold Factory iOS Trojan<br /><a href="https://www.group-ib.com/blog/goldfactory-ios-trojan/" target="_blank" rel="noreferrer noopener">https://www.group-ib.com/blog/goldfactory-ios-trojan/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8858.mp3</guid><pubDate>Mon, 19 Feb 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58730557/8858.mp3" length="6726175" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>SolarWinds Security Advisories
https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-3_release_notes.htm
 Google Chrome Adds Private Network Checks
https://chromestatus.com/feature/4869685172764672
 Gold Factory...</itunes:subtitle><itunes:summary><![CDATA[SolarWinds Security Advisories<br /><a href="https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-3_release_notes.htm" target="_blank" rel="noreferrer noopener">https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-3_release_notes.htm</a><br /> Google Chrome Adds Private Network Checks<br /><a href="https://chromestatus.com/feature/4869685172764672" target="_blank" rel="noreferrer noopener">https://chromestatus.com/feature/4869685172764672</a><br /> Gold Factory iOS Trojan<br /><a href="https://www.group-ib.com/blog/goldfactory-ios-trojan/" target="_blank" rel="noreferrer noopener">https://www.group-ib.com/blog/goldfactory-ios-trojan/</a><br />]]></itunes:summary><itunes:duration>459</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,goldfactory; ios; trojan; chro,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8858</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, February 16th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-february-16th-2024--62129480</link><description><![CDATA[USPS Anchors Snowballing Smishing Campaigns<br /><a href="https://www.sentinelone.com/labs/sns-sender-active-campaigns-unleash-messaging-spam-through-the-cloud/" target="_blank" rel="noreferrer noopener">https://www.sentinelone.com/labs/sns-sender-active-campaigns-unleash-messaging-spam-through-the-cloud/</a><br /> Linux Issuing CVEs<br /><a href="http://www.kroah.com/log/blog/2024/02/13/linux-is-a-cna/" target="_blank" rel="noreferrer noopener">http://www.kroah.com/log/blog/2024/02/13/linux-is-a-cna/</a><br /> Analyzing Pulse Secure Firmware and Bypassing Integrity Checking<br /><a href="https://eclypsium.com/blog/flatlined-analyzing-pulse-secure-firmware-and-bypassing-integrity-checking/" target="_blank" rel="noreferrer noopener">https://eclypsium.com/blog/flatlined-analyzing-pulse-secure-firmware-and-bypassing-integrity-checking/</a><br /> Jennifer Walker: Detecting Rogue Ethernet Switches Using Layer 1 Techniques<br /><a href="https://www.sans.edu/cyber-research/detecting-rogue-ethernet-switches-using-layer-1-techniques/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/detecting-rogue-ethernet-switches-using-layer-1-techniques/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8856.mp3</guid><pubDate>Fri, 16 Feb 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129480/8856.mp3" length="11383737" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>USPS Anchors Snowballing Smishing Campaigns
https://www.sentinelone.com/labs/sns-sender-active-campaigns-unleash-messaging-spam-through-the-cloud/
 Linux Issuing CVEs
http://www.kroah.com/log/blog/2024/02/13/linux-is-a-cna/
 Analyzing Pulse Secure...</itunes:subtitle><itunes:summary><![CDATA[USPS Anchors Snowballing Smishing Campaigns<br /><a href="https://www.sentinelone.com/labs/sns-sender-active-campaigns-unleash-messaging-spam-through-the-cloud/" target="_blank" rel="noreferrer noopener">https://www.sentinelone.com/labs/sns-sender-active-campaigns-unleash-messaging-spam-through-the-cloud/</a><br /> Linux Issuing CVEs<br /><a href="http://www.kroah.com/log/blog/2024/02/13/linux-is-a-cna/" target="_blank" rel="noreferrer noopener">http://www.kroah.com/log/blog/2024/02/13/linux-is-a-cna/</a><br /> Analyzing Pulse Secure Firmware and Bypassing Integrity Checking<br /><a href="https://eclypsium.com/blog/flatlined-analyzing-pulse-secure-firmware-and-bypassing-integrity-checking/" target="_blank" rel="noreferrer noopener">https://eclypsium.com/blog/flatlined-analyzing-pulse-secure-firmware-and-bypassing-integrity-checking/</a><br /> Jennifer Walker: Detecting Rogue Ethernet Switches Using Layer 1 Techniques<br /><a href="https://www.sans.edu/cyber-research/detecting-rogue-ethernet-switches-using-layer-1-techniques/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/detecting-rogue-ethernet-switches-using-layer-1-techniques/</a><br />]]></itunes:summary><itunes:duration>791</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,jennifer walker; switches; eth,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8856</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, February 16th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-february-16th-2024--58702436</link><description><![CDATA[USPS Anchors Snowballing Smishing Campaigns<br /><a href="https://www.sentinelone.com/labs/sns-sender-active-campaigns-unleash-messaging-spam-through-the-cloud/" target="_blank" rel="noreferrer noopener">https://www.sentinelone.com/labs/sns-sender-active-campaigns-unleash-messaging-spam-through-the-cloud/</a><br /> Linux Issuing CVEs<br /><a href="http://www.kroah.com/log/blog/2024/02/13/linux-is-a-cna/" target="_blank" rel="noreferrer noopener">http://www.kroah.com/log/blog/2024/02/13/linux-is-a-cna/</a><br /> Analyzing Pulse Secure Firmware and Bypassing Integrity Checking<br /><a href="https://eclypsium.com/blog/flatlined-analyzing-pulse-secure-firmware-and-bypassing-integrity-checking/" target="_blank" rel="noreferrer noopener">https://eclypsium.com/blog/flatlined-analyzing-pulse-secure-firmware-and-bypassing-integrity-checking/</a><br /> Jennifer Walker: Detecting Rogue Ethernet Switches Using Layer 1 Techniques<br /><a href="https://www.sans.edu/cyber-research/detecting-rogue-ethernet-switches-using-layer-1-techniques/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/detecting-rogue-ethernet-switches-using-layer-1-techniques/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8856.mp3</guid><pubDate>Fri, 16 Feb 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58702436/8856.mp3" length="11383737" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>USPS Anchors Snowballing Smishing Campaigns
https://www.sentinelone.com/labs/sns-sender-active-campaigns-unleash-messaging-spam-through-the-cloud/
 Linux Issuing CVEs
http://www.kroah.com/log/blog/2024/02/13/linux-is-a-cna/
 Analyzing Pulse Secure...</itunes:subtitle><itunes:summary><![CDATA[USPS Anchors Snowballing Smishing Campaigns<br /><a href="https://www.sentinelone.com/labs/sns-sender-active-campaigns-unleash-messaging-spam-through-the-cloud/" target="_blank" rel="noreferrer noopener">https://www.sentinelone.com/labs/sns-sender-active-campaigns-unleash-messaging-spam-through-the-cloud/</a><br /> Linux Issuing CVEs<br /><a href="http://www.kroah.com/log/blog/2024/02/13/linux-is-a-cna/" target="_blank" rel="noreferrer noopener">http://www.kroah.com/log/blog/2024/02/13/linux-is-a-cna/</a><br /> Analyzing Pulse Secure Firmware and Bypassing Integrity Checking<br /><a href="https://eclypsium.com/blog/flatlined-analyzing-pulse-secure-firmware-and-bypassing-integrity-checking/" target="_blank" rel="noreferrer noopener">https://eclypsium.com/blog/flatlined-analyzing-pulse-secure-firmware-and-bypassing-integrity-checking/</a><br /> Jennifer Walker: Detecting Rogue Ethernet Switches Using Layer 1 Techniques<br /><a href="https://www.sans.edu/cyber-research/detecting-rogue-ethernet-switches-using-layer-1-techniques/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/detecting-rogue-ethernet-switches-using-layer-1-techniques/</a><br />]]></itunes:summary><itunes:duration>791</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,jennifer walker; switches; eth,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8856</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, February 15th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-february-15th-2024--62129483</link><description><![CDATA[Guest Diary: Learning by Doing An Interative Adventure in Troubleshooting<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Learning%20by%20doing%3A%20Iterative%20adventures%20in%20troubleshooting/30648" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Learning%20by%20doing%3A%20Iterative%20adventures%20in%20troubleshooting/30648</a><br /> Snap Trap: The Hidden Dangers within Ubuntu's Package Suggestion System<br /><a href="https://www.aquasec.com/blog/snap-trap-the-hidden-dangers-within-ubuntus-package-suggestion-system/" target="_blank" rel="noreferrer noopener">https://www.aquasec.com/blog/snap-trap-the-hidden-dangers-within-ubuntus-package-suggestion-system/</a><br /> The Risks of the Monikerlink Bug in Microsoft Outlook<br /><a href="https://research.checkpoint.com/2024/the-risks-of-the-monikerlink-bug-in-microsoft-outlook-and-the-big-picture/" target="_blank" rel="noreferrer noopener">https://research.checkpoint.com/2024/the-risks-of-the-monikerlink-bug-in-microsoft-outlook-and-the-big-picture/</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> AMD Patches<br /><a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7009.html" target="_blank" rel="noreferrer noopener">https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7009.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8854.mp3</guid><pubDate>Thu, 15 Feb 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129483/8854.mp3" length="5119464" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Guest Diary: Learning by Doing An Interative Adventure in Troubleshooting
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Learning%20by%20doing%3A%20Iterative%20adventures%20in%20troubleshooting/30648
 Snap Trap: The Hidden Dangers within Ubuntu's...</itunes:subtitle><itunes:summary><![CDATA[Guest Diary: Learning by Doing An Interative Adventure in Troubleshooting<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Learning%20by%20doing%3A%20Iterative%20adventures%20in%20troubleshooting/30648" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Learning%20by%20doing%3A%20Iterative%20adventures%20in%20troubleshooting/30648</a><br /> Snap Trap: The Hidden Dangers within Ubuntu's Package Suggestion System<br /><a href="https://www.aquasec.com/blog/snap-trap-the-hidden-dangers-within-ubuntus-package-suggestion-system/" target="_blank" rel="noreferrer noopener">https://www.aquasec.com/blog/snap-trap-the-hidden-dangers-within-ubuntus-package-suggestion-system/</a><br /> The Risks of the Monikerlink Bug in Microsoft Outlook<br /><a href="https://research.checkpoint.com/2024/the-risks-of-the-monikerlink-bug-in-microsoft-outlook-and-the-big-picture/" target="_blank" rel="noreferrer noopener">https://research.checkpoint.com/2024/the-risks-of-the-monikerlink-bug-in-microsoft-outlook-and-the-big-picture/</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> AMD Patches<br /><a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7009.html" target="_blank" rel="noreferrer noopener">https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7009.html</a><br />]]></itunes:summary><itunes:duration>344</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,monikerlink; outlook; smb; sna,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8854</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, February 15th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-february-15th-2024--58690798</link><description><![CDATA[Guest Diary: Learning by Doing An Interative Adventure in Troubleshooting<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Learning%20by%20doing%3A%20Iterative%20adventures%20in%20troubleshooting/30648" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Learning%20by%20doing%3A%20Iterative%20adventures%20in%20troubleshooting/30648</a><br /> Snap Trap: The Hidden Dangers within Ubuntu's Package Suggestion System<br /><a href="https://www.aquasec.com/blog/snap-trap-the-hidden-dangers-within-ubuntus-package-suggestion-system/" target="_blank" rel="noreferrer noopener">https://www.aquasec.com/blog/snap-trap-the-hidden-dangers-within-ubuntus-package-suggestion-system/</a><br /> The Risks of the Monikerlink Bug in Microsoft Outlook<br /><a href="https://research.checkpoint.com/2024/the-risks-of-the-monikerlink-bug-in-microsoft-outlook-and-the-big-picture/" target="_blank" rel="noreferrer noopener">https://research.checkpoint.com/2024/the-risks-of-the-monikerlink-bug-in-microsoft-outlook-and-the-big-picture/</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> AMD Patches<br /><a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7009.html" target="_blank" rel="noreferrer noopener">https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7009.html</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8854.mp3</guid><pubDate>Thu, 15 Feb 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58690798/8854.mp3" length="5119464" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Guest Diary: Learning by Doing An Interative Adventure in Troubleshooting
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Learning%20by%20doing%3A%20Iterative%20adventures%20in%20troubleshooting/30648
 Snap Trap: The Hidden Dangers within Ubuntu's...</itunes:subtitle><itunes:summary><![CDATA[Guest Diary: Learning by Doing An Interative Adventure in Troubleshooting<br /><a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Learning%20by%20doing%3A%20Iterative%20adventures%20in%20troubleshooting/30648" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Learning%20by%20doing%3A%20Iterative%20adventures%20in%20troubleshooting/30648</a><br /> Snap Trap: The Hidden Dangers within Ubuntu's Package Suggestion System<br /><a href="https://www.aquasec.com/blog/snap-trap-the-hidden-dangers-within-ubuntus-package-suggestion-system/" target="_blank" rel="noreferrer noopener">https://www.aquasec.com/blog/snap-trap-the-hidden-dangers-within-ubuntus-package-suggestion-system/</a><br /> The Risks of the Monikerlink Bug in Microsoft Outlook<br /><a href="https://research.checkpoint.com/2024/the-risks-of-the-monikerlink-bug-in-microsoft-outlook-and-the-big-picture/" target="_blank" rel="noreferrer noopener">https://research.checkpoint.com/2024/the-risks-of-the-monikerlink-bug-in-microsoft-outlook-and-the-big-picture/</a><br /> Adobe Patches<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> AMD Patches<br /><a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7009.html" target="_blank" rel="noreferrer noopener">https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7009.html</a><br />]]></itunes:summary><itunes:duration>344</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,monikerlink; outlook; smb; sna,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8854</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, February 14th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-february-14th-2024--62129458</link><description><![CDATA[Microsoft Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20February%202024%20Patch%20Tuesday/30646" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20February%202024%20Patch%20Tuesday/30646</a><br /> DNSSEC DoS Vulnerability CVE-2023-50387<br /><a href="https://www.presseportal.de/pm/173495/5713546" target="_blank" rel="noreferrer noopener">https://www.presseportal.de/pm/173495/5713546</a><br /> Zoom Desktop Client Vuln<br /><a href="https://www.zoom.com/en/trust/security-bulletin" target="_blank" rel="noreferrer noopener">https://www.zoom.com/en/trust/security-bulletin</a><br /> QNAP Vulnerablity<br /><a href="https://www.qnap.com/de-de/security-advisory/qsa-23-57" target="_blank" rel="noreferrer noopener">https://www.qnap.com/de-de/security-advisory/qsa-23-57</a><br /><a href="https://unit42.paloaltonetworks.com/qnap-qts-firmware-cve-2023-50358/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/qnap-qts-firmware-cve-2023-50358/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8852.mp3</guid><pubDate>Wed, 14 Feb 2024 03:20:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129458/8852.mp3" length="5684301" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20February%202024%20Patch%20Tuesday/30646
 DNSSEC DoS Vulnerability CVE-2023-50387
https://www.presseportal.de/pm/173495/5713546
 Zoom Desktop Client Vuln...</itunes:subtitle><itunes:summary><![CDATA[Microsoft Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20February%202024%20Patch%20Tuesday/30646" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20February%202024%20Patch%20Tuesday/30646</a><br /> DNSSEC DoS Vulnerability CVE-2023-50387<br /><a href="https://www.presseportal.de/pm/173495/5713546" target="_blank" rel="noreferrer noopener">https://www.presseportal.de/pm/173495/5713546</a><br /> Zoom Desktop Client Vuln<br /><a href="https://www.zoom.com/en/trust/security-bulletin" target="_blank" rel="noreferrer noopener">https://www.zoom.com/en/trust/security-bulletin</a><br /> QNAP Vulnerablity<br /><a href="https://www.qnap.com/de-de/security-advisory/qsa-23-57" target="_blank" rel="noreferrer noopener">https://www.qnap.com/de-de/security-advisory/qsa-23-57</a><br /><a href="https://unit42.paloaltonetworks.com/qnap-qts-firmware-cve-2023-50358/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/qnap-qts-firmware-cve-2023-50358/</a><br />]]></itunes:summary><itunes:duration>384</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,qnap; zoom; dnssec; dos; bind;,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8852</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, February 14th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-february-14th-2024--58680057</link><description><![CDATA[Microsoft Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20February%202024%20Patch%20Tuesday/30646" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20February%202024%20Patch%20Tuesday/30646</a><br /> DNSSEC DoS Vulnerability CVE-2023-50387<br /><a href="https://www.presseportal.de/pm/173495/5713546" target="_blank" rel="noreferrer noopener">https://www.presseportal.de/pm/173495/5713546</a><br /> Zoom Desktop Client Vuln<br /><a href="https://www.zoom.com/en/trust/security-bulletin" target="_blank" rel="noreferrer noopener">https://www.zoom.com/en/trust/security-bulletin</a><br /> QNAP Vulnerablity<br /><a href="https://www.qnap.com/de-de/security-advisory/qsa-23-57" target="_blank" rel="noreferrer noopener">https://www.qnap.com/de-de/security-advisory/qsa-23-57</a><br /><a href="https://unit42.paloaltonetworks.com/qnap-qts-firmware-cve-2023-50358/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/qnap-qts-firmware-cve-2023-50358/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8852.mp3</guid><pubDate>Wed, 14 Feb 2024 03:20:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58680057/8852.mp3" length="5684301" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20February%202024%20Patch%20Tuesday/30646
 DNSSEC DoS Vulnerability CVE-2023-50387
https://www.presseportal.de/pm/173495/5713546
 Zoom Desktop Client Vuln...</itunes:subtitle><itunes:summary><![CDATA[Microsoft Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20February%202024%20Patch%20Tuesday/30646" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20February%202024%20Patch%20Tuesday/30646</a><br /> DNSSEC DoS Vulnerability CVE-2023-50387<br /><a href="https://www.presseportal.de/pm/173495/5713546" target="_blank" rel="noreferrer noopener">https://www.presseportal.de/pm/173495/5713546</a><br /> Zoom Desktop Client Vuln<br /><a href="https://www.zoom.com/en/trust/security-bulletin" target="_blank" rel="noreferrer noopener">https://www.zoom.com/en/trust/security-bulletin</a><br /> QNAP Vulnerablity<br /><a href="https://www.qnap.com/de-de/security-advisory/qsa-23-57" target="_blank" rel="noreferrer noopener">https://www.qnap.com/de-de/security-advisory/qsa-23-57</a><br /><a href="https://unit42.paloaltonetworks.com/qnap-qts-firmware-cve-2023-50358/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/qnap-qts-firmware-cve-2023-50358/</a><br />]]></itunes:summary><itunes:duration>384</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,qnap; zoom; dnssec; dos; bind;,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8852</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, February 13th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-february-13th-2024--62129451</link><description><![CDATA[Exploit Against Unnamed BYTEVALUE Router Vulnerablity Included in Mirai<br /><a href="https://isc.sans.edu/diary/Exploit%20against%20Unnamed%20%22Bytevalue%22%20router%20vulnerability%20included%20in%20Mirai%20Bot/30642" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit%20against%20Unnamed%20%22Bytevalue%22%20router%20vulnerability%20included%20in%20Mirai%20Bot/30642</a><br /> Senior Executives Targeted in Ongoing Azure Account Takeover<br /><a href="https://www.darkreading.com/cloud-security/senior-executives-targeted-ongoing-azure-account-takeover" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/cloud-security/senior-executives-targeted-ongoing-azure-account-takeover</a><br /> CISA Parners With OpenSSF To Secure Software Repositories<br /><a href="https://www.cisa.gov/news-events/alerts/2024/02/08/cisa-partners-openssf-securing-software-repositories-working-group-release-principles-package" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2024/02/08/cisa-partners-openssf-securing-software-repositories-working-group-release-principles-package</a><br /> PostgreSQL Vulnerability<br /><a href="https://www.postgresql.org/support/security/CVE-2024-0985/" target="_blank" rel="noreferrer noopener">https://www.postgresql.org/support/security/CVE-2024-0985/</a><br /> Microsoft Defender Bypass via Comma<br /><a href="https://hyp3rlinx.altervista.org/advisories/MICROSOFT_WINDOWS_DEFENDER_TROJAN.WIN32.POWESSERE.G_MITIGATION_BYPASS_PART2.txt" target="_blank" rel="noreferrer noopener">https://hyp3rlinx.altervista.org/advisories/MICROSOFT_WINDOWS_DEFENDER_TROJAN.WIN32.POWESSERE.G_MITIGATION_BYPASS_PART2.txt</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8850.mp3</guid><pubDate>Tue, 13 Feb 2024 03:00:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129451/8850.mp3" length="4970157" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Exploit Against Unnamed BYTEVALUE Router Vulnerablity Included in Mirai
https://isc.sans.edu/diary/Exploit%20against%20Unnamed%20%22Bytevalue%22%20router%20vulnerability%20included%20in%20Mirai%20Bot/30642
 Senior Executives Targeted in Ongoing Azure...</itunes:subtitle><itunes:summary><![CDATA[Exploit Against Unnamed BYTEVALUE Router Vulnerablity Included in Mirai<br /><a href="https://isc.sans.edu/diary/Exploit%20against%20Unnamed%20%22Bytevalue%22%20router%20vulnerability%20included%20in%20Mirai%20Bot/30642" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit%20against%20Unnamed%20%22Bytevalue%22%20router%20vulnerability%20included%20in%20Mirai%20Bot/30642</a><br /> Senior Executives Targeted in Ongoing Azure Account Takeover<br /><a href="https://www.darkreading.com/cloud-security/senior-executives-targeted-ongoing-azure-account-takeover" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/cloud-security/senior-executives-targeted-ongoing-azure-account-takeover</a><br /> CISA Parners With OpenSSF To Secure Software Repositories<br /><a href="https://www.cisa.gov/news-events/alerts/2024/02/08/cisa-partners-openssf-securing-software-repositories-working-group-release-principles-package" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2024/02/08/cisa-partners-openssf-securing-software-repositories-working-group-release-principles-package</a><br /> PostgreSQL Vulnerability<br /><a href="https://www.postgresql.org/support/security/CVE-2024-0985/" target="_blank" rel="noreferrer noopener">https://www.postgresql.org/support/security/CVE-2024-0985/</a><br /> Microsoft Defender Bypass via Comma<br /><a href="https://hyp3rlinx.altervista.org/advisories/MICROSOFT_WINDOWS_DEFENDER_TROJAN.WIN32.POWESSERE.G_MITIGATION_BYPASS_PART2.txt" target="_blank" rel="noreferrer noopener">https://hyp3rlinx.altervista.org/advisories/MICROSOFT_WINDOWS_DEFENDER_TROJAN.WIN32.POWESSERE.G_MITIGATION_BYPASS_PART2.txt</a><br />]]></itunes:summary><itunes:duration>333</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microsoft; defender; comma; po,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8850</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, February 13th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-february-13th-2024--58669090</link><description><![CDATA[Exploit Against Unnamed BYTEVALUE Router Vulnerablity Included in Mirai<br /><a href="https://isc.sans.edu/diary/Exploit%20against%20Unnamed%20%22Bytevalue%22%20router%20vulnerability%20included%20in%20Mirai%20Bot/30642" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit%20against%20Unnamed%20%22Bytevalue%22%20router%20vulnerability%20included%20in%20Mirai%20Bot/30642</a><br /> Senior Executives Targeted in Ongoing Azure Account Takeover<br /><a href="https://www.darkreading.com/cloud-security/senior-executives-targeted-ongoing-azure-account-takeover" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/cloud-security/senior-executives-targeted-ongoing-azure-account-takeover</a><br /> CISA Parners With OpenSSF To Secure Software Repositories<br /><a href="https://www.cisa.gov/news-events/alerts/2024/02/08/cisa-partners-openssf-securing-software-repositories-working-group-release-principles-package" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2024/02/08/cisa-partners-openssf-securing-software-repositories-working-group-release-principles-package</a><br /> PostgreSQL Vulnerability<br /><a href="https://www.postgresql.org/support/security/CVE-2024-0985/" target="_blank" rel="noreferrer noopener">https://www.postgresql.org/support/security/CVE-2024-0985/</a><br /> Microsoft Defender Bypass via Comma<br /><a href="https://hyp3rlinx.altervista.org/advisories/MICROSOFT_WINDOWS_DEFENDER_TROJAN.WIN32.POWESSERE.G_MITIGATION_BYPASS_PART2.txt" target="_blank" rel="noreferrer noopener">https://hyp3rlinx.altervista.org/advisories/MICROSOFT_WINDOWS_DEFENDER_TROJAN.WIN32.POWESSERE.G_MITIGATION_BYPASS_PART2.txt</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8850.mp3</guid><pubDate>Tue, 13 Feb 2024 03:00:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58669090/8850.mp3" length="4970157" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Exploit Against Unnamed BYTEVALUE Router Vulnerablity Included in Mirai
https://isc.sans.edu/diary/Exploit%20against%20Unnamed%20%22Bytevalue%22%20router%20vulnerability%20included%20in%20Mirai%20Bot/30642
 Senior Executives Targeted in Ongoing Azure...</itunes:subtitle><itunes:summary><![CDATA[Exploit Against Unnamed BYTEVALUE Router Vulnerablity Included in Mirai<br /><a href="https://isc.sans.edu/diary/Exploit%20against%20Unnamed%20%22Bytevalue%22%20router%20vulnerability%20included%20in%20Mirai%20Bot/30642" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit%20against%20Unnamed%20%22Bytevalue%22%20router%20vulnerability%20included%20in%20Mirai%20Bot/30642</a><br /> Senior Executives Targeted in Ongoing Azure Account Takeover<br /><a href="https://www.darkreading.com/cloud-security/senior-executives-targeted-ongoing-azure-account-takeover" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/cloud-security/senior-executives-targeted-ongoing-azure-account-takeover</a><br /> CISA Parners With OpenSSF To Secure Software Repositories<br /><a href="https://www.cisa.gov/news-events/alerts/2024/02/08/cisa-partners-openssf-securing-software-repositories-working-group-release-principles-package" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2024/02/08/cisa-partners-openssf-securing-software-repositories-working-group-release-principles-package</a><br /> PostgreSQL Vulnerability<br /><a href="https://www.postgresql.org/support/security/CVE-2024-0985/" target="_blank" rel="noreferrer noopener">https://www.postgresql.org/support/security/CVE-2024-0985/</a><br /> Microsoft Defender Bypass via Comma<br /><a href="https://hyp3rlinx.altervista.org/advisories/MICROSOFT_WINDOWS_DEFENDER_TROJAN.WIN32.POWESSERE.G_MITIGATION_BYPASS_PART2.txt" target="_blank" rel="noreferrer noopener">https://hyp3rlinx.altervista.org/advisories/MICROSOFT_WINDOWS_DEFENDER_TROJAN.WIN32.POWESSERE.G_MITIGATION_BYPASS_PART2.txt</a><br />]]></itunes:summary><itunes:duration>333</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microsoft; defender; comma; po,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8850</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, February 12th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-february-12th-2024--62129486</link><description><![CDATA[MSIX With Heaviliy Obfuscated PowerShell Script<br /><a href="https://isc.sans.edu/diary/MSIX%20With%20Heavily%20Obfuscated%20PowerShell%20Script/30636" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/MSIX%20With%20Heavily%20Obfuscated%20PowerShell%20Script/30636</a><br /> Too Many Honeypots<br /><a href="https://vulncheck.com/blog/too-many-honeypots" target="_blank" rel="noreferrer noopener">https://vulncheck.com/blog/too-many-honeypots</a><br /> ClamAV Command Injection Vulnerability CVE-2024-20328<br /><a href="https://amitschendel.github.io/vulnerabilites/CVE-2024-20328/" target="_blank" rel="noreferrer noopener">https://amitschendel.github.io/vulnerabilites/CVE-2024-20328/</a><br /> ExpressVPN DNS Leaks<br /><a href="https://www.expressvpn.com/blog/windows-app-dns-requests/" target="_blank" rel="noreferrer noopener">https://www.expressvpn.com/blog/windows-app-dns-requests/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8848.mp3</guid><pubDate>Mon, 12 Feb 2024 02:25:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129486/8848.mp3" length="5210026" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>MSIX With Heaviliy Obfuscated PowerShell Script
https://isc.sans.edu/diary/MSIX%20With%20Heavily%20Obfuscated%20PowerShell%20Script/30636
 Too Many Honeypots
https://vulncheck.com/blog/too-many-honeypots
 ClamAV Command Injection Vulnerability...</itunes:subtitle><itunes:summary><![CDATA[MSIX With Heaviliy Obfuscated PowerShell Script<br /><a href="https://isc.sans.edu/diary/MSIX%20With%20Heavily%20Obfuscated%20PowerShell%20Script/30636" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/MSIX%20With%20Heavily%20Obfuscated%20PowerShell%20Script/30636</a><br /> Too Many Honeypots<br /><a href="https://vulncheck.com/blog/too-many-honeypots" target="_blank" rel="noreferrer noopener">https://vulncheck.com/blog/too-many-honeypots</a><br /> ClamAV Command Injection Vulnerability CVE-2024-20328<br /><a href="https://amitschendel.github.io/vulnerabilites/CVE-2024-20328/" target="_blank" rel="noreferrer noopener">https://amitschendel.github.io/vulnerabilites/CVE-2024-20328/</a><br /> ExpressVPN DNS Leaks<br /><a href="https://www.expressvpn.com/blog/windows-app-dns-requests/" target="_blank" rel="noreferrer noopener">https://www.expressvpn.com/blog/windows-app-dns-requests/</a><br />]]></itunes:summary><itunes:duration>351</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,expressvpn; dns; leak; clamav;,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8848</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, February 12th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-february-12th-2024--58652651</link><description><![CDATA[MSIX With Heaviliy Obfuscated PowerShell Script<br /><a href="https://isc.sans.edu/diary/MSIX%20With%20Heavily%20Obfuscated%20PowerShell%20Script/30636" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/MSIX%20With%20Heavily%20Obfuscated%20PowerShell%20Script/30636</a><br /> Too Many Honeypots<br /><a href="https://vulncheck.com/blog/too-many-honeypots" target="_blank" rel="noreferrer noopener">https://vulncheck.com/blog/too-many-honeypots</a><br /> ClamAV Command Injection Vulnerability CVE-2024-20328<br /><a href="https://amitschendel.github.io/vulnerabilites/CVE-2024-20328/" target="_blank" rel="noreferrer noopener">https://amitschendel.github.io/vulnerabilites/CVE-2024-20328/</a><br /> ExpressVPN DNS Leaks<br /><a href="https://www.expressvpn.com/blog/windows-app-dns-requests/" target="_blank" rel="noreferrer noopener">https://www.expressvpn.com/blog/windows-app-dns-requests/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8848.mp3</guid><pubDate>Mon, 12 Feb 2024 02:25:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58652651/8848.mp3" length="5210026" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>MSIX With Heaviliy Obfuscated PowerShell Script
https://isc.sans.edu/diary/MSIX%20With%20Heavily%20Obfuscated%20PowerShell%20Script/30636
 Too Many Honeypots
https://vulncheck.com/blog/too-many-honeypots
 ClamAV Command Injection Vulnerability...</itunes:subtitle><itunes:summary><![CDATA[MSIX With Heaviliy Obfuscated PowerShell Script<br /><a href="https://isc.sans.edu/diary/MSIX%20With%20Heavily%20Obfuscated%20PowerShell%20Script/30636" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/MSIX%20With%20Heavily%20Obfuscated%20PowerShell%20Script/30636</a><br /> Too Many Honeypots<br /><a href="https://vulncheck.com/blog/too-many-honeypots" target="_blank" rel="noreferrer noopener">https://vulncheck.com/blog/too-many-honeypots</a><br /> ClamAV Command Injection Vulnerability CVE-2024-20328<br /><a href="https://amitschendel.github.io/vulnerabilites/CVE-2024-20328/" target="_blank" rel="noreferrer noopener">https://amitschendel.github.io/vulnerabilites/CVE-2024-20328/</a><br /> ExpressVPN DNS Leaks<br /><a href="https://www.expressvpn.com/blog/windows-app-dns-requests/" target="_blank" rel="noreferrer noopener">https://www.expressvpn.com/blog/windows-app-dns-requests/</a><br />]]></itunes:summary><itunes:duration>351</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,expressvpn; dns; leak; clamav;,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8848</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, February 9th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-february-9th-2024--62129453</link><description><![CDATA[A Python MP3 Player With Builtin Keylogger Capability<br /><a href="https://isc.sans.edu/diary/A%20Python%20MP3%20Player%20with%20Builtin%20Keylogger%20Capability/30632" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20Python%20MP3%20Player%20with%20Builtin%20Keylogger%20Capability/30632</a><br /> Fake LastPass App in Apple App Store<br /><a href="https://blog.lastpass.com/2024/02/warning-fraudulent-app-impersonating-lastpass-currently-available-in-apple-app-store/" target="_blank" rel="noreferrer noopener">https://blog.lastpass.com/2024/02/warning-fraudulent-app-impersonating-lastpass-currently-available-in-apple-app-store/</a><br /> Ivanti XXE Vulnerability<br /><a href="https://forums.ivanti.com/s/article/CVE-2024-22024-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/CVE-2024-22024-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure</a><br /> FortiOS sslvpnd vulnerability<br /><a href="https://www.fortiguard.com/psirt/FG-IR-24-015" target="_blank" rel="noreferrer noopener">https://www.fortiguard.com/psirt/FG-IR-24-015</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8846.mp3</guid><pubDate>Fri, 09 Feb 2024 03:10:06 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129453/8846.mp3" length="5146976" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>A Python MP3 Player With Builtin Keylogger Capability
https://isc.sans.edu/diary/A%20Python%20MP3%20Player%20with%20Builtin%20Keylogger%20Capability/30632
 Fake LastPass App in Apple App Store...</itunes:subtitle><itunes:summary><![CDATA[A Python MP3 Player With Builtin Keylogger Capability<br /><a href="https://isc.sans.edu/diary/A%20Python%20MP3%20Player%20with%20Builtin%20Keylogger%20Capability/30632" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20Python%20MP3%20Player%20with%20Builtin%20Keylogger%20Capability/30632</a><br /> Fake LastPass App in Apple App Store<br /><a href="https://blog.lastpass.com/2024/02/warning-fraudulent-app-impersonating-lastpass-currently-available-in-apple-app-store/" target="_blank" rel="noreferrer noopener">https://blog.lastpass.com/2024/02/warning-fraudulent-app-impersonating-lastpass-currently-available-in-apple-app-store/</a><br /> Ivanti XXE Vulnerability<br /><a href="https://forums.ivanti.com/s/article/CVE-2024-22024-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/CVE-2024-22024-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure</a><br /> FortiOS sslvpnd vulnerability<br /><a href="https://www.fortiguard.com/psirt/FG-IR-24-015" target="_blank" rel="noreferrer noopener">https://www.fortiguard.com/psirt/FG-IR-24-015</a><br />]]></itunes:summary><itunes:duration>346</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,fortios; sslvpnd; ivanti; xxe;,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8846</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, February 9th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-february-9th-2024--58619195</link><description><![CDATA[A Python MP3 Player With Builtin Keylogger Capability<br /><a href="https://isc.sans.edu/diary/A%20Python%20MP3%20Player%20with%20Builtin%20Keylogger%20Capability/30632" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20Python%20MP3%20Player%20with%20Builtin%20Keylogger%20Capability/30632</a><br /> Fake LastPass App in Apple App Store<br /><a href="https://blog.lastpass.com/2024/02/warning-fraudulent-app-impersonating-lastpass-currently-available-in-apple-app-store/" target="_blank" rel="noreferrer noopener">https://blog.lastpass.com/2024/02/warning-fraudulent-app-impersonating-lastpass-currently-available-in-apple-app-store/</a><br /> Ivanti XXE Vulnerability<br /><a href="https://forums.ivanti.com/s/article/CVE-2024-22024-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/CVE-2024-22024-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure</a><br /> FortiOS sslvpnd vulnerability<br /><a href="https://www.fortiguard.com/psirt/FG-IR-24-015" target="_blank" rel="noreferrer noopener">https://www.fortiguard.com/psirt/FG-IR-24-015</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8846.mp3</guid><pubDate>Fri, 09 Feb 2024 03:10:06 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58619195/8846.mp3" length="5146976" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>A Python MP3 Player With Builtin Keylogger Capability
https://isc.sans.edu/diary/A%20Python%20MP3%20Player%20with%20Builtin%20Keylogger%20Capability/30632
 Fake LastPass App in Apple App Store...</itunes:subtitle><itunes:summary><![CDATA[A Python MP3 Player With Builtin Keylogger Capability<br /><a href="https://isc.sans.edu/diary/A%20Python%20MP3%20Player%20with%20Builtin%20Keylogger%20Capability/30632" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20Python%20MP3%20Player%20with%20Builtin%20Keylogger%20Capability/30632</a><br /> Fake LastPass App in Apple App Store<br /><a href="https://blog.lastpass.com/2024/02/warning-fraudulent-app-impersonating-lastpass-currently-available-in-apple-app-store/" target="_blank" rel="noreferrer noopener">https://blog.lastpass.com/2024/02/warning-fraudulent-app-impersonating-lastpass-currently-available-in-apple-app-store/</a><br /> Ivanti XXE Vulnerability<br /><a href="https://forums.ivanti.com/s/article/CVE-2024-22024-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/CVE-2024-22024-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure</a><br /> FortiOS sslvpnd vulnerability<br /><a href="https://www.fortiguard.com/psirt/FG-IR-24-015" target="_blank" rel="noreferrer noopener">https://www.fortiguard.com/psirt/FG-IR-24-015</a><br />]]></itunes:summary><itunes:duration>346</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,fortios; sslvpnd; ivanti; xxe;,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8846</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, February 8th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-february-8th-2024--62129411</link><description><![CDATA[Anybody knows what this URL is about? Maybe Balena API request?<br /><a href="https://isc.sans.edu/forums/diary/Anybody%20knows%20that%20this%20URL%20is%20about%3F%20Maybe%20Balena%20API%20request%3F/30628/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Anybody%20knows%20that%20this%20URL%20is%20about%3F%20Maybe%20Balena%20API%20request%3F/30628/</a><br /> Critical shim vulnerability and patch<br /><a href="https://github.com/rhboot/shim/releases/tag/15.8" target="_blank" rel="noreferrer noopener">https://github.com/rhboot/shim/releases/tag/15.8</a><br /> Volt Typhoon Lessons Learned<br /><a href="https://www.cisa.gov/resources-tools/resources/identifying-and-mitigating-living-land-techniques" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/resources-tools/resources/identifying-and-mitigating-living-land-techniques</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8844.mp3</guid><pubDate>Thu, 08 Feb 2024 02:55:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129411/8844.mp3" length="4919966" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Anybody knows what this URL is about? Maybe Balena API request?
https://isc.sans.edu/forums/diary/Anybody%20knows%20that%20this%20URL%20is%20about%3F%20Maybe%20Balena%20API%20request%3F/30628/
 Critical shim vulnerability and patch...</itunes:subtitle><itunes:summary><![CDATA[Anybody knows what this URL is about? Maybe Balena API request?<br /><a href="https://isc.sans.edu/forums/diary/Anybody%20knows%20that%20this%20URL%20is%20about%3F%20Maybe%20Balena%20API%20request%3F/30628/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Anybody%20knows%20that%20this%20URL%20is%20about%3F%20Maybe%20Balena%20API%20request%3F/30628/</a><br /> Critical shim vulnerability and patch<br /><a href="https://github.com/rhboot/shim/releases/tag/15.8" target="_blank" rel="noreferrer noopener">https://github.com/rhboot/shim/releases/tag/15.8</a><br /> Volt Typhoon Lessons Learned<br /><a href="https://www.cisa.gov/resources-tools/resources/identifying-and-mitigating-living-land-techniques" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/resources-tools/resources/identifying-and-mitigating-living-land-techniques</a><br />]]></itunes:summary><itunes:duration>330</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,volt; typhoon; shim; bios; uef</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8844</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, February 8th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-february-8th-2024--58606303</link><description><![CDATA[Anybody knows what this URL is about? Maybe Balena API request?<br /><a href="https://isc.sans.edu/forums/diary/Anybody%20knows%20that%20this%20URL%20is%20about%3F%20Maybe%20Balena%20API%20request%3F/30628/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Anybody%20knows%20that%20this%20URL%20is%20about%3F%20Maybe%20Balena%20API%20request%3F/30628/</a><br /> Critical shim vulnerability and patch<br /><a href="https://github.com/rhboot/shim/releases/tag/15.8" target="_blank" rel="noreferrer noopener">https://github.com/rhboot/shim/releases/tag/15.8</a><br /> Volt Typhoon Lessons Learned<br /><a href="https://www.cisa.gov/resources-tools/resources/identifying-and-mitigating-living-land-techniques" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/resources-tools/resources/identifying-and-mitigating-living-land-techniques</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8844.mp3</guid><pubDate>Thu, 08 Feb 2024 02:55:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58606303/8844.mp3" length="4919966" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Anybody knows what this URL is about? Maybe Balena API request?
https://isc.sans.edu/forums/diary/Anybody%20knows%20that%20this%20URL%20is%20about%3F%20Maybe%20Balena%20API%20request%3F/30628/
 Critical shim vulnerability and patch...</itunes:subtitle><itunes:summary><![CDATA[Anybody knows what this URL is about? Maybe Balena API request?<br /><a href="https://isc.sans.edu/forums/diary/Anybody%20knows%20that%20this%20URL%20is%20about%3F%20Maybe%20Balena%20API%20request%3F/30628/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Anybody%20knows%20that%20this%20URL%20is%20about%3F%20Maybe%20Balena%20API%20request%3F/30628/</a><br /> Critical shim vulnerability and patch<br /><a href="https://github.com/rhboot/shim/releases/tag/15.8" target="_blank" rel="noreferrer noopener">https://github.com/rhboot/shim/releases/tag/15.8</a><br /> Volt Typhoon Lessons Learned<br /><a href="https://www.cisa.gov/resources-tools/resources/identifying-and-mitigating-living-land-techniques" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/resources-tools/resources/identifying-and-mitigating-living-land-techniques</a><br />]]></itunes:summary><itunes:duration>330</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,volt; typhoon; shim; bios; uef</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8844</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, February 7th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-february-7th-2024--62129420</link><description><![CDATA[Computer viruses are celebrating their 40th birthday (well, 54th, really)<br /><a href="https://isc.sans.edu/diary/Computer%20viruses%20are%20celebrating%20their%2040th%20birthday%20%28well%2C%2054th%2C%20really%29/30624" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Computer%20viruses%20are%20celebrating%20their%2040th%20birthday%20%28well%2C%2054th%2C%20really%29/30624</a><br /> Three million malware-infected smart toothbrushes used in Swiss DDoS attacks<br /><a href="https://www.tomshardware.com/networking/three-million-malware-infected-smart-toothbrushes-used-in-swiss-ddos-attacks-botnet-causes-millions-of-euros-in-damages" target="_blank" rel="noreferrer noopener">https://www.tomshardware.com/networking/three-million-malware-infected-smart-toothbrushes-used-in-swiss-ddos-attacks-botnet-causes-millions-of-euros-in-damages</a><br /> Critical Security Issue Affecting TeamCity On-Premises CVE-2024-23917<br /><a href="https://blog.jetbrains.com/teamcity/2024/02/critical-security-issue-affecting-teamcity-on-premises-cve-2024-23917/" target="_blank" rel="noreferrer noopener">https://blog.jetbrains.com/teamcity/2024/02/critical-security-issue-affecting-teamcity-on-premises-cve-2024-23917/</a><br /> Resume Looters<br /><a href="https://www.group-ib.com/blog/resumelooters/" target="_blank" rel="noreferrer noopener">https://www.group-ib.com/blog/resumelooters/</a><br /> Facebook Advertising Spreads Novel Malware Variant<br /><a href="https://www.trustwave.com/hubfs/Web/Library/Documents_pdf/FaceBook_Ad_Spreads_Novel_Malware.pdf" target="_blank" rel="noreferrer noopener">https://www.trustwave.com/hubfs/Web/Library/Documents_pdf/FaceBook_Ad_Spreads_Novel_Malware.pdf</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8842.mp3</guid><pubDate>Wed, 07 Feb 2024 03:05:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129420/8842.mp3" length="5852617" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Computer viruses are celebrating their 40th birthday (well, 54th, really)
https://isc.sans.edu/diary/Computer%20viruses%20are%20celebrating%20their%2040th%20birthday%20%28well%2C%2054th%2C%20really%29/30624
 Three million malware-infected smart...</itunes:subtitle><itunes:summary><![CDATA[Computer viruses are celebrating their 40th birthday (well, 54th, really)<br /><a href="https://isc.sans.edu/diary/Computer%20viruses%20are%20celebrating%20their%2040th%20birthday%20%28well%2C%2054th%2C%20really%29/30624" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Computer%20viruses%20are%20celebrating%20their%2040th%20birthday%20%28well%2C%2054th%2C%20really%29/30624</a><br /> Three million malware-infected smart toothbrushes used in Swiss DDoS attacks<br /><a href="https://www.tomshardware.com/networking/three-million-malware-infected-smart-toothbrushes-used-in-swiss-ddos-attacks-botnet-causes-millions-of-euros-in-damages" target="_blank" rel="noreferrer noopener">https://www.tomshardware.com/networking/three-million-malware-infected-smart-toothbrushes-used-in-swiss-ddos-attacks-botnet-causes-millions-of-euros-in-damages</a><br /> Critical Security Issue Affecting TeamCity On-Premises CVE-2024-23917<br /><a href="https://blog.jetbrains.com/teamcity/2024/02/critical-security-issue-affecting-teamcity-on-premises-cve-2024-23917/" target="_blank" rel="noreferrer noopener">https://blog.jetbrains.com/teamcity/2024/02/critical-security-issue-affecting-teamcity-on-premises-cve-2024-23917/</a><br /> Resume Looters<br /><a href="https://www.group-ib.com/blog/resumelooters/" target="_blank" rel="noreferrer noopener">https://www.group-ib.com/blog/resumelooters/</a><br /> Facebook Advertising Spreads Novel Malware Variant<br /><a href="https://www.trustwave.com/hubfs/Web/Library/Documents_pdf/FaceBook_Ad_Spreads_Novel_Malware.pdf" target="_blank" rel="noreferrer noopener">https://www.trustwave.com/hubfs/Web/Library/Documents_pdf/FaceBook_Ad_Spreads_Novel_Malware.pdf</a><br />]]></itunes:summary><itunes:duration>396</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,facebook; advertising; malware,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8842</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, February 7th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-february-7th-2024--58593798</link><description><![CDATA[Computer viruses are celebrating their 40th birthday (well, 54th, really)<br /><a href="https://isc.sans.edu/diary/Computer%20viruses%20are%20celebrating%20their%2040th%20birthday%20%28well%2C%2054th%2C%20really%29/30624" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Computer%20viruses%20are%20celebrating%20their%2040th%20birthday%20%28well%2C%2054th%2C%20really%29/30624</a><br /> Three million malware-infected smart toothbrushes used in Swiss DDoS attacks<br /><a href="https://www.tomshardware.com/networking/three-million-malware-infected-smart-toothbrushes-used-in-swiss-ddos-attacks-botnet-causes-millions-of-euros-in-damages" target="_blank" rel="noreferrer noopener">https://www.tomshardware.com/networking/three-million-malware-infected-smart-toothbrushes-used-in-swiss-ddos-attacks-botnet-causes-millions-of-euros-in-damages</a><br /> Critical Security Issue Affecting TeamCity On-Premises CVE-2024-23917<br /><a href="https://blog.jetbrains.com/teamcity/2024/02/critical-security-issue-affecting-teamcity-on-premises-cve-2024-23917/" target="_blank" rel="noreferrer noopener">https://blog.jetbrains.com/teamcity/2024/02/critical-security-issue-affecting-teamcity-on-premises-cve-2024-23917/</a><br /> Resume Looters<br /><a href="https://www.group-ib.com/blog/resumelooters/" target="_blank" rel="noreferrer noopener">https://www.group-ib.com/blog/resumelooters/</a><br /> Facebook Advertising Spreads Novel Malware Variant<br /><a href="https://www.trustwave.com/hubfs/Web/Library/Documents_pdf/FaceBook_Ad_Spreads_Novel_Malware.pdf" target="_blank" rel="noreferrer noopener">https://www.trustwave.com/hubfs/Web/Library/Documents_pdf/FaceBook_Ad_Spreads_Novel_Malware.pdf</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8842.mp3</guid><pubDate>Wed, 07 Feb 2024 03:05:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58593798/8842.mp3" length="5852617" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Computer viruses are celebrating their 40th birthday (well, 54th, really)
https://isc.sans.edu/diary/Computer%20viruses%20are%20celebrating%20their%2040th%20birthday%20%28well%2C%2054th%2C%20really%29/30624
 Three million malware-infected smart...</itunes:subtitle><itunes:summary><![CDATA[Computer viruses are celebrating their 40th birthday (well, 54th, really)<br /><a href="https://isc.sans.edu/diary/Computer%20viruses%20are%20celebrating%20their%2040th%20birthday%20%28well%2C%2054th%2C%20really%29/30624" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Computer%20viruses%20are%20celebrating%20their%2040th%20birthday%20%28well%2C%2054th%2C%20really%29/30624</a><br /> Three million malware-infected smart toothbrushes used in Swiss DDoS attacks<br /><a href="https://www.tomshardware.com/networking/three-million-malware-infected-smart-toothbrushes-used-in-swiss-ddos-attacks-botnet-causes-millions-of-euros-in-damages" target="_blank" rel="noreferrer noopener">https://www.tomshardware.com/networking/three-million-malware-infected-smart-toothbrushes-used-in-swiss-ddos-attacks-botnet-causes-millions-of-euros-in-damages</a><br /> Critical Security Issue Affecting TeamCity On-Premises CVE-2024-23917<br /><a href="https://blog.jetbrains.com/teamcity/2024/02/critical-security-issue-affecting-teamcity-on-premises-cve-2024-23917/" target="_blank" rel="noreferrer noopener">https://blog.jetbrains.com/teamcity/2024/02/critical-security-issue-affecting-teamcity-on-premises-cve-2024-23917/</a><br /> Resume Looters<br /><a href="https://www.group-ib.com/blog/resumelooters/" target="_blank" rel="noreferrer noopener">https://www.group-ib.com/blog/resumelooters/</a><br /> Facebook Advertising Spreads Novel Malware Variant<br /><a href="https://www.trustwave.com/hubfs/Web/Library/Documents_pdf/FaceBook_Ad_Spreads_Novel_Malware.pdf" target="_blank" rel="noreferrer noopener">https://www.trustwave.com/hubfs/Web/Library/Documents_pdf/FaceBook_Ad_Spreads_Novel_Malware.pdf</a><br />]]></itunes:summary><itunes:duration>396</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,facebook; advertising; malware,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8842</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, February 6th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-february-6th-2024--62129387</link><description><![CDATA[Public Information and Email Spam<br /><a href="https://isc.sans.edu/diary/Public+Information+and+Email+Spam/30620/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Public+Information+and+Email+Spam/30620/</a><br /> Anydesk Update<br /><a href="https://www.bleepingcomputer.com/news/security/anydesk-says-hackers-breached-its-production-servers-reset-passwords/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/anydesk-says-hackers-breached-its-production-servers-reset-passwords/</a><br /><a href="https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2024/2024-213655-1032.pdf" target="_blank" rel="noreferrer noopener">https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2024/2024-213655-1032.pdf</a><br /> Ivanti POC For CVE-2024-21893<br /><a href="https://attackerkb.com/topics/FGlK1TVnB2/cve-2024-21893/rapid7-analysis" target="_blank" rel="noreferrer noopener">https://attackerkb.com/topics/FGlK1TVnB2/cve-2024-21893/rapid7-analysis</a><br /> Deepfake Exploits<br /><a href="https://www.scmp.com/news/hong-kong/law-and-crime/article/3250851/everyone-looked-real-multinational-firms-hong-kong-office-loses-hk200-million-after-scammers-stage" target="_blank" rel="noreferrer noopener">https://www.scmp.com/news/hong-kong/law-and-crime/article/3250851/everyone-looked-real-multinational-firms-hong-kong-office-loses-hk200-million-after-scammers-stage</a><br /><a href="https://www.404media.co/inside-the-underground-site-where-ai-neural-networks-churns-out-fake-ids-onlyfake/" target="_blank" rel="noreferrer noopener">https://www.404media.co/inside-the-underground-site-where-ai-neural-networks-churns-out-fake-ids-onlyfake/</a><br /><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8840.mp3</guid><pubDate>Tue, 06 Feb 2024 02:40:07 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129387/8840.mp3" length="5269053" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Public Information and Email Spam
https://isc.sans.edu/diary/Public+Information+and+Email+Spam/30620/
 Anydesk Update
https://www.bleepingcomputer.com/news/security/anydesk-says-hackers-breached-its-production-servers-reset-passwords/...</itunes:subtitle><itunes:summary><![CDATA[Public Information and Email Spam<br /><a href="https://isc.sans.edu/diary/Public+Information+and+Email+Spam/30620/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Public+Information+and+Email+Spam/30620/</a><br /> Anydesk Update<br /><a href="https://www.bleepingcomputer.com/news/security/anydesk-says-hackers-breached-its-production-servers-reset-passwords/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/anydesk-says-hackers-breached-its-production-servers-reset-passwords/</a><br /><a href="https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2024/2024-213655-1032.pdf" target="_blank" rel="noreferrer noopener">https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2024/2024-213655-1032.pdf</a><br /> Ivanti POC For CVE-2024-21893<br /><a href="https://attackerkb.com/topics/FGlK1TVnB2/cve-2024-21893/rapid7-analysis" target="_blank" rel="noreferrer noopener">https://attackerkb.com/topics/FGlK1TVnB2/cve-2024-21893/rapid7-analysis</a><br /> Deepfake Exploits<br /><a href="https://www.scmp.com/news/hong-kong/law-and-crime/article/3250851/everyone-looked-real-multinational-firms-hong-kong-office-loses-hk200-million-after-scammers-stage" target="_blank" rel="noreferrer noopener">https://www.scmp.com/news/hong-kong/law-and-crime/article/3250851/everyone-looked-real-multinational-firms-hong-kong-office-loses-hk200-million-after-scammers-stage</a><br /><a href="https://www.404media.co/inside-the-underground-site-where-ai-neural-networks-churns-out-fake-ids-onlyfake/" target="_blank" rel="noreferrer noopener">https://www.404media.co/inside-the-underground-site-where-ai-neural-networks-churns-out-fake-ids-onlyfake/</a><br /><br />]]></itunes:summary><itunes:duration>355</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,deepfake; ivanti; poc; cve-202,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8840</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, February 6th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-february-6th-2024--58581948</link><description><![CDATA[Public Information and Email Spam<br /><a href="https://isc.sans.edu/diary/Public+Information+and+Email+Spam/30620/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Public+Information+and+Email+Spam/30620/</a><br /> Anydesk Update<br /><a href="https://www.bleepingcomputer.com/news/security/anydesk-says-hackers-breached-its-production-servers-reset-passwords/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/anydesk-says-hackers-breached-its-production-servers-reset-passwords/</a><br /><a href="https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2024/2024-213655-1032.pdf" target="_blank" rel="noreferrer noopener">https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2024/2024-213655-1032.pdf</a><br /> Ivanti POC For CVE-2024-21893<br /><a href="https://attackerkb.com/topics/FGlK1TVnB2/cve-2024-21893/rapid7-analysis" target="_blank" rel="noreferrer noopener">https://attackerkb.com/topics/FGlK1TVnB2/cve-2024-21893/rapid7-analysis</a><br /> Deepfake Exploits<br /><a href="https://www.scmp.com/news/hong-kong/law-and-crime/article/3250851/everyone-looked-real-multinational-firms-hong-kong-office-loses-hk200-million-after-scammers-stage" target="_blank" rel="noreferrer noopener">https://www.scmp.com/news/hong-kong/law-and-crime/article/3250851/everyone-looked-real-multinational-firms-hong-kong-office-loses-hk200-million-after-scammers-stage</a><br /><a href="https://www.404media.co/inside-the-underground-site-where-ai-neural-networks-churns-out-fake-ids-onlyfake/" target="_blank" rel="noreferrer noopener">https://www.404media.co/inside-the-underground-site-where-ai-neural-networks-churns-out-fake-ids-onlyfake/</a><br /><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8840.mp3</guid><pubDate>Tue, 06 Feb 2024 02:40:07 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58581948/8840.mp3" length="5269053" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Public Information and Email Spam
https://isc.sans.edu/diary/Public+Information+and+Email+Spam/30620/
 Anydesk Update
https://www.bleepingcomputer.com/news/security/anydesk-says-hackers-breached-its-production-servers-reset-passwords/...</itunes:subtitle><itunes:summary><![CDATA[Public Information and Email Spam<br /><a href="https://isc.sans.edu/diary/Public+Information+and+Email+Spam/30620/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Public+Information+and+Email+Spam/30620/</a><br /> Anydesk Update<br /><a href="https://www.bleepingcomputer.com/news/security/anydesk-says-hackers-breached-its-production-servers-reset-passwords/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/anydesk-says-hackers-breached-its-production-servers-reset-passwords/</a><br /><a href="https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2024/2024-213655-1032.pdf" target="_blank" rel="noreferrer noopener">https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2024/2024-213655-1032.pdf</a><br /> Ivanti POC For CVE-2024-21893<br /><a href="https://attackerkb.com/topics/FGlK1TVnB2/cve-2024-21893/rapid7-analysis" target="_blank" rel="noreferrer noopener">https://attackerkb.com/topics/FGlK1TVnB2/cve-2024-21893/rapid7-analysis</a><br /> Deepfake Exploits<br /><a href="https://www.scmp.com/news/hong-kong/law-and-crime/article/3250851/everyone-looked-real-multinational-firms-hong-kong-office-loses-hk200-million-after-scammers-stage" target="_blank" rel="noreferrer noopener">https://www.scmp.com/news/hong-kong/law-and-crime/article/3250851/everyone-looked-real-multinational-firms-hong-kong-office-loses-hk200-million-after-scammers-stage</a><br /><a href="https://www.404media.co/inside-the-underground-site-where-ai-neural-networks-churns-out-fake-ids-onlyfake/" target="_blank" rel="noreferrer noopener">https://www.404media.co/inside-the-underground-site-where-ai-neural-networks-churns-out-fake-ids-onlyfake/</a><br /><br />]]></itunes:summary><itunes:duration>355</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,deepfake; ivanti; poc; cve-202,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8840</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, February 5th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-february-5th-2024--62129463</link><description><![CDATA[DShield Sensor Log Collection with Elasticsearch<br /><a href="https://isc.sans.edu/forums/diary/DShield%20Sensor%20Log%20Collection%20with%20Elasticsearch/30616/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/DShield%20Sensor%20Log%20Collection%20with%20Elasticsearch/30616/</a><br /> Anydesk Breach<br /><a href="https://anydesk.com/en/public-statement" target="_blank" rel="noreferrer noopener">https://anydesk.com/en/public-statement</a><br /> Leaky Vessels<br /><a href="https://snyk.io/blog/leaky-vessels-docker-runc-container-breakout-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://snyk.io/blog/leaky-vessels-docker-runc-container-breakout-vulnerabilities/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8838.mp3</guid><pubDate>Mon, 05 Feb 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129463/8838.mp3" length="5138541" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>DShield Sensor Log Collection with Elasticsearch
https://isc.sans.edu/forums/diary/DShield%20Sensor%20Log%20Collection%20with%20Elasticsearch/30616/
 Anydesk Breach
https://anydesk.com/en/public-statement
 Leaky Vessels...</itunes:subtitle><itunes:summary><![CDATA[DShield Sensor Log Collection with Elasticsearch<br /><a href="https://isc.sans.edu/forums/diary/DShield%20Sensor%20Log%20Collection%20with%20Elasticsearch/30616/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/DShield%20Sensor%20Log%20Collection%20with%20Elasticsearch/30616/</a><br /> Anydesk Breach<br /><a href="https://anydesk.com/en/public-statement" target="_blank" rel="noreferrer noopener">https://anydesk.com/en/public-statement</a><br /> Leaky Vessels<br /><a href="https://snyk.io/blog/leaky-vessels-docker-runc-container-breakout-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://snyk.io/blog/leaky-vessels-docker-runc-container-breakout-vulnerabilities/</a><br />]]></itunes:summary><itunes:duration>345</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,docker; dshield; elastic; kiba,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8838</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, February 5th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-february-5th-2024--58570068</link><description><![CDATA[DShield Sensor Log Collection with Elasticsearch<br /><a href="https://isc.sans.edu/forums/diary/DShield%20Sensor%20Log%20Collection%20with%20Elasticsearch/30616/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/DShield%20Sensor%20Log%20Collection%20with%20Elasticsearch/30616/</a><br /> Anydesk Breach<br /><a href="https://anydesk.com/en/public-statement" target="_blank" rel="noreferrer noopener">https://anydesk.com/en/public-statement</a><br /> Leaky Vessels<br /><a href="https://snyk.io/blog/leaky-vessels-docker-runc-container-breakout-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://snyk.io/blog/leaky-vessels-docker-runc-container-breakout-vulnerabilities/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8838.mp3</guid><pubDate>Mon, 05 Feb 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58570068/8838.mp3" length="5138541" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>DShield Sensor Log Collection with Elasticsearch
https://isc.sans.edu/forums/diary/DShield%20Sensor%20Log%20Collection%20with%20Elasticsearch/30616/
 Anydesk Breach
https://anydesk.com/en/public-statement
 Leaky Vessels...</itunes:subtitle><itunes:summary><![CDATA[DShield Sensor Log Collection with Elasticsearch<br /><a href="https://isc.sans.edu/forums/diary/DShield%20Sensor%20Log%20Collection%20with%20Elasticsearch/30616/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/DShield%20Sensor%20Log%20Collection%20with%20Elasticsearch/30616/</a><br /> Anydesk Breach<br /><a href="https://anydesk.com/en/public-statement" target="_blank" rel="noreferrer noopener">https://anydesk.com/en/public-statement</a><br /> Leaky Vessels<br /><a href="https://snyk.io/blog/leaky-vessels-docker-runc-container-breakout-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://snyk.io/blog/leaky-vessels-docker-runc-container-breakout-vulnerabilities/</a><br />]]></itunes:summary><itunes:duration>345</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,docker; dshield; elastic; kiba,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8838</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, February 2nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-february-2nd-2024--62129464</link><description><![CDATA[What is a Top Level Domain<br /><a href="https://isc.sans.edu/forums/diary/What%20is%20a%20%22Top%20Level%20Domain%22%3F/30612/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/What%20is%20a%20%22Top%20Level%20Domain%22%3F/30612/</a><br /> Updated CISA Ivanti Policy<br /><a href="https://www.cisa.gov/news-events/directives/supplemental-direction-v1-ed-24-01-mitigate-ivanti-connect-secure-and-ivanti-policy-secure" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/directives/supplemental-direction-v1-ed-24-01-mitigate-ivanti-connect-secure-and-ivanti-policy-secure</a><br /> Cloudflare Publishes Breach Details<br /><a href="https://blog.cloudflare.com/thanksgiving-2023-security-incident" target="_blank" rel="noreferrer noopener">https://blog.cloudflare.com/thanksgiving-2023-security-incident</a><br /> Vision Pro Update<br /><a href="https://support.apple.com/en-us/HT214070" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/HT214070</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8836.mp3</guid><pubDate>Fri, 02 Feb 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129464/8836.mp3" length="6224951" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>What is a Top Level Domain
https://isc.sans.edu/forums/diary/What%20is%20a%20%22Top%20Level%20Domain%22%3F/30612/
 Updated CISA Ivanti Policy...</itunes:subtitle><itunes:summary><![CDATA[What is a Top Level Domain<br /><a href="https://isc.sans.edu/forums/diary/What%20is%20a%20%22Top%20Level%20Domain%22%3F/30612/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/What%20is%20a%20%22Top%20Level%20Domain%22%3F/30612/</a><br /> Updated CISA Ivanti Policy<br /><a href="https://www.cisa.gov/news-events/directives/supplemental-direction-v1-ed-24-01-mitigate-ivanti-connect-secure-and-ivanti-policy-secure" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/directives/supplemental-direction-v1-ed-24-01-mitigate-ivanti-connect-secure-and-ivanti-policy-secure</a><br /> Cloudflare Publishes Breach Details<br /><a href="https://blog.cloudflare.com/thanksgiving-2023-security-incident" target="_blank" rel="noreferrer noopener">https://blog.cloudflare.com/thanksgiving-2023-security-incident</a><br /> Vision Pro Update<br /><a href="https://support.apple.com/en-us/HT214070" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/HT214070</a><br />]]></itunes:summary><itunes:duration>423</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,vision pro; cisa; ivanti; clou</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8836</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, February 2nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-february-2nd-2024--58539408</link><description><![CDATA[What is a Top Level Domain<br /><a href="https://isc.sans.edu/forums/diary/What%20is%20a%20%22Top%20Level%20Domain%22%3F/30612/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/What%20is%20a%20%22Top%20Level%20Domain%22%3F/30612/</a><br /> Updated CISA Ivanti Policy<br /><a href="https://www.cisa.gov/news-events/directives/supplemental-direction-v1-ed-24-01-mitigate-ivanti-connect-secure-and-ivanti-policy-secure" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/directives/supplemental-direction-v1-ed-24-01-mitigate-ivanti-connect-secure-and-ivanti-policy-secure</a><br /> Cloudflare Publishes Breach Details<br /><a href="https://blog.cloudflare.com/thanksgiving-2023-security-incident" target="_blank" rel="noreferrer noopener">https://blog.cloudflare.com/thanksgiving-2023-security-incident</a><br /> Vision Pro Update<br /><a href="https://support.apple.com/en-us/HT214070" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/HT214070</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8836.mp3</guid><pubDate>Fri, 02 Feb 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58539408/8836.mp3" length="6224951" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>What is a Top Level Domain
https://isc.sans.edu/forums/diary/What%20is%20a%20%22Top%20Level%20Domain%22%3F/30612/
 Updated CISA Ivanti Policy...</itunes:subtitle><itunes:summary><![CDATA[What is a Top Level Domain<br /><a href="https://isc.sans.edu/forums/diary/What%20is%20a%20%22Top%20Level%20Domain%22%3F/30612/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/What%20is%20a%20%22Top%20Level%20Domain%22%3F/30612/</a><br /> Updated CISA Ivanti Policy<br /><a href="https://www.cisa.gov/news-events/directives/supplemental-direction-v1-ed-24-01-mitigate-ivanti-connect-secure-and-ivanti-policy-secure" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/directives/supplemental-direction-v1-ed-24-01-mitigate-ivanti-connect-secure-and-ivanti-policy-secure</a><br /> Cloudflare Publishes Breach Details<br /><a href="https://blog.cloudflare.com/thanksgiving-2023-security-incident" target="_blank" rel="noreferrer noopener">https://blog.cloudflare.com/thanksgiving-2023-security-incident</a><br /> Vision Pro Update<br /><a href="https://support.apple.com/en-us/HT214070" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/HT214070</a><br />]]></itunes:summary><itunes:duration>423</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,vision pro; cisa; ivanti; clou</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8836</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, February 1st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-february-1st-2024--62129461</link><description><![CDATA[The Fun and Dangers of Top Level Domains (TLDs)<br /><a href="https://isc.sans.edu/diary/The%20Fun%20and%20Dangers%20of%20Top%20Level%20Domains%20%28TLDs%29/30608" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20Fun%20and%20Dangers%20of%20Top%20Level%20Domains%20%28TLDs%29/30608</a><br /> Ivanti Releases Patches and New Vulnerabilities<br /><a href="https://forums.ivanti.com/s/article/CVE-2024-21888-Privilege-Escalation-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/CVE-2024-21888-Privilege-Escalation-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US</a><br /> glibc syslog() vulnerablity<br /><a href="https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt" target="_blank" rel="noreferrer noopener">https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt</a><br /> modsecurity WAF bypass<br /><a href="https://owasp.org/www-project-modsecurity/tab_cves#cve-2024-1019-2024-01-30" target="_blank" rel="noreferrer noopener">https://owasp.org/www-project-modsecurity/tab_cves#cve-2024-1019-2024-01-30</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8834.mp3</guid><pubDate>Thu, 01 Feb 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129461/8834.mp3" length="5244505" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>The Fun and Dangers of Top Level Domains (TLDs)
https://isc.sans.edu/diary/The%20Fun%20and%20Dangers%20of%20Top%20Level%20Domains%20%28TLDs%29/30608
 Ivanti Releases Patches and New Vulnerabilities...</itunes:subtitle><itunes:summary><![CDATA[The Fun and Dangers of Top Level Domains (TLDs)<br /><a href="https://isc.sans.edu/diary/The%20Fun%20and%20Dangers%20of%20Top%20Level%20Domains%20%28TLDs%29/30608" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20Fun%20and%20Dangers%20of%20Top%20Level%20Domains%20%28TLDs%29/30608</a><br /> Ivanti Releases Patches and New Vulnerabilities<br /><a href="https://forums.ivanti.com/s/article/CVE-2024-21888-Privilege-Escalation-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/CVE-2024-21888-Privilege-Escalation-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US</a><br /> glibc syslog() vulnerablity<br /><a href="https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt" target="_blank" rel="noreferrer noopener">https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt</a><br /> modsecurity WAF bypass<br /><a href="https://owasp.org/www-project-modsecurity/tab_cves#cve-2024-1019-2024-01-30" target="_blank" rel="noreferrer noopener">https://owasp.org/www-project-modsecurity/tab_cves#cve-2024-1019-2024-01-30</a><br />]]></itunes:summary><itunes:duration>353</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,modsecurity; waf; glibc; syslo,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8834</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, February 1st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-february-1st-2024--58527239</link><description><![CDATA[The Fun and Dangers of Top Level Domains (TLDs)<br /><a href="https://isc.sans.edu/diary/The%20Fun%20and%20Dangers%20of%20Top%20Level%20Domains%20%28TLDs%29/30608" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20Fun%20and%20Dangers%20of%20Top%20Level%20Domains%20%28TLDs%29/30608</a><br /> Ivanti Releases Patches and New Vulnerabilities<br /><a href="https://forums.ivanti.com/s/article/CVE-2024-21888-Privilege-Escalation-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/CVE-2024-21888-Privilege-Escalation-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US</a><br /> glibc syslog() vulnerablity<br /><a href="https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt" target="_blank" rel="noreferrer noopener">https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt</a><br /> modsecurity WAF bypass<br /><a href="https://owasp.org/www-project-modsecurity/tab_cves#cve-2024-1019-2024-01-30" target="_blank" rel="noreferrer noopener">https://owasp.org/www-project-modsecurity/tab_cves#cve-2024-1019-2024-01-30</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8834.mp3</guid><pubDate>Thu, 01 Feb 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58527239/8834.mp3" length="5244505" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>The Fun and Dangers of Top Level Domains (TLDs)
https://isc.sans.edu/diary/The%20Fun%20and%20Dangers%20of%20Top%20Level%20Domains%20%28TLDs%29/30608
 Ivanti Releases Patches and New Vulnerabilities...</itunes:subtitle><itunes:summary><![CDATA[The Fun and Dangers of Top Level Domains (TLDs)<br /><a href="https://isc.sans.edu/diary/The%20Fun%20and%20Dangers%20of%20Top%20Level%20Domains%20%28TLDs%29/30608" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/The%20Fun%20and%20Dangers%20of%20Top%20Level%20Domains%20%28TLDs%29/30608</a><br /> Ivanti Releases Patches and New Vulnerabilities<br /><a href="https://forums.ivanti.com/s/article/CVE-2024-21888-Privilege-Escalation-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/CVE-2024-21888-Privilege-Escalation-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US</a><br /> glibc syslog() vulnerablity<br /><a href="https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt" target="_blank" rel="noreferrer noopener">https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt</a><br /> modsecurity WAF bypass<br /><a href="https://owasp.org/www-project-modsecurity/tab_cves#cve-2024-1019-2024-01-30" target="_blank" rel="noreferrer noopener">https://owasp.org/www-project-modsecurity/tab_cves#cve-2024-1019-2024-01-30</a><br />]]></itunes:summary><itunes:duration>353</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,modsecurity; waf; glibc; syslo,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8834</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, January 31st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-january-31st-2024--62129489</link><description><![CDATA[What did I say to make you stop talking to me<br /><a href="https://isc.sans.edu/diary/What%20did%20I%20say%20to%20make%20you%20stop%20talking%20to%20me%3F/30604" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20did%20I%20say%20to%20make%20you%20stop%20talking%20to%20me%3F/30604</a><br /> Identification of a top-level domain for private use<br /><a href="https://itp.cdn.icann.org/en/files/root-system/identification-tld-private-use-24-01-2024-en.pdf" target="_blank" rel="noreferrer noopener">https://itp.cdn.icann.org/en/files/root-system/identification-tld-private-use-24-01-2024-en.pdf</a><br /> Juniper Patches Patching<br /><a href="https://supportportal.juniper.net/s/article/2024-01-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-have-been-addressed?language=en_US" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/article/2024-01-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-have-been-addressed?language=en_US</a><br /><a href="https://www.theregister.com/2024/01/30/juniper_networks_vulnerabilities/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2024/01/30/juniper_networks_vulnerabilities/</a><br /> Chat GPT Leaking Conversations Again<br /><a href="https://arstechnica.com/security/2024/01/ars-reader-reports-chatgpt-is-sending-him-conversations-from-unrelated-ai-users/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2024/01/ars-reader-reports-chatgpt-is-sending-him-conversations-from-unrelated-ai-users/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8832.mp3</guid><pubDate>Wed, 31 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129489/8832.mp3" length="6053586" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>What did I say to make you stop talking to me
https://isc.sans.edu/diary/What%20did%20I%20say%20to%20make%20you%20stop%20talking%20to%20me%3F/30604
 Identification of a top-level domain for private use...</itunes:subtitle><itunes:summary><![CDATA[What did I say to make you stop talking to me<br /><a href="https://isc.sans.edu/diary/What%20did%20I%20say%20to%20make%20you%20stop%20talking%20to%20me%3F/30604" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20did%20I%20say%20to%20make%20you%20stop%20talking%20to%20me%3F/30604</a><br /> Identification of a top-level domain for private use<br /><a href="https://itp.cdn.icann.org/en/files/root-system/identification-tld-private-use-24-01-2024-en.pdf" target="_blank" rel="noreferrer noopener">https://itp.cdn.icann.org/en/files/root-system/identification-tld-private-use-24-01-2024-en.pdf</a><br /> Juniper Patches Patching<br /><a href="https://supportportal.juniper.net/s/article/2024-01-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-have-been-addressed?language=en_US" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/article/2024-01-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-have-been-addressed?language=en_US</a><br /><a href="https://www.theregister.com/2024/01/30/juniper_networks_vulnerabilities/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2024/01/30/juniper_networks_vulnerabilities/</a><br /> Chat GPT Leaking Conversations Again<br /><a href="https://arstechnica.com/security/2024/01/ars-reader-reports-chatgpt-is-sending-him-conversations-from-unrelated-ai-users/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2024/01/ars-reader-reports-chatgpt-is-sending-him-conversations-from-unrelated-ai-users/</a><br />]]></itunes:summary><itunes:duration>411</itunes:duration><itunes:keywords>business,chatgpt; juniper; patches; tld,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8832</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, January 31st, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-january-31st-2024--58508574</link><description><![CDATA[What did I say to make you stop talking to me<br /><a href="https://isc.sans.edu/diary/What%20did%20I%20say%20to%20make%20you%20stop%20talking%20to%20me%3F/30604" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20did%20I%20say%20to%20make%20you%20stop%20talking%20to%20me%3F/30604</a><br /> Identification of a top-level domain for private use<br /><a href="https://itp.cdn.icann.org/en/files/root-system/identification-tld-private-use-24-01-2024-en.pdf" target="_blank" rel="noreferrer noopener">https://itp.cdn.icann.org/en/files/root-system/identification-tld-private-use-24-01-2024-en.pdf</a><br /> Juniper Patches Patching<br /><a href="https://supportportal.juniper.net/s/article/2024-01-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-have-been-addressed?language=en_US" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/article/2024-01-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-have-been-addressed?language=en_US</a><br /><a href="https://www.theregister.com/2024/01/30/juniper_networks_vulnerabilities/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2024/01/30/juniper_networks_vulnerabilities/</a><br /> Chat GPT Leaking Conversations Again<br /><a href="https://arstechnica.com/security/2024/01/ars-reader-reports-chatgpt-is-sending-him-conversations-from-unrelated-ai-users/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2024/01/ars-reader-reports-chatgpt-is-sending-him-conversations-from-unrelated-ai-users/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8832.mp3</guid><pubDate>Wed, 31 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58508574/8832.mp3" length="6053586" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>What did I say to make you stop talking to me
https://isc.sans.edu/diary/What%20did%20I%20say%20to%20make%20you%20stop%20talking%20to%20me%3F/30604
 Identification of a top-level domain for private use...</itunes:subtitle><itunes:summary><![CDATA[What did I say to make you stop talking to me<br /><a href="https://isc.sans.edu/diary/What%20did%20I%20say%20to%20make%20you%20stop%20talking%20to%20me%3F/30604" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20did%20I%20say%20to%20make%20you%20stop%20talking%20to%20me%3F/30604</a><br /> Identification of a top-level domain for private use<br /><a href="https://itp.cdn.icann.org/en/files/root-system/identification-tld-private-use-24-01-2024-en.pdf" target="_blank" rel="noreferrer noopener">https://itp.cdn.icann.org/en/files/root-system/identification-tld-private-use-24-01-2024-en.pdf</a><br /> Juniper Patches Patching<br /><a href="https://supportportal.juniper.net/s/article/2024-01-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-have-been-addressed?language=en_US" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/article/2024-01-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-have-been-addressed?language=en_US</a><br /><a href="https://www.theregister.com/2024/01/30/juniper_networks_vulnerabilities/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2024/01/30/juniper_networks_vulnerabilities/</a><br /> Chat GPT Leaking Conversations Again<br /><a href="https://arstechnica.com/security/2024/01/ars-reader-reports-chatgpt-is-sending-him-conversations-from-unrelated-ai-users/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2024/01/ars-reader-reports-chatgpt-is-sending-him-conversations-from-unrelated-ai-users/</a><br />]]></itunes:summary><itunes:duration>411</itunes:duration><itunes:keywords>business,chatgpt; juniper; patches; tld,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8832</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, January 30th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-january-30th-2024--62129460</link><description><![CDATA[Exploit Flare Up Against Older Atlassian Confluence Vulnerability<br /><a href="https://isc.sans.edu/diary/Exploit%20Flare%20Up%20Against%20Older%20Altassian%20Confluence%20Vulnerability/30600" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit%20Flare%20Up%20Against%20Older%20Altassian%20Confluence%20Vulnerability/30600</a><br /> Malicious Python Packages install Infostealer<br /><a href="https://www.fortinet.com/blog/threat-research/info-stealing-packages-hidden-in-pypi" target="_blank" rel="noreferrer noopener">https://www.fortinet.com/blog/threat-research/info-stealing-packages-hidden-in-pypi</a><br /> Linux ICMPv6 Router Adv. RCE<br /><a href="https://access.redhat.com/security/cve/cve-2023-6200" target="_blank" rel="noreferrer noopener">https://access.redhat.com/security/cve/cve-2023-6200</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8830.mp3</guid><pubDate>Tue, 30 Jan 2024 02:15:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129460/8830.mp3" length="5081516" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Exploit Flare Up Against Older Atlassian Confluence Vulnerability
https://isc.sans.edu/diary/Exploit%20Flare%20Up%20Against%20Older%20Altassian%20Confluence%20Vulnerability/30600
 Malicious Python Packages install Infostealer...</itunes:subtitle><itunes:summary><![CDATA[Exploit Flare Up Against Older Atlassian Confluence Vulnerability<br /><a href="https://isc.sans.edu/diary/Exploit%20Flare%20Up%20Against%20Older%20Altassian%20Confluence%20Vulnerability/30600" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit%20Flare%20Up%20Against%20Older%20Altassian%20Confluence%20Vulnerability/30600</a><br /> Malicious Python Packages install Infostealer<br /><a href="https://www.fortinet.com/blog/threat-research/info-stealing-packages-hidden-in-pypi" target="_blank" rel="noreferrer noopener">https://www.fortinet.com/blog/threat-research/info-stealing-packages-hidden-in-pypi</a><br /> Linux ICMPv6 Router Adv. RCE<br /><a href="https://access.redhat.com/security/cve/cve-2023-6200" target="_blank" rel="noreferrer noopener">https://access.redhat.com/security/cve/cve-2023-6200</a><br />]]></itunes:summary><itunes:duration>341</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,linux; icmpv6; router adv; rce,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8830</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, January 30th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-january-30th-2024--58495817</link><description><![CDATA[Exploit Flare Up Against Older Atlassian Confluence Vulnerability<br /><a href="https://isc.sans.edu/diary/Exploit%20Flare%20Up%20Against%20Older%20Altassian%20Confluence%20Vulnerability/30600" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit%20Flare%20Up%20Against%20Older%20Altassian%20Confluence%20Vulnerability/30600</a><br /> Malicious Python Packages install Infostealer<br /><a href="https://www.fortinet.com/blog/threat-research/info-stealing-packages-hidden-in-pypi" target="_blank" rel="noreferrer noopener">https://www.fortinet.com/blog/threat-research/info-stealing-packages-hidden-in-pypi</a><br /> Linux ICMPv6 Router Adv. RCE<br /><a href="https://access.redhat.com/security/cve/cve-2023-6200" target="_blank" rel="noreferrer noopener">https://access.redhat.com/security/cve/cve-2023-6200</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8830.mp3</guid><pubDate>Tue, 30 Jan 2024 02:15:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58495817/8830.mp3" length="5081516" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Exploit Flare Up Against Older Atlassian Confluence Vulnerability
https://isc.sans.edu/diary/Exploit%20Flare%20Up%20Against%20Older%20Altassian%20Confluence%20Vulnerability/30600
 Malicious Python Packages install Infostealer...</itunes:subtitle><itunes:summary><![CDATA[Exploit Flare Up Against Older Atlassian Confluence Vulnerability<br /><a href="https://isc.sans.edu/diary/Exploit%20Flare%20Up%20Against%20Older%20Altassian%20Confluence%20Vulnerability/30600" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit%20Flare%20Up%20Against%20Older%20Altassian%20Confluence%20Vulnerability/30600</a><br /> Malicious Python Packages install Infostealer<br /><a href="https://www.fortinet.com/blog/threat-research/info-stealing-packages-hidden-in-pypi" target="_blank" rel="noreferrer noopener">https://www.fortinet.com/blog/threat-research/info-stealing-packages-hidden-in-pypi</a><br /> Linux ICMPv6 Router Adv. RCE<br /><a href="https://access.redhat.com/security/cve/cve-2023-6200" target="_blank" rel="noreferrer noopener">https://access.redhat.com/security/cve/cve-2023-6200</a><br />]]></itunes:summary><itunes:duration>341</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,linux; icmpv6; router adv; rce,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8830</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, January 29th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-january-29th-2024--62129490</link><description><![CDATA[A Batch File With Multiple Payloads<br /><a href="https://isc.sans.edu/diary/A%20Batch%20File%20With%20Multiple%20Payloads/30592" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20Batch%20File%20With%20Multiple%20Payloads/30592</a><br /> fritz.box domain used to advertise NFTs<br /><a href="https://www.heise.de/news/Verwirrend-Internet-Domain-fritz-box-zeigt-NFT-Galerie-statt-Router-Verwaltung-9610149.html" target="_blank" rel="noreferrer noopener">https://www.heise.de/news/Verwirrend-Internet-Domain-fritz-box-zeigt-NFT-Galerie-statt-Router-Verwaltung-9610149.html</a><br /> Jenkins CVE-2024-23897 PoC<br /><a href="https://github.com/gquere/pwn_jenkins/blob/master/README.md#jenkins-cli-arbitrary-read-cve-2024-23897-applies-to-versions-below-2442-and-lts-24263" target="_blank" rel="noreferrer noopener">https://github.com/gquere/pwn_jenkins/blob/master/README.md#jenkins-cli-arbitrary-read-cve-2024-23897-applies-to-versions-below-2442-and-lts-24263</a><br /> Malicious Google Ads Target Chinese Users<br /><a href="https://www.malwarebytes.com/blog/threat-intelligence/2024/01/malicious-ads-for-restricted-messaging-applications-target-chinese-users" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/threat-intelligence/2024/01/malicious-ads-for-restricted-messaging-applications-target-chinese-users</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8828.mp3</guid><pubDate>Mon, 29 Jan 2024 02:15:04 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129490/8828.mp3" length="6210829" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>A Batch File With Multiple Payloads
https://isc.sans.edu/diary/A%20Batch%20File%20With%20Multiple%20Payloads/30592
 fritz.box domain used to advertise NFTs...</itunes:subtitle><itunes:summary><![CDATA[A Batch File With Multiple Payloads<br /><a href="https://isc.sans.edu/diary/A%20Batch%20File%20With%20Multiple%20Payloads/30592" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20Batch%20File%20With%20Multiple%20Payloads/30592</a><br /> fritz.box domain used to advertise NFTs<br /><a href="https://www.heise.de/news/Verwirrend-Internet-Domain-fritz-box-zeigt-NFT-Galerie-statt-Router-Verwaltung-9610149.html" target="_blank" rel="noreferrer noopener">https://www.heise.de/news/Verwirrend-Internet-Domain-fritz-box-zeigt-NFT-Galerie-statt-Router-Verwaltung-9610149.html</a><br /> Jenkins CVE-2024-23897 PoC<br /><a href="https://github.com/gquere/pwn_jenkins/blob/master/README.md#jenkins-cli-arbitrary-read-cve-2024-23897-applies-to-versions-below-2442-and-lts-24263" target="_blank" rel="noreferrer noopener">https://github.com/gquere/pwn_jenkins/blob/master/README.md#jenkins-cli-arbitrary-read-cve-2024-23897-applies-to-versions-below-2442-and-lts-24263</a><br /> Malicious Google Ads Target Chinese Users<br /><a href="https://www.malwarebytes.com/blog/threat-intelligence/2024/01/malicious-ads-for-restricted-messaging-applications-target-chinese-users" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/threat-intelligence/2024/01/malicious-ads-for-restricted-messaging-applications-target-chinese-users</a><br />]]></itunes:summary><itunes:duration>422</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,google; ads; malware; china; j,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8828</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, January 29th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-january-29th-2024--58483936</link><description><![CDATA[A Batch File With Multiple Payloads<br /><a href="https://isc.sans.edu/diary/A%20Batch%20File%20With%20Multiple%20Payloads/30592" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20Batch%20File%20With%20Multiple%20Payloads/30592</a><br /> fritz.box domain used to advertise NFTs<br /><a href="https://www.heise.de/news/Verwirrend-Internet-Domain-fritz-box-zeigt-NFT-Galerie-statt-Router-Verwaltung-9610149.html" target="_blank" rel="noreferrer noopener">https://www.heise.de/news/Verwirrend-Internet-Domain-fritz-box-zeigt-NFT-Galerie-statt-Router-Verwaltung-9610149.html</a><br /> Jenkins CVE-2024-23897 PoC<br /><a href="https://github.com/gquere/pwn_jenkins/blob/master/README.md#jenkins-cli-arbitrary-read-cve-2024-23897-applies-to-versions-below-2442-and-lts-24263" target="_blank" rel="noreferrer noopener">https://github.com/gquere/pwn_jenkins/blob/master/README.md#jenkins-cli-arbitrary-read-cve-2024-23897-applies-to-versions-below-2442-and-lts-24263</a><br /> Malicious Google Ads Target Chinese Users<br /><a href="https://www.malwarebytes.com/blog/threat-intelligence/2024/01/malicious-ads-for-restricted-messaging-applications-target-chinese-users" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/threat-intelligence/2024/01/malicious-ads-for-restricted-messaging-applications-target-chinese-users</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8828.mp3</guid><pubDate>Mon, 29 Jan 2024 02:15:04 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58483936/8828.mp3" length="6210829" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>A Batch File With Multiple Payloads
https://isc.sans.edu/diary/A%20Batch%20File%20With%20Multiple%20Payloads/30592
 fritz.box domain used to advertise NFTs...</itunes:subtitle><itunes:summary><![CDATA[A Batch File With Multiple Payloads<br /><a href="https://isc.sans.edu/diary/A%20Batch%20File%20With%20Multiple%20Payloads/30592" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20Batch%20File%20With%20Multiple%20Payloads/30592</a><br /> fritz.box domain used to advertise NFTs<br /><a href="https://www.heise.de/news/Verwirrend-Internet-Domain-fritz-box-zeigt-NFT-Galerie-statt-Router-Verwaltung-9610149.html" target="_blank" rel="noreferrer noopener">https://www.heise.de/news/Verwirrend-Internet-Domain-fritz-box-zeigt-NFT-Galerie-statt-Router-Verwaltung-9610149.html</a><br /> Jenkins CVE-2024-23897 PoC<br /><a href="https://github.com/gquere/pwn_jenkins/blob/master/README.md#jenkins-cli-arbitrary-read-cve-2024-23897-applies-to-versions-below-2442-and-lts-24263" target="_blank" rel="noreferrer noopener">https://github.com/gquere/pwn_jenkins/blob/master/README.md#jenkins-cli-arbitrary-read-cve-2024-23897-applies-to-versions-below-2442-and-lts-24263</a><br /> Malicious Google Ads Target Chinese Users<br /><a href="https://www.malwarebytes.com/blog/threat-intelligence/2024/01/malicious-ads-for-restricted-messaging-applications-target-chinese-users" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/threat-intelligence/2024/01/malicious-ads-for-restricted-messaging-applications-target-chinese-users</a><br />]]></itunes:summary><itunes:duration>422</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,google; ads; malware; china; j,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8828</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, January 26th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-january-26th-2024--62129491</link><description><![CDATA[Fecebook AdsManager Targeted by a Python Infostealer<br /><a href="https://isc.sans.edu/diary/Facebook%20AdsManager%20Targeted%20by%20a%20Python%20Infostealer/30590" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Facebook%20AdsManager%20Targeted%20by%20a%20Python%20Infostealer/30590</a><br /> Privacy Concerns about Apple Push Notifications<br /><a href="https://twitter.com/mysk_co/status/1750502700112916504" target="_blank" rel="noreferrer noopener">https://twitter.com/mysk_co/status/1750502700112916504</a><br /><a href="https://www.youtube.com/watch?v=4ZPTjGG9t7s" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=4ZPTjGG9t7s</a><br /> Inside a Global Phone Spy Tool Monitoring Billions<br /><a href="https://www.404media.co/inside-global-phone-spy-tool-patternz-nuviad-real-time-bidding/" target="_blank" rel="noreferrer noopener">https://www.404media.co/inside-global-phone-spy-tool-patternz-nuviad-real-time-bidding/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8826.mp3</guid><pubDate>Fri, 26 Jan 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129491/8826.mp3" length="5732502" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Fecebook AdsManager Targeted by a Python Infostealer
https://isc.sans.edu/diary/Facebook%20AdsManager%20Targeted%20by%20a%20Python%20Infostealer/30590
 Privacy Concerns about Apple Push Notifications...</itunes:subtitle><itunes:summary><![CDATA[Fecebook AdsManager Targeted by a Python Infostealer<br /><a href="https://isc.sans.edu/diary/Facebook%20AdsManager%20Targeted%20by%20a%20Python%20Infostealer/30590" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Facebook%20AdsManager%20Targeted%20by%20a%20Python%20Infostealer/30590</a><br /> Privacy Concerns about Apple Push Notifications<br /><a href="https://twitter.com/mysk_co/status/1750502700112916504" target="_blank" rel="noreferrer noopener">https://twitter.com/mysk_co/status/1750502700112916504</a><br /><a href="https://www.youtube.com/watch?v=4ZPTjGG9t7s" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=4ZPTjGG9t7s</a><br /> Inside a Global Phone Spy Tool Monitoring Billions<br /><a href="https://www.404media.co/inside-global-phone-spy-tool-patternz-nuviad-real-time-bidding/" target="_blank" rel="noreferrer noopener">https://www.404media.co/inside-global-phone-spy-tool-patternz-nuviad-real-time-bidding/</a><br />]]></itunes:summary><itunes:duration>388</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,patternz; phone; mobile; spy; ,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8826</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, January 26th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-january-26th-2024--58451939</link><description><![CDATA[Fecebook AdsManager Targeted by a Python Infostealer<br /><a href="https://isc.sans.edu/diary/Facebook%20AdsManager%20Targeted%20by%20a%20Python%20Infostealer/30590" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Facebook%20AdsManager%20Targeted%20by%20a%20Python%20Infostealer/30590</a><br /> Privacy Concerns about Apple Push Notifications<br /><a href="https://twitter.com/mysk_co/status/1750502700112916504" target="_blank" rel="noreferrer noopener">https://twitter.com/mysk_co/status/1750502700112916504</a><br /><a href="https://www.youtube.com/watch?v=4ZPTjGG9t7s" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=4ZPTjGG9t7s</a><br /> Inside a Global Phone Spy Tool Monitoring Billions<br /><a href="https://www.404media.co/inside-global-phone-spy-tool-patternz-nuviad-real-time-bidding/" target="_blank" rel="noreferrer noopener">https://www.404media.co/inside-global-phone-spy-tool-patternz-nuviad-real-time-bidding/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8826.mp3</guid><pubDate>Fri, 26 Jan 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58451939/8826.mp3" length="5732502" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Fecebook AdsManager Targeted by a Python Infostealer
https://isc.sans.edu/diary/Facebook%20AdsManager%20Targeted%20by%20a%20Python%20Infostealer/30590
 Privacy Concerns about Apple Push Notifications...</itunes:subtitle><itunes:summary><![CDATA[Fecebook AdsManager Targeted by a Python Infostealer<br /><a href="https://isc.sans.edu/diary/Facebook%20AdsManager%20Targeted%20by%20a%20Python%20Infostealer/30590" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Facebook%20AdsManager%20Targeted%20by%20a%20Python%20Infostealer/30590</a><br /> Privacy Concerns about Apple Push Notifications<br /><a href="https://twitter.com/mysk_co/status/1750502700112916504" target="_blank" rel="noreferrer noopener">https://twitter.com/mysk_co/status/1750502700112916504</a><br /><a href="https://www.youtube.com/watch?v=4ZPTjGG9t7s" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=4ZPTjGG9t7s</a><br /> Inside a Global Phone Spy Tool Monitoring Billions<br /><a href="https://www.404media.co/inside-global-phone-spy-tool-patternz-nuviad-real-time-bidding/" target="_blank" rel="noreferrer noopener">https://www.404media.co/inside-global-phone-spy-tool-patternz-nuviad-real-time-bidding/</a><br />]]></itunes:summary><itunes:duration>388</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,patternz; phone; mobile; spy; ,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8826</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, January 25th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-january-25th-2024--62129433</link><description><![CDATA[How Bad User Interfaces Make Security Tools Harmful<br /><a href="https://isc.sans.edu/diary/How%20Bad%20User%20Interfaces%20Make%20Security%20Tools%20Harmful/30586" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20Bad%20User%20Interfaces%20Make%20Security%20Tools%20Harmful/30586</a><br /> Sys:All Loophole Alloed Us to Penetrate GKE Clusters in Production<br /><a href="https://orca.security/resources/blog/sys-all-google-kubernetes-engine-risk-example/" target="_blank" rel="noreferrer noopener">https://orca.security/resources/blog/sys-all-google-kubernetes-engine-risk-example/</a><br /> Automotive Pwn2Own<br /><a href="https://www.zerodayinitiative.com/blog/2024/1/23/pwn2own-automotive-2024-the-full-schedule" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/blog/2024/1/23/pwn2own-automotive-2024-the-full-schedule</a><br /> Android Keystroke Injection Vulnerability Exploit<br /><a href="https://www.mobile-hacker.com/2024/01/23/exploiting-0-click-android-bluetooth-vulnerability-to-inject-keystrokes-without-pairing/" target="_blank" rel="noreferrer noopener">https://www.mobile-hacker.com/2024/01/23/exploiting-0-click-android-bluetooth-vulnerability-to-inject-keystrokes-without-pairing/</a><br /> CVE-2024-0769 D-Link DIR-859<br /><a href="https://securityonline.info/cve-2024-0769-the-vulnerability-d-link-wont-fix-in-dir-859-router/" target="_blank" rel="noreferrer noopener">https://securityonline.info/cve-2024-0769-the-vulnerability-d-link-wont-fix-in-dir-859-router/</a><br /> SANS.edu Dean's List<br /><a href="https://www.sans.edu/students/awards" target="_blank" rel="noreferrer noopener">https://www.sans.edu/students/awards</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8824.mp3</guid><pubDate>Thu, 25 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129433/8824.mp3" length="4920879" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>How Bad User Interfaces Make Security Tools Harmful
https://isc.sans.edu/diary/How%20Bad%20User%20Interfaces%20Make%20Security%20Tools%20Harmful/30586
 Sys:All Loophole Alloed Us to Penetrate GKE Clusters in Production...</itunes:subtitle><itunes:summary><![CDATA[How Bad User Interfaces Make Security Tools Harmful<br /><a href="https://isc.sans.edu/diary/How%20Bad%20User%20Interfaces%20Make%20Security%20Tools%20Harmful/30586" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20Bad%20User%20Interfaces%20Make%20Security%20Tools%20Harmful/30586</a><br /> Sys:All Loophole Alloed Us to Penetrate GKE Clusters in Production<br /><a href="https://orca.security/resources/blog/sys-all-google-kubernetes-engine-risk-example/" target="_blank" rel="noreferrer noopener">https://orca.security/resources/blog/sys-all-google-kubernetes-engine-risk-example/</a><br /> Automotive Pwn2Own<br /><a href="https://www.zerodayinitiative.com/blog/2024/1/23/pwn2own-automotive-2024-the-full-schedule" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/blog/2024/1/23/pwn2own-automotive-2024-the-full-schedule</a><br /> Android Keystroke Injection Vulnerability Exploit<br /><a href="https://www.mobile-hacker.com/2024/01/23/exploiting-0-click-android-bluetooth-vulnerability-to-inject-keystrokes-without-pairing/" target="_blank" rel="noreferrer noopener">https://www.mobile-hacker.com/2024/01/23/exploiting-0-click-android-bluetooth-vulnerability-to-inject-keystrokes-without-pairing/</a><br /> CVE-2024-0769 D-Link DIR-859<br /><a href="https://securityonline.info/cve-2024-0769-the-vulnerability-d-link-wont-fix-in-dir-859-router/" target="_blank" rel="noreferrer noopener">https://securityonline.info/cve-2024-0769-the-vulnerability-d-link-wont-fix-in-dir-859-router/</a><br /> SANS.edu Dean's List<br /><a href="https://www.sans.edu/students/awards" target="_blank" rel="noreferrer noopener">https://www.sans.edu/students/awards</a><br />]]></itunes:summary><itunes:duration>330</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,sans.edu; deans list; d-link; ,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8824</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, January 25th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-january-25th-2024--58440090</link><description><![CDATA[How Bad User Interfaces Make Security Tools Harmful<br /><a href="https://isc.sans.edu/diary/How%20Bad%20User%20Interfaces%20Make%20Security%20Tools%20Harmful/30586" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20Bad%20User%20Interfaces%20Make%20Security%20Tools%20Harmful/30586</a><br /> Sys:All Loophole Alloed Us to Penetrate GKE Clusters in Production<br /><a href="https://orca.security/resources/blog/sys-all-google-kubernetes-engine-risk-example/" target="_blank" rel="noreferrer noopener">https://orca.security/resources/blog/sys-all-google-kubernetes-engine-risk-example/</a><br /> Automotive Pwn2Own<br /><a href="https://www.zerodayinitiative.com/blog/2024/1/23/pwn2own-automotive-2024-the-full-schedule" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/blog/2024/1/23/pwn2own-automotive-2024-the-full-schedule</a><br /> Android Keystroke Injection Vulnerability Exploit<br /><a href="https://www.mobile-hacker.com/2024/01/23/exploiting-0-click-android-bluetooth-vulnerability-to-inject-keystrokes-without-pairing/" target="_blank" rel="noreferrer noopener">https://www.mobile-hacker.com/2024/01/23/exploiting-0-click-android-bluetooth-vulnerability-to-inject-keystrokes-without-pairing/</a><br /> CVE-2024-0769 D-Link DIR-859<br /><a href="https://securityonline.info/cve-2024-0769-the-vulnerability-d-link-wont-fix-in-dir-859-router/" target="_blank" rel="noreferrer noopener">https://securityonline.info/cve-2024-0769-the-vulnerability-d-link-wont-fix-in-dir-859-router/</a><br /> SANS.edu Dean's List<br /><a href="https://www.sans.edu/students/awards" target="_blank" rel="noreferrer noopener">https://www.sans.edu/students/awards</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8824.mp3</guid><pubDate>Thu, 25 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58440090/8824.mp3" length="4920879" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>How Bad User Interfaces Make Security Tools Harmful
https://isc.sans.edu/diary/How%20Bad%20User%20Interfaces%20Make%20Security%20Tools%20Harmful/30586
 Sys:All Loophole Alloed Us to Penetrate GKE Clusters in Production...</itunes:subtitle><itunes:summary><![CDATA[How Bad User Interfaces Make Security Tools Harmful<br /><a href="https://isc.sans.edu/diary/How%20Bad%20User%20Interfaces%20Make%20Security%20Tools%20Harmful/30586" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20Bad%20User%20Interfaces%20Make%20Security%20Tools%20Harmful/30586</a><br /> Sys:All Loophole Alloed Us to Penetrate GKE Clusters in Production<br /><a href="https://orca.security/resources/blog/sys-all-google-kubernetes-engine-risk-example/" target="_blank" rel="noreferrer noopener">https://orca.security/resources/blog/sys-all-google-kubernetes-engine-risk-example/</a><br /> Automotive Pwn2Own<br /><a href="https://www.zerodayinitiative.com/blog/2024/1/23/pwn2own-automotive-2024-the-full-schedule" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/blog/2024/1/23/pwn2own-automotive-2024-the-full-schedule</a><br /> Android Keystroke Injection Vulnerability Exploit<br /><a href="https://www.mobile-hacker.com/2024/01/23/exploiting-0-click-android-bluetooth-vulnerability-to-inject-keystrokes-without-pairing/" target="_blank" rel="noreferrer noopener">https://www.mobile-hacker.com/2024/01/23/exploiting-0-click-android-bluetooth-vulnerability-to-inject-keystrokes-without-pairing/</a><br /> CVE-2024-0769 D-Link DIR-859<br /><a href="https://securityonline.info/cve-2024-0769-the-vulnerability-d-link-wont-fix-in-dir-859-router/" target="_blank" rel="noreferrer noopener">https://securityonline.info/cve-2024-0769-the-vulnerability-d-link-wont-fix-in-dir-859-router/</a><br /> SANS.edu Dean's List<br /><a href="https://www.sans.edu/students/awards" target="_blank" rel="noreferrer noopener">https://www.sans.edu/students/awards</a><br />]]></itunes:summary><itunes:duration>330</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,sans.edu; deans list; d-link; ,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8824</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, January 24th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-january-24th-2024--62129425</link><description><![CDATA[Update on Atlassian Exploit Activity<br /><a href="https://isc.sans.edu/forums/diary/Update%20on%20Atlassian%20Exploit%20Activity%20/30582/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Update%20on%20Atlassian%20Exploit%20Activity%20/30582/</a><br /> POC For Fortra GoAnywhere MFT Authentication Bypass CVE-2024-0204<br /><a href="https://www.horizon3.ai/cve-2024-0204-fortra-goanywhere-mft-authentication-bypass-deep-dive/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/cve-2024-0204-fortra-goanywhere-mft-authentication-bypass-deep-dive/</a><br /> Baracuda Web Application Firewall<br /><a href="https://campus.barracuda.com/product/webapplicationfirewall/doc/102888530/security-advisory/" target="_blank" rel="noreferrer noopener">https://campus.barracuda.com/product/webapplicationfirewall/doc/102888530/security-advisory/</a><br /> GitGot: GitHub leveraged by cybercriminals to store stolen data<br /><a href="https://www.reversinglabs.com/blog/gitgot-cybercriminals-using-github-to-store-stolen-data" target="_blank" rel="noreferrer noopener">https://www.reversinglabs.com/blog/gitgot-cybercriminals-using-github-to-store-stolen-data</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8822.mp3</guid><pubDate>Wed, 24 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129425/8822.mp3" length="5093324" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Update on Atlassian Exploit Activity
https://isc.sans.edu/forums/diary/Update%20on%20Atlassian%20Exploit%20Activity%20/30582/
 POC For Fortra GoAnywhere MFT Authentication Bypass CVE-2024-0204...</itunes:subtitle><itunes:summary><![CDATA[Update on Atlassian Exploit Activity<br /><a href="https://isc.sans.edu/forums/diary/Update%20on%20Atlassian%20Exploit%20Activity%20/30582/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Update%20on%20Atlassian%20Exploit%20Activity%20/30582/</a><br /> POC For Fortra GoAnywhere MFT Authentication Bypass CVE-2024-0204<br /><a href="https://www.horizon3.ai/cve-2024-0204-fortra-goanywhere-mft-authentication-bypass-deep-dive/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/cve-2024-0204-fortra-goanywhere-mft-authentication-bypass-deep-dive/</a><br /> Baracuda Web Application Firewall<br /><a href="https://campus.barracuda.com/product/webapplicationfirewall/doc/102888530/security-advisory/" target="_blank" rel="noreferrer noopener">https://campus.barracuda.com/product/webapplicationfirewall/doc/102888530/security-advisory/</a><br /> GitGot: GitHub leveraged by cybercriminals to store stolen data<br /><a href="https://www.reversinglabs.com/blog/gitgot-cybercriminals-using-github-to-store-stolen-data" target="_blank" rel="noreferrer noopener">https://www.reversinglabs.com/blog/gitgot-cybercriminals-using-github-to-store-stolen-data</a><br />]]></itunes:summary><itunes:duration>342</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,gitgot; github; baracuda; fire,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8822</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, January 24th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-january-24th-2024--58424602</link><description><![CDATA[Update on Atlassian Exploit Activity<br /><a href="https://isc.sans.edu/forums/diary/Update%20on%20Atlassian%20Exploit%20Activity%20/30582/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Update%20on%20Atlassian%20Exploit%20Activity%20/30582/</a><br /> POC For Fortra GoAnywhere MFT Authentication Bypass CVE-2024-0204<br /><a href="https://www.horizon3.ai/cve-2024-0204-fortra-goanywhere-mft-authentication-bypass-deep-dive/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/cve-2024-0204-fortra-goanywhere-mft-authentication-bypass-deep-dive/</a><br /> Baracuda Web Application Firewall<br /><a href="https://campus.barracuda.com/product/webapplicationfirewall/doc/102888530/security-advisory/" target="_blank" rel="noreferrer noopener">https://campus.barracuda.com/product/webapplicationfirewall/doc/102888530/security-advisory/</a><br /> GitGot: GitHub leveraged by cybercriminals to store stolen data<br /><a href="https://www.reversinglabs.com/blog/gitgot-cybercriminals-using-github-to-store-stolen-data" target="_blank" rel="noreferrer noopener">https://www.reversinglabs.com/blog/gitgot-cybercriminals-using-github-to-store-stolen-data</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8822.mp3</guid><pubDate>Wed, 24 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58424602/8822.mp3" length="5093324" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Update on Atlassian Exploit Activity
https://isc.sans.edu/forums/diary/Update%20on%20Atlassian%20Exploit%20Activity%20/30582/
 POC For Fortra GoAnywhere MFT Authentication Bypass CVE-2024-0204...</itunes:subtitle><itunes:summary><![CDATA[Update on Atlassian Exploit Activity<br /><a href="https://isc.sans.edu/forums/diary/Update%20on%20Atlassian%20Exploit%20Activity%20/30582/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Update%20on%20Atlassian%20Exploit%20Activity%20/30582/</a><br /> POC For Fortra GoAnywhere MFT Authentication Bypass CVE-2024-0204<br /><a href="https://www.horizon3.ai/cve-2024-0204-fortra-goanywhere-mft-authentication-bypass-deep-dive/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/cve-2024-0204-fortra-goanywhere-mft-authentication-bypass-deep-dive/</a><br /> Baracuda Web Application Firewall<br /><a href="https://campus.barracuda.com/product/webapplicationfirewall/doc/102888530/security-advisory/" target="_blank" rel="noreferrer noopener">https://campus.barracuda.com/product/webapplicationfirewall/doc/102888530/security-advisory/</a><br /> GitGot: GitHub leveraged by cybercriminals to store stolen data<br /><a href="https://www.reversinglabs.com/blog/gitgot-cybercriminals-using-github-to-store-stolen-data" target="_blank" rel="noreferrer noopener">https://www.reversinglabs.com/blog/gitgot-cybercriminals-using-github-to-store-stolen-data</a><br />]]></itunes:summary><itunes:duration>342</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,gitgot; github; baracuda; fire,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8822</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, January 23rd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-january-23rd-2024--62129427</link><description><![CDATA[Apple Updates Everything<br /><a href="https://isc.sans.edu/forums/diary/Apple%20Updates%20Everything%20-%20New%200%20Day%20in%20WebKit/30578/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Apple%20Updates%20Everything%20-%20New%200%20Day%20in%20WebKit/30578/</a><br /> Atlassian Confluence RCE Vulnerability Exploits CVE-2023-22527<br /><a href="https://isc.sans.edu/forums/diary/Scans%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20RCE%20Vulnerability%20CVE-2023-22527/30576/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Scans%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20RCE%20Vulnerability%20CVE-2023-22527/30576/</a><br /> Updated Ivanti Mitigation Advise<br /><a href="https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US</a><br /> Czech Republic Sets IPv4 Shutdown date<br /><a href="https://konecipv4.cz/en/" target="_blank" rel="noreferrer noopener">https://konecipv4.cz/en/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8820.mp3</guid><pubDate>Tue, 23 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129427/8820.mp3" length="6420665" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Apple Updates Everything
https://isc.sans.edu/forums/diary/Apple%20Updates%20Everything%20-%20New%200%20Day%20in%20WebKit/30578/
 Atlassian Confluence RCE Vulnerability Exploits CVE-2023-22527...</itunes:subtitle><itunes:summary><![CDATA[Apple Updates Everything<br /><a href="https://isc.sans.edu/forums/diary/Apple%20Updates%20Everything%20-%20New%200%20Day%20in%20WebKit/30578/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Apple%20Updates%20Everything%20-%20New%200%20Day%20in%20WebKit/30578/</a><br /> Atlassian Confluence RCE Vulnerability Exploits CVE-2023-22527<br /><a href="https://isc.sans.edu/forums/diary/Scans%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20RCE%20Vulnerability%20CVE-2023-22527/30576/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Scans%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20RCE%20Vulnerability%20CVE-2023-22527/30576/</a><br /> Updated Ivanti Mitigation Advise<br /><a href="https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US</a><br /> Czech Republic Sets IPv4 Shutdown date<br /><a href="https://konecipv4.cz/en/" target="_blank" rel="noreferrer noopener">https://konecipv4.cz/en/</a><br />]]></itunes:summary><itunes:duration>437</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,czech; ivanti; atlassian; ipv6,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8820</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, January 23rd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-january-23rd-2024--58411806</link><description><![CDATA[Apple Updates Everything<br /><a href="https://isc.sans.edu/forums/diary/Apple%20Updates%20Everything%20-%20New%200%20Day%20in%20WebKit/30578/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Apple%20Updates%20Everything%20-%20New%200%20Day%20in%20WebKit/30578/</a><br /> Atlassian Confluence RCE Vulnerability Exploits CVE-2023-22527<br /><a href="https://isc.sans.edu/forums/diary/Scans%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20RCE%20Vulnerability%20CVE-2023-22527/30576/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Scans%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20RCE%20Vulnerability%20CVE-2023-22527/30576/</a><br /> Updated Ivanti Mitigation Advise<br /><a href="https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US</a><br /> Czech Republic Sets IPv6 Shutdown date<br /><a href="https://konecipv4.cz/en/" target="_blank" rel="noreferrer noopener">https://konecipv4.cz/en/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8820.mp3</guid><pubDate>Tue, 23 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58411806/8820.mp3" length="6420665" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Apple Updates Everything
https://isc.sans.edu/forums/diary/Apple%20Updates%20Everything%20-%20New%200%20Day%20in%20WebKit/30578/
 Atlassian Confluence RCE Vulnerability Exploits CVE-2023-22527...</itunes:subtitle><itunes:summary><![CDATA[Apple Updates Everything<br /><a href="https://isc.sans.edu/forums/diary/Apple%20Updates%20Everything%20-%20New%200%20Day%20in%20WebKit/30578/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Apple%20Updates%20Everything%20-%20New%200%20Day%20in%20WebKit/30578/</a><br /> Atlassian Confluence RCE Vulnerability Exploits CVE-2023-22527<br /><a href="https://isc.sans.edu/forums/diary/Scans%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20RCE%20Vulnerability%20CVE-2023-22527/30576/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Scans%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20RCE%20Vulnerability%20CVE-2023-22527/30576/</a><br /> Updated Ivanti Mitigation Advise<br /><a href="https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US</a><br /> Czech Republic Sets IPv6 Shutdown date<br /><a href="https://konecipv4.cz/en/" target="_blank" rel="noreferrer noopener">https://konecipv4.cz/en/</a><br />]]></itunes:summary><itunes:duration>437</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,czech; ivanti; atlassian; ipv6,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8820</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, January 22nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-january-22nd-2024--62129436</link><description><![CDATA[macOS Python Script Replacing Walling Applications with Rogue Apps<br /><a href="https://isc.sans.edu/diary/macOS%20Python%20Script%20Replacing%20Wallet%20Applications%20with%20Rogue%20Apps/30572" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/macOS%20Python%20Script%20Replacing%20Wallet%20Applications%20with%20Rogue%20Apps/30572</a><br /> Microsoft Breach<br /><a href="https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/</a><br /> Juniper Vulnerabilities<br /><a href="https://labs.watchtowr.com/the-second-wednesday-of-the-first-month-of-every-quarter-juniper-0day-revisited/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/the-second-wednesday-of-the-first-month-of-every-quarter-juniper-0day-revisited/</a><br /> Brave Removing Strict Fingerprint Mode<br /><a href="https://brave.com/privacy-updates/28-sunsetting-strict-fingerprinting-mode/" target="_blank" rel="noreferrer noopener">https://brave.com/privacy-updates/28-sunsetting-strict-fingerprinting-mode/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8818.mp3</guid><pubDate>Mon, 22 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129436/8818.mp3" length="5867345" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>macOS Python Script Replacing Walling Applications with Rogue Apps
https://isc.sans.edu/diary/macOS%20Python%20Script%20Replacing%20Wallet%20Applications%20with%20Rogue%20Apps/30572
 Microsoft Breach...</itunes:subtitle><itunes:summary><![CDATA[macOS Python Script Replacing Walling Applications with Rogue Apps<br /><a href="https://isc.sans.edu/diary/macOS%20Python%20Script%20Replacing%20Wallet%20Applications%20with%20Rogue%20Apps/30572" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/macOS%20Python%20Script%20Replacing%20Wallet%20Applications%20with%20Rogue%20Apps/30572</a><br /> Microsoft Breach<br /><a href="https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/</a><br /> Juniper Vulnerabilities<br /><a href="https://labs.watchtowr.com/the-second-wednesday-of-the-first-month-of-every-quarter-juniper-0day-revisited/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/the-second-wednesday-of-the-first-month-of-every-quarter-juniper-0day-revisited/</a><br /> Brave Removing Strict Fingerprint Mode<br /><a href="https://brave.com/privacy-updates/28-sunsetting-strict-fingerprinting-mode/" target="_blank" rel="noreferrer noopener">https://brave.com/privacy-updates/28-sunsetting-strict-fingerprinting-mode/</a><br />]]></itunes:summary><itunes:duration>397</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,macos; brave; microsoft; pytho,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8818</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, January 22nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-january-22nd-2024--58398428</link><description><![CDATA[macOS Python Script Replacing Walling Applications with Rogue Apps<br /><a href="https://isc.sans.edu/diary/macOS%20Python%20Script%20Replacing%20Wallet%20Applications%20with%20Rogue%20Apps/30572" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/macOS%20Python%20Script%20Replacing%20Wallet%20Applications%20with%20Rogue%20Apps/30572</a><br /> Microsoft Breach<br /><a href="https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/</a><br /> Juniper Vulnerabilities<br /><a href="https://labs.watchtowr.com/the-second-wednesday-of-the-first-month-of-every-quarter-juniper-0day-revisited/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/the-second-wednesday-of-the-first-month-of-every-quarter-juniper-0day-revisited/</a><br /> Brave Removing Strict Fingerprint Mode<br /><a href="https://brave.com/privacy-updates/28-sunsetting-strict-fingerprinting-mode/" target="_blank" rel="noreferrer noopener">https://brave.com/privacy-updates/28-sunsetting-strict-fingerprinting-mode/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8818.mp3</guid><pubDate>Mon, 22 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58398428/8818.mp3" length="5867345" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>macOS Python Script Replacing Walling Applications with Rogue Apps
https://isc.sans.edu/diary/macOS%20Python%20Script%20Replacing%20Wallet%20Applications%20with%20Rogue%20Apps/30572
 Microsoft Breach...</itunes:subtitle><itunes:summary><![CDATA[macOS Python Script Replacing Walling Applications with Rogue Apps<br /><a href="https://isc.sans.edu/diary/macOS%20Python%20Script%20Replacing%20Wallet%20Applications%20with%20Rogue%20Apps/30572" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/macOS%20Python%20Script%20Replacing%20Wallet%20Applications%20with%20Rogue%20Apps/30572</a><br /> Microsoft Breach<br /><a href="https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/</a><br /> Juniper Vulnerabilities<br /><a href="https://labs.watchtowr.com/the-second-wednesday-of-the-first-month-of-every-quarter-juniper-0day-revisited/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/the-second-wednesday-of-the-first-month-of-every-quarter-juniper-0day-revisited/</a><br /> Brave Removing Strict Fingerprint Mode<br /><a href="https://brave.com/privacy-updates/28-sunsetting-strict-fingerprinting-mode/" target="_blank" rel="noreferrer noopener">https://brave.com/privacy-updates/28-sunsetting-strict-fingerprinting-mode/</a><br />]]></itunes:summary><itunes:duration>397</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,macos; brave; microsoft; pytho,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8818</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, January 19th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-january-19th-2024--62129476</link><description><![CDATA[More Scans for Ivanti Connect "Secure" VPN. Exploits Public<br /><a href="https://isc.sans.edu/diary/More%20Scans%20for%20Ivanti%20Connect%20%22Secure%22%20VPN.%20Exploits%20Public/30568" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/More%20Scans%20for%20Ivanti%20Connect%20%22Secure%22%20VPN.%20Exploits%20Public/30568</a><br /> Ivanti Endpoint Manager Mobile / MobileIron Core Vuln exploited CVE-2023-35082<br /><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a><br /> Attacks against Exposed Databases<br /><a href="https://twitter.com/fasterthanlime/status/1741935393413402739" target="_blank" rel="noreferrer noopener">https://twitter.com/fasterthanlime/status/1741935393413402739</a><br /> Outlook Vulnerability Discovery and New Ways to Leak NTLM Hashes<br /><a href="https://www.varonis.com/blog/outlook-vulnerability-new-ways-to-leak-ntlm-hashes" target="_blank" rel="noreferrer noopener">https://www.varonis.com/blog/outlook-vulnerability-new-ways-to-leak-ntlm-hashes</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8816.mp3</guid><pubDate>Fri, 19 Jan 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129476/8816.mp3" length="5885177" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>More Scans for Ivanti Connect "Secure" VPN. Exploits Public
https://isc.sans.edu/diary/More%20Scans%20for%20Ivanti%20Connect%20%22Secure%22%20VPN.%20Exploits%20Public/30568
 Ivanti Endpoint Manager Mobile / MobileIron Core Vuln exploited...</itunes:subtitle><itunes:summary><![CDATA[More Scans for Ivanti Connect "Secure" VPN. Exploits Public<br /><a href="https://isc.sans.edu/diary/More%20Scans%20for%20Ivanti%20Connect%20%22Secure%22%20VPN.%20Exploits%20Public/30568" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/More%20Scans%20for%20Ivanti%20Connect%20%22Secure%22%20VPN.%20Exploits%20Public/30568</a><br /> Ivanti Endpoint Manager Mobile / MobileIron Core Vuln exploited CVE-2023-35082<br /><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a><br /> Attacks against Exposed Databases<br /><a href="https://twitter.com/fasterthanlime/status/1741935393413402739" target="_blank" rel="noreferrer noopener">https://twitter.com/fasterthanlime/status/1741935393413402739</a><br /> Outlook Vulnerability Discovery and New Ways to Leak NTLM Hashes<br /><a href="https://www.varonis.com/blog/outlook-vulnerability-new-ways-to-leak-ntlm-hashes" target="_blank" rel="noreferrer noopener">https://www.varonis.com/blog/outlook-vulnerability-new-ways-to-leak-ntlm-hashes</a><br />]]></itunes:summary><itunes:duration>399</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,outlook; postgres; ivanti; vpn,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8816</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, January 19th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-january-19th-2024--58359603</link><description><![CDATA[More Scans for Ivanti Connect "Secure" VPN. Exploits Public<br /><a href="https://isc.sans.edu/diary/More%20Scans%20for%20Ivanti%20Connect%20%22Secure%22%20VPN.%20Exploits%20Public/30568" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/More%20Scans%20for%20Ivanti%20Connect%20%22Secure%22%20VPN.%20Exploits%20Public/30568</a><br /> Ivanti Endpoint Manager Mobile / MobileIron Core Vuln exploited CVE-2023-35082<br /><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a><br /> Attacks against Exposed Databases<br /><a href="https://twitter.com/fasterthanlime/status/1741935393413402739" target="_blank" rel="noreferrer noopener">https://twitter.com/fasterthanlime/status/1741935393413402739</a><br /> Outlook Vulnerability Discovery and New Ways to Leak NTLM Hashes<br /><a href="https://www.varonis.com/blog/outlook-vulnerability-new-ways-to-leak-ntlm-hashes" target="_blank" rel="noreferrer noopener">https://www.varonis.com/blog/outlook-vulnerability-new-ways-to-leak-ntlm-hashes</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8816.mp3</guid><pubDate>Fri, 19 Jan 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58359603/8816.mp3" length="5885177" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>More Scans for Ivanti Connect "Secure" VPN. Exploits Public
https://isc.sans.edu/diary/More%20Scans%20for%20Ivanti%20Connect%20%22Secure%22%20VPN.%20Exploits%20Public/30568
 Ivanti Endpoint Manager Mobile / MobileIron Core Vuln exploited...</itunes:subtitle><itunes:summary><![CDATA[More Scans for Ivanti Connect "Secure" VPN. Exploits Public<br /><a href="https://isc.sans.edu/diary/More%20Scans%20for%20Ivanti%20Connect%20%22Secure%22%20VPN.%20Exploits%20Public/30568" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/More%20Scans%20for%20Ivanti%20Connect%20%22Secure%22%20VPN.%20Exploits%20Public/30568</a><br /> Ivanti Endpoint Manager Mobile / MobileIron Core Vuln exploited CVE-2023-35082<br /><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a><br /> Attacks against Exposed Databases<br /><a href="https://twitter.com/fasterthanlime/status/1741935393413402739" target="_blank" rel="noreferrer noopener">https://twitter.com/fasterthanlime/status/1741935393413402739</a><br /> Outlook Vulnerability Discovery and New Ways to Leak NTLM Hashes<br /><a href="https://www.varonis.com/blog/outlook-vulnerability-new-ways-to-leak-ntlm-hashes" target="_blank" rel="noreferrer noopener">https://www.varonis.com/blog/outlook-vulnerability-new-ways-to-leak-ntlm-hashes</a><br />]]></itunes:summary><itunes:duration>399</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,outlook; postgres; ivanti; vpn,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8816</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, January 18th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-january-18th-2024--62129424</link><description><![CDATA[Number Usage in Passwords<br /><a href="https://isc.sans.edu/diary/Number%20Usage%20in%20Passwords/30540" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Number%20Usage%20in%20Passwords/30540</a><br /> A Lightweight Method to Detect Potential iOS Malware<br /><a href="https://securelist.com/shutdown-log-lightweight-ios-malware-detection-method/111734/" target="_blank" rel="noreferrer noopener">https://securelist.com/shutdown-log-lightweight-ios-malware-detection-method/111734/</a><br /> CISA and FBI Release Known IOCs Associated with Androxgh0st Malware<br /><a href="https://www.cisa.gov/news-events/alerts/2024/01/16/cisa-and-fbi-release-known-iocs-associated-androxgh0st-malware" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2024/01/16/cisa-and-fbi-release-known-iocs-associated-androxgh0st-malware</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8814.mp3</guid><pubDate>Thu, 18 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129424/8814.mp3" length="5982354" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Number Usage in Passwords
https://isc.sans.edu/diary/Number%20Usage%20in%20Passwords/30540
 A Lightweight Method to Detect Potential iOS Malware
https://securelist.com/shutdown-log-lightweight-ios-malware-detection-method/111734/
 CISA and FBI Release...</itunes:subtitle><itunes:summary><![CDATA[Number Usage in Passwords<br /><a href="https://isc.sans.edu/diary/Number%20Usage%20in%20Passwords/30540" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Number%20Usage%20in%20Passwords/30540</a><br /> A Lightweight Method to Detect Potential iOS Malware<br /><a href="https://securelist.com/shutdown-log-lightweight-ios-malware-detection-method/111734/" target="_blank" rel="noreferrer noopener">https://securelist.com/shutdown-log-lightweight-ios-malware-detection-method/111734/</a><br /> CISA and FBI Release Known IOCs Associated with Androxgh0st Malware<br /><a href="https://www.cisa.gov/news-events/alerts/2024/01/16/cisa-and-fbi-release-known-iocs-associated-androxgh0st-malware" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2024/01/16/cisa-and-fbi-release-known-iocs-associated-androxgh0st-malware</a><br />]]></itunes:summary><itunes:duration>406</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,passwords; numbers; ios malwar,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8814</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, January 18th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-january-18th-2024--58339923</link><description><![CDATA[Number Usage in Passwords<br /><a href="https://isc.sans.edu/diary/Number%20Usage%20in%20Passwords/30540" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Number%20Usage%20in%20Passwords/30540</a><br /> A Lightweight Method to Detect Potential iOS Malware<br /><a href="https://securelist.com/shutdown-log-lightweight-ios-malware-detection-method/111734/" target="_blank" rel="noreferrer noopener">https://securelist.com/shutdown-log-lightweight-ios-malware-detection-method/111734/</a><br /> CISA and FBI Release Known IOCs Associated with Androxgh0st Malware<br /><a href="https://www.cisa.gov/news-events/alerts/2024/01/16/cisa-and-fbi-release-known-iocs-associated-androxgh0st-malware" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2024/01/16/cisa-and-fbi-release-known-iocs-associated-androxgh0st-malware</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8814.mp3</guid><pubDate>Thu, 18 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58339923/8814.mp3" length="5982354" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Number Usage in Passwords
https://isc.sans.edu/diary/Number%20Usage%20in%20Passwords/30540
 A Lightweight Method to Detect Potential iOS Malware
https://securelist.com/shutdown-log-lightweight-ios-malware-detection-method/111734/
 CISA and FBI Release...</itunes:subtitle><itunes:summary><![CDATA[Number Usage in Passwords<br /><a href="https://isc.sans.edu/diary/Number%20Usage%20in%20Passwords/30540" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Number%20Usage%20in%20Passwords/30540</a><br /> A Lightweight Method to Detect Potential iOS Malware<br /><a href="https://securelist.com/shutdown-log-lightweight-ios-malware-detection-method/111734/" target="_blank" rel="noreferrer noopener">https://securelist.com/shutdown-log-lightweight-ios-malware-detection-method/111734/</a><br /> CISA and FBI Release Known IOCs Associated with Androxgh0st Malware<br /><a href="https://www.cisa.gov/news-events/alerts/2024/01/16/cisa-and-fbi-release-known-iocs-associated-androxgh0st-malware" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2024/01/16/cisa-and-fbi-release-known-iocs-associated-androxgh0st-malware</a><br />]]></itunes:summary><itunes:duration>406</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,passwords; numbers; ios malwar,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8814</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, January 17th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-january-17th-2024--62129479</link><description><![CDATA[Ivanti Vulnerability Widespread Scanning<br /><a href="https://isc.sans.edu/diary/Scans%20for%20Ivanti%20Connect%20%22Secure%22%20VPN%20%20Vulnerability%20%28CVE-2023-46805%2C%20CVE-2024-21887%29/30562" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20Ivanti%20Connect%20%22Secure%22%20VPN%20%20Vulnerability%20%28CVE-2023-46805%2C%20CVE-2024-21887%29/30562</a><br /><a href="https://www.volexity.com/blog/2024/01/15/ivanti-connect-secure-vpn-exploitation-goes-global/" target="_blank" rel="noreferrer noopener">https://www.volexity.com/blog/2024/01/15/ivanti-connect-secure-vpn-exploitation-goes-global/</a><br /> Citrix Patches Already Exploited Vulnerability <br /><a href="https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549" target="_blank" rel="noreferrer noopener">https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549</a><br /> Atlassian Confluence Remote Code Execution Vulnerability<br /><a href="https://confluence.atlassian.com/security/cve-2023-22527-rce-remote-code-execution-vulnerability-in-confluence-data-center-and-confluence-server-1333990257.html" target="_blank" rel="noreferrer noopener">https://confluence.atlassian.com/security/cve-2023-22527-rce-remote-code-execution-vulnerability-in-confluence-data-center-and-confluence-server-1333990257.html</a><br /> macOS Infostealers<br /><a href="https://www.sentinelone.com/blog/the-many-faces-of-undetected-macos-infostealers-keysteal-atomic-cherrypie-continue-to-adapt/" target="_blank" rel="noreferrer noopener">https://www.sentinelone.com/blog/the-many-faces-of-undetected-macos-infostealers-keysteal-atomic-cherrypie-continue-to-adapt/</a><br /> Google Chrome 0-day<br /><a href="https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_16.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_16.html</a><br /> GitHub Key Rotation<br /><a href="https://www.bleepingcomputer.com/news/security/github-rotates-keys-to-mitigate-impact-of-credential-exposing-flaw/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/github-rotates-keys-to-mitigate-impact-of-credential-exposing-flaw/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8812.mp3</guid><pubDate>Wed, 17 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129479/8812.mp3" length="5100194" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Ivanti Vulnerability Widespread Scanning
https://isc.sans.edu/diary/Scans%20for%20Ivanti%20Connect%20%22Secure%22%20VPN%20%20Vulnerability%20%28CVE-2023-46805%2C%20CVE-2024-21887%29/30562...</itunes:subtitle><itunes:summary><![CDATA[Ivanti Vulnerability Widespread Scanning<br /><a href="https://isc.sans.edu/diary/Scans%20for%20Ivanti%20Connect%20%22Secure%22%20VPN%20%20Vulnerability%20%28CVE-2023-46805%2C%20CVE-2024-21887%29/30562" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20Ivanti%20Connect%20%22Secure%22%20VPN%20%20Vulnerability%20%28CVE-2023-46805%2C%20CVE-2024-21887%29/30562</a><br /><a href="https://www.volexity.com/blog/2024/01/15/ivanti-connect-secure-vpn-exploitation-goes-global/" target="_blank" rel="noreferrer noopener">https://www.volexity.com/blog/2024/01/15/ivanti-connect-secure-vpn-exploitation-goes-global/</a><br /> Citrix Patches Already Exploited Vulnerability <br /><a href="https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549" target="_blank" rel="noreferrer noopener">https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549</a><br /> Atlassian Confluence Remote Code Execution Vulnerability<br /><a href="https://confluence.atlassian.com/security/cve-2023-22527-rce-remote-code-execution-vulnerability-in-confluence-data-center-and-confluence-server-1333990257.html" target="_blank" rel="noreferrer noopener">https://confluence.atlassian.com/security/cve-2023-22527-rce-remote-code-execution-vulnerability-in-confluence-data-center-and-confluence-server-1333990257.html</a><br /> macOS Infostealers<br /><a href="https://www.sentinelone.com/blog/the-many-faces-of-undetected-macos-infostealers-keysteal-atomic-cherrypie-continue-to-adapt/" target="_blank" rel="noreferrer noopener">https://www.sentinelone.com/blog/the-many-faces-of-undetected-macos-infostealers-keysteal-atomic-cherrypie-continue-to-adapt/</a><br /> Google Chrome 0-day<br /><a href="https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_16.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_16.html</a><br /> GitHub Key Rotation<br /><a href="https://www.bleepingcomputer.com/news/security/github-rotates-keys-to-mitigate-impact-of-credential-exposing-flaw/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/github-rotates-keys-to-mitigate-impact-of-credential-exposing-flaw/</a><br />]]></itunes:summary><itunes:duration>343</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,github; chrome; macos; infoste,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8812</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, January 17th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-january-17th-2024--58325795</link><description><![CDATA[Ivanti Vulnerability Widespread Scanning<br /><a href="https://isc.sans.edu/diary/Scans%20for%20Ivanti%20Connect%20%22Secure%22%20VPN%20%20Vulnerability%20%28CVE-2023-46805%2C%20CVE-2024-21887%29/30562" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20Ivanti%20Connect%20%22Secure%22%20VPN%20%20Vulnerability%20%28CVE-2023-46805%2C%20CVE-2024-21887%29/30562</a><br /><a href="https://www.volexity.com/blog/2024/01/15/ivanti-connect-secure-vpn-exploitation-goes-global/" target="_blank" rel="noreferrer noopener">https://www.volexity.com/blog/2024/01/15/ivanti-connect-secure-vpn-exploitation-goes-global/</a><br /> Citrix Patches Already Exploited Vulnerability <br /><a href="https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549" target="_blank" rel="noreferrer noopener">https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549</a><br /> Atlassian Confluence Remote Code Execution Vulnerability<br /><a href="https://confluence.atlassian.com/security/cve-2023-22527-rce-remote-code-execution-vulnerability-in-confluence-data-center-and-confluence-server-1333990257.html" target="_blank" rel="noreferrer noopener">https://confluence.atlassian.com/security/cve-2023-22527-rce-remote-code-execution-vulnerability-in-confluence-data-center-and-confluence-server-1333990257.html</a><br /> macOS Infostealers<br /><a href="https://www.sentinelone.com/blog/the-many-faces-of-undetected-macos-infostealers-keysteal-atomic-cherrypie-continue-to-adapt/" target="_blank" rel="noreferrer noopener">https://www.sentinelone.com/blog/the-many-faces-of-undetected-macos-infostealers-keysteal-atomic-cherrypie-continue-to-adapt/</a><br /> Google Chrome 0-day<br /><a href="https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_16.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_16.html</a><br /> GitHub Key Rotation<br /><a href="https://www.bleepingcomputer.com/news/security/github-rotates-keys-to-mitigate-impact-of-credential-exposing-flaw/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/github-rotates-keys-to-mitigate-impact-of-credential-exposing-flaw/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8812.mp3</guid><pubDate>Wed, 17 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58325795/8812.mp3" length="5100194" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Ivanti Vulnerability Widespread Scanning
https://isc.sans.edu/diary/Scans%20for%20Ivanti%20Connect%20%22Secure%22%20VPN%20%20Vulnerability%20%28CVE-2023-46805%2C%20CVE-2024-21887%29/30562...</itunes:subtitle><itunes:summary><![CDATA[Ivanti Vulnerability Widespread Scanning<br /><a href="https://isc.sans.edu/diary/Scans%20for%20Ivanti%20Connect%20%22Secure%22%20VPN%20%20Vulnerability%20%28CVE-2023-46805%2C%20CVE-2024-21887%29/30562" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20Ivanti%20Connect%20%22Secure%22%20VPN%20%20Vulnerability%20%28CVE-2023-46805%2C%20CVE-2024-21887%29/30562</a><br /><a href="https://www.volexity.com/blog/2024/01/15/ivanti-connect-secure-vpn-exploitation-goes-global/" target="_blank" rel="noreferrer noopener">https://www.volexity.com/blog/2024/01/15/ivanti-connect-secure-vpn-exploitation-goes-global/</a><br /> Citrix Patches Already Exploited Vulnerability <br /><a href="https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549" target="_blank" rel="noreferrer noopener">https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549</a><br /> Atlassian Confluence Remote Code Execution Vulnerability<br /><a href="https://confluence.atlassian.com/security/cve-2023-22527-rce-remote-code-execution-vulnerability-in-confluence-data-center-and-confluence-server-1333990257.html" target="_blank" rel="noreferrer noopener">https://confluence.atlassian.com/security/cve-2023-22527-rce-remote-code-execution-vulnerability-in-confluence-data-center-and-confluence-server-1333990257.html</a><br /> macOS Infostealers<br /><a href="https://www.sentinelone.com/blog/the-many-faces-of-undetected-macos-infostealers-keysteal-atomic-cherrypie-continue-to-adapt/" target="_blank" rel="noreferrer noopener">https://www.sentinelone.com/blog/the-many-faces-of-undetected-macos-infostealers-keysteal-atomic-cherrypie-continue-to-adapt/</a><br /> Google Chrome 0-day<br /><a href="https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_16.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_16.html</a><br /> GitHub Key Rotation<br /><a href="https://www.bleepingcomputer.com/news/security/github-rotates-keys-to-mitigate-impact-of-credential-exposing-flaw/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/github-rotates-keys-to-mitigate-impact-of-credential-exposing-flaw/</a><br />]]></itunes:summary><itunes:duration>343</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,github; chrome; macos; infoste,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8812</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, January 16th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-january-16th-2024--62129439</link><description><![CDATA[One File, Two Payloads<br /><a href="https://isc.sans.edu/diary/One%20File%2C%20Two%20Payloads/30558" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/One%20File%2C%20Two%20Payloads/30558</a><br /> Ivanti Vulnerability Updates<br /><a href="https://labs.watchtowr.com/welcome-to-2024-the-sslvpn-chaos-continues-ivanti-cve-2023-46805-cve-2024-21887/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/welcome-to-2024-the-sslvpn-chaos-continues-ivanti-cve-2023-46805-cve-2024-21887/</a><br /> NVidia DGX H100 and A100 Updates<br /><a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5510" target="_blank" rel="noreferrer noopener">https://nvidia.custhelp.com/app/answers/detail/a_id/5510</a><br /> GitLab Vulnerability<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-7028" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2023-7028</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8810.mp3</guid><pubDate>Tue, 16 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129439/8810.mp3" length="5344333" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>One File, Two Payloads
https://isc.sans.edu/diary/One%20File%2C%20Two%20Payloads/30558
 Ivanti Vulnerability Updates
https://labs.watchtowr.com/welcome-to-2024-the-sslvpn-chaos-continues-ivanti-cve-2023-46805-cve-2024-21887/
 NVidia DGX H100 and A100...</itunes:subtitle><itunes:summary><![CDATA[One File, Two Payloads<br /><a href="https://isc.sans.edu/diary/One%20File%2C%20Two%20Payloads/30558" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/One%20File%2C%20Two%20Payloads/30558</a><br /> Ivanti Vulnerability Updates<br /><a href="https://labs.watchtowr.com/welcome-to-2024-the-sslvpn-chaos-continues-ivanti-cve-2023-46805-cve-2024-21887/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/welcome-to-2024-the-sslvpn-chaos-continues-ivanti-cve-2023-46805-cve-2024-21887/</a><br /> NVidia DGX H100 and A100 Updates<br /><a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5510" target="_blank" rel="noreferrer noopener">https://nvidia.custhelp.com/app/answers/detail/a_id/5510</a><br /> GitLab Vulnerability<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-7028" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2023-7028</a><br />]]></itunes:summary><itunes:duration>360</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,gitlab; nvidia; ivanti;,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8810</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, January 16th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-january-16th-2024--58315538</link><description><![CDATA[One File, Two Payloads<br /><a href="https://isc.sans.edu/diary/One%20File%2C%20Two%20Payloads/30558" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/One%20File%2C%20Two%20Payloads/30558</a><br /> Ivanti Vulnerability Updates<br /><a href="https://labs.watchtowr.com/welcome-to-2024-the-sslvpn-chaos-continues-ivanti-cve-2023-46805-cve-2024-21887/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/welcome-to-2024-the-sslvpn-chaos-continues-ivanti-cve-2023-46805-cve-2024-21887/</a><br /> NVidia DGX H100 and A100 Updates<br /><a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5510" target="_blank" rel="noreferrer noopener">https://nvidia.custhelp.com/app/answers/detail/a_id/5510</a><br /> GitLab Vulnerability<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-7028" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2023-7028</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8810.mp3</guid><pubDate>Tue, 16 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58315538/8810.mp3" length="5344333" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>One File, Two Payloads
https://isc.sans.edu/diary/One%20File%2C%20Two%20Payloads/30558
 Ivanti Vulnerability Updates
https://labs.watchtowr.com/welcome-to-2024-the-sslvpn-chaos-continues-ivanti-cve-2023-46805-cve-2024-21887/
 NVidia DGX H100 and A100...</itunes:subtitle><itunes:summary><![CDATA[One File, Two Payloads<br /><a href="https://isc.sans.edu/diary/One%20File%2C%20Two%20Payloads/30558" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/One%20File%2C%20Two%20Payloads/30558</a><br /> Ivanti Vulnerability Updates<br /><a href="https://labs.watchtowr.com/welcome-to-2024-the-sslvpn-chaos-continues-ivanti-cve-2023-46805-cve-2024-21887/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/welcome-to-2024-the-sslvpn-chaos-continues-ivanti-cve-2023-46805-cve-2024-21887/</a><br /> NVidia DGX H100 and A100 Updates<br /><a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5510" target="_blank" rel="noreferrer noopener">https://nvidia.custhelp.com/app/answers/detail/a_id/5510</a><br /> GitLab Vulnerability<br /><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-7028" target="_blank" rel="noreferrer noopener">https://nvd.nist.gov/vuln/detail/CVE-2023-7028</a><br />]]></itunes:summary><itunes:duration>360</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,gitlab; nvidia; ivanti;,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8810</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, January 12th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-january-12th-2024--62129492</link><description><![CDATA[Timeline to Remove DSA Support in OpenSSH<br /><a href="https://lists.mindrot.org/pipermail/openssh-unix-announce/2024-January/000156.html" target="_blank" rel="noreferrer noopener">https://lists.mindrot.org/pipermail/openssh-unix-announce/2024-January/000156.html</a><br /> Juniper Patches<br /><a href="https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;numberOfResults=50&amp;f:ctype=%5BSecurity%20Advisories%5D" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;numberOfResults=50&amp;f:ctype=[Security%20Advisories]</a><br /> ManageEngine ADSelfService Plus Patch CVE-2024-0252<br /><a href="https://www.manageengine.com/products/self-service-password/advisory/CVE-2024-0252.html" target="_blank" rel="noreferrer noopener">https://www.manageengine.com/products/self-service-password/advisory/CVE-2024-0252.html</a><br /> Atomic Stealer for Mac Update<br /><a href="https://www.malwarebytes.com/blog/threat-intelligence/2024/01/atomic-stealer-rings-in-the-new-year-with-updated-version" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/threat-intelligence/2024/01/atomic-stealer-rings-in-the-new-year-with-updated-version</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8808.mp3</guid><pubDate>Fri, 12 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129492/8808.mp3" length="5178683" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Timeline to Remove DSA Support in OpenSSH
https://lists.mindrot.org/pipermail/openssh-unix-announce/2024-January/000156.html
 Juniper Patches...</itunes:subtitle><itunes:summary><![CDATA[Timeline to Remove DSA Support in OpenSSH<br /><a href="https://lists.mindrot.org/pipermail/openssh-unix-announce/2024-January/000156.html" target="_blank" rel="noreferrer noopener">https://lists.mindrot.org/pipermail/openssh-unix-announce/2024-January/000156.html</a><br /> Juniper Patches<br /><a href="https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;numberOfResults=50&amp;f:ctype=%5BSecurity%20Advisories%5D" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;numberOfResults=50&amp;f:ctype=[Security%20Advisories]</a><br /> ManageEngine ADSelfService Plus Patch CVE-2024-0252<br /><a href="https://www.manageengine.com/products/self-service-password/advisory/CVE-2024-0252.html" target="_blank" rel="noreferrer noopener">https://www.manageengine.com/products/self-service-password/advisory/CVE-2024-0252.html</a><br /> Atomic Stealer for Mac Update<br /><a href="https://www.malwarebytes.com/blog/threat-intelligence/2024/01/atomic-stealer-rings-in-the-new-year-with-updated-version" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/threat-intelligence/2024/01/atomic-stealer-rings-in-the-new-year-with-updated-version</a><br />]]></itunes:summary><itunes:duration>348</itunes:duration><itunes:keywords>atomic; stealer; mac; malware;,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8808</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, January 12th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-january-12th-2024--58270784</link><description><![CDATA[Timeline to Remove DSA Support in OpenSSH<br /><a href="https://lists.mindrot.org/pipermail/openssh-unix-announce/2024-January/000156.html" target="_blank" rel="noreferrer noopener">https://lists.mindrot.org/pipermail/openssh-unix-announce/2024-January/000156.html</a><br /> Juniper Patches<br /><a href="https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;numberOfResults=50&amp;f:ctype=%5BSecurity%20Advisories%5D" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;numberOfResults=50&amp;f:ctype=[Security%20Advisories]</a><br /> ManageEngine ADSelfService Plus Patch CVE-2024-0252<br /><a href="https://www.manageengine.com/products/self-service-password/advisory/CVE-2024-0252.html" target="_blank" rel="noreferrer noopener">https://www.manageengine.com/products/self-service-password/advisory/CVE-2024-0252.html</a><br /> Atomic Stealer for Mac Update<br /><a href="https://www.malwarebytes.com/blog/threat-intelligence/2024/01/atomic-stealer-rings-in-the-new-year-with-updated-version" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/threat-intelligence/2024/01/atomic-stealer-rings-in-the-new-year-with-updated-version</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8808.mp3</guid><pubDate>Fri, 12 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58270784/8808.mp3" length="5178683" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Timeline to Remove DSA Support in OpenSSH
https://lists.mindrot.org/pipermail/openssh-unix-announce/2024-January/000156.html
 Juniper Patches...</itunes:subtitle><itunes:summary><![CDATA[Timeline to Remove DSA Support in OpenSSH<br /><a href="https://lists.mindrot.org/pipermail/openssh-unix-announce/2024-January/000156.html" target="_blank" rel="noreferrer noopener">https://lists.mindrot.org/pipermail/openssh-unix-announce/2024-January/000156.html</a><br /> Juniper Patches<br /><a href="https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;numberOfResults=50&amp;f:ctype=%5BSecurity%20Advisories%5D" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;numberOfResults=50&amp;f:ctype=[Security%20Advisories]</a><br /> ManageEngine ADSelfService Plus Patch CVE-2024-0252<br /><a href="https://www.manageengine.com/products/self-service-password/advisory/CVE-2024-0252.html" target="_blank" rel="noreferrer noopener">https://www.manageengine.com/products/self-service-password/advisory/CVE-2024-0252.html</a><br /> Atomic Stealer for Mac Update<br /><a href="https://www.malwarebytes.com/blog/threat-intelligence/2024/01/atomic-stealer-rings-in-the-new-year-with-updated-version" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/threat-intelligence/2024/01/atomic-stealer-rings-in-the-new-year-with-updated-version</a><br />]]></itunes:summary><itunes:duration>348</itunes:duration><itunes:keywords>atomic; stealer; mac; malware;,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8808</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, January 11th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-january-11th-2024--62129442</link><description><![CDATA[Jenkins Brute Force Scans<br /><a href="https://isc.sans.edu/diary/Jenkins%20Brute%20Force%20Scans/30546" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Jenkins%20Brute%20Force%20Scans/30546</a><br /> Ivanti Connect Security VPN Vulnerability Exploited<br /><a href="https://www.volexity.com/blog/2024/01/10/active-exploitation-of-two-zero-day-vulnerabilities-in-ivanti-connect-secure-vpn/" target="_blank" rel="noreferrer noopener">https://www.volexity.com/blog/2024/01/10/active-exploitation-of-two-zero-day-vulnerabilities-in-ivanti-connect-secure-vpn/</a><br /> Zoom Privilege Escalation Vulnerability<br /><a href="https://www.zoom.com/en/trust/security-bulletin/ZSB-24001/" target="_blank" rel="noreferrer noopener">https://www.zoom.com/en/trust/security-bulletin/ZSB-24001/</a><br /> Apache Applictions Targeted by Stealthy Attacker<br /><a href="https://blog.aquasec.com/threat-alert-apache-applications-targeted-by-stealthy-attacker" target="_blank" rel="noreferrer noopener">https://blog.aquasec.com/threat-alert-apache-applications-targeted-by-stealthy-attacker</a><br /> Infosec Toolshed<br /><a href="https://youtu.be/qDK1PQ1OZjk?si=_vTpHqlovD2Hjd4M" target="_blank" rel="noreferrer noopener">https://youtu.be/qDK1PQ1OZjk?si=_vTpHqlovD2Hjd4M</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8806.mp3</guid><pubDate>Thu, 11 Jan 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129442/8806.mp3" length="4673885" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Jenkins Brute Force Scans
https://isc.sans.edu/diary/Jenkins%20Brute%20Force%20Scans/30546
 Ivanti Connect Security VPN Vulnerability Exploited...</itunes:subtitle><itunes:summary><![CDATA[Jenkins Brute Force Scans<br /><a href="https://isc.sans.edu/diary/Jenkins%20Brute%20Force%20Scans/30546" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Jenkins%20Brute%20Force%20Scans/30546</a><br /> Ivanti Connect Security VPN Vulnerability Exploited<br /><a href="https://www.volexity.com/blog/2024/01/10/active-exploitation-of-two-zero-day-vulnerabilities-in-ivanti-connect-secure-vpn/" target="_blank" rel="noreferrer noopener">https://www.volexity.com/blog/2024/01/10/active-exploitation-of-two-zero-day-vulnerabilities-in-ivanti-connect-secure-vpn/</a><br /> Zoom Privilege Escalation Vulnerability<br /><a href="https://www.zoom.com/en/trust/security-bulletin/ZSB-24001/" target="_blank" rel="noreferrer noopener">https://www.zoom.com/en/trust/security-bulletin/ZSB-24001/</a><br /> Apache Applictions Targeted by Stealthy Attacker<br /><a href="https://blog.aquasec.com/threat-alert-apache-applications-targeted-by-stealthy-attacker" target="_blank" rel="noreferrer noopener">https://blog.aquasec.com/threat-alert-apache-applications-targeted-by-stealthy-attacker</a><br /> Infosec Toolshed<br /><a href="https://youtu.be/qDK1PQ1OZjk?si=_vTpHqlovD2Hjd4M" target="_blank" rel="noreferrer noopener">https://youtu.be/qDK1PQ1OZjk?si=_vTpHqlovD2Hjd4M</a><br />]]></itunes:summary><itunes:duration>312</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,infosec; toolshed; apache; had,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8806</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, January 11th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-january-11th-2024--58259813</link><description><![CDATA[Jenkins Brute Force Scans<br /><a href="https://isc.sans.edu/diary/Jenkins%20Brute%20Force%20Scans/30546" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Jenkins%20Brute%20Force%20Scans/30546</a><br /> Ivanti Connect Security VPN Vulnerability Exploited<br /><a href="https://www.volexity.com/blog/2024/01/10/active-exploitation-of-two-zero-day-vulnerabilities-in-ivanti-connect-secure-vpn/" target="_blank" rel="noreferrer noopener">https://www.volexity.com/blog/2024/01/10/active-exploitation-of-two-zero-day-vulnerabilities-in-ivanti-connect-secure-vpn/</a><br /> Zoom Privilege Escalation Vulnerability<br /><a href="https://www.zoom.com/en/trust/security-bulletin/ZSB-24001/" target="_blank" rel="noreferrer noopener">https://www.zoom.com/en/trust/security-bulletin/ZSB-24001/</a><br /> Apache Applictions Targeted by Stealthy Attacker<br /><a href="https://blog.aquasec.com/threat-alert-apache-applications-targeted-by-stealthy-attacker" target="_blank" rel="noreferrer noopener">https://blog.aquasec.com/threat-alert-apache-applications-targeted-by-stealthy-attacker</a><br /> Infosec Toolshed<br /><a href="https://youtu.be/qDK1PQ1OZjk?si=_vTpHqlovD2Hjd4M" target="_blank" rel="noreferrer noopener">https://youtu.be/qDK1PQ1OZjk?si=_vTpHqlovD2Hjd4M</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8806.mp3</guid><pubDate>Thu, 11 Jan 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58259813/8806.mp3" length="4673885" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Jenkins Brute Force Scans
https://isc.sans.edu/diary/Jenkins%20Brute%20Force%20Scans/30546
 Ivanti Connect Security VPN Vulnerability Exploited...</itunes:subtitle><itunes:summary><![CDATA[Jenkins Brute Force Scans<br /><a href="https://isc.sans.edu/diary/Jenkins%20Brute%20Force%20Scans/30546" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Jenkins%20Brute%20Force%20Scans/30546</a><br /> Ivanti Connect Security VPN Vulnerability Exploited<br /><a href="https://www.volexity.com/blog/2024/01/10/active-exploitation-of-two-zero-day-vulnerabilities-in-ivanti-connect-secure-vpn/" target="_blank" rel="noreferrer noopener">https://www.volexity.com/blog/2024/01/10/active-exploitation-of-two-zero-day-vulnerabilities-in-ivanti-connect-secure-vpn/</a><br /> Zoom Privilege Escalation Vulnerability<br /><a href="https://www.zoom.com/en/trust/security-bulletin/ZSB-24001/" target="_blank" rel="noreferrer noopener">https://www.zoom.com/en/trust/security-bulletin/ZSB-24001/</a><br /> Apache Applictions Targeted by Stealthy Attacker<br /><a href="https://blog.aquasec.com/threat-alert-apache-applications-targeted-by-stealthy-attacker" target="_blank" rel="noreferrer noopener">https://blog.aquasec.com/threat-alert-apache-applications-targeted-by-stealthy-attacker</a><br /> Infosec Toolshed<br /><a href="https://youtu.be/qDK1PQ1OZjk?si=_vTpHqlovD2Hjd4M" target="_blank" rel="noreferrer noopener">https://youtu.be/qDK1PQ1OZjk?si=_vTpHqlovD2Hjd4M</a><br />]]></itunes:summary><itunes:duration>312</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,infosec; toolshed; apache; had,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8806</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, January 10th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-january-10th-2024--62129435</link><description><![CDATA[Microsoft January 2024 Patch Tuesday<br /><a href="https://isc.sans.edu/forums/diary/Microsoft+January+2024+Patch+Tuesday/30548/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Microsoft+January+2024+Patch+Tuesday/30548/</a><br /> Adobe Vulnerabilities<br /><a href="https://helpx.adobe.com/security/products/substance3d_stager/apsb24-06.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/products/substance3d_stager/apsb24-06.html</a><br /> CVE-2023-50916: Authentication Coercion Vulnerablity in Kyocera Device Manager<br /><a href="https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/cve-2023-50916-authentication-coercion-vulnerability-in-kyocera-device-manager/" target="_blank" rel="noreferrer noopener">https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/cve-2023-50916-authentication-coercion-vulnerability-in-kyocera-device-manager/</a><br /> Network Connected Wrenches Used in Factories can be hacked<br /><a href="https://arstechnica.com/security/2024/01/network-connected-wrenches-used-in-factories-can-be-hacked-for-sabotage-or-ransomware/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2024/01/network-connected-wrenches-used-in-factories-can-be-hacked-for-sabotage-or-ransomware/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8804.mp3</guid><pubDate>Wed, 10 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129435/8804.mp3" length="5428418" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft January 2024 Patch Tuesday
https://isc.sans.edu/forums/diary/Microsoft+January+2024+Patch+Tuesday/30548/
 Adobe Vulnerabilities
https://helpx.adobe.com/security/products/substance3d_stager/apsb24-06.html
 CVE-2023-50916: Authentication...</itunes:subtitle><itunes:summary><![CDATA[Microsoft January 2024 Patch Tuesday<br /><a href="https://isc.sans.edu/forums/diary/Microsoft+January+2024+Patch+Tuesday/30548/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Microsoft+January+2024+Patch+Tuesday/30548/</a><br /> Adobe Vulnerabilities<br /><a href="https://helpx.adobe.com/security/products/substance3d_stager/apsb24-06.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/products/substance3d_stager/apsb24-06.html</a><br /> CVE-2023-50916: Authentication Coercion Vulnerablity in Kyocera Device Manager<br /><a href="https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/cve-2023-50916-authentication-coercion-vulnerability-in-kyocera-device-manager/" target="_blank" rel="noreferrer noopener">https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/cve-2023-50916-authentication-coercion-vulnerability-in-kyocera-device-manager/</a><br /> Network Connected Wrenches Used in Factories can be hacked<br /><a href="https://arstechnica.com/security/2024/01/network-connected-wrenches-used-in-factories-can-be-hacked-for-sabotage-or-ransomware/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2024/01/network-connected-wrenches-used-in-factories-can-be-hacked-for-sabotage-or-ransomware/</a><br />]]></itunes:summary><itunes:duration>366</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,network; wrench; hack; kyocera,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8804</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, January 10th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-january-10th-2024--58247867</link><description><![CDATA[Microsoft January 2024 Patch Tuesday<br /><a href="https://isc.sans.edu/forums/diary/Microsoft+January+2024+Patch+Tuesday/30548/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Microsoft+January+2024+Patch+Tuesday/30548/</a><br /> Adobe Vulnerabilities<br /><a href="https://helpx.adobe.com/security/products/substance3d_stager/apsb24-06.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/products/substance3d_stager/apsb24-06.html</a><br /> CVE-2023-50916: Authentication Coercion Vulnerablity in Kyocera Device Manager<br /><a href="https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/cve-2023-50916-authentication-coercion-vulnerability-in-kyocera-device-manager/" target="_blank" rel="noreferrer noopener">https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/cve-2023-50916-authentication-coercion-vulnerability-in-kyocera-device-manager/</a><br /> Network Connected Wrenches Used in Factories can be hacked<br /><a href="https://arstechnica.com/security/2024/01/network-connected-wrenches-used-in-factories-can-be-hacked-for-sabotage-or-ransomware/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2024/01/network-connected-wrenches-used-in-factories-can-be-hacked-for-sabotage-or-ransomware/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8804.mp3</guid><pubDate>Wed, 10 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58247867/8804.mp3" length="5428418" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft January 2024 Patch Tuesday
https://isc.sans.edu/forums/diary/Microsoft+January+2024+Patch+Tuesday/30548/
 Adobe Vulnerabilities
https://helpx.adobe.com/security/products/substance3d_stager/apsb24-06.html
 CVE-2023-50916: Authentication...</itunes:subtitle><itunes:summary><![CDATA[Microsoft January 2024 Patch Tuesday<br /><a href="https://isc.sans.edu/forums/diary/Microsoft+January+2024+Patch+Tuesday/30548/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Microsoft+January+2024+Patch+Tuesday/30548/</a><br /> Adobe Vulnerabilities<br /><a href="https://helpx.adobe.com/security/products/substance3d_stager/apsb24-06.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/products/substance3d_stager/apsb24-06.html</a><br /> CVE-2023-50916: Authentication Coercion Vulnerablity in Kyocera Device Manager<br /><a href="https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/cve-2023-50916-authentication-coercion-vulnerability-in-kyocera-device-manager/" target="_blank" rel="noreferrer noopener">https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/cve-2023-50916-authentication-coercion-vulnerability-in-kyocera-device-manager/</a><br /> Network Connected Wrenches Used in Factories can be hacked<br /><a href="https://arstechnica.com/security/2024/01/network-connected-wrenches-used-in-factories-can-be-hacked-for-sabotage-or-ransomware/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2024/01/network-connected-wrenches-used-in-factories-can-be-hacked-for-sabotage-or-ransomware/</a><br />]]></itunes:summary><itunes:duration>366</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,network; wrench; hack; kyocera,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8804</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, January 9th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-january-9th-2024--62129445</link><description><![CDATA[What is That User Agent<br /><a href="https://isc.sans.edu/diary/What%20is%20that%20User%20Agent%3F/30536" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20is%20that%20User%20Agent%3F/30536</a><br /> KyberSlash Vulnerability<br /><a href="https://kyberslash.cr.yp.to/faq.html" target="_blank" rel="noreferrer noopener">https://kyberslash.cr.yp.to/faq.html</a><br /> Netfilter DoS Vulnerability CVE-2024-0193<br /><a href="https://access.redhat.com/security/cve/CVE-2024-0193" target="_blank" rel="noreferrer noopener">https://access.redhat.com/security/cve/CVE-2024-0193</a><br /> Cacti Vulnerability<br /><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-pfh9-gwm6-86vp" target="_blank" rel="noreferrer noopener">https://github.com/Cacti/cacti/security/advisories/GHSA-pfh9-gwm6-86vp</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8802.mp3</guid><pubDate>Tue, 09 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129445/8802.mp3" length="5412204" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>What is That User Agent
https://isc.sans.edu/diary/What%20is%20that%20User%20Agent%3F/30536
 KyberSlash Vulnerability
https://kyberslash.cr.yp.to/faq.html
 Netfilter DoS Vulnerability CVE-2024-0193
https://access.redhat.com/security/cve/CVE-2024-0193...</itunes:subtitle><itunes:summary><![CDATA[What is That User Agent<br /><a href="https://isc.sans.edu/diary/What%20is%20that%20User%20Agent%3F/30536" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20is%20that%20User%20Agent%3F/30536</a><br /> KyberSlash Vulnerability<br /><a href="https://kyberslash.cr.yp.to/faq.html" target="_blank" rel="noreferrer noopener">https://kyberslash.cr.yp.to/faq.html</a><br /> Netfilter DoS Vulnerability CVE-2024-0193<br /><a href="https://access.redhat.com/security/cve/CVE-2024-0193" target="_blank" rel="noreferrer noopener">https://access.redhat.com/security/cve/CVE-2024-0193</a><br /> Cacti Vulnerability<br /><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-pfh9-gwm6-86vp" target="_blank" rel="noreferrer noopener">https://github.com/Cacti/cacti/security/advisories/GHSA-pfh9-gwm6-86vp</a><br />]]></itunes:summary><itunes:duration>365</itunes:duration><itunes:keywords>business,cacti; netfilter; kyberslash; ,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8802</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, January 9th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-january-9th-2024--58236267</link><description><![CDATA[What is That User Agent<br /><a href="https://isc.sans.edu/diary/What%20is%20that%20User%20Agent%3F/30536" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20is%20that%20User%20Agent%3F/30536</a><br /> KyberSlash Vulnerability<br /><a href="https://kyberslash.cr.yp.to/faq.html" target="_blank" rel="noreferrer noopener">https://kyberslash.cr.yp.to/faq.html</a><br /> Netfilter DoS Vulnerability CVE-2024-0193<br /><a href="https://access.redhat.com/security/cve/CVE-2024-0193" target="_blank" rel="noreferrer noopener">https://access.redhat.com/security/cve/CVE-2024-0193</a><br /> Cacti Vulnerability<br /><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-pfh9-gwm6-86vp" target="_blank" rel="noreferrer noopener">https://github.com/Cacti/cacti/security/advisories/GHSA-pfh9-gwm6-86vp</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8802.mp3</guid><pubDate>Tue, 09 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58236267/8802.mp3" length="5412204" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>What is That User Agent
https://isc.sans.edu/diary/What%20is%20that%20User%20Agent%3F/30536
 KyberSlash Vulnerability
https://kyberslash.cr.yp.to/faq.html
 Netfilter DoS Vulnerability CVE-2024-0193
https://access.redhat.com/security/cve/CVE-2024-0193...</itunes:subtitle><itunes:summary><![CDATA[What is That User Agent<br /><a href="https://isc.sans.edu/diary/What%20is%20that%20User%20Agent%3F/30536" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20is%20that%20User%20Agent%3F/30536</a><br /> KyberSlash Vulnerability<br /><a href="https://kyberslash.cr.yp.to/faq.html" target="_blank" rel="noreferrer noopener">https://kyberslash.cr.yp.to/faq.html</a><br /> Netfilter DoS Vulnerability CVE-2024-0193<br /><a href="https://access.redhat.com/security/cve/CVE-2024-0193" target="_blank" rel="noreferrer noopener">https://access.redhat.com/security/cve/CVE-2024-0193</a><br /> Cacti Vulnerability<br /><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-pfh9-gwm6-86vp" target="_blank" rel="noreferrer noopener">https://github.com/Cacti/cacti/security/advisories/GHSA-pfh9-gwm6-86vp</a><br />]]></itunes:summary><itunes:duration>365</itunes:duration><itunes:keywords>business,cacti; netfilter; kyberslash; ,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8802</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, January 8th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-january-8th-2024--62129454</link><description><![CDATA[Netstat But Better and in PowerShell<br /><a href="https://isc.sans.edu/diary/Netstat%2C%20but%20Better%20and%20in%20PowerShell/30532" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Netstat%2C%20but%20Better%20and%20in%20PowerShell/30532</a><br /> Double Phishing Submission<br /><a href="https://isc.sans.edu/diary/Are%20you%20sure%20of%20your%20password%3F/30534" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Are%20you%20sure%20of%20your%20password%3F/30534</a><br /> Suspicious Prometei Botnet Activity<br /><a href="https://isc.sans.edu/diary/Suspicious%20Prometei%20Botnet%20Activity/30538" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Suspicious%20Prometei%20Botnet%20Activity/30538</a><br /> Spectral Blur Mac Malware<br /><a href="https://g-les.github.io/yara/2024/01/03/100DaysofYARA_SpectralBlur.html" target="_blank" rel="noreferrer noopener">https://g-les.github.io/yara/2024/01/03/100DaysofYARA_SpectralBlur.html</a><br /> Google Malware Abusing API is Standard Token Theft not an API Issue<br /><a href="https://www.bleepingcomputer.com/news/security/google-malware-abusing-api-is-standard-token-theft-not-an-api-issue/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/google-malware-abusing-api-is-standard-token-theft-not-an-api-issue/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8800.mp3</guid><pubDate>Mon, 08 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129454/8800.mp3" length="4625180" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Netstat But Better and in PowerShell
https://isc.sans.edu/diary/Netstat%2C%20but%20Better%20and%20in%20PowerShell/30532
 Double Phishing Submission
https://isc.sans.edu/diary/Are%20you%20sure%20of%20your%20password%3F/30534
 Suspicious Prometei Botnet...</itunes:subtitle><itunes:summary><![CDATA[Netstat But Better and in PowerShell<br /><a href="https://isc.sans.edu/diary/Netstat%2C%20but%20Better%20and%20in%20PowerShell/30532" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Netstat%2C%20but%20Better%20and%20in%20PowerShell/30532</a><br /> Double Phishing Submission<br /><a href="https://isc.sans.edu/diary/Are%20you%20sure%20of%20your%20password%3F/30534" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Are%20you%20sure%20of%20your%20password%3F/30534</a><br /> Suspicious Prometei Botnet Activity<br /><a href="https://isc.sans.edu/diary/Suspicious%20Prometei%20Botnet%20Activity/30538" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Suspicious%20Prometei%20Botnet%20Activity/30538</a><br /> Spectral Blur Mac Malware<br /><a href="https://g-les.github.io/yara/2024/01/03/100DaysofYARA_SpectralBlur.html" target="_blank" rel="noreferrer noopener">https://g-les.github.io/yara/2024/01/03/100DaysofYARA_SpectralBlur.html</a><br /> Google Malware Abusing API is Standard Token Theft not an API Issue<br /><a href="https://www.bleepingcomputer.com/news/security/google-malware-abusing-api-is-standard-token-theft-not-an-api-issue/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/google-malware-abusing-api-is-standard-token-theft-not-an-api-issue/</a><br />]]></itunes:summary><itunes:duration>309</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,google; authentiction; api; sp,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8800</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, January 8th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-january-8th-2024--58226940</link><description><![CDATA[Netstat But Better and in PowerShell<br /><a href="https://isc.sans.edu/diary/Netstat%2C%20but%20Better%20and%20in%20PowerShell/30532" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Netstat%2C%20but%20Better%20and%20in%20PowerShell/30532</a><br /> Double Phishing Submission<br /><a href="https://isc.sans.edu/diary/Are%20you%20sure%20of%20your%20password%3F/30534" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Are%20you%20sure%20of%20your%20password%3F/30534</a><br /> Suspicious Prometei Botnet Activity<br /><a href="https://isc.sans.edu/diary/Suspicious%20Prometei%20Botnet%20Activity/30538" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Suspicious%20Prometei%20Botnet%20Activity/30538</a><br /> Spectral Blur Mac Malware<br /><a href="https://g-les.github.io/yara/2024/01/03/100DaysofYARA_SpectralBlur.html" target="_blank" rel="noreferrer noopener">https://g-les.github.io/yara/2024/01/03/100DaysofYARA_SpectralBlur.html</a><br /> Google Malware Abusing API is Standard Token Theft not an API Issue<br /><a href="https://www.bleepingcomputer.com/news/security/google-malware-abusing-api-is-standard-token-theft-not-an-api-issue/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/google-malware-abusing-api-is-standard-token-theft-not-an-api-issue/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8800.mp3</guid><pubDate>Mon, 08 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58226940/8800.mp3" length="4625180" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Netstat But Better and in PowerShell
https://isc.sans.edu/diary/Netstat%2C%20but%20Better%20and%20in%20PowerShell/30532
 Double Phishing Submission
https://isc.sans.edu/diary/Are%20you%20sure%20of%20your%20password%3F/30534
 Suspicious Prometei Botnet...</itunes:subtitle><itunes:summary><![CDATA[Netstat But Better and in PowerShell<br /><a href="https://isc.sans.edu/diary/Netstat%2C%20but%20Better%20and%20in%20PowerShell/30532" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Netstat%2C%20but%20Better%20and%20in%20PowerShell/30532</a><br /> Double Phishing Submission<br /><a href="https://isc.sans.edu/diary/Are%20you%20sure%20of%20your%20password%3F/30534" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Are%20you%20sure%20of%20your%20password%3F/30534</a><br /> Suspicious Prometei Botnet Activity<br /><a href="https://isc.sans.edu/diary/Suspicious%20Prometei%20Botnet%20Activity/30538" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Suspicious%20Prometei%20Botnet%20Activity/30538</a><br /> Spectral Blur Mac Malware<br /><a href="https://g-les.github.io/yara/2024/01/03/100DaysofYARA_SpectralBlur.html" target="_blank" rel="noreferrer noopener">https://g-les.github.io/yara/2024/01/03/100DaysofYARA_SpectralBlur.html</a><br /> Google Malware Abusing API is Standard Token Theft not an API Issue<br /><a href="https://www.bleepingcomputer.com/news/security/google-malware-abusing-api-is-standard-token-theft-not-an-api-issue/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/google-malware-abusing-api-is-standard-token-theft-not-an-api-issue/</a><br />]]></itunes:summary><itunes:duration>309</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,google; authentiction; api; sp,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8800</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, January 5th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-january-5th-2024--62129443</link><description><![CDATA[Wireshark Updates<br /><a href="https://isc.sans.edu/diary/Wireshark%20updates/30528" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Wireshark%20updates/30528</a><br /> Android Updates<br /><a href="https://source.android.com/docs/security/bulletin/2024-01-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2024-01-01</a><br /> Ivanti Critical Vulnerability<br /><a href="https://forums.ivanti.com/s/article/SA-2023-12-19-CVE-2023-39336?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/SA-2023-12-19-CVE-2023-39336?language=en_US</a><br /> Malicious PyPi Packages<br /><a href="https://www.fortinet.com/blog/threat-research/malicious-pypi-packages-deploy-coinminer-on-linux-devices" target="_blank" rel="noreferrer noopener">https://www.fortinet.com/blog/threat-research/malicious-pypi-packages-deploy-coinminer-on-linux-devices</a><br /> Everything npm package<br /><a href="https://www.bleepingcomputer.com/news/security/everything-blocks-devs-from-removing-their-own-npm-packages/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/everything-blocks-devs-from-removing-their-own-npm-packages/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8798.mp3</guid><pubDate>Fri, 05 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129443/8798.mp3" length="4612033" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Wireshark Updates
https://isc.sans.edu/diary/Wireshark%20updates/30528
 Android Updates
https://source.android.com/docs/security/bulletin/2024-01-01
 Ivanti Critical Vulnerability...</itunes:subtitle><itunes:summary><![CDATA[Wireshark Updates<br /><a href="https://isc.sans.edu/diary/Wireshark%20updates/30528" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Wireshark%20updates/30528</a><br /> Android Updates<br /><a href="https://source.android.com/docs/security/bulletin/2024-01-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2024-01-01</a><br /> Ivanti Critical Vulnerability<br /><a href="https://forums.ivanti.com/s/article/SA-2023-12-19-CVE-2023-39336?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/SA-2023-12-19-CVE-2023-39336?language=en_US</a><br /> Malicious PyPi Packages<br /><a href="https://www.fortinet.com/blog/threat-research/malicious-pypi-packages-deploy-coinminer-on-linux-devices" target="_blank" rel="noreferrer noopener">https://www.fortinet.com/blog/threat-research/malicious-pypi-packages-deploy-coinminer-on-linux-devices</a><br /> Everything npm package<br /><a href="https://www.bleepingcomputer.com/news/security/everything-blocks-devs-from-removing-their-own-npm-packages/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/everything-blocks-devs-from-removing-their-own-npm-packages/</a><br />]]></itunes:summary><itunes:duration>308</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,pypi; npm; everything; ivanti;,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8798</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, January 5th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-january-5th-2024--58203005</link><description><![CDATA[Wireshark Updates<br /><a href="https://isc.sans.edu/diary/Wireshark%20updates/30528" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Wireshark%20updates/30528</a><br /> Android Updates<br /><a href="https://source.android.com/docs/security/bulletin/2024-01-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2024-01-01</a><br /> Ivanti Critical Vulnerability<br /><a href="https://forums.ivanti.com/s/article/SA-2023-12-19-CVE-2023-39336?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/SA-2023-12-19-CVE-2023-39336?language=en_US</a><br /> Malicious PyPi Packages<br /><a href="https://www.fortinet.com/blog/threat-research/malicious-pypi-packages-deploy-coinminer-on-linux-devices" target="_blank" rel="noreferrer noopener">https://www.fortinet.com/blog/threat-research/malicious-pypi-packages-deploy-coinminer-on-linux-devices</a><br /> Everything npm package<br /><a href="https://www.bleepingcomputer.com/news/security/everything-blocks-devs-from-removing-their-own-npm-packages/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/everything-blocks-devs-from-removing-their-own-npm-packages/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8798.mp3</guid><pubDate>Fri, 05 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58203005/8798.mp3" length="4612033" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Wireshark Updates
https://isc.sans.edu/diary/Wireshark%20updates/30528
 Android Updates
https://source.android.com/docs/security/bulletin/2024-01-01
 Ivanti Critical Vulnerability...</itunes:subtitle><itunes:summary><![CDATA[Wireshark Updates<br /><a href="https://isc.sans.edu/diary/Wireshark%20updates/30528" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Wireshark%20updates/30528</a><br /> Android Updates<br /><a href="https://source.android.com/docs/security/bulletin/2024-01-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2024-01-01</a><br /> Ivanti Critical Vulnerability<br /><a href="https://forums.ivanti.com/s/article/SA-2023-12-19-CVE-2023-39336?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/SA-2023-12-19-CVE-2023-39336?language=en_US</a><br /> Malicious PyPi Packages<br /><a href="https://www.fortinet.com/blog/threat-research/malicious-pypi-packages-deploy-coinminer-on-linux-devices" target="_blank" rel="noreferrer noopener">https://www.fortinet.com/blog/threat-research/malicious-pypi-packages-deploy-coinminer-on-linux-devices</a><br /> Everything npm package<br /><a href="https://www.bleepingcomputer.com/news/security/everything-blocks-devs-from-removing-their-own-npm-packages/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/everything-blocks-devs-from-removing-their-own-npm-packages/</a><br />]]></itunes:summary><itunes:duration>308</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,pypi; npm; everything; ivanti;,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8798</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, January 4th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-january-4th-2024--62129465</link><description><![CDATA[Interesting large and small malspam attachments from 2023<br /><a href="https://isc.sans.edu/diary/Interesting%20large%20and%20small%20malspam%20attachments%20from%202023/30524" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Interesting%20large%20and%20small%20malspam%20attachments%20from%202023/30524</a><br /> Orange Spain RIPE Account Compromise<br /><a href="https://www.bleepingcomputer.com/news/security/hacker-hijacks-orange-spain-ripe-account-to-cause-bgp-havoc/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/hacker-hijacks-orange-spain-ripe-account-to-cause-bgp-havoc/</a><br /> Bitwarden Heist<br /><a href="https://blog.redteam-pentesting.de/2024/bitwarden-heist/" target="_blank" rel="noreferrer noopener">https://blog.redteam-pentesting.de/2024/bitwarden-heist/</a><br /> Apple iOS PoC Exploits<br /><a href="https://github.com/felix-pb/kfd/blob/main/writeups/smith.md" target="_blank" rel="noreferrer noopener">https://github.com/felix-pb/kfd/blob/main/writeups/smith.md</a><br /><a href="https://github.com/felix-pb/kfd/blob/main/writeups/landa.md" target="_blank" rel="noreferrer noopener">https://github.com/felix-pb/kfd/blob/main/writeups/landa.md</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8796.mp3</guid><pubDate>Thu, 04 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129465/8796.mp3" length="5715927" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Interesting large and small malspam attachments from 2023
https://isc.sans.edu/diary/Interesting%20large%20and%20small%20malspam%20attachments%20from%202023/30524
 Orange Spain RIPE Account Compromise...</itunes:subtitle><itunes:summary><![CDATA[Interesting large and small malspam attachments from 2023<br /><a href="https://isc.sans.edu/diary/Interesting%20large%20and%20small%20malspam%20attachments%20from%202023/30524" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Interesting%20large%20and%20small%20malspam%20attachments%20from%202023/30524</a><br /> Orange Spain RIPE Account Compromise<br /><a href="https://www.bleepingcomputer.com/news/security/hacker-hijacks-orange-spain-ripe-account-to-cause-bgp-havoc/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/hacker-hijacks-orange-spain-ripe-account-to-cause-bgp-havoc/</a><br /> Bitwarden Heist<br /><a href="https://blog.redteam-pentesting.de/2024/bitwarden-heist/" target="_blank" rel="noreferrer noopener">https://blog.redteam-pentesting.de/2024/bitwarden-heist/</a><br /> Apple iOS PoC Exploits<br /><a href="https://github.com/felix-pb/kfd/blob/main/writeups/smith.md" target="_blank" rel="noreferrer noopener">https://github.com/felix-pb/kfd/blob/main/writeups/smith.md</a><br /><a href="https://github.com/felix-pb/kfd/blob/main/writeups/landa.md" target="_blank" rel="noreferrer noopener">https://github.com/felix-pb/kfd/blob/main/writeups/landa.md</a><br />]]></itunes:summary><itunes:duration>387</itunes:duration><itunes:keywords>apple; ios; poc; bitwarden; or,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8796</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, January 4th, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-january-4th-2024--58193630</link><description><![CDATA[Interesting large and small malspam attachments from 2023<br /><a href="https://isc.sans.edu/diary/Interesting%20large%20and%20small%20malspam%20attachments%20from%202023/30524" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Interesting%20large%20and%20small%20malspam%20attachments%20from%202023/30524</a><br /> Orange Spain RIPE Account Compromise<br /><a href="https://www.bleepingcomputer.com/news/security/hacker-hijacks-orange-spain-ripe-account-to-cause-bgp-havoc/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/hacker-hijacks-orange-spain-ripe-account-to-cause-bgp-havoc/</a><br /> Bitwarden Heist<br /><a href="https://blog.redteam-pentesting.de/2024/bitwarden-heist/" target="_blank" rel="noreferrer noopener">https://blog.redteam-pentesting.de/2024/bitwarden-heist/</a><br /> Apple iOS PoC Exploits<br /><a href="https://github.com/felix-pb/kfd/blob/main/writeups/smith.md" target="_blank" rel="noreferrer noopener">https://github.com/felix-pb/kfd/blob/main/writeups/smith.md</a><br /><a href="https://github.com/felix-pb/kfd/blob/main/writeups/landa.md" target="_blank" rel="noreferrer noopener">https://github.com/felix-pb/kfd/blob/main/writeups/landa.md</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8796.mp3</guid><pubDate>Thu, 04 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58193630/8796.mp3" length="5715927" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Interesting large and small malspam attachments from 2023
https://isc.sans.edu/diary/Interesting%20large%20and%20small%20malspam%20attachments%20from%202023/30524
 Orange Spain RIPE Account Compromise...</itunes:subtitle><itunes:summary><![CDATA[Interesting large and small malspam attachments from 2023<br /><a href="https://isc.sans.edu/diary/Interesting%20large%20and%20small%20malspam%20attachments%20from%202023/30524" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Interesting%20large%20and%20small%20malspam%20attachments%20from%202023/30524</a><br /> Orange Spain RIPE Account Compromise<br /><a href="https://www.bleepingcomputer.com/news/security/hacker-hijacks-orange-spain-ripe-account-to-cause-bgp-havoc/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/hacker-hijacks-orange-spain-ripe-account-to-cause-bgp-havoc/</a><br /> Bitwarden Heist<br /><a href="https://blog.redteam-pentesting.de/2024/bitwarden-heist/" target="_blank" rel="noreferrer noopener">https://blog.redteam-pentesting.de/2024/bitwarden-heist/</a><br /> Apple iOS PoC Exploits<br /><a href="https://github.com/felix-pb/kfd/blob/main/writeups/smith.md" target="_blank" rel="noreferrer noopener">https://github.com/felix-pb/kfd/blob/main/writeups/smith.md</a><br /><a href="https://github.com/felix-pb/kfd/blob/main/writeups/landa.md" target="_blank" rel="noreferrer noopener">https://github.com/felix-pb/kfd/blob/main/writeups/landa.md</a><br />]]></itunes:summary><itunes:duration>387</itunes:duration><itunes:keywords>apple; ios; poc; bitwarden; or,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8796</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, January 3rd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-january-3rd-2024--62129444</link><description><![CDATA[Fingerprinting SSH Identification Strings<br /><a href="https://isc.sans.edu/diary/Fingerprinting%20SSH%20Identification%20Strings/30520" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Fingerprinting%20SSH%20Identification%20Strings/30520</a><br /> Google OAUTH2 Exploited by Malware<br /><a href="https://www.cloudsek.com/blog/compromising-google-accounts-malwares-exploiting-undocumented-oauth2-functionality-for-session-hijacking" target="_blank" rel="noreferrer noopener">https://www.cloudsek.com/blog/compromising-google-accounts-malwares-exploiting-undocumented-oauth2-functionality-for-session-hijacking</a><br /> TsuKing DNS Amplification<br /><a href="https://lixiang521.com/publication/ccs23/ccs23-xu-tsuking.pdf" target="_blank" rel="noreferrer noopener">https://lixiang521.com/publication/ccs23/ccs23-xu-tsuking.pdf</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8794.mp3</guid><pubDate>Wed, 03 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129444/8794.mp3" length="7673052" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Fingerprinting SSH Identification Strings
https://isc.sans.edu/diary/Fingerprinting%20SSH%20Identification%20Strings/30520
 Google OAUTH2 Exploited by Malware...</itunes:subtitle><itunes:summary><![CDATA[Fingerprinting SSH Identification Strings<br /><a href="https://isc.sans.edu/diary/Fingerprinting%20SSH%20Identification%20Strings/30520" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Fingerprinting%20SSH%20Identification%20Strings/30520</a><br /> Google OAUTH2 Exploited by Malware<br /><a href="https://www.cloudsek.com/blog/compromising-google-accounts-malwares-exploiting-undocumented-oauth2-functionality-for-session-hijacking" target="_blank" rel="noreferrer noopener">https://www.cloudsek.com/blog/compromising-google-accounts-malwares-exploiting-undocumented-oauth2-functionality-for-session-hijacking</a><br /> TsuKing DNS Amplification<br /><a href="https://lixiang521.com/publication/ccs23/ccs23-xu-tsuking.pdf" target="_blank" rel="noreferrer noopener">https://lixiang521.com/publication/ccs23/ccs23-xu-tsuking.pdf</a><br />]]></itunes:summary><itunes:duration>527</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dns; tsuking; google; oauth; c,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8794</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, January 3rd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-january-3rd-2024--58179216</link><description><![CDATA[Fingerprinting SSH Identification Strings<br /><a href="https://isc.sans.edu/diary/Fingerprinting%20SSH%20Identification%20Strings/30520" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Fingerprinting%20SSH%20Identification%20Strings/30520</a><br /> Google OAUTH2 Exploited by Malware<br /><a href="https://www.cloudsek.com/blog/compromising-google-accounts-malwares-exploiting-undocumented-oauth2-functionality-for-session-hijacking" target="_blank" rel="noreferrer noopener">https://www.cloudsek.com/blog/compromising-google-accounts-malwares-exploiting-undocumented-oauth2-functionality-for-session-hijacking</a><br /> TsuKing DNS Amplification<br /><a href="https://lixiang521.com/publication/ccs23/ccs23-xu-tsuking.pdf" target="_blank" rel="noreferrer noopener">https://lixiang521.com/publication/ccs23/ccs23-xu-tsuking.pdf</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8794.mp3</guid><pubDate>Wed, 03 Jan 2024 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58179216/8794.mp3" length="7673052" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Fingerprinting SSH Identification Strings
https://isc.sans.edu/diary/Fingerprinting%20SSH%20Identification%20Strings/30520
 Google OAUTH2 Exploited by Malware...</itunes:subtitle><itunes:summary><![CDATA[Fingerprinting SSH Identification Strings<br /><a href="https://isc.sans.edu/diary/Fingerprinting%20SSH%20Identification%20Strings/30520" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Fingerprinting%20SSH%20Identification%20Strings/30520</a><br /> Google OAUTH2 Exploited by Malware<br /><a href="https://www.cloudsek.com/blog/compromising-google-accounts-malwares-exploiting-undocumented-oauth2-functionality-for-session-hijacking" target="_blank" rel="noreferrer noopener">https://www.cloudsek.com/blog/compromising-google-accounts-malwares-exploiting-undocumented-oauth2-functionality-for-session-hijacking</a><br /> TsuKing DNS Amplification<br /><a href="https://lixiang521.com/publication/ccs23/ccs23-xu-tsuking.pdf" target="_blank" rel="noreferrer noopener">https://lixiang521.com/publication/ccs23/ccs23-xu-tsuking.pdf</a><br />]]></itunes:summary><itunes:duration>526</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dns; tsuking; google; oauth; c,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8794</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, January 2nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-january-2nd-2024--62129493</link><description><![CDATA[Shall We Play a Game<br /><a href="https://isc.sans.edu/diary/Shall+We+Play+a+Game/30510" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Shall+We+Play+a+Game/30510</a><br /> Mailtrap.io Exfiltration<br /><a href="https://isc.sans.edu/diary/Python%20Keylogger%20Using%20Mailtrap.io/30512" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Python%20Keylogger%20Using%20Mailtrap.io/30512</a><br /> Pi Hole Docker<br /><a href="https://isc.sans.edu/forums/diary/Pi-Hole%20Pi4%20Docker%20Deployment/30516/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Pi-Hole%20Pi4%20Docker%20Deployment/30516/</a><br /> Mirai Update<br /><a href="https://isc.sans.edu/diary/Unveiling%20the%20Mirai%3A%20Insights%20into%20Recent%20DShield%20Honeypot%20Activity%20%5BGuest%20Diary%5D/30514" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Unveiling%20the%20Mirai%3A%20Insights%20into%20Recent%20DShield%20Honeypot%20Activity%20%5BGuest%20Diary%5D/30514</a><br /> Barracuda 0-Day Vulnerability<br /><a href="https://www.barracuda.com/company/legal/esg-vulnerability" target="_blank" rel="noreferrer noopener">https://www.barracuda.com/company/legal/esg-vulnerability</a><br /> Apache OFBiz 0-Day Exploited against Atlassian (and possibly others)<br /><a href="https://blog.sonicwall.com/en-us/2023/12/sonicwall-discovers-critical-apache-ofbiz-zero-day-authbiz/" target="_blank" rel="noreferrer noopener">https://blog.sonicwall.com/en-us/2023/12/sonicwall-discovers-critical-apache-ofbiz-zero-day-authbiz/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8792.mp3</guid><pubDate>Tue, 02 Jan 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129493/8792.mp3" length="5492616" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Shall We Play a Game
https://isc.sans.edu/diary/Shall+We+Play+a+Game/30510
 Mailtrap.io Exfiltration
https://isc.sans.edu/diary/Python%20Keylogger%20Using%20Mailtrap.io/30512
 Pi Hole Docker...</itunes:subtitle><itunes:summary><![CDATA[Shall We Play a Game<br /><a href="https://isc.sans.edu/diary/Shall+We+Play+a+Game/30510" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Shall+We+Play+a+Game/30510</a><br /> Mailtrap.io Exfiltration<br /><a href="https://isc.sans.edu/diary/Python%20Keylogger%20Using%20Mailtrap.io/30512" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Python%20Keylogger%20Using%20Mailtrap.io/30512</a><br /> Pi Hole Docker<br /><a href="https://isc.sans.edu/forums/diary/Pi-Hole%20Pi4%20Docker%20Deployment/30516/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Pi-Hole%20Pi4%20Docker%20Deployment/30516/</a><br /> Mirai Update<br /><a href="https://isc.sans.edu/diary/Unveiling%20the%20Mirai%3A%20Insights%20into%20Recent%20DShield%20Honeypot%20Activity%20%5BGuest%20Diary%5D/30514" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Unveiling%20the%20Mirai%3A%20Insights%20into%20Recent%20DShield%20Honeypot%20Activity%20%5BGuest%20Diary%5D/30514</a><br /> Barracuda 0-Day Vulnerability<br /><a href="https://www.barracuda.com/company/legal/esg-vulnerability" target="_blank" rel="noreferrer noopener">https://www.barracuda.com/company/legal/esg-vulnerability</a><br /> Apache OFBiz 0-Day Exploited against Atlassian (and possibly others)<br /><a href="https://blog.sonicwall.com/en-us/2023/12/sonicwall-discovers-critical-apache-ofbiz-zero-day-authbiz/" target="_blank" rel="noreferrer noopener">https://blog.sonicwall.com/en-us/2023/12/sonicwall-discovers-critical-apache-ofbiz-zero-day-authbiz/</a><br />]]></itunes:summary><itunes:duration>371</itunes:duration><itunes:keywords>apache; ofbiz; altassian; jira,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8792</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, January 2nd, 2024</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-january-2nd-2024--58168490</link><description><![CDATA[Shall We Play a Game<br /><a href="https://isc.sans.edu/diary/Shall+We+Play+a+Game/30510" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Shall+We+Play+a+Game/30510</a><br /> Mailtrap.io Exfiltration<br /><a href="https://isc.sans.edu/diary/Python%20Keylogger%20Using%20Mailtrap.io/30512" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Python%20Keylogger%20Using%20Mailtrap.io/30512</a><br /> Pi Hole Docker<br /><a href="https://isc.sans.edu/forums/diary/Pi-Hole%20Pi4%20Docker%20Deployment/30516/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Pi-Hole%20Pi4%20Docker%20Deployment/30516/</a><br /> Mirai Update<br /><a href="https://isc.sans.edu/diary/Unveiling%20the%20Mirai%3A%20Insights%20into%20Recent%20DShield%20Honeypot%20Activity%20%5BGuest%20Diary%5D/30514" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Unveiling%20the%20Mirai%3A%20Insights%20into%20Recent%20DShield%20Honeypot%20Activity%20%5BGuest%20Diary%5D/30514</a><br /> Barracuda 0-Day Vulnerability<br /><a href="https://www.barracuda.com/company/legal/esg-vulnerability" target="_blank" rel="noreferrer noopener">https://www.barracuda.com/company/legal/esg-vulnerability</a><br /> Apache OFBiz 0-Day Exploited against Atlassian (and possibly others)<br /><a href="https://blog.sonicwall.com/en-us/2023/12/sonicwall-discovers-critical-apache-ofbiz-zero-day-authbiz/" target="_blank" rel="noreferrer noopener">https://blog.sonicwall.com/en-us/2023/12/sonicwall-discovers-critical-apache-ofbiz-zero-day-authbiz/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8792.mp3</guid><pubDate>Tue, 02 Jan 2024 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58168490/8792.mp3" length="5492616" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Shall We Play a Game
https://isc.sans.edu/diary/Shall+We+Play+a+Game/30510
 Mailtrap.io Exfiltration
https://isc.sans.edu/diary/Python%20Keylogger%20Using%20Mailtrap.io/30512
 Pi Hole Docker...</itunes:subtitle><itunes:summary><![CDATA[Shall We Play a Game<br /><a href="https://isc.sans.edu/diary/Shall+We+Play+a+Game/30510" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Shall+We+Play+a+Game/30510</a><br /> Mailtrap.io Exfiltration<br /><a href="https://isc.sans.edu/diary/Python%20Keylogger%20Using%20Mailtrap.io/30512" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Python%20Keylogger%20Using%20Mailtrap.io/30512</a><br /> Pi Hole Docker<br /><a href="https://isc.sans.edu/forums/diary/Pi-Hole%20Pi4%20Docker%20Deployment/30516/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Pi-Hole%20Pi4%20Docker%20Deployment/30516/</a><br /> Mirai Update<br /><a href="https://isc.sans.edu/diary/Unveiling%20the%20Mirai%3A%20Insights%20into%20Recent%20DShield%20Honeypot%20Activity%20%5BGuest%20Diary%5D/30514" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Unveiling%20the%20Mirai%3A%20Insights%20into%20Recent%20DShield%20Honeypot%20Activity%20%5BGuest%20Diary%5D/30514</a><br /> Barracuda 0-Day Vulnerability<br /><a href="https://www.barracuda.com/company/legal/esg-vulnerability" target="_blank" rel="noreferrer noopener">https://www.barracuda.com/company/legal/esg-vulnerability</a><br /> Apache OFBiz 0-Day Exploited against Atlassian (and possibly others)<br /><a href="https://blog.sonicwall.com/en-us/2023/12/sonicwall-discovers-critical-apache-ofbiz-zero-day-authbiz/" target="_blank" rel="noreferrer noopener">https://blog.sonicwall.com/en-us/2023/12/sonicwall-discovers-critical-apache-ofbiz-zero-day-authbiz/</a><br />]]></itunes:summary><itunes:duration>371</itunes:duration><itunes:keywords>apache; ofbiz; altassian; jira,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8792</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, December 22nd, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-december-22nd-2023--62129467</link><description><![CDATA[Securing Web Servers<br /><a href="https://isc.sans.edu/diary/How%20to%20Protect%20your%20Webserver%20from%20Directory%20Enumeration%20Attack%20%3F%20Apache2%20%5BGuest%20Diary%5D/30504" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20to%20Protect%20your%20Webserver%20from%20Directory%20Enumeration%20Attack%20%3F%20Apache2%20%5BGuest%20Diary%5D/30504</a><br /> Chrome 0-Day (last one for the year?)<br /><a href="https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_20.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_20.html</a><br /> Note that there will be no daily stormcast for the rest of the year. Returning January 2nd<br /> SANS Cloud Defender 2024<br /><a href="https://www.sans.org/cyber-security-training-events/cloud-defender-2024-live-online/" target="_blank" rel="noreferrer noopener">https://www.sans.org/cyber-security-training-events/cloud-defender-2024-live-online/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8790.mp3</guid><pubDate>Fri, 22 Dec 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129467/8790.mp3" length="4347438" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Securing Web Servers
https://isc.sans.edu/diary/How%20to%20Protect%20your%20Webserver%20from%20Directory%20Enumeration%20Attack%20%3F%20Apache2%20%5BGuest%20Diary%5D/30504
 Chrome 0-Day (last one for the year?)...</itunes:subtitle><itunes:summary><![CDATA[Securing Web Servers<br /><a href="https://isc.sans.edu/diary/How%20to%20Protect%20your%20Webserver%20from%20Directory%20Enumeration%20Attack%20%3F%20Apache2%20%5BGuest%20Diary%5D/30504" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20to%20Protect%20your%20Webserver%20from%20Directory%20Enumeration%20Attack%20%3F%20Apache2%20%5BGuest%20Diary%5D/30504</a><br /> Chrome 0-Day (last one for the year?)<br /><a href="https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_20.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_20.html</a><br /> Note that there will be no daily stormcast for the rest of the year. Returning January 2nd<br /> SANS Cloud Defender 2024<br /><a href="https://www.sans.org/cyber-security-training-events/cloud-defender-2024-live-online/" target="_blank" rel="noreferrer noopener">https://www.sans.org/cyber-security-training-events/cloud-defender-2024-live-online/</a><br />]]></itunes:summary><itunes:duration>289</itunes:duration><itunes:keywords>business,chrome; web; apache; holidays,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8790</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, December 22nd, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-december-22nd-2023--58092096</link><description><![CDATA[Securing Web Servers<br /><a href="https://isc.sans.edu/diary/How%20to%20Protect%20your%20Webserver%20from%20Directory%20Enumeration%20Attack%20%3F%20Apache2%20%5BGuest%20Diary%5D/30504" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20to%20Protect%20your%20Webserver%20from%20Directory%20Enumeration%20Attack%20%3F%20Apache2%20%5BGuest%20Diary%5D/30504</a><br /> Chrome 0-Day (last one for the year?)<br /><a href="https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_20.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_20.html</a><br /> Note that there will be no daily stormcast for the rest of the year. Returning January 2nd<br /> SANS Cloud Defender 2024<br /><a href="https://www.sans.org/cyber-security-training-events/cloud-defender-2024-live-online/" target="_blank" rel="noreferrer noopener">https://www.sans.org/cyber-security-training-events/cloud-defender-2024-live-online/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8790.mp3</guid><pubDate>Fri, 22 Dec 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58092096/8790.mp3" length="4347438" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Securing Web Servers
https://isc.sans.edu/diary/How%20to%20Protect%20your%20Webserver%20from%20Directory%20Enumeration%20Attack%20%3F%20Apache2%20%5BGuest%20Diary%5D/30504
 Chrome 0-Day (last one for the year?)...</itunes:subtitle><itunes:summary><![CDATA[Securing Web Servers<br /><a href="https://isc.sans.edu/diary/How%20to%20Protect%20your%20Webserver%20from%20Directory%20Enumeration%20Attack%20%3F%20Apache2%20%5BGuest%20Diary%5D/30504" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20to%20Protect%20your%20Webserver%20from%20Directory%20Enumeration%20Attack%20%3F%20Apache2%20%5BGuest%20Diary%5D/30504</a><br /> Chrome 0-Day (last one for the year?)<br /><a href="https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_20.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_20.html</a><br /> Note that there will be no daily stormcast for the rest of the year. Returning January 2nd<br /> SANS Cloud Defender 2024<br /><a href="https://www.sans.org/cyber-security-training-events/cloud-defender-2024-live-online/" target="_blank" rel="noreferrer noopener">https://www.sans.org/cyber-security-training-events/cloud-defender-2024-live-online/</a><br />]]></itunes:summary><itunes:duration>289</itunes:duration><itunes:keywords>business,chrome; web; apache; holidays,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8790</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, December 21st, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-december-21st-2023--62129482</link><description><![CDATA[Increase in Exploit Attempts for Atlassian Confluence Server (CVE-2023-22518)<br /><a href="https://isc.sans.edu/diary/Increase%20in%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20Server%20%28CVE-2023-22518%29/30502" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Increase%20in%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20Server%20%28CVE-2023-22518%29/30502</a><br /> Fake F5 BigIP Update<br /><a href="https://www.bleepingcomputer.com/news/security/fake-f5-big-ip-zero-day-warning-emails-push-data-wipers/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/fake-f5-big-ip-zero-day-warning-emails-push-data-wipers/</a><br /> Google OAUTH Problems<br /><a href="https://trufflesecurity.com/blog/google-oauth-is-broken-sort-of/" target="_blank" rel="noreferrer noopener">https://trufflesecurity.com/blog/google-oauth-is-broken-sort-of/</a><br /> Remembering Adrien de Beaupre<br /><a href="https://www.hpmcgarry.ca/memorials/ernest-adrien-de-beaupre/5344136/index.php" target="_blank" rel="noreferrer noopener">https://www.hpmcgarry.ca/memorials/ernest-adrien-de-beaupre/5344136/index.php</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8788.mp3</guid><pubDate>Thu, 21 Dec 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129482/8788.mp3" length="6411186" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Increase in Exploit Attempts for Atlassian Confluence Server (CVE-2023-22518)
https://isc.sans.edu/diary/Increase%20in%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20Server%20%28CVE-2023-22518%29/30502
 Fake F5 BigIP Update...</itunes:subtitle><itunes:summary><![CDATA[Increase in Exploit Attempts for Atlassian Confluence Server (CVE-2023-22518)<br /><a href="https://isc.sans.edu/diary/Increase%20in%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20Server%20%28CVE-2023-22518%29/30502" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Increase%20in%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20Server%20%28CVE-2023-22518%29/30502</a><br /> Fake F5 BigIP Update<br /><a href="https://www.bleepingcomputer.com/news/security/fake-f5-big-ip-zero-day-warning-emails-push-data-wipers/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/fake-f5-big-ip-zero-day-warning-emails-push-data-wipers/</a><br /> Google OAUTH Problems<br /><a href="https://trufflesecurity.com/blog/google-oauth-is-broken-sort-of/" target="_blank" rel="noreferrer noopener">https://trufflesecurity.com/blog/google-oauth-is-broken-sort-of/</a><br /> Remembering Adrien de Beaupre<br /><a href="https://www.hpmcgarry.ca/memorials/ernest-adrien-de-beaupre/5344136/index.php" target="_blank" rel="noreferrer noopener">https://www.hpmcgarry.ca/memorials/ernest-adrien-de-beaupre/5344136/index.php</a><br />]]></itunes:summary><itunes:duration>436</itunes:duration><itunes:keywords>adrien; google; oauth; f5; big,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8788</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, December 21st, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-december-21st-2023--58079054</link><description><![CDATA[Increase in Exploit Attempts for Atlassian Confluence Server (CVE-2023-22518)<br /><a href="https://isc.sans.edu/diary/Increase%20in%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20Server%20%28CVE-2023-22518%29/30502" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Increase%20in%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20Server%20%28CVE-2023-22518%29/30502</a><br /> Fake F5 BigIP Update<br /><a href="https://www.bleepingcomputer.com/news/security/fake-f5-big-ip-zero-day-warning-emails-push-data-wipers/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/fake-f5-big-ip-zero-day-warning-emails-push-data-wipers/</a><br /> Google OAUTH Problems<br /><a href="https://trufflesecurity.com/blog/google-oauth-is-broken-sort-of/" target="_blank" rel="noreferrer noopener">https://trufflesecurity.com/blog/google-oauth-is-broken-sort-of/</a><br /> Remembering Adrien de Beaupre<br /><a href="https://www.hpmcgarry.ca/memorials/ernest-adrien-de-beaupre/5344136/index.php" target="_blank" rel="noreferrer noopener">https://www.hpmcgarry.ca/memorials/ernest-adrien-de-beaupre/5344136/index.php</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8788.mp3</guid><pubDate>Thu, 21 Dec 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58079054/8788.mp3" length="6411186" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Increase in Exploit Attempts for Atlassian Confluence Server (CVE-2023-22518)
https://isc.sans.edu/diary/Increase%20in%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20Server%20%28CVE-2023-22518%29/30502
 Fake F5 BigIP Update...</itunes:subtitle><itunes:summary><![CDATA[Increase in Exploit Attempts for Atlassian Confluence Server (CVE-2023-22518)<br /><a href="https://isc.sans.edu/diary/Increase%20in%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20Server%20%28CVE-2023-22518%29/30502" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Increase%20in%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20Server%20%28CVE-2023-22518%29/30502</a><br /> Fake F5 BigIP Update<br /><a href="https://www.bleepingcomputer.com/news/security/fake-f5-big-ip-zero-day-warning-emails-push-data-wipers/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/fake-f5-big-ip-zero-day-warning-emails-push-data-wipers/</a><br /> Google OAUTH Problems<br /><a href="https://trufflesecurity.com/blog/google-oauth-is-broken-sort-of/" target="_blank" rel="noreferrer noopener">https://trufflesecurity.com/blog/google-oauth-is-broken-sort-of/</a><br /> Remembering Adrien de Beaupre<br /><a href="https://www.hpmcgarry.ca/memorials/ernest-adrien-de-beaupre/5344136/index.php" target="_blank" rel="noreferrer noopener">https://www.hpmcgarry.ca/memorials/ernest-adrien-de-beaupre/5344136/index.php</a><br />]]></itunes:summary><itunes:duration>436</itunes:duration><itunes:keywords>adrien; google; oauth; f5; big,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8788</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, December 20th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-december-20th-2023--62129484</link><description><![CDATA[What are they looking for? Scans for OpenID Connect Configuration<br /><a href="https://isc.sans.edu/diary/What%20are%20they%20looking%20for%3F%20Scans%20for%20OpenID%20Connect%20Configuration%20%28Update%3A%20CitrixBleed%29/30498" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20are%20they%20looking%20for%3F%20Scans%20for%20OpenID%20Connect%20Configuration%20%28Update%3A%20CitrixBleed%29/30498</a><br /> Terrapin Attack Against SSH<br /><a href="https://terrapin-attack.com/TerrapinAttack.pdf" target="_blank" rel="noreferrer noopener">https://terrapin-attack.com/TerrapinAttack.pdf</a><br /> ALPHV/Blackcat Ransomware Disrupted and Decryptor Available<br /><a href="https://www.justice.gov/opa/pr/justice-department-disrupts-prolific-alphvblackcat-ransomware-variant" target="_blank" rel="noreferrer noopener">https://www.justice.gov/opa/pr/justice-department-disrupts-prolific-alphvblackcat-ransomware-variant</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8786.mp3</guid><pubDate>Wed, 20 Dec 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129484/8786.mp3" length="5501061" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>What are they looking for? Scans for OpenID Connect Configuration
https://isc.sans.edu/diary/What%20are%20they%20looking%20for%3F%20Scans%20for%20OpenID%20Connect%20Configuration%20%28Update%3A%20CitrixBleed%29/30498
 Terrapin Attack Against SSH...</itunes:subtitle><itunes:summary><![CDATA[What are they looking for? Scans for OpenID Connect Configuration<br /><a href="https://isc.sans.edu/diary/What%20are%20they%20looking%20for%3F%20Scans%20for%20OpenID%20Connect%20Configuration%20%28Update%3A%20CitrixBleed%29/30498" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20are%20they%20looking%20for%3F%20Scans%20for%20OpenID%20Connect%20Configuration%20%28Update%3A%20CitrixBleed%29/30498</a><br /> Terrapin Attack Against SSH<br /><a href="https://terrapin-attack.com/TerrapinAttack.pdf" target="_blank" rel="noreferrer noopener">https://terrapin-attack.com/TerrapinAttack.pdf</a><br /> ALPHV/Blackcat Ransomware Disrupted and Decryptor Available<br /><a href="https://www.justice.gov/opa/pr/justice-department-disrupts-prolific-alphvblackcat-ransomware-variant" target="_blank" rel="noreferrer noopener">https://www.justice.gov/opa/pr/justice-department-disrupts-prolific-alphvblackcat-ransomware-variant</a><br />]]></itunes:summary><itunes:duration>371</itunes:duration><itunes:keywords>alphv; blackcat; ransomware; d,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8786</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, December 20th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-december-20th-2023--58067155</link><description><![CDATA[What are they looking for? Scans for OpenID Connect Configuration<br /><a href="https://isc.sans.edu/diary/What%20are%20they%20looking%20for%3F%20Scans%20for%20OpenID%20Connect%20Configuration%20%28Update%3A%20CitrixBleed%29/30498" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20are%20they%20looking%20for%3F%20Scans%20for%20OpenID%20Connect%20Configuration%20%28Update%3A%20CitrixBleed%29/30498</a><br /> Terrapin Attack Against SSH<br /><a href="https://terrapin-attack.com/TerrapinAttack.pdf" target="_blank" rel="noreferrer noopener">https://terrapin-attack.com/TerrapinAttack.pdf</a><br /> ALPHV/Blackcat Ransomware Disrupted and Decryptor Available<br /><a href="https://www.justice.gov/opa/pr/justice-department-disrupts-prolific-alphvblackcat-ransomware-variant" target="_blank" rel="noreferrer noopener">https://www.justice.gov/opa/pr/justice-department-disrupts-prolific-alphvblackcat-ransomware-variant</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8786.mp3</guid><pubDate>Wed, 20 Dec 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58067155/8786.mp3" length="5501061" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>What are they looking for? Scans for OpenID Connect Configuration
https://isc.sans.edu/diary/What%20are%20they%20looking%20for%3F%20Scans%20for%20OpenID%20Connect%20Configuration%20%28Update%3A%20CitrixBleed%29/30498
 Terrapin Attack Against SSH...</itunes:subtitle><itunes:summary><![CDATA[What are they looking for? Scans for OpenID Connect Configuration<br /><a href="https://isc.sans.edu/diary/What%20are%20they%20looking%20for%3F%20Scans%20for%20OpenID%20Connect%20Configuration%20%28Update%3A%20CitrixBleed%29/30498" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20are%20they%20looking%20for%3F%20Scans%20for%20OpenID%20Connect%20Configuration%20%28Update%3A%20CitrixBleed%29/30498</a><br /> Terrapin Attack Against SSH<br /><a href="https://terrapin-attack.com/TerrapinAttack.pdf" target="_blank" rel="noreferrer noopener">https://terrapin-attack.com/TerrapinAttack.pdf</a><br /> ALPHV/Blackcat Ransomware Disrupted and Decryptor Available<br /><a href="https://www.justice.gov/opa/pr/justice-department-disrupts-prolific-alphvblackcat-ransomware-variant" target="_blank" rel="noreferrer noopener">https://www.justice.gov/opa/pr/justice-department-disrupts-prolific-alphvblackcat-ransomware-variant</a><br />]]></itunes:summary><itunes:duration>371</itunes:duration><itunes:keywords>alphv; blackcat; ransomware; d,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8786</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, December 19th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-december-19th-2023--62129456</link><description><![CDATA[SMTP Smuggling - Spoofing E-Mails Worldwide<br /><a href="https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/" target="_blank" rel="noreferrer noopener">https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/</a><br /> Ledger Supply Chain Attack<br /><a href="https://www.ledger.com/blog/a-letter-from-ledger-chairman-ceo-pascal-gauthier-regarding-ledger-connect-kit-exploit" target="_blank" rel="noreferrer noopener">https://www.ledger.com/blog/a-letter-from-ledger-chairman-ceo-pascal-gauthier-regarding-ledger-connect-kit-exploit</a><br /> December Windows 11 Patch Breacks Wi-Fi Connectivity<br /><a href="https://www.bleepingcomputer.com/news/microsoft/decembers-windows-11-kb5033375-update-breaks-wi-fi-connectivity/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/microsoft/decembers-windows-11-kb5033375-update-breaks-wi-fi-connectivity/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8784.mp3</guid><pubDate>Tue, 19 Dec 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129456/8784.mp3" length="5491252" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>SMTP Smuggling - Spoofing E-Mails Worldwide
https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/
 Ledger Supply Chain Attack...</itunes:subtitle><itunes:summary><![CDATA[SMTP Smuggling - Spoofing E-Mails Worldwide<br /><a href="https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/" target="_blank" rel="noreferrer noopener">https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/</a><br /> Ledger Supply Chain Attack<br /><a href="https://www.ledger.com/blog/a-letter-from-ledger-chairman-ceo-pascal-gauthier-regarding-ledger-connect-kit-exploit" target="_blank" rel="noreferrer noopener">https://www.ledger.com/blog/a-letter-from-ledger-chairman-ceo-pascal-gauthier-regarding-ledger-connect-kit-exploit</a><br /> December Windows 11 Patch Breacks Wi-Fi Connectivity<br /><a href="https://www.bleepingcomputer.com/news/microsoft/decembers-windows-11-kb5033375-update-breaks-wi-fi-connectivity/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/microsoft/decembers-windows-11-kb5033375-update-breaks-wi-fi-connectivity/</a><br />]]></itunes:summary><itunes:duration>371</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,windows 11; wifi; ledger; smtp</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8784</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, December 19th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-december-19th-2023--58053656</link><description><![CDATA[SMTP Smuggling - Spoofing E-Mails Worldwide<br /><a href="https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/" target="_blank" rel="noreferrer noopener">https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/</a><br /> Ledger Supply Chain Attack<br /><a href="https://www.ledger.com/blog/a-letter-from-ledger-chairman-ceo-pascal-gauthier-regarding-ledger-connect-kit-exploit" target="_blank" rel="noreferrer noopener">https://www.ledger.com/blog/a-letter-from-ledger-chairman-ceo-pascal-gauthier-regarding-ledger-connect-kit-exploit</a><br /> December Windows 11 Patch Breacks Wi-Fi Connectivity<br /><a href="https://www.bleepingcomputer.com/news/microsoft/decembers-windows-11-kb5033375-update-breaks-wi-fi-connectivity/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/microsoft/decembers-windows-11-kb5033375-update-breaks-wi-fi-connectivity/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8784.mp3</guid><pubDate>Tue, 19 Dec 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58053656/8784.mp3" length="5491252" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>SMTP Smuggling - Spoofing E-Mails Worldwide
https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/
 Ledger Supply Chain Attack...</itunes:subtitle><itunes:summary><![CDATA[SMTP Smuggling - Spoofing E-Mails Worldwide<br /><a href="https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/" target="_blank" rel="noreferrer noopener">https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/</a><br /> Ledger Supply Chain Attack<br /><a href="https://www.ledger.com/blog/a-letter-from-ledger-chairman-ceo-pascal-gauthier-regarding-ledger-connect-kit-exploit" target="_blank" rel="noreferrer noopener">https://www.ledger.com/blog/a-letter-from-ledger-chairman-ceo-pascal-gauthier-regarding-ledger-connect-kit-exploit</a><br /> December Windows 11 Patch Breacks Wi-Fi Connectivity<br /><a href="https://www.bleepingcomputer.com/news/microsoft/decembers-windows-11-kb5033375-update-breaks-wi-fi-connectivity/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/microsoft/decembers-windows-11-kb5033375-update-breaks-wi-fi-connectivity/</a><br />]]></itunes:summary><itunes:duration>371</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,windows 11; wifi; ledger; smtp</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8784</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, December 18th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-december-18th-2023--62129494</link><description><![CDATA[An Example of a RocketMQ Exploit Scanner<br /><a href="https://isc.sans.edu/diary/An%20Example%20of%20RocketMQ%20Exploit%20Scanner/30492" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/An%20Example%20of%20RocketMQ%20Exploit%20Scanner/30492</a><br /> C# Payload Phoning to a Cobalt Strike Server<br /><a href="https://isc.sans.edu/diary/CSharp%20Payload%20Phoning%20to%20a%20CobaltStrike%20Server/30490" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CSharp%20Payload%20Phoning%20to%20a%20CobaltStrike%20Server/30490</a><br /> 3CX SQL Injection Vulnerability<br /><a href="https://www.3cx.com/blog/news/sql-database-integration/" target="_blank" rel="noreferrer noopener">https://www.3cx.com/blog/news/sql-database-integration/</a><br /> QNAP Viostor 0-Day Vulnerablity<br /><a href="https://www.akamai.com/blog/security-research/qnap-viostor-zero-day-vulnerability-spreading-mirai-patched" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/qnap-viostor-zero-day-vulnerability-spreading-mirai-patched</a><br /> PFSense Vulnerability<br /><a href="https://www.sonarsource.com/blog/pfsense-vulnerabilities-sonarcloud/" target="_blank" rel="noreferrer noopener">https://www.sonarsource.com/blog/pfsense-vulnerabilities-sonarcloud/</a><br /> SANS Holiday Hack Challenge<br /><a href="https://sans.org/holidayhack" target="_blank" rel="noreferrer noopener">https://sans.org/holidayhack</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8782.mp3</guid><pubDate>Mon, 18 Dec 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129494/8782.mp3" length="8981230" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>An Example of a RocketMQ Exploit Scanner
https://isc.sans.edu/diary/An%20Example%20of%20RocketMQ%20Exploit%20Scanner/30492
 C# Payload Phoning to a Cobalt Strike Server...</itunes:subtitle><itunes:summary><![CDATA[An Example of a RocketMQ Exploit Scanner<br /><a href="https://isc.sans.edu/diary/An%20Example%20of%20RocketMQ%20Exploit%20Scanner/30492" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/An%20Example%20of%20RocketMQ%20Exploit%20Scanner/30492</a><br /> C# Payload Phoning to a Cobalt Strike Server<br /><a href="https://isc.sans.edu/diary/CSharp%20Payload%20Phoning%20to%20a%20CobaltStrike%20Server/30490" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CSharp%20Payload%20Phoning%20to%20a%20CobaltStrike%20Server/30490</a><br /> 3CX SQL Injection Vulnerability<br /><a href="https://www.3cx.com/blog/news/sql-database-integration/" target="_blank" rel="noreferrer noopener">https://www.3cx.com/blog/news/sql-database-integration/</a><br /> QNAP Viostor 0-Day Vulnerablity<br /><a href="https://www.akamai.com/blog/security-research/qnap-viostor-zero-day-vulnerability-spreading-mirai-patched" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/qnap-viostor-zero-day-vulnerability-spreading-mirai-patched</a><br /> PFSense Vulnerability<br /><a href="https://www.sonarsource.com/blog/pfsense-vulnerabilities-sonarcloud/" target="_blank" rel="noreferrer noopener">https://www.sonarsource.com/blog/pfsense-vulnerabilities-sonarcloud/</a><br /> SANS Holiday Hack Challenge<br /><a href="https://sans.org/holidayhack" target="_blank" rel="noreferrer noopener">https://sans.org/holidayhack</a><br />]]></itunes:summary><itunes:duration>620</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,sans; holiday; hack; challenge,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8782</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, December 18th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-december-18th-2023--58041780</link><description><![CDATA[An Example of a RocketMQ Exploit Scanner<br /><a href="https://isc.sans.edu/diary/An%20Example%20of%20RocketMQ%20Exploit%20Scanner/30492" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/An%20Example%20of%20RocketMQ%20Exploit%20Scanner/30492</a><br /> C# Payload Phoning to a Cobalt Strike Server<br /><a href="https://isc.sans.edu/diary/CSharp%20Payload%20Phoning%20to%20a%20CobaltStrike%20Server/30490" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CSharp%20Payload%20Phoning%20to%20a%20CobaltStrike%20Server/30490</a><br /> 3CX SQL Injection Vulnerability<br /><a href="https://www.3cx.com/blog/news/sql-database-integration/" target="_blank" rel="noreferrer noopener">https://www.3cx.com/blog/news/sql-database-integration/</a><br /> QNAP Viostor 0-Day Vulnerablity<br /><a href="https://www.akamai.com/blog/security-research/qnap-viostor-zero-day-vulnerability-spreading-mirai-patched" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/qnap-viostor-zero-day-vulnerability-spreading-mirai-patched</a><br /> PFSense Vulnerability<br /><a href="https://www.sonarsource.com/blog/pfsense-vulnerabilities-sonarcloud/" target="_blank" rel="noreferrer noopener">https://www.sonarsource.com/blog/pfsense-vulnerabilities-sonarcloud/</a><br /> SANS Holiday Hack Challenge<br /><a href="https://sans.org/holidayhack" target="_blank" rel="noreferrer noopener">https://sans.org/holidayhack</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8782.mp3</guid><pubDate>Mon, 18 Dec 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58041780/8782.mp3" length="8981230" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>An Example of a RocketMQ Exploit Scanner
https://isc.sans.edu/diary/An%20Example%20of%20RocketMQ%20Exploit%20Scanner/30492
 C# Payload Phoning to a Cobalt Strike Server...</itunes:subtitle><itunes:summary><![CDATA[An Example of a RocketMQ Exploit Scanner<br /><a href="https://isc.sans.edu/diary/An%20Example%20of%20RocketMQ%20Exploit%20Scanner/30492" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/An%20Example%20of%20RocketMQ%20Exploit%20Scanner/30492</a><br /> C# Payload Phoning to a Cobalt Strike Server<br /><a href="https://isc.sans.edu/diary/CSharp%20Payload%20Phoning%20to%20a%20CobaltStrike%20Server/30490" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CSharp%20Payload%20Phoning%20to%20a%20CobaltStrike%20Server/30490</a><br /> 3CX SQL Injection Vulnerability<br /><a href="https://www.3cx.com/blog/news/sql-database-integration/" target="_blank" rel="noreferrer noopener">https://www.3cx.com/blog/news/sql-database-integration/</a><br /> QNAP Viostor 0-Day Vulnerablity<br /><a href="https://www.akamai.com/blog/security-research/qnap-viostor-zero-day-vulnerability-spreading-mirai-patched" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/qnap-viostor-zero-day-vulnerability-spreading-mirai-patched</a><br /> PFSense Vulnerability<br /><a href="https://www.sonarsource.com/blog/pfsense-vulnerabilities-sonarcloud/" target="_blank" rel="noreferrer noopener">https://www.sonarsource.com/blog/pfsense-vulnerabilities-sonarcloud/</a><br /> SANS Holiday Hack Challenge<br /><a href="https://sans.org/holidayhack" target="_blank" rel="noreferrer noopener">https://sans.org/holidayhack</a><br />]]></itunes:summary><itunes:duration>620</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,sans; holiday; hack; challenge,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8782</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, December 15th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-december-15th-2023--62129468</link><description><![CDATA[T-shooting Terraform for DShield Honeypot in Azure<br /><a href="https://isc.sans.edu/diary/T-shooting%20Terraform%20for%20DShield%20Honeypot%20in%20Azure%20%5BGuest%20Diary%5D/30484" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/T-shooting%20Terraform%20for%20DShield%20Honeypot%20in%20Azure%20%5BGuest%20Diary%5D/30484</a><br /> Ubiquity Unifi Cameras Visible in Wrong Account<br /><a href="https://community.ui.com/questions/Bug-Fix-Cloud-Access-Misconfiguration/fe8d4479-e187-4471-bf95-b2799183ceb7" target="_blank" rel="noreferrer noopener">https://community.ui.com/questions/Bug-Fix-Cloud-Access-Misconfiguration/fe8d4479-e187-4471-bf95-b2799183ceb7</a><br /> Zoom Vulnerabilities and VISS<br /><a href="https://viss.zoom.com/specifications" target="_blank" rel="noreferrer noopener">https://viss.zoom.com/specifications</a><br /><a href="https://www.zoom.com/en/trust/security-bulletin/" target="_blank" rel="noreferrer noopener">https://www.zoom.com/en/trust/security-bulletin/</a><br /> Squid Denial of Service Vulnerability<br /><a href="https://github.com/squid-cache/squid/security/advisories/GHSA-wgq4-4cfg-c4x3" target="_blank" rel="noreferrer noopener">https://github.com/squid-cache/squid/security/advisories/GHSA-wgq4-4cfg-c4x3</a>]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8780.mp3</guid><pubDate>Fri, 15 Dec 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129468/8780.mp3" length="4836734" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>T-shooting Terraform for DShield Honeypot in Azure
https://isc.sans.edu/diary/T-shooting%20Terraform%20for%20DShield%20Honeypot%20in%20Azure%20%5BGuest%20Diary%5D/30484
 Ubiquity Unifi Cameras Visible in Wrong Account...</itunes:subtitle><itunes:summary><![CDATA[T-shooting Terraform for DShield Honeypot in Azure<br /><a href="https://isc.sans.edu/diary/T-shooting%20Terraform%20for%20DShield%20Honeypot%20in%20Azure%20%5BGuest%20Diary%5D/30484" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/T-shooting%20Terraform%20for%20DShield%20Honeypot%20in%20Azure%20%5BGuest%20Diary%5D/30484</a><br /> Ubiquity Unifi Cameras Visible in Wrong Account<br /><a href="https://community.ui.com/questions/Bug-Fix-Cloud-Access-Misconfiguration/fe8d4479-e187-4471-bf95-b2799183ceb7" target="_blank" rel="noreferrer noopener">https://community.ui.com/questions/Bug-Fix-Cloud-Access-Misconfiguration/fe8d4479-e187-4471-bf95-b2799183ceb7</a><br /> Zoom Vulnerabilities and VISS<br /><a href="https://viss.zoom.com/specifications" target="_blank" rel="noreferrer noopener">https://viss.zoom.com/specifications</a><br /><a href="https://www.zoom.com/en/trust/security-bulletin/" target="_blank" rel="noreferrer noopener">https://www.zoom.com/en/trust/security-bulletin/</a><br /> Squid Denial of Service Vulnerability<br /><a href="https://github.com/squid-cache/squid/security/advisories/GHSA-wgq4-4cfg-c4x3" target="_blank" rel="noreferrer noopener">https://github.com/squid-cache/squid/security/advisories/GHSA-wgq4-4cfg-c4x3</a>]]></itunes:summary><itunes:duration>324</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,squid; zoom; ubiquity; unifi; </itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8780</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, December 15th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-december-15th-2023--58013925</link><description><![CDATA[T-shooting Terraform for DShield Honeypot in Azure<br /><a href="https://isc.sans.edu/diary/T-shooting%20Terraform%20for%20DShield%20Honeypot%20in%20Azure%20%5BGuest%20Diary%5D/30484" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/T-shooting%20Terraform%20for%20DShield%20Honeypot%20in%20Azure%20%5BGuest%20Diary%5D/30484</a><br /> Ubiquity Unifi Cameras Visible in Wrong Account<br /><a href="https://community.ui.com/questions/Bug-Fix-Cloud-Access-Misconfiguration/fe8d4479-e187-4471-bf95-b2799183ceb7" target="_blank" rel="noreferrer noopener">https://community.ui.com/questions/Bug-Fix-Cloud-Access-Misconfiguration/fe8d4479-e187-4471-bf95-b2799183ceb7</a><br /> Zoom Vulnerabilities and VISS<br /><a href="https://viss.zoom.com/specifications" target="_blank" rel="noreferrer noopener">https://viss.zoom.com/specifications</a><br /><a href="https://www.zoom.com/en/trust/security-bulletin/" target="_blank" rel="noreferrer noopener">https://www.zoom.com/en/trust/security-bulletin/</a><br /> Squid Denial of Service Vulnerability<br /><a href="https://www.zoom.com/en/trust/security-bulletin/" target="_blank" rel="noreferrer noopener">https://www.zoom.com/en/trust/security-bulletin/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8780.mp3</guid><pubDate>Fri, 15 Dec 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58013925/8780.mp3" length="4836734" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>T-shooting Terraform for DShield Honeypot in Azure
https://isc.sans.edu/diary/T-shooting%20Terraform%20for%20DShield%20Honeypot%20in%20Azure%20%5BGuest%20Diary%5D/30484
 Ubiquity Unifi Cameras Visible in Wrong Account...</itunes:subtitle><itunes:summary><![CDATA[T-shooting Terraform for DShield Honeypot in Azure<br /><a href="https://isc.sans.edu/diary/T-shooting%20Terraform%20for%20DShield%20Honeypot%20in%20Azure%20%5BGuest%20Diary%5D/30484" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/T-shooting%20Terraform%20for%20DShield%20Honeypot%20in%20Azure%20%5BGuest%20Diary%5D/30484</a><br /> Ubiquity Unifi Cameras Visible in Wrong Account<br /><a href="https://community.ui.com/questions/Bug-Fix-Cloud-Access-Misconfiguration/fe8d4479-e187-4471-bf95-b2799183ceb7" target="_blank" rel="noreferrer noopener">https://community.ui.com/questions/Bug-Fix-Cloud-Access-Misconfiguration/fe8d4479-e187-4471-bf95-b2799183ceb7</a><br /> Zoom Vulnerabilities and VISS<br /><a href="https://viss.zoom.com/specifications" target="_blank" rel="noreferrer noopener">https://viss.zoom.com/specifications</a><br /><a href="https://www.zoom.com/en/trust/security-bulletin/" target="_blank" rel="noreferrer noopener">https://www.zoom.com/en/trust/security-bulletin/</a><br /> Squid Denial of Service Vulnerability<br /><a href="https://www.zoom.com/en/trust/security-bulletin/" target="_blank" rel="noreferrer noopener">https://www.zoom.com/en/trust/security-bulletin/</a><br />]]></itunes:summary><itunes:duration>324</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,squid; zoom; ubiquity; unifi; </itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8780</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, December 14th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-december-14th-2023--62129485</link><description><![CDATA[Malicious Python Script with a TCL/TK GUI<br /><a href="https://isc.sans.edu/diary/Malicious%20Python%20Script%20with%20a%20TCL%20TK%20GUI/30478" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Malicious%20Python%20Script%20with%20a%20TCL%20TK%20GUI/30478</a><br /> Adobe Updates<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> TeamCity Exploited<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-347a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-347a</a><br /> Sophos Firewall Exploit for EOL Devices CVE-2022-3236<br /><a href="https://www.sophos.com/en-us/security-advisories/sophos-sa-20220923-sfos-rce" target="_blank" rel="noreferrer noopener">https://www.sophos.com/en-us/security-advisories/sophos-sa-20220923-sfos-rce</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8778.mp3</guid><pubDate>Thu, 14 Dec 2023 02:10:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129485/8778.mp3" length="4640247" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Malicious Python Script with a TCL/TK GUI
https://isc.sans.edu/diary/Malicious%20Python%20Script%20with%20a%20TCL%20TK%20GUI/30478
 Adobe Updates
https://helpx.adobe.com/security/security-bulletin.html
 TeamCity Exploited...</itunes:subtitle><itunes:summary><![CDATA[Malicious Python Script with a TCL/TK GUI<br /><a href="https://isc.sans.edu/diary/Malicious%20Python%20Script%20with%20a%20TCL%20TK%20GUI/30478" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Malicious%20Python%20Script%20with%20a%20TCL%20TK%20GUI/30478</a><br /> Adobe Updates<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> TeamCity Exploited<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-347a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-347a</a><br /> Sophos Firewall Exploit for EOL Devices CVE-2022-3236<br /><a href="https://www.sophos.com/en-us/security-advisories/sophos-sa-20220923-sfos-rce" target="_blank" rel="noreferrer noopener">https://www.sophos.com/en-us/security-advisories/sophos-sa-20220923-sfos-rce</a><br />]]></itunes:summary><itunes:duration>310</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,sophos; teamcity; adobe; pytho</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8778</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, December 14th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-december-14th-2023--58003729</link><description><![CDATA[Malicious Python Script with a TCL/TK GUI<br /><a href="https://isc.sans.edu/diary/Malicious%20Python%20Script%20with%20a%20TCL%20TK%20GUI/30478" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Malicious%20Python%20Script%20with%20a%20TCL%20TK%20GUI/30478</a><br /> Adobe Updates<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> TeamCity Exploited<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-347a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-347a</a><br /> Sophos Firewall Exploit for EOL Devices CVE-2022-3236<br /><a href="https://www.sophos.com/en-us/security-advisories/sophos-sa-20220923-sfos-rce" target="_blank" rel="noreferrer noopener">https://www.sophos.com/en-us/security-advisories/sophos-sa-20220923-sfos-rce</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8778.mp3</guid><pubDate>Thu, 14 Dec 2023 02:10:05 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/58003729/8778.mp3" length="4640247" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Malicious Python Script with a TCL/TK GUI
https://isc.sans.edu/diary/Malicious%20Python%20Script%20with%20a%20TCL%20TK%20GUI/30478
 Adobe Updates
https://helpx.adobe.com/security/security-bulletin.html
 TeamCity Exploited...</itunes:subtitle><itunes:summary><![CDATA[Malicious Python Script with a TCL/TK GUI<br /><a href="https://isc.sans.edu/diary/Malicious%20Python%20Script%20with%20a%20TCL%20TK%20GUI/30478" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Malicious%20Python%20Script%20with%20a%20TCL%20TK%20GUI/30478</a><br /> Adobe Updates<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> TeamCity Exploited<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-347a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-347a</a><br /> Sophos Firewall Exploit for EOL Devices CVE-2022-3236<br /><a href="https://www.sophos.com/en-us/security-advisories/sophos-sa-20220923-sfos-rce" target="_blank" rel="noreferrer noopener">https://www.sophos.com/en-us/security-advisories/sophos-sa-20220923-sfos-rce</a><br />]]></itunes:summary><itunes:duration>310</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,sophos; teamcity; adobe; pytho</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8778</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, December 13th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-december-13th-2023--62129441</link><description><![CDATA[Microsoft Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20December%202023/30480" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20December%202023/30480</a><br /> Microsoft Warns of Malicious OAUTH Applications<br /><a href="https://www.microsoft.com/en-us/security/blog/2023/12/12/threat-actors-misuse-oauth-applications-to-automate-financially-driven-attacks/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2023/12/12/threat-actors-misuse-oauth-applications-to-automate-financially-driven-attacks/</a><br /> Apache Struts2 Exploit CVE-2023-50164<br /><a href="https://xz.aliyun.com/t/13172" target="_blank" rel="noreferrer noopener">https://xz.aliyun.com/t/13172</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8776.mp3</guid><pubDate>Wed, 13 Dec 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129441/8776.mp3" length="5386652" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20December%202023/30480
 Microsoft Warns of Malicious OAUTH Applications...</itunes:subtitle><itunes:summary><![CDATA[Microsoft Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20December%202023/30480" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20December%202023/30480</a><br /> Microsoft Warns of Malicious OAUTH Applications<br /><a href="https://www.microsoft.com/en-us/security/blog/2023/12/12/threat-actors-misuse-oauth-applications-to-automate-financially-driven-attacks/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2023/12/12/threat-actors-misuse-oauth-applications-to-automate-financially-driven-attacks/</a><br /> Apache Struts2 Exploit CVE-2023-50164<br /><a href="https://xz.aliyun.com/t/13172" target="_blank" rel="noreferrer noopener">https://xz.aliyun.com/t/13172</a><br />]]></itunes:summary><itunes:duration>363</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,struts2; microsoft; patches; o</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8776</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, December 13th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-december-13th-2023--57990902</link><description><![CDATA[Microsoft Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20December%202023/30480" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20December%202023/30480</a><br /> Microsoft Warns of Malicious OAUTH Applications<br /><a href="https://www.microsoft.com/en-us/security/blog/2023/12/12/threat-actors-misuse-oauth-applications-to-automate-financially-driven-attacks/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2023/12/12/threat-actors-misuse-oauth-applications-to-automate-financially-driven-attacks/</a><br /> Apache Struts2 Exploit CVE-2023-50164<br /><a href="https://xz.aliyun.com/t/13172" target="_blank" rel="noreferrer noopener">https://xz.aliyun.com/t/13172</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8776.mp3</guid><pubDate>Wed, 13 Dec 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57990902/8776.mp3" length="5386652" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20December%202023/30480
 Microsoft Warns of Malicious OAUTH Applications...</itunes:subtitle><itunes:summary><![CDATA[Microsoft Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20December%202023/30480" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20December%202023/30480</a><br /> Microsoft Warns of Malicious OAUTH Applications<br /><a href="https://www.microsoft.com/en-us/security/blog/2023/12/12/threat-actors-misuse-oauth-applications-to-automate-financially-driven-attacks/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2023/12/12/threat-actors-misuse-oauth-applications-to-automate-financially-driven-attacks/</a><br /> Apache Struts2 Exploit CVE-2023-50164<br /><a href="https://xz.aliyun.com/t/13172" target="_blank" rel="noreferrer noopener">https://xz.aliyun.com/t/13172</a><br />]]></itunes:summary><itunes:duration>363</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,struts2; microsoft; patches; o</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8776</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, December 12th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-december-12th-2023--62129446</link><description><![CDATA[What is Sitemap.xml and Why a Pentester Should Care<br /><a href="https://isc.sans.edu/diary/What%20is%20sitemap.xml%2C%20and%20Why%20a%20Pentester%20Should%20Care/30472" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20is%20sitemap.xml%2C%20and%20Why%20a%20Pentester%20Should%20Care/30472</a><br /> Apple Patches Everything<br /><a href="https://isc.sans.edu/forums/diary/Apple%20Patches%20Everything/30474/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Apple%20Patches%20Everything/30474/</a><br /> Android Password Manager Auto Spill<br /><a href="https://i.blackhat.com/EU-23/Presentations/EU-23-Gangwal-AutoSpill-Zero-Effort-Credential-Stealing.pdf" target="_blank" rel="noreferrer noopener">https://i.blackhat.com/EU-23/Presentations/EU-23-Gangwal-AutoSpill-Zero-Effort-Credential-Stealing.pdf</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8774.mp3</guid><pubDate>Tue, 12 Dec 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129446/8774.mp3" length="5000685" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>What is Sitemap.xml and Why a Pentester Should Care
https://isc.sans.edu/diary/What%20is%20sitemap.xml%2C%20and%20Why%20a%20Pentester%20Should%20Care/30472
 Apple Patches Everything
https://isc.sans.edu/forums/diary/Apple%20Patches%20Everything/30474/...</itunes:subtitle><itunes:summary><![CDATA[What is Sitemap.xml and Why a Pentester Should Care<br /><a href="https://isc.sans.edu/diary/What%20is%20sitemap.xml%2C%20and%20Why%20a%20Pentester%20Should%20Care/30472" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20is%20sitemap.xml%2C%20and%20Why%20a%20Pentester%20Should%20Care/30472</a><br /> Apple Patches Everything<br /><a href="https://isc.sans.edu/forums/diary/Apple%20Patches%20Everything/30474/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Apple%20Patches%20Everything/30474/</a><br /> Android Password Manager Auto Spill<br /><a href="https://i.blackhat.com/EU-23/Presentations/EU-23-Gangwal-AutoSpill-Zero-Effort-Credential-Stealing.pdf" target="_blank" rel="noreferrer noopener">https://i.blackhat.com/EU-23/Presentations/EU-23-Gangwal-AutoSpill-Zero-Effort-Credential-Stealing.pdf</a><br />]]></itunes:summary><itunes:duration>336</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,sitemap.xml; apple patches; an</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8774</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, December 12th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-december-12th-2023--57980319</link><description><![CDATA[What is Sitemap.xml and Why a Pentester Should Care<br /><a href="https://isc.sans.edu/diary/What%20is%20sitemap.xml%2C%20and%20Why%20a%20Pentester%20Should%20Care/30472" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20is%20sitemap.xml%2C%20and%20Why%20a%20Pentester%20Should%20Care/30472</a><br /> Apple Patches Everything<br /><a href="https://isc.sans.edu/forums/diary/Apple%20Patches%20Everything/30474/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Apple%20Patches%20Everything/30474/</a><br /> Android Password Manager Auto Spill<br /><a href="https://i.blackhat.com/EU-23/Presentations/EU-23-Gangwal-AutoSpill-Zero-Effort-Credential-Stealing.pdf" target="_blank" rel="noreferrer noopener">https://i.blackhat.com/EU-23/Presentations/EU-23-Gangwal-AutoSpill-Zero-Effort-Credential-Stealing.pdf</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8774.mp3</guid><pubDate>Tue, 12 Dec 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57980319/8774.mp3" length="5000685" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>What is Sitemap.xml and Why a Pentester Should Care
https://isc.sans.edu/diary/What%20is%20sitemap.xml%2C%20and%20Why%20a%20Pentester%20Should%20Care/30472
 Apple Patches Everything
https://isc.sans.edu/forums/diary/Apple%20Patches%20Everything/30474/...</itunes:subtitle><itunes:summary><![CDATA[What is Sitemap.xml and Why a Pentester Should Care<br /><a href="https://isc.sans.edu/diary/What%20is%20sitemap.xml%2C%20and%20Why%20a%20Pentester%20Should%20Care/30472" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20is%20sitemap.xml%2C%20and%20Why%20a%20Pentester%20Should%20Care/30472</a><br /> Apple Patches Everything<br /><a href="https://isc.sans.edu/forums/diary/Apple%20Patches%20Everything/30474/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Apple%20Patches%20Everything/30474/</a><br /> Android Password Manager Auto Spill<br /><a href="https://i.blackhat.com/EU-23/Presentations/EU-23-Gangwal-AutoSpill-Zero-Effort-Credential-Stealing.pdf" target="_blank" rel="noreferrer noopener">https://i.blackhat.com/EU-23/Presentations/EU-23-Gangwal-AutoSpill-Zero-Effort-Credential-Stealing.pdf</a><br />]]></itunes:summary><itunes:duration>336</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,sitemap.xml; apple patches; an</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8774</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, December 11th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-december-11th-2023--62129448</link><description><![CDATA[IPv4 Mapped IPv6 Addresses<br /><a href="https://isc.sans.edu/diary/IPv4-mapped%20IPv6%20Address%20Used%20For%20Obfuscation/30466" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/IPv4-mapped%20IPv6%20Address%20Used%20For%20Obfuscation/30466</a><br /> Honeypots From the Skeptical Beginner to the Tactical Enthusiast<br /><a href="https://isc.sans.edu/diary/Honeypots%3A%20From%20the%20Skeptical%20Beginner%20to%20the%20Tactical%20Enthusiast/30468" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Honeypots%3A%20From%20the%20Skeptical%20Beginner%20to%20the%20Tactical%20Enthusiast/30468</a><br /> Bluetooth Weakness CVE-2023-45866<br /><a href="https://github.com/skysafe/reblog/tree/main/cve-2023-45866" target="_blank" rel="noreferrer noopener">https://github.com/skysafe/reblog/tree/main/cve-2023-45866</a><br /> Syrus 4 IoT Gateway Vulnerability CVE-2023-6248<br /><a href="https://socradar.io/syrus4-iot-gateway-vulnerability-could-allow-code-execution-on-thousands-of-vehicles-simultaneously-cve-2023-6248/" target="_blank" rel="noreferrer noopener">https://socradar.io/syrus4-iot-gateway-vulnerability-could-allow-code-execution-on-thousands-of-vehicles-simultaneously-cve-2023-6248/</a><br /> Microsoft Edge Vulnerability CVE-2023-35618<br /><a href="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#december-7-2023" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#december-7-2023</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8772.mp3</guid><pubDate>Mon, 11 Dec 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129448/8772.mp3" length="5557316" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>IPv4 Mapped IPv6 Addresses
https://isc.sans.edu/diary/IPv4-mapped%20IPv6%20Address%20Used%20For%20Obfuscation/30466
 Honeypots From the Skeptical Beginner to the Tactical Enthusiast...</itunes:subtitle><itunes:summary><![CDATA[IPv4 Mapped IPv6 Addresses<br /><a href="https://isc.sans.edu/diary/IPv4-mapped%20IPv6%20Address%20Used%20For%20Obfuscation/30466" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/IPv4-mapped%20IPv6%20Address%20Used%20For%20Obfuscation/30466</a><br /> Honeypots From the Skeptical Beginner to the Tactical Enthusiast<br /><a href="https://isc.sans.edu/diary/Honeypots%3A%20From%20the%20Skeptical%20Beginner%20to%20the%20Tactical%20Enthusiast/30468" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Honeypots%3A%20From%20the%20Skeptical%20Beginner%20to%20the%20Tactical%20Enthusiast/30468</a><br /> Bluetooth Weakness CVE-2023-45866<br /><a href="https://github.com/skysafe/reblog/tree/main/cve-2023-45866" target="_blank" rel="noreferrer noopener">https://github.com/skysafe/reblog/tree/main/cve-2023-45866</a><br /> Syrus 4 IoT Gateway Vulnerability CVE-2023-6248<br /><a href="https://socradar.io/syrus4-iot-gateway-vulnerability-could-allow-code-execution-on-thousands-of-vehicles-simultaneously-cve-2023-6248/" target="_blank" rel="noreferrer noopener">https://socradar.io/syrus4-iot-gateway-vulnerability-could-allow-code-execution-on-thousands-of-vehicles-simultaneously-cve-2023-6248/</a><br /> Microsoft Edge Vulnerability CVE-2023-35618<br /><a href="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#december-7-2023" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#december-7-2023</a><br />]]></itunes:summary><itunes:duration>375</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microsoft; edge; syrus; iot; g,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8772</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, December 11th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-december-11th-2023--57969504</link><description><![CDATA[IPv4 Mapped IPv6 Addresses<br /><a href="https://isc.sans.edu/diary/IPv4-mapped%20IPv6%20Address%20Used%20For%20Obfuscation/30466" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/IPv4-mapped%20IPv6%20Address%20Used%20For%20Obfuscation/30466</a><br /> Honeypots From the Skeptical Beginner to the Tactical Enthusiast<br /><a href="https://isc.sans.edu/diary/Honeypots%3A%20From%20the%20Skeptical%20Beginner%20to%20the%20Tactical%20Enthusiast/30468" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Honeypots%3A%20From%20the%20Skeptical%20Beginner%20to%20the%20Tactical%20Enthusiast/30468</a><br /> Bluetooth Weakness CVE-2023-45866<br /><a href="https://github.com/skysafe/reblog/tree/main/cve-2023-45866" target="_blank" rel="noreferrer noopener">https://github.com/skysafe/reblog/tree/main/cve-2023-45866</a><br /> Syrus 4 IoT Gateway Vulnerability CVE-2023-6248<br /><a href="https://socradar.io/syrus4-iot-gateway-vulnerability-could-allow-code-execution-on-thousands-of-vehicles-simultaneously-cve-2023-6248/" target="_blank" rel="noreferrer noopener">https://socradar.io/syrus4-iot-gateway-vulnerability-could-allow-code-execution-on-thousands-of-vehicles-simultaneously-cve-2023-6248/</a><br /> Microsoft Edge Vulnerability CVE-2023-35618<br /><a href="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#december-7-2023" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#december-7-2023</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8772.mp3</guid><pubDate>Mon, 11 Dec 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57969504/8772.mp3" length="5557316" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>IPv4 Mapped IPv6 Addresses
https://isc.sans.edu/diary/IPv4-mapped%20IPv6%20Address%20Used%20For%20Obfuscation/30466
 Honeypots From the Skeptical Beginner to the Tactical Enthusiast...</itunes:subtitle><itunes:summary><![CDATA[IPv4 Mapped IPv6 Addresses<br /><a href="https://isc.sans.edu/diary/IPv4-mapped%20IPv6%20Address%20Used%20For%20Obfuscation/30466" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/IPv4-mapped%20IPv6%20Address%20Used%20For%20Obfuscation/30466</a><br /> Honeypots From the Skeptical Beginner to the Tactical Enthusiast<br /><a href="https://isc.sans.edu/diary/Honeypots%3A%20From%20the%20Skeptical%20Beginner%20to%20the%20Tactical%20Enthusiast/30468" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Honeypots%3A%20From%20the%20Skeptical%20Beginner%20to%20the%20Tactical%20Enthusiast/30468</a><br /> Bluetooth Weakness CVE-2023-45866<br /><a href="https://github.com/skysafe/reblog/tree/main/cve-2023-45866" target="_blank" rel="noreferrer noopener">https://github.com/skysafe/reblog/tree/main/cve-2023-45866</a><br /> Syrus 4 IoT Gateway Vulnerability CVE-2023-6248<br /><a href="https://socradar.io/syrus4-iot-gateway-vulnerability-could-allow-code-execution-on-thousands-of-vehicles-simultaneously-cve-2023-6248/" target="_blank" rel="noreferrer noopener">https://socradar.io/syrus4-iot-gateway-vulnerability-could-allow-code-execution-on-thousands-of-vehicles-simultaneously-cve-2023-6248/</a><br /> Microsoft Edge Vulnerability CVE-2023-35618<br /><a href="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#december-7-2023" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#december-7-2023</a><br />]]></itunes:summary><itunes:duration>375</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microsoft; edge; syrus; iot; g,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8772</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, December 8th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-december-8th-2023--62129487</link><description><![CDATA[5G Vulnerabilities<br /><a href="https://isc.sans.edu/diary/5Ghoul%3A%20Impacts%2C%20Implications%20and%20Next%20Steps/30462" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/5Ghoul%3A%20Impacts%2C%20Implications%20and%20Next%20Steps/30462</a><br /> Revealing the hidden Risks of QR Codes<br /><a href="https://isc.sans.edu/diary/Revealing%20the%20Hidden%20Risks%20of%20QR%20Codes%20%5BGuest%20Diary%5D/30458" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Revealing%20the%20Hidden%20Risks%20of%20QR%20Codes%20%5BGuest%20Diary%5D/30458</a><br /> Window 10 End of Support<br /><a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/plan-for-windows-10-eos-with-windows-11-windows-365-and-esu/ba-p/4000414" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/windows-it-pro-blog/plan-for-windows-10-eos-with-windows-11-windows-365-and-esu/ba-p/4000414</a><br /> Apache Struts 2 Vulnerability CVE-2023-50164<br /><a href="https://cwiki.apache.org/confluence/display/WW/S2-066" target="_blank" rel="noreferrer noopener">https://cwiki.apache.org/confluence/display/WW/S2-066</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8770.mp3</guid><pubDate>Fri, 08 Dec 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129487/8770.mp3" length="5542157" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>5G Vulnerabilities
https://isc.sans.edu/diary/5Ghoul%3A%20Impacts%2C%20Implications%20and%20Next%20Steps/30462
 Revealing the hidden Risks of QR Codes...</itunes:subtitle><itunes:summary><![CDATA[5G Vulnerabilities<br /><a href="https://isc.sans.edu/diary/5Ghoul%3A%20Impacts%2C%20Implications%20and%20Next%20Steps/30462" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/5Ghoul%3A%20Impacts%2C%20Implications%20and%20Next%20Steps/30462</a><br /> Revealing the hidden Risks of QR Codes<br /><a href="https://isc.sans.edu/diary/Revealing%20the%20Hidden%20Risks%20of%20QR%20Codes%20%5BGuest%20Diary%5D/30458" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Revealing%20the%20Hidden%20Risks%20of%20QR%20Codes%20%5BGuest%20Diary%5D/30458</a><br /> Window 10 End of Support<br /><a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/plan-for-windows-10-eos-with-windows-11-windows-365-and-esu/ba-p/4000414" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/windows-it-pro-blog/plan-for-windows-10-eos-with-windows-11-windows-365-and-esu/ba-p/4000414</a><br /> Apache Struts 2 Vulnerability CVE-2023-50164<br /><a href="https://cwiki.apache.org/confluence/display/WW/S2-066" target="_blank" rel="noreferrer noopener">https://cwiki.apache.org/confluence/display/WW/S2-066</a><br />]]></itunes:summary><itunes:duration>374</itunes:duration><itunes:keywords>apache; struts; windows 10; en,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8770</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, December 8th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-december-8th-2023--57947539</link><description><![CDATA[5G Vulnerabilities<br /><a href="https://isc.sans.edu/diary/5Ghoul%3A%20Impacts%2C%20Implications%20and%20Next%20Steps/30462" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/5Ghoul%3A%20Impacts%2C%20Implications%20and%20Next%20Steps/30462</a><br /> Revealing the hidden Risks of QR Codes<br /><a href="https://isc.sans.edu/diary/Revealing%20the%20Hidden%20Risks%20of%20QR%20Codes%20%5BGuest%20Diary%5D/30458" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Revealing%20the%20Hidden%20Risks%20of%20QR%20Codes%20%5BGuest%20Diary%5D/30458</a><br /> Window 10 End of Support<br /><a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/plan-for-windows-10-eos-with-windows-11-windows-365-and-esu/ba-p/4000414" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/windows-it-pro-blog/plan-for-windows-10-eos-with-windows-11-windows-365-and-esu/ba-p/4000414</a><br /> Apache Struts 2 Vulnerability CVE-2023-50164<br /><a href="https://cwiki.apache.org/confluence/display/WW/S2-066" target="_blank" rel="noreferrer noopener">https://cwiki.apache.org/confluence/display/WW/S2-066</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8770.mp3</guid><pubDate>Fri, 08 Dec 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57947539/8770.mp3" length="5542157" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>5G Vulnerabilities
https://isc.sans.edu/diary/5Ghoul%3A%20Impacts%2C%20Implications%20and%20Next%20Steps/30462
 Revealing the hidden Risks of QR Codes...</itunes:subtitle><itunes:summary><![CDATA[5G Vulnerabilities<br /><a href="https://isc.sans.edu/diary/5Ghoul%3A%20Impacts%2C%20Implications%20and%20Next%20Steps/30462" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/5Ghoul%3A%20Impacts%2C%20Implications%20and%20Next%20Steps/30462</a><br /> Revealing the hidden Risks of QR Codes<br /><a href="https://isc.sans.edu/diary/Revealing%20the%20Hidden%20Risks%20of%20QR%20Codes%20%5BGuest%20Diary%5D/30458" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Revealing%20the%20Hidden%20Risks%20of%20QR%20Codes%20%5BGuest%20Diary%5D/30458</a><br /> Window 10 End of Support<br /><a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/plan-for-windows-10-eos-with-windows-11-windows-365-and-esu/ba-p/4000414" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/windows-it-pro-blog/plan-for-windows-10-eos-with-windows-11-windows-365-and-esu/ba-p/4000414</a><br /> Apache Struts 2 Vulnerability CVE-2023-50164<br /><a href="https://cwiki.apache.org/confluence/display/WW/S2-066" target="_blank" rel="noreferrer noopener">https://cwiki.apache.org/confluence/display/WW/S2-066</a><br />]]></itunes:summary><itunes:duration>374</itunes:duration><itunes:keywords>apache; struts; windows 10; en,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8770</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, December 7th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-december-7th-2023--62129459</link><description><![CDATA[Whose packet is is anyway: a new RFC for attribution of internet probes<br /><a href="https://isc.sans.edu/forums/diary/Whose%20packet%20is%20it%20anyway%3A%20a%20new%20RFC%20for%20attribution%20of%20internet%20probes/30456/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Whose%20packet%20is%20it%20anyway%3A%20a%20new%20RFC%20for%20attribution%20of%20internet%20probes/30456/</a><br /> MLFlow Vulnerability<br /><a href="https://www.contrastsecurity.com/security-influencers/discovering-mlflow-framework-zero-day-vulnerability-machine-language-model-security-contrast-security" target="_blank" rel="noreferrer noopener">https://www.contrastsecurity.com/security-influencers/discovering-mlflow-framework-zero-day-vulnerability-machine-language-model-security-contrast-security</a><br /><a href="https://mlflow.org/category/news/index.html" target="_blank" rel="noreferrer noopener">https://mlflow.org/category/news/index.html</a><br /> Abusing STS Tokens<br /><a href="https://redcanary.com/blog/aws-sts/" target="_blank" rel="noreferrer noopener">https://redcanary.com/blog/aws-sts/</a><br /> Atlasian Vulnerabilities<br /><a href="https://confluence.atlassian.com/security/security-advisories-bulletins-1236937381.html" target="_blank" rel="noreferrer noopener">https://confluence.atlassian.com/security/security-advisories-bulletins-1236937381.html</a><br /> Holiday Hack Challenge<br /><a href="https://www.sans.org/mlp/holiday-hack-challenge-2023/" target="_blank" rel="noreferrer noopener">https://www.sans.org/mlp/holiday-hack-challenge-2023/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8768.mp3</guid><pubDate>Thu, 07 Dec 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129459/8768.mp3" length="5203792" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Whose packet is is anyway: a new RFC for attribution of internet probes
https://isc.sans.edu/forums/diary/Whose%20packet%20is%20it%20anyway%3A%20a%20new%20RFC%20for%20attribution%20of%20internet%20probes/30456/
 MLFlow Vulnerability...</itunes:subtitle><itunes:summary><![CDATA[Whose packet is is anyway: a new RFC for attribution of internet probes<br /><a href="https://isc.sans.edu/forums/diary/Whose%20packet%20is%20it%20anyway%3A%20a%20new%20RFC%20for%20attribution%20of%20internet%20probes/30456/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Whose%20packet%20is%20it%20anyway%3A%20a%20new%20RFC%20for%20attribution%20of%20internet%20probes/30456/</a><br /> MLFlow Vulnerability<br /><a href="https://www.contrastsecurity.com/security-influencers/discovering-mlflow-framework-zero-day-vulnerability-machine-language-model-security-contrast-security" target="_blank" rel="noreferrer noopener">https://www.contrastsecurity.com/security-influencers/discovering-mlflow-framework-zero-day-vulnerability-machine-language-model-security-contrast-security</a><br /><a href="https://mlflow.org/category/news/index.html" target="_blank" rel="noreferrer noopener">https://mlflow.org/category/news/index.html</a><br /> Abusing STS Tokens<br /><a href="https://redcanary.com/blog/aws-sts/" target="_blank" rel="noreferrer noopener">https://redcanary.com/blog/aws-sts/</a><br /> Atlasian Vulnerabilities<br /><a href="https://confluence.atlassian.com/security/security-advisories-bulletins-1236937381.html" target="_blank" rel="noreferrer noopener">https://confluence.atlassian.com/security/security-advisories-bulletins-1236937381.html</a><br /> Holiday Hack Challenge<br /><a href="https://www.sans.org/mlp/holiday-hack-challenge-2023/" target="_blank" rel="noreferrer noopener">https://www.sans.org/mlp/holiday-hack-challenge-2023/</a><br />]]></itunes:summary><itunes:duration>350</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,holiday hack challenge; atlasi,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8768</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, December 7th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-december-7th-2023--57935284</link><description><![CDATA[Whose packet is is anyway: a new RFC for attribution of internet probes<br /><a href="https://isc.sans.edu/forums/diary/Whose%20packet%20is%20it%20anyway%3A%20a%20new%20RFC%20for%20attribution%20of%20internet%20probes/30456/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Whose%20packet%20is%20it%20anyway%3A%20a%20new%20RFC%20for%20attribution%20of%20internet%20probes/30456/</a><br /> MLFlow Vulnerability<br /><a href="https://www.contrastsecurity.com/security-influencers/discovering-mlflow-framework-zero-day-vulnerability-machine-language-model-security-contrast-security" target="_blank" rel="noreferrer noopener">https://www.contrastsecurity.com/security-influencers/discovering-mlflow-framework-zero-day-vulnerability-machine-language-model-security-contrast-security</a><br /><a href="https://mlflow.org/category/news/index.html" target="_blank" rel="noreferrer noopener">https://mlflow.org/category/news/index.html</a><br /> Abusing STS Tokens<br /><a href="https://redcanary.com/blog/aws-sts/" target="_blank" rel="noreferrer noopener">https://redcanary.com/blog/aws-sts/</a><br /> Atlasian Vulnerabilities<br /><a href="https://confluence.atlassian.com/security/security-advisories-bulletins-1236937381.html" target="_blank" rel="noreferrer noopener">https://confluence.atlassian.com/security/security-advisories-bulletins-1236937381.html</a><br /> Holiday Hack Challenge<br /><a href="https://www.sans.org/mlp/holiday-hack-challenge-2023/" target="_blank" rel="noreferrer noopener">https://www.sans.org/mlp/holiday-hack-challenge-2023/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8768.mp3</guid><pubDate>Thu, 07 Dec 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57935284/8768.mp3" length="5203792" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Whose packet is is anyway: a new RFC for attribution of internet probes
https://isc.sans.edu/forums/diary/Whose%20packet%20is%20it%20anyway%3A%20a%20new%20RFC%20for%20attribution%20of%20internet%20probes/30456/
 MLFlow Vulnerability...</itunes:subtitle><itunes:summary><![CDATA[Whose packet is is anyway: a new RFC for attribution of internet probes<br /><a href="https://isc.sans.edu/forums/diary/Whose%20packet%20is%20it%20anyway%3A%20a%20new%20RFC%20for%20attribution%20of%20internet%20probes/30456/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Whose%20packet%20is%20it%20anyway%3A%20a%20new%20RFC%20for%20attribution%20of%20internet%20probes/30456/</a><br /> MLFlow Vulnerability<br /><a href="https://www.contrastsecurity.com/security-influencers/discovering-mlflow-framework-zero-day-vulnerability-machine-language-model-security-contrast-security" target="_blank" rel="noreferrer noopener">https://www.contrastsecurity.com/security-influencers/discovering-mlflow-framework-zero-day-vulnerability-machine-language-model-security-contrast-security</a><br /><a href="https://mlflow.org/category/news/index.html" target="_blank" rel="noreferrer noopener">https://mlflow.org/category/news/index.html</a><br /> Abusing STS Tokens<br /><a href="https://redcanary.com/blog/aws-sts/" target="_blank" rel="noreferrer noopener">https://redcanary.com/blog/aws-sts/</a><br /> Atlasian Vulnerabilities<br /><a href="https://confluence.atlassian.com/security/security-advisories-bulletins-1236937381.html" target="_blank" rel="noreferrer noopener">https://confluence.atlassian.com/security/security-advisories-bulletins-1236937381.html</a><br /> Holiday Hack Challenge<br /><a href="https://www.sans.org/mlp/holiday-hack-challenge-2023/" target="_blank" rel="noreferrer noopener">https://www.sans.org/mlp/holiday-hack-challenge-2023/</a><br />]]></itunes:summary><itunes:duration>350</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,holiday hack challenge; atlasi,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8768</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, December 6th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-december-6th-2023--62129473</link><description><![CDATA[Cobalt Strike's "Runtime Configuration"<br /><a href="https://isc.sans.edu/diary/Cobalt%20Strike%27s%20%22Runtime%20Configuration%22/30426" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Cobalt%20Strike%27s%20%22Runtime%20Configuration%22/30426</a><br /> Adobe ColdFusion Exploit Abused<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-339a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-339a</a><br /> Atos Unify OpenScape Vulnerability<br /><a href="https://sec-consult.com/vulnerability-lab/advisory/argument-injection-vulnerability-in-multiple-atos-unify-openscape-products/" target="_blank" rel="noreferrer noopener">https://sec-consult.com/vulnerability-lab/advisory/argument-injection-vulnerability-in-multiple-atos-unify-openscape-products/</a><br /> ExtremeXOS Vulnerabilities<br /><a href="https://rhinosecuritylabs.com/research/extreme-networks-extremexos-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://rhinosecuritylabs.com/research/extreme-networks-extremexos-vulnerabilities/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8766.mp3</guid><pubDate>Wed, 06 Dec 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129473/8766.mp3" length="4988445" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Cobalt Strike's "Runtime Configuration"
https://isc.sans.edu/diary/Cobalt%20Strike%27s%20%22Runtime%20Configuration%22/30426
 Adobe ColdFusion Exploit Abused
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-339a
 Atos Unify OpenScape...</itunes:subtitle><itunes:summary><![CDATA[Cobalt Strike's "Runtime Configuration"<br /><a href="https://isc.sans.edu/diary/Cobalt%20Strike%27s%20%22Runtime%20Configuration%22/30426" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Cobalt%20Strike%27s%20%22Runtime%20Configuration%22/30426</a><br /> Adobe ColdFusion Exploit Abused<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-339a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-339a</a><br /> Atos Unify OpenScape Vulnerability<br /><a href="https://sec-consult.com/vulnerability-lab/advisory/argument-injection-vulnerability-in-multiple-atos-unify-openscape-products/" target="_blank" rel="noreferrer noopener">https://sec-consult.com/vulnerability-lab/advisory/argument-injection-vulnerability-in-multiple-atos-unify-openscape-products/</a><br /> ExtremeXOS Vulnerabilities<br /><a href="https://rhinosecuritylabs.com/research/extreme-networks-extremexos-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://rhinosecuritylabs.com/research/extreme-networks-extremexos-vulnerabilities/</a><br />]]></itunes:summary><itunes:duration>335</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,extremexos; atos; unify; opens,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8766</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, December 6th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-december-6th-2023--57924200</link><description><![CDATA[Cobalt Strike's "Runtime Configuration"<br /><a href="https://isc.sans.edu/diary/Cobalt%20Strike%27s%20%22Runtime%20Configuration%22/30426" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Cobalt%20Strike%27s%20%22Runtime%20Configuration%22/30426</a><br /> Adobe ColdFusion Exploit Abused<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-339a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-339a</a><br /> Atos Unify OpenScape Vulnerability<br /><a href="https://sec-consult.com/vulnerability-lab/advisory/argument-injection-vulnerability-in-multiple-atos-unify-openscape-products/" target="_blank" rel="noreferrer noopener">https://sec-consult.com/vulnerability-lab/advisory/argument-injection-vulnerability-in-multiple-atos-unify-openscape-products/</a><br /> ExtremeXOS Vulnerabilities<br /><a href="https://rhinosecuritylabs.com/research/extreme-networks-extremexos-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://rhinosecuritylabs.com/research/extreme-networks-extremexos-vulnerabilities/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8766.mp3</guid><pubDate>Wed, 06 Dec 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57924200/8766.mp3" length="4988445" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Cobalt Strike's "Runtime Configuration"
https://isc.sans.edu/diary/Cobalt%20Strike%27s%20%22Runtime%20Configuration%22/30426
 Adobe ColdFusion Exploit Abused
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-339a
 Atos Unify OpenScape...</itunes:subtitle><itunes:summary><![CDATA[Cobalt Strike's "Runtime Configuration"<br /><a href="https://isc.sans.edu/diary/Cobalt%20Strike%27s%20%22Runtime%20Configuration%22/30426" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Cobalt%20Strike%27s%20%22Runtime%20Configuration%22/30426</a><br /> Adobe ColdFusion Exploit Abused<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-339a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-339a</a><br /> Atos Unify OpenScape Vulnerability<br /><a href="https://sec-consult.com/vulnerability-lab/advisory/argument-injection-vulnerability-in-multiple-atos-unify-openscape-products/" target="_blank" rel="noreferrer noopener">https://sec-consult.com/vulnerability-lab/advisory/argument-injection-vulnerability-in-multiple-atos-unify-openscape-products/</a><br /> ExtremeXOS Vulnerabilities<br /><a href="https://rhinosecuritylabs.com/research/extreme-networks-extremexos-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://rhinosecuritylabs.com/research/extreme-networks-extremexos-vulnerabilities/</a><br />]]></itunes:summary><itunes:duration>335</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,extremexos; atos; unify; opens,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8766</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, December 5th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-december-5th-2023--62129478</link><description><![CDATA[Zarya Hacktivists: More than just Sharepoint<br /><a href="https://isc.sans.edu/diary/Zarya%20Hacktivists%3A%20More%20than%20just%20Sharepoint./30450" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Zarya%20Hacktivists%3A%20More%20than%20just%20Sharepoint./30450</a><br /> ICANN Registration Data Request Service (RDRS)<br /><a href="https://rdrs.icann.org/" target="_blank" rel="noreferrer noopener">https://rdrs.icann.org/</a><br /> Android Updates<br /><a href="https://source.android.com/docs/security/bulletin/2023-12-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2023-12-01</a><br /> GitLab Patches<br /><a href="https://about.gitlab.com/releases/2023/11/30/security-release-gitlab-16-6-1-released/" target="_blank" rel="noreferrer noopener">https://about.gitlab.com/releases/2023/11/30/security-release-gitlab-16-6-1-released/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8764.mp3</guid><pubDate>Tue, 05 Dec 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129478/8764.mp3" length="5348777" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Zarya Hacktivists: More than just Sharepoint
https://isc.sans.edu/diary/Zarya%20Hacktivists%3A%20More%20than%20just%20Sharepoint./30450
 ICANN Registration Data Request Service (RDRS)
https://rdrs.icann.org/
 Android Updates...</itunes:subtitle><itunes:summary><![CDATA[Zarya Hacktivists: More than just Sharepoint<br /><a href="https://isc.sans.edu/diary/Zarya%20Hacktivists%3A%20More%20than%20just%20Sharepoint./30450" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Zarya%20Hacktivists%3A%20More%20than%20just%20Sharepoint./30450</a><br /> ICANN Registration Data Request Service (RDRS)<br /><a href="https://rdrs.icann.org/" target="_blank" rel="noreferrer noopener">https://rdrs.icann.org/</a><br /> Android Updates<br /><a href="https://source.android.com/docs/security/bulletin/2023-12-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2023-12-01</a><br /> GitLab Patches<br /><a href="https://about.gitlab.com/releases/2023/11/30/security-release-gitlab-16-6-1-released/" target="_blank" rel="noreferrer noopener">https://about.gitlab.com/releases/2023/11/30/security-release-gitlab-16-6-1-released/</a><br />]]></itunes:summary><itunes:duration>360</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,gitlab; android; icann; rdrs; ,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8764</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, December 5th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-december-5th-2023--57912677</link><description><![CDATA[Zarya Hacktivists: More than just Sharepoint<br /><a href="https://isc.sans.edu/diary/Zarya%20Hacktivists%3A%20More%20than%20just%20Sharepoint./30450" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Zarya%20Hacktivists%3A%20More%20than%20just%20Sharepoint./30450</a><br /> ICANN Registration Data Request Service (RDRS)<br /><a href="https://rdrs.icann.org/" target="_blank" rel="noreferrer noopener">https://rdrs.icann.org/</a><br /> Android Updates<br /><a href="https://source.android.com/docs/security/bulletin/2023-12-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2023-12-01</a><br /> GitLab Patches<br /><a href="https://about.gitlab.com/releases/2023/11/30/security-release-gitlab-16-6-1-released/" target="_blank" rel="noreferrer noopener">https://about.gitlab.com/releases/2023/11/30/security-release-gitlab-16-6-1-released/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8764.mp3</guid><pubDate>Tue, 05 Dec 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57912677/8764.mp3" length="5348777" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Zarya Hacktivists: More than just Sharepoint
https://isc.sans.edu/diary/Zarya%20Hacktivists%3A%20More%20than%20just%20Sharepoint./30450
 ICANN Registration Data Request Service (RDRS)
https://rdrs.icann.org/
 Android Updates...</itunes:subtitle><itunes:summary><![CDATA[Zarya Hacktivists: More than just Sharepoint<br /><a href="https://isc.sans.edu/diary/Zarya%20Hacktivists%3A%20More%20than%20just%20Sharepoint./30450" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Zarya%20Hacktivists%3A%20More%20than%20just%20Sharepoint./30450</a><br /> ICANN Registration Data Request Service (RDRS)<br /><a href="https://rdrs.icann.org/" target="_blank" rel="noreferrer noopener">https://rdrs.icann.org/</a><br /> Android Updates<br /><a href="https://source.android.com/docs/security/bulletin/2023-12-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2023-12-01</a><br /> GitLab Patches<br /><a href="https://about.gitlab.com/releases/2023/11/30/security-release-gitlab-16-6-1-released/" target="_blank" rel="noreferrer noopener">https://about.gitlab.com/releases/2023/11/30/security-release-gitlab-16-6-1-released/</a><br />]]></itunes:summary><itunes:duration>360</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,gitlab; android; icann; rdrs; ,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8764</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, December 4th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-december-4th-2023--62129495</link><description><![CDATA[UEFI Exploit via Boot Image<br /><a href="https://binarly.io/posts/The_Far_Reaching_Consequences_of_LogoFAIL/index.html" target="_blank" rel="noreferrer noopener">https://binarly.io/posts/The_Far_Reaching_Consequences_of_LogoFAIL/index.html</a><br /> Fake Phishing Scan Tricks Users into Installing Backdoor Plugin<br /><a href="https://www.wordfence.com/blog/2023/12/psa-fake-cve-2023-45124-phishing-scam-tricks-users-into-installing-backdoor-plugin/" target="_blank" rel="noreferrer noopener">https://www.wordfence.com/blog/2023/12/psa-fake-cve-2023-45124-phishing-scam-tricks-users-into-installing-backdoor-plugin/</a><br /> Qlik Sense Exploited by Cactus Ransomware<br /><a href="https://arcticwolf.com/resources/blog/qlik-sense-exploited-in-cactus-ransomware-campaign/" target="_blank" rel="noreferrer noopener">https://arcticwolf.com/resources/blog/qlik-sense-exploited-in-cactus-ransomware-campaign/</a><br /><a href="https://www.praetorian.com/blog/qlik-sense-technical-exploit/" target="_blank" rel="noreferrer noopener">https://www.praetorian.com/blog/qlik-sense-technical-exploit/</a><br /> VMWare Vulnerability Patched<br /><a href="https://www.vmware.com/security/advisories/VMSA-2023-0026.html" target="_blank" rel="noreferrer noopener">https://www.vmware.com/security/advisories/VMSA-2023-0026.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8762.mp3</guid><pubDate>Mon, 04 Dec 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129495/8762.mp3" length="5360990" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>UEFI Exploit via Boot Image
https://binarly.io/posts/The_Far_Reaching_Consequences_of_LogoFAIL/index.html
 Fake Phishing Scan Tricks Users into Installing Backdoor Plugin...</itunes:subtitle><itunes:summary><![CDATA[UEFI Exploit via Boot Image<br /><a href="https://binarly.io/posts/The_Far_Reaching_Consequences_of_LogoFAIL/index.html" target="_blank" rel="noreferrer noopener">https://binarly.io/posts/The_Far_Reaching_Consequences_of_LogoFAIL/index.html</a><br /> Fake Phishing Scan Tricks Users into Installing Backdoor Plugin<br /><a href="https://www.wordfence.com/blog/2023/12/psa-fake-cve-2023-45124-phishing-scam-tricks-users-into-installing-backdoor-plugin/" target="_blank" rel="noreferrer noopener">https://www.wordfence.com/blog/2023/12/psa-fake-cve-2023-45124-phishing-scam-tricks-users-into-installing-backdoor-plugin/</a><br /> Qlik Sense Exploited by Cactus Ransomware<br /><a href="https://arcticwolf.com/resources/blog/qlik-sense-exploited-in-cactus-ransomware-campaign/" target="_blank" rel="noreferrer noopener">https://arcticwolf.com/resources/blog/qlik-sense-exploited-in-cactus-ransomware-campaign/</a><br /><a href="https://www.praetorian.com/blog/qlik-sense-technical-exploit/" target="_blank" rel="noreferrer noopener">https://www.praetorian.com/blog/qlik-sense-technical-exploit/</a><br /> VMWare Vulnerability Patched<br /><a href="https://www.vmware.com/security/advisories/VMSA-2023-0026.html" target="_blank" rel="noreferrer noopener">https://www.vmware.com/security/advisories/VMSA-2023-0026.html</a><br />]]></itunes:summary><itunes:duration>361</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,vmware; qlik; ransomware; phis</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8762</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, December 4th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-december-4th-2023--57900133</link><description><![CDATA[UEFI Exploit via Boot Image<br /><a href="https://binarly.io/posts/The_Far_Reaching_Consequences_of_LogoFAIL/index.html" target="_blank" rel="noreferrer noopener">https://binarly.io/posts/The_Far_Reaching_Consequences_of_LogoFAIL/index.html</a><br /> Fake Phishing Scan Tricks Users into Installing Backdoor Plugin<br /><a href="https://www.wordfence.com/blog/2023/12/psa-fake-cve-2023-45124-phishing-scam-tricks-users-into-installing-backdoor-plugin/" target="_blank" rel="noreferrer noopener">https://www.wordfence.com/blog/2023/12/psa-fake-cve-2023-45124-phishing-scam-tricks-users-into-installing-backdoor-plugin/</a><br /> Qlik Sense Exploited by Cactus Ransomware<br /><a href="https://arcticwolf.com/resources/blog/qlik-sense-exploited-in-cactus-ransomware-campaign/" target="_blank" rel="noreferrer noopener">https://arcticwolf.com/resources/blog/qlik-sense-exploited-in-cactus-ransomware-campaign/</a><br /><a href="https://www.praetorian.com/blog/qlik-sense-technical-exploit/" target="_blank" rel="noreferrer noopener">https://www.praetorian.com/blog/qlik-sense-technical-exploit/</a><br /> VMWare Vulnerability Patched<br /><a href="https://www.vmware.com/security/advisories/VMSA-2023-0026.html" target="_blank" rel="noreferrer noopener">https://www.vmware.com/security/advisories/VMSA-2023-0026.html</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8762.mp3</guid><pubDate>Mon, 04 Dec 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57900133/8762.mp3" length="5360990" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>UEFI Exploit via Boot Image
https://binarly.io/posts/The_Far_Reaching_Consequences_of_LogoFAIL/index.html
 Fake Phishing Scan Tricks Users into Installing Backdoor Plugin...</itunes:subtitle><itunes:summary><![CDATA[UEFI Exploit via Boot Image<br /><a href="https://binarly.io/posts/The_Far_Reaching_Consequences_of_LogoFAIL/index.html" target="_blank" rel="noreferrer noopener">https://binarly.io/posts/The_Far_Reaching_Consequences_of_LogoFAIL/index.html</a><br /> Fake Phishing Scan Tricks Users into Installing Backdoor Plugin<br /><a href="https://www.wordfence.com/blog/2023/12/psa-fake-cve-2023-45124-phishing-scam-tricks-users-into-installing-backdoor-plugin/" target="_blank" rel="noreferrer noopener">https://www.wordfence.com/blog/2023/12/psa-fake-cve-2023-45124-phishing-scam-tricks-users-into-installing-backdoor-plugin/</a><br /> Qlik Sense Exploited by Cactus Ransomware<br /><a href="https://arcticwolf.com/resources/blog/qlik-sense-exploited-in-cactus-ransomware-campaign/" target="_blank" rel="noreferrer noopener">https://arcticwolf.com/resources/blog/qlik-sense-exploited-in-cactus-ransomware-campaign/</a><br /><a href="https://www.praetorian.com/blog/qlik-sense-technical-exploit/" target="_blank" rel="noreferrer noopener">https://www.praetorian.com/blog/qlik-sense-technical-exploit/</a><br /> VMWare Vulnerability Patched<br /><a href="https://www.vmware.com/security/advisories/VMSA-2023-0026.html" target="_blank" rel="noreferrer noopener">https://www.vmware.com/security/advisories/VMSA-2023-0026.html</a><br />]]></itunes:summary><itunes:duration>361</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,vmware; qlik; ransomware; phis</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8762</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, December 1st, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-december-1st-2023--62129462</link><description><![CDATA[Apple Updates<br /><a href="https://isc.sans.edu/diary/Apple+Patches+Exploited+WebKit+Vulnerabilitiues+in+iOSiPadOSmacOS/30444" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple+Patches+Exploited+WebKit+Vulnerabilitiues+in+iOSiPadOSmacOS/30444</a><br /> Prophetic Post by Intern on CVE-2023-1389 Foreshadows Mirai Botnet Expansion Today<br /><a href="https://isc.sans.edu/forums/diary/Prophetic+Post+by+Intern+on+CVE20231389+Foreshadows+Mirai+Botnet+Expansion+Today/30442/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Prophetic+Post+by+Intern+on+CVE20231389+Foreshadows+Mirai+Botnet+Expansion+Today/30442/</a><br /> Zyxel Vulnerabilities<br /><a href="https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-authentication-bypass-and-command-injection-vulnerabilities-in-nas-products" target="_blank" rel="noreferrer noopener">https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-authentication-bypass-and-command-injection-vulnerabilities-in-nas-products</a><br /> Solarwinds Update<br /><a href="https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2023-4_release_notes.htm#link3" target="_blank" rel="noreferrer noopener">https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2023-4_release_notes.htm#link3</a><br /> DNS Looking Glass<br /><a href="https://isc.sans.edu/tools/dnslookup/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/tools/dnslookup/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8760.mp3</guid><pubDate>Fri, 01 Dec 2023 03:08:45 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129462/8760.mp3" length="5002077" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Apple Updates
https://isc.sans.edu/diary/Apple+Patches+Exploited+WebKit+Vulnerabilitiues+in+iOSiPadOSmacOS/30444
 Prophetic Post by Intern on CVE-2023-1389 Foreshadows Mirai Botnet Expansion Today...</itunes:subtitle><itunes:summary><![CDATA[Apple Updates<br /><a href="https://isc.sans.edu/diary/Apple+Patches+Exploited+WebKit+Vulnerabilitiues+in+iOSiPadOSmacOS/30444" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple+Patches+Exploited+WebKit+Vulnerabilitiues+in+iOSiPadOSmacOS/30444</a><br /> Prophetic Post by Intern on CVE-2023-1389 Foreshadows Mirai Botnet Expansion Today<br /><a href="https://isc.sans.edu/forums/diary/Prophetic+Post+by+Intern+on+CVE20231389+Foreshadows+Mirai+Botnet+Expansion+Today/30442/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Prophetic+Post+by+Intern+on+CVE20231389+Foreshadows+Mirai+Botnet+Expansion+Today/30442/</a><br /> Zyxel Vulnerabilities<br /><a href="https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-authentication-bypass-and-command-injection-vulnerabilities-in-nas-products" target="_blank" rel="noreferrer noopener">https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-authentication-bypass-and-command-injection-vulnerabilities-in-nas-products</a><br /> Solarwinds Update<br /><a href="https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2023-4_release_notes.htm#link3" target="_blank" rel="noreferrer noopener">https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2023-4_release_notes.htm#link3</a><br /> DNS Looking Glass<br /><a href="https://isc.sans.edu/tools/dnslookup/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/tools/dnslookup/</a><br />]]></itunes:summary><itunes:duration>336</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dns; looking glass; solarwinds,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8760</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, December 1st, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-december-1st-2023--57872674</link><description><![CDATA[Apple Updates<br /><a href="https://isc.sans.edu/diary/Apple+Patches+Exploited+WebKit+Vulnerabilitiues+in+iOSiPadOSmacOS/30444" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple+Patches+Exploited+WebKit+Vulnerabilitiues+in+iOSiPadOSmacOS/30444</a><br /> Prophetic Post by Intern on CVE-2023-1389 Foreshadows Mirai Botnet Expansion Today<br /><a href="https://isc.sans.edu/forums/diary/Prophetic+Post+by+Intern+on+CVE20231389+Foreshadows+Mirai+Botnet+Expansion+Today/30442/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Prophetic+Post+by+Intern+on+CVE20231389+Foreshadows+Mirai+Botnet+Expansion+Today/30442/</a><br /> Zyxel Vulnerabilities<br /><a href="https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-authentication-bypass-and-command-injection-vulnerabilities-in-nas-products" target="_blank" rel="noreferrer noopener">https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-authentication-bypass-and-command-injection-vulnerabilities-in-nas-products</a><br /> Solarwinds Update<br /><a href="https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2023-4_release_notes.htm#link3" target="_blank" rel="noreferrer noopener">https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2023-4_release_notes.htm#link3</a><br /> DNS Looking Glass<br /><a href="https://isc.sans.edu/tools/dnslookup/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/tools/dnslookup/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8760.mp3</guid><pubDate>Fri, 01 Dec 2023 03:08:45 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57872674/8760.mp3" length="5002077" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Apple Updates
https://isc.sans.edu/diary/Apple+Patches+Exploited+WebKit+Vulnerabilitiues+in+iOSiPadOSmacOS/30444
 Prophetic Post by Intern on CVE-2023-1389 Foreshadows Mirai Botnet Expansion Today...</itunes:subtitle><itunes:summary><![CDATA[Apple Updates<br /><a href="https://isc.sans.edu/diary/Apple+Patches+Exploited+WebKit+Vulnerabilitiues+in+iOSiPadOSmacOS/30444" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple+Patches+Exploited+WebKit+Vulnerabilitiues+in+iOSiPadOSmacOS/30444</a><br /> Prophetic Post by Intern on CVE-2023-1389 Foreshadows Mirai Botnet Expansion Today<br /><a href="https://isc.sans.edu/forums/diary/Prophetic+Post+by+Intern+on+CVE20231389+Foreshadows+Mirai+Botnet+Expansion+Today/30442/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Prophetic+Post+by+Intern+on+CVE20231389+Foreshadows+Mirai+Botnet+Expansion+Today/30442/</a><br /> Zyxel Vulnerabilities<br /><a href="https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-authentication-bypass-and-command-injection-vulnerabilities-in-nas-products" target="_blank" rel="noreferrer noopener">https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-authentication-bypass-and-command-injection-vulnerabilities-in-nas-products</a><br /> Solarwinds Update<br /><a href="https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2023-4_release_notes.htm#link3" target="_blank" rel="noreferrer noopener">https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2023-4_release_notes.htm#link3</a><br /> DNS Looking Glass<br /><a href="https://isc.sans.edu/tools/dnslookup/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/tools/dnslookup/</a><br />]]></itunes:summary><itunes:duration>336</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dns; looking glass; solarwinds,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8760</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, November 30th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-november-30th-2023--62129457</link><description><![CDATA[Decoding the Patterns: Analzying DShield Honeypot Activity<br /><a href="https://isc.sans.edu/diary/Decoding%20the%20Patterns%3A%20Analyzing%20DShield%20Honeypot%20Activity%20%5BGuest%20Diary%5D/30428" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Decoding%20the%20Patterns%3A%20Analyzing%20DShield%20Honeypot%20Activity%20%5BGuest%20Diary%5D/30428</a><br /> Arcserve Unified Data Protection Multiple Vulnerabilities<br /><a href="https://www.tenable.com/security/research/tra-2023-37" target="_blank" rel="noreferrer noopener">https://www.tenable.com/security/research/tra-2023-37</a><br /> Hikvision Vulnerabilities<br /><a href="https://www.hikvision.com/hk/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-products/" target="_blank" rel="noreferrer noopener">https://www.hikvision.com/hk/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-products/</a><br /> Assessing Prompt Injection Risks in 200+ Custom GPTs<br /><a href="https://arxiv.org/pdf/2311.11538.pdf" target="_blank" rel="noreferrer noopener">https://arxiv.org/pdf/2311.11538.pdf</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8758.mp3</guid><pubDate>Thu, 30 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62129457/8758.mp3" length="4939532" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Decoding the Patterns: Analzying DShield Honeypot Activity
https://isc.sans.edu/diary/Decoding%20the%20Patterns%3A%20Analyzing%20DShield%20Honeypot%20Activity%20%5BGuest%20Diary%5D/30428
 Arcserve Unified Data Protection Multiple Vulnerabilities...</itunes:subtitle><itunes:summary><![CDATA[Decoding the Patterns: Analzying DShield Honeypot Activity<br /><a href="https://isc.sans.edu/diary/Decoding%20the%20Patterns%3A%20Analyzing%20DShield%20Honeypot%20Activity%20%5BGuest%20Diary%5D/30428" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Decoding%20the%20Patterns%3A%20Analyzing%20DShield%20Honeypot%20Activity%20%5BGuest%20Diary%5D/30428</a><br /> Arcserve Unified Data Protection Multiple Vulnerabilities<br /><a href="https://www.tenable.com/security/research/tra-2023-37" target="_blank" rel="noreferrer noopener">https://www.tenable.com/security/research/tra-2023-37</a><br /> Hikvision Vulnerabilities<br /><a href="https://www.hikvision.com/hk/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-products/" target="_blank" rel="noreferrer noopener">https://www.hikvision.com/hk/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-products/</a><br /> Assessing Prompt Injection Risks in 200+ Custom GPTs<br /><a href="https://arxiv.org/pdf/2311.11538.pdf" target="_blank" rel="noreferrer noopener">https://arxiv.org/pdf/2311.11538.pdf</a><br />]]></itunes:summary><itunes:duration>331</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,gpt; prompt injection; hikvisi,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8758</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, November 30th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-november-30th-2023--57855930</link><description><![CDATA[Decoding the Patterns: Analzying DShield Honeypot Activity<br /><a href="https://isc.sans.edu/diary/Decoding%20the%20Patterns%3A%20Analyzing%20DShield%20Honeypot%20Activity%20%5BGuest%20Diary%5D/30428" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Decoding%20the%20Patterns%3A%20Analyzing%20DShield%20Honeypot%20Activity%20%5BGuest%20Diary%5D/30428</a><br /> Arcserve Unified Data Protection Multiple Vulnerabilities<br /><a href="https://www.tenable.com/security/research/tra-2023-37" target="_blank" rel="noreferrer noopener">https://www.tenable.com/security/research/tra-2023-37</a><br /> Hikvision Vulnerabilities<br /><a href="https://www.hikvision.com/hk/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-products/" target="_blank" rel="noreferrer noopener">https://www.hikvision.com/hk/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-products/</a><br /> Assessing Prompt Injection Risks in 200+ Custom GPTs<br /><a href="https://arxiv.org/pdf/2311.11538.pdf" target="_blank" rel="noreferrer noopener">https://arxiv.org/pdf/2311.11538.pdf</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8758.mp3</guid><pubDate>Thu, 30 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57855930/8758.mp3" length="4939532" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Decoding the Patterns: Analzying DShield Honeypot Activity
https://isc.sans.edu/diary/Decoding%20the%20Patterns%3A%20Analyzing%20DShield%20Honeypot%20Activity%20%5BGuest%20Diary%5D/30428
 Arcserve Unified Data Protection Multiple Vulnerabilities...</itunes:subtitle><itunes:summary><![CDATA[Decoding the Patterns: Analzying DShield Honeypot Activity<br /><a href="https://isc.sans.edu/diary/Decoding%20the%20Patterns%3A%20Analyzing%20DShield%20Honeypot%20Activity%20%5BGuest%20Diary%5D/30428" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Decoding%20the%20Patterns%3A%20Analyzing%20DShield%20Honeypot%20Activity%20%5BGuest%20Diary%5D/30428</a><br /> Arcserve Unified Data Protection Multiple Vulnerabilities<br /><a href="https://www.tenable.com/security/research/tra-2023-37" target="_blank" rel="noreferrer noopener">https://www.tenable.com/security/research/tra-2023-37</a><br /> Hikvision Vulnerabilities<br /><a href="https://www.hikvision.com/hk/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-products/" target="_blank" rel="noreferrer noopener">https://www.hikvision.com/hk/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-products/</a><br /> Assessing Prompt Injection Risks in 200+ Custom GPTs<br /><a href="https://arxiv.org/pdf/2311.11538.pdf" target="_blank" rel="noreferrer noopener">https://arxiv.org/pdf/2311.11538.pdf</a><br />]]></itunes:summary><itunes:duration>331</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,gpt; prompt injection; hikvisi,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8758</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, November 29th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-november-29th-2023--62130953</link><description><![CDATA[Pro-Russian Attackers Scanning for Sharepoint Servers to Exploit CVE-2023-29357<br /><a href="https://isc.sans.edu/diary/Pro%20Russian%20Attackers%20Scanning%20for%20Sharepoint%20Servers%20to%20Exploit%20CVE-2023-29357/30436" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Pro%20Russian%20Attackers%20Scanning%20for%20Sharepoint%20Servers%20to%20Exploit%20CVE-2023-29357/30436</a><br /> Microsoft Deprecates Microsoft Defender Application Guard for Office<br /><a href="https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features</a><br /> Synology Vulnerability<br /><a href="https://www.synology.com/en-global/security/advisory/Synology_SA_23_16" target="_blank" rel="noreferrer noopener">https://www.synology.com/en-global/security/advisory/Synology_SA_23_16</a><br /> Apache Tomcat Request Smuggling Vulnerability CVE-2023-46589<br /><a href="https://lists.apache.org/thread/0rqq6ktozqc42ro8hhxdmmdjm1k1tpxr" target="_blank" rel="noreferrer noopener">https://lists.apache.org/thread/0rqq6ktozqc42ro8hhxdmmdjm1k1tpxr</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8756.mp3</guid><pubDate>Wed, 29 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62130953/8756.mp3" length="5014883" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Pro-Russian Attackers Scanning for Sharepoint Servers to Exploit CVE-2023-29357
https://isc.sans.edu/diary/Pro%20Russian%20Attackers%20Scanning%20for%20Sharepoint%20Servers%20to%20Exploit%20CVE-2023-29357/30436
 Microsoft Deprecates Microsoft Defender...</itunes:subtitle><itunes:summary><![CDATA[Pro-Russian Attackers Scanning for Sharepoint Servers to Exploit CVE-2023-29357<br /><a href="https://isc.sans.edu/diary/Pro%20Russian%20Attackers%20Scanning%20for%20Sharepoint%20Servers%20to%20Exploit%20CVE-2023-29357/30436" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Pro%20Russian%20Attackers%20Scanning%20for%20Sharepoint%20Servers%20to%20Exploit%20CVE-2023-29357/30436</a><br /> Microsoft Deprecates Microsoft Defender Application Guard for Office<br /><a href="https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features</a><br /> Synology Vulnerability<br /><a href="https://www.synology.com/en-global/security/advisory/Synology_SA_23_16" target="_blank" rel="noreferrer noopener">https://www.synology.com/en-global/security/advisory/Synology_SA_23_16</a><br /> Apache Tomcat Request Smuggling Vulnerability CVE-2023-46589<br /><a href="https://lists.apache.org/thread/0rqq6ktozqc42ro8hhxdmmdjm1k1tpxr" target="_blank" rel="noreferrer noopener">https://lists.apache.org/thread/0rqq6ktozqc42ro8hhxdmmdjm1k1tpxr</a><br />]]></itunes:summary><itunes:duration>337</itunes:duration><itunes:keywords>apache; tomcat; synology; micr,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8756</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, November 29th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-november-29th-2023--57839304</link><description><![CDATA[Pro-Russian Attackers Scanning for Sharepoint Servers to Exploit CVE-2023-29357<br /><a href="https://isc.sans.edu/diary/Pro%20Russian%20Attackers%20Scanning%20for%20Sharepoint%20Servers%20to%20Exploit%20CVE-2023-29357/30436" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Pro%20Russian%20Attackers%20Scanning%20for%20Sharepoint%20Servers%20to%20Exploit%20CVE-2023-29357/30436</a><br /> Microsoft Deprecates Microsoft Defender Application Guard for Office<br /><a href="https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features</a><br /> Synology Vulnerability<br /><a href="https://www.synology.com/en-global/security/advisory/Synology_SA_23_16" target="_blank" rel="noreferrer noopener">https://www.synology.com/en-global/security/advisory/Synology_SA_23_16</a><br /> Apache Tomcat Request Smuggling Vulnerability CVE-2023-46589<br /><a href="https://lists.apache.org/thread/0rqq6ktozqc42ro8hhxdmmdjm1k1tpxr" target="_blank" rel="noreferrer noopener">https://lists.apache.org/thread/0rqq6ktozqc42ro8hhxdmmdjm1k1tpxr</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8756.mp3</guid><pubDate>Wed, 29 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57839304/8756.mp3" length="5014883" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Pro-Russian Attackers Scanning for Sharepoint Servers to Exploit CVE-2023-29357
https://isc.sans.edu/diary/Pro%20Russian%20Attackers%20Scanning%20for%20Sharepoint%20Servers%20to%20Exploit%20CVE-2023-29357/30436
 Microsoft Deprecates Microsoft Defender...</itunes:subtitle><itunes:summary><![CDATA[Pro-Russian Attackers Scanning for Sharepoint Servers to Exploit CVE-2023-29357<br /><a href="https://isc.sans.edu/diary/Pro%20Russian%20Attackers%20Scanning%20for%20Sharepoint%20Servers%20to%20Exploit%20CVE-2023-29357/30436" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Pro%20Russian%20Attackers%20Scanning%20for%20Sharepoint%20Servers%20to%20Exploit%20CVE-2023-29357/30436</a><br /> Microsoft Deprecates Microsoft Defender Application Guard for Office<br /><a href="https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features</a><br /> Synology Vulnerability<br /><a href="https://www.synology.com/en-global/security/advisory/Synology_SA_23_16" target="_blank" rel="noreferrer noopener">https://www.synology.com/en-global/security/advisory/Synology_SA_23_16</a><br /> Apache Tomcat Request Smuggling Vulnerability CVE-2023-46589<br /><a href="https://lists.apache.org/thread/0rqq6ktozqc42ro8hhxdmmdjm1k1tpxr" target="_blank" rel="noreferrer noopener">https://lists.apache.org/thread/0rqq6ktozqc42ro8hhxdmmdjm1k1tpxr</a><br />]]></itunes:summary><itunes:duration>337</itunes:duration><itunes:keywords>apache; tomcat; synology; micr,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8756</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, November 28th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-november-28th-2023--62130952</link><description><![CDATA[Scans for ownCloud Vulnerability (CVE-2023-49103)<br /><a href="https://isc.sans.edu/diary/Scans%20for%20ownCloud%20Vulnerability%20%28CVE-2023-49103%29/30432" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20ownCloud%20Vulnerability%20%28CVE-2023-49103%29/30432</a><br /> Windows Hello Fingerprint Reader Weakness<br /><a href="https://blackwinghq.com/blog/posts/a-touch-of-pwn-part-i/" target="_blank" rel="noreferrer noopener">https://blackwinghq.com/blog/posts/a-touch-of-pwn-part-i/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8754.mp3</guid><pubDate>Tue, 28 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62130952/8754.mp3" length="5860853" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Scans for ownCloud Vulnerability (CVE-2023-49103)
https://isc.sans.edu/diary/Scans%20for%20ownCloud%20Vulnerability%20%28CVE-2023-49103%29/30432
 Windows Hello Fingerprint Reader Weakness
https://blackwinghq.com/blog/posts/a-touch-of-pwn-part-i/
</itunes:subtitle><itunes:summary><![CDATA[Scans for ownCloud Vulnerability (CVE-2023-49103)<br /><a href="https://isc.sans.edu/diary/Scans%20for%20ownCloud%20Vulnerability%20%28CVE-2023-49103%29/30432" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20ownCloud%20Vulnerability%20%28CVE-2023-49103%29/30432</a><br /> Windows Hello Fingerprint Reader Weakness<br /><a href="https://blackwinghq.com/blog/posts/a-touch-of-pwn-part-i/" target="_blank" rel="noreferrer noopener">https://blackwinghq.com/blog/posts/a-touch-of-pwn-part-i/</a><br />]]></itunes:summary><itunes:duration>397</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,windows; hello; fingerprint; o</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8754</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, November 28th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-november-28th-2023--57826225</link><description><![CDATA[Scans for ownCloud Vulnerability (CVE-2023-49103)<br /><a href="https://isc.sans.edu/diary/Scans%20for%20ownCloud%20Vulnerability%20%28CVE-2023-49103%29/30432" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20ownCloud%20Vulnerability%20%28CVE-2023-49103%29/30432</a><br /> Windows Hello Fingerprint Reader Weakness<br /><a href="https://blackwinghq.com/blog/posts/a-touch-of-pwn-part-i/" target="_blank" rel="noreferrer noopener">https://blackwinghq.com/blog/posts/a-touch-of-pwn-part-i/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8754.mp3</guid><pubDate>Tue, 28 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57826225/8754.mp3" length="5860853" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Scans for ownCloud Vulnerability (CVE-2023-49103)
https://isc.sans.edu/diary/Scans%20for%20ownCloud%20Vulnerability%20%28CVE-2023-49103%29/30432
 Windows Hello Fingerprint Reader Weakness
https://blackwinghq.com/blog/posts/a-touch-of-pwn-part-i/
</itunes:subtitle><itunes:summary><![CDATA[Scans for ownCloud Vulnerability (CVE-2023-49103)<br /><a href="https://isc.sans.edu/diary/Scans%20for%20ownCloud%20Vulnerability%20%28CVE-2023-49103%29/30432" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Scans%20for%20ownCloud%20Vulnerability%20%28CVE-2023-49103%29/30432</a><br /> Windows Hello Fingerprint Reader Weakness<br /><a href="https://blackwinghq.com/blog/posts/a-touch-of-pwn-part-i/" target="_blank" rel="noreferrer noopener">https://blackwinghq.com/blog/posts/a-touch-of-pwn-part-i/</a><br />]]></itunes:summary><itunes:duration>397</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,windows; hello; fingerprint; o</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8754</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, November 27th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-november-27th-2023--62130956</link><description><![CDATA[DShield Birthday<br /><a href="https://isc.sans.edu/diary/Happy%20Birthday%20DShield/30420" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Happy%20Birthday%20DShield/30420</a><br /> Mirai uses CVE-2023-1389<br /><a href="https://isc.sans.edu/diary/CVE-2023-1389%3A%20A%20New%20Means%20to%20Expand%20Botnets/30418" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CVE-2023-1389%3A%20A%20New%20Means%20to%20Expand%20Botnets/30418</a><br /> More Mirai Vulnerabilities<br /><a href="https://www.akamai.com/blog/security-research/new-rce-botnet-spreads-mirai-via-zero-days" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/new-rce-botnet-spreads-mirai-via-zero-days</a><br /> Analyzing OVA Files<br /><a href="https://isc.sans.edu/diary/OVA%20Files/30424" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/OVA%20Files/30424</a><br /> Static Code Injections in OpenCart (CVE-2023-47444)<br /><a href="https://github.com/opencart/opencart/issues/12947" target="_blank" rel="noreferrer noopener">https://github.com/opencart/opencart/issues/12947</a><br /> Holiday Hackchallenge<br /><a href="https://www.sans.org/mlp/holiday-hack-challenge-2023/" target="_blank" rel="noreferrer noopener">https://www.sans.org/mlp/holiday-hack-challenge-2023/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8752.mp3</guid><pubDate>Mon, 27 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62130956/8752.mp3" length="5358057" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>DShield Birthday
https://isc.sans.edu/diary/Happy%20Birthday%20DShield/30420
 Mirai uses CVE-2023-1389
https://isc.sans.edu/diary/CVE-2023-1389%3A%20A%20New%20Means%20to%20Expand%20Botnets/30418
 More Mirai Vulnerabilities...</itunes:subtitle><itunes:summary><![CDATA[DShield Birthday<br /><a href="https://isc.sans.edu/diary/Happy%20Birthday%20DShield/30420" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Happy%20Birthday%20DShield/30420</a><br /> Mirai uses CVE-2023-1389<br /><a href="https://isc.sans.edu/diary/CVE-2023-1389%3A%20A%20New%20Means%20to%20Expand%20Botnets/30418" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CVE-2023-1389%3A%20A%20New%20Means%20to%20Expand%20Botnets/30418</a><br /> More Mirai Vulnerabilities<br /><a href="https://www.akamai.com/blog/security-research/new-rce-botnet-spreads-mirai-via-zero-days" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/new-rce-botnet-spreads-mirai-via-zero-days</a><br /> Analyzing OVA Files<br /><a href="https://isc.sans.edu/diary/OVA%20Files/30424" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/OVA%20Files/30424</a><br /> Static Code Injections in OpenCart (CVE-2023-47444)<br /><a href="https://github.com/opencart/opencart/issues/12947" target="_blank" rel="noreferrer noopener">https://github.com/opencart/opencart/issues/12947</a><br /> Holiday Hackchallenge<br /><a href="https://www.sans.org/mlp/holiday-hack-challenge-2023/" target="_blank" rel="noreferrer noopener">https://www.sans.org/mlp/holiday-hack-challenge-2023/</a><br />]]></itunes:summary><itunes:duration>361</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,holiday; hackchallenge; openca,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8752</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, November 27th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-november-27th-2023--57814869</link><description><![CDATA[DShield Birthday<br /><a href="https://isc.sans.edu/diary/Happy%20Birthday%20DShield/30420" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Happy%20Birthday%20DShield/30420</a><br /> Mirai uses CVE-2023-1389<br /><a href="https://isc.sans.edu/diary/CVE-2023-1389%3A%20A%20New%20Means%20to%20Expand%20Botnets/30418" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CVE-2023-1389%3A%20A%20New%20Means%20to%20Expand%20Botnets/30418</a><br /> More Mirai Vulnerabilities<br /><a href="https://www.akamai.com/blog/security-research/new-rce-botnet-spreads-mirai-via-zero-days" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/new-rce-botnet-spreads-mirai-via-zero-days</a><br /> Analyzing OVA Files<br /><a href="https://isc.sans.edu/diary/OVA%20Files/30424" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/OVA%20Files/30424</a><br /> Static Code Injections in OpenCart (CVE-2023-47444)<br /><a href="https://github.com/opencart/opencart/issues/12947" target="_blank" rel="noreferrer noopener">https://github.com/opencart/opencart/issues/12947</a><br /> Holiday Hackchallenge<br /><a href="https://www.sans.org/mlp/holiday-hack-challenge-2023/" target="_blank" rel="noreferrer noopener">https://www.sans.org/mlp/holiday-hack-challenge-2023/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8752.mp3</guid><pubDate>Mon, 27 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57814869/8752.mp3" length="5358057" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>DShield Birthday
https://isc.sans.edu/diary/Happy%20Birthday%20DShield/30420
 Mirai uses CVE-2023-1389
https://isc.sans.edu/diary/CVE-2023-1389%3A%20A%20New%20Means%20to%20Expand%20Botnets/30418
 More Mirai Vulnerabilities...</itunes:subtitle><itunes:summary><![CDATA[DShield Birthday<br /><a href="https://isc.sans.edu/diary/Happy%20Birthday%20DShield/30420" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Happy%20Birthday%20DShield/30420</a><br /> Mirai uses CVE-2023-1389<br /><a href="https://isc.sans.edu/diary/CVE-2023-1389%3A%20A%20New%20Means%20to%20Expand%20Botnets/30418" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CVE-2023-1389%3A%20A%20New%20Means%20to%20Expand%20Botnets/30418</a><br /> More Mirai Vulnerabilities<br /><a href="https://www.akamai.com/blog/security-research/new-rce-botnet-spreads-mirai-via-zero-days" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/new-rce-botnet-spreads-mirai-via-zero-days</a><br /> Analyzing OVA Files<br /><a href="https://isc.sans.edu/diary/OVA%20Files/30424" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/OVA%20Files/30424</a><br /> Static Code Injections in OpenCart (CVE-2023-47444)<br /><a href="https://github.com/opencart/opencart/issues/12947" target="_blank" rel="noreferrer noopener">https://github.com/opencart/opencart/issues/12947</a><br /> Holiday Hackchallenge<br /><a href="https://www.sans.org/mlp/holiday-hack-challenge-2023/" target="_blank" rel="noreferrer noopener">https://www.sans.org/mlp/holiday-hack-challenge-2023/</a><br />]]></itunes:summary><itunes:duration>361</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,holiday; hackchallenge; openca,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8752</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, November 17th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-november-17th-2023--62130954</link><description><![CDATA[Beyond -n: Optimizign tcpdump performance<br /><a href="https://isc.sans.edu/forums/diary/Beyond%20-n%3A%20Optimizing%20tcpdump%20performance/30408/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Beyond%20-n%3A%20Optimizing%20tcpdump%20performance/30408/</a><br /> Zimbra 0-day used to target international government organizations<br /><a href="https://blog.google/threat-analysis-group/zimbra-0-day-used-to-target-international-government-organizations/" target="_blank" rel="noreferrer noopener">https://blog.google/threat-analysis-group/zimbra-0-day-used-to-target-international-government-organizations/</a><br /> FortiSIEM OS command injection in Report Server<br /><a href="https://www.fortiguard.com/psirt/FG-IR-23-135" target="_blank" rel="noreferrer noopener">https://www.fortiguard.com/psirt/FG-IR-23-135</a><br /> AI Exploit Collection<br /><a href="https://github.com/protectai/ai-exploits" target="_blank" rel="noreferrer noopener">https://github.com/protectai/ai-exploits</a><br /> CrushFTP Remote Code Execution<br /><a href="https://convergetp.com/2023/11/16/crushftp-zero-day-cve-2023-43177-discovered/" target="_blank" rel="noreferrer noopener">https://convergetp.com/2023/11/16/crushftp-zero-day-cve-2023-43177-discovered/</a><br /> Scott Poley: The Cyber Date Paradox: Storing Less, Discovering More<br /><a href="https://www.sans.edu/cyber-research/cyber-data-paradox-storing-less-discovering-more/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/cyber-data-paradox-storing-less-discovering-more/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8750.mp3</guid><pubDate>Fri, 17 Nov 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62130954/8750.mp3" length="13247860" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Beyond -n: Optimizign tcpdump performance
https://isc.sans.edu/forums/diary/Beyond%20-n%3A%20Optimizing%20tcpdump%20performance/30408/
 Zimbra 0-day used to target international government organizations...</itunes:subtitle><itunes:summary><![CDATA[Beyond -n: Optimizign tcpdump performance<br /><a href="https://isc.sans.edu/forums/diary/Beyond%20-n%3A%20Optimizing%20tcpdump%20performance/30408/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Beyond%20-n%3A%20Optimizing%20tcpdump%20performance/30408/</a><br /> Zimbra 0-day used to target international government organizations<br /><a href="https://blog.google/threat-analysis-group/zimbra-0-day-used-to-target-international-government-organizations/" target="_blank" rel="noreferrer noopener">https://blog.google/threat-analysis-group/zimbra-0-day-used-to-target-international-government-organizations/</a><br /> FortiSIEM OS command injection in Report Server<br /><a href="https://www.fortiguard.com/psirt/FG-IR-23-135" target="_blank" rel="noreferrer noopener">https://www.fortiguard.com/psirt/FG-IR-23-135</a><br /> AI Exploit Collection<br /><a href="https://github.com/protectai/ai-exploits" target="_blank" rel="noreferrer noopener">https://github.com/protectai/ai-exploits</a><br /> CrushFTP Remote Code Execution<br /><a href="https://convergetp.com/2023/11/16/crushftp-zero-day-cve-2023-43177-discovered/" target="_blank" rel="noreferrer noopener">https://convergetp.com/2023/11/16/crushftp-zero-day-cve-2023-43177-discovered/</a><br /> Scott Poley: The Cyber Date Paradox: Storing Less, Discovering More<br /><a href="https://www.sans.edu/cyber-research/cyber-data-paradox-storing-less-discovering-more/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/cyber-data-paradox-storing-less-discovering-more/</a><br />]]></itunes:summary><itunes:duration>925</itunes:duration><itunes:keywords>business,computer,crushftp; ai; exploit; fortisi,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8750</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, November 17th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-november-17th-2023--57672978</link><description><![CDATA[Beyond -n: Optimizign tcpdump performance<br /><a href="https://isc.sans.edu/forums/diary/Beyond%20-n%3A%20Optimizing%20tcpdump%20performance/30408/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Beyond%20-n%3A%20Optimizing%20tcpdump%20performance/30408/</a><br /> Zimbra 0-day used to target international government organizations<br /><a href="https://blog.google/threat-analysis-group/zimbra-0-day-used-to-target-international-government-organizations/" target="_blank" rel="noreferrer noopener">https://blog.google/threat-analysis-group/zimbra-0-day-used-to-target-international-government-organizations/</a><br /> FortiSIEM OS command injection in Report Server<br /><a href="https://www.fortiguard.com/psirt/FG-IR-23-135" target="_blank" rel="noreferrer noopener">https://www.fortiguard.com/psirt/FG-IR-23-135</a><br /> AI Exploit Collection<br /><a href="https://github.com/protectai/ai-exploits" target="_blank" rel="noreferrer noopener">https://github.com/protectai/ai-exploits</a><br /> CrushFTP Remote Code Execution<br /><a href="https://convergetp.com/2023/11/16/crushftp-zero-day-cve-2023-43177-discovered/" target="_blank" rel="noreferrer noopener">https://convergetp.com/2023/11/16/crushftp-zero-day-cve-2023-43177-discovered/</a><br /> Scott Poley: The Cyber Date Paradox: Storing Less, Discovering More<br /><a href="https://www.sans.edu/cyber-research/cyber-data-paradox-storing-less-discovering-more/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/cyber-data-paradox-storing-less-discovering-more/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8750.mp3</guid><pubDate>Fri, 17 Nov 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57672978/8750.mp3" length="13247860" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Beyond -n: Optimizign tcpdump performance
https://isc.sans.edu/forums/diary/Beyond%20-n%3A%20Optimizing%20tcpdump%20performance/30408/
 Zimbra 0-day used to target international government organizations...</itunes:subtitle><itunes:summary><![CDATA[Beyond -n: Optimizign tcpdump performance<br /><a href="https://isc.sans.edu/forums/diary/Beyond%20-n%3A%20Optimizing%20tcpdump%20performance/30408/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Beyond%20-n%3A%20Optimizing%20tcpdump%20performance/30408/</a><br /> Zimbra 0-day used to target international government organizations<br /><a href="https://blog.google/threat-analysis-group/zimbra-0-day-used-to-target-international-government-organizations/" target="_blank" rel="noreferrer noopener">https://blog.google/threat-analysis-group/zimbra-0-day-used-to-target-international-government-organizations/</a><br /> FortiSIEM OS command injection in Report Server<br /><a href="https://www.fortiguard.com/psirt/FG-IR-23-135" target="_blank" rel="noreferrer noopener">https://www.fortiguard.com/psirt/FG-IR-23-135</a><br /> AI Exploit Collection<br /><a href="https://github.com/protectai/ai-exploits" target="_blank" rel="noreferrer noopener">https://github.com/protectai/ai-exploits</a><br /> CrushFTP Remote Code Execution<br /><a href="https://convergetp.com/2023/11/16/crushftp-zero-day-cve-2023-43177-discovered/" target="_blank" rel="noreferrer noopener">https://convergetp.com/2023/11/16/crushftp-zero-day-cve-2023-43177-discovered/</a><br /> Scott Poley: The Cyber Date Paradox: Storing Less, Discovering More<br /><a href="https://www.sans.edu/cyber-research/cyber-data-paradox-storing-less-discovering-more/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/cyber-data-paradox-storing-less-discovering-more/</a><br />]]></itunes:summary><itunes:duration>925</itunes:duration><itunes:keywords>business,computer,crushftp; ai; exploit; fortisi,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8750</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, November 16th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-november-16th-2023--62130955</link><description><![CDATA[Redline Dropped Through MSIX Package<br /><a href="https://isc.sans.edu/diary/Redline%20Dropped%20Through%20MSIX%20Package/30404" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Redline%20Dropped%20Through%20MSIX%20Package/30404</a><br /> ChatGPT Code Interpreter Security Hole<br /><a href="https://www.tomshardware.com/news/chatgpt-code-interpreter-security-hole" target="_blank" rel="noreferrer noopener">https://www.tomshardware.com/news/chatgpt-code-interpreter-security-hole</a><br /> Directory Traversal in Reactor Netty CVE-2023-34062<br /><a href="https://spring.io/security/cve-2023-34062" target="_blank" rel="noreferrer noopener">https://spring.io/security/cve-2023-34062</a><br /> Aruba Networking Product Vulnerabilities<br /><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-017.txt" target="_blank" rel="noreferrer noopener">https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-017.txt</a><br /> HARArmor<br /><a href="https://harmor.dev/" target="_blank" rel="noreferrer noopener">https://harmor.dev/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8748.mp3</guid><pubDate>Thu, 16 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62130955/8748.mp3" length="5305468" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Redline Dropped Through MSIX Package
https://isc.sans.edu/diary/Redline%20Dropped%20Through%20MSIX%20Package/30404
 ChatGPT Code Interpreter Security Hole
https://www.tomshardware.com/news/chatgpt-code-interpreter-security-hole
 Directory Traversal in...</itunes:subtitle><itunes:summary><![CDATA[Redline Dropped Through MSIX Package<br /><a href="https://isc.sans.edu/diary/Redline%20Dropped%20Through%20MSIX%20Package/30404" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Redline%20Dropped%20Through%20MSIX%20Package/30404</a><br /> ChatGPT Code Interpreter Security Hole<br /><a href="https://www.tomshardware.com/news/chatgpt-code-interpreter-security-hole" target="_blank" rel="noreferrer noopener">https://www.tomshardware.com/news/chatgpt-code-interpreter-security-hole</a><br /> Directory Traversal in Reactor Netty CVE-2023-34062<br /><a href="https://spring.io/security/cve-2023-34062" target="_blank" rel="noreferrer noopener">https://spring.io/security/cve-2023-34062</a><br /> Aruba Networking Product Vulnerabilities<br /><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-017.txt" target="_blank" rel="noreferrer noopener">https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-017.txt</a><br /> HARArmor<br /><a href="https://harmor.dev/" target="_blank" rel="noreferrer noopener">https://harmor.dev/</a><br />]]></itunes:summary><itunes:duration>357</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,harmor; aruba; netty; reactor;,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8748</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, November 16th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-november-16th-2023--57655648</link><description><![CDATA[Redline Dropped Through MSIX Package<br /><a href="https://isc.sans.edu/diary/Redline%20Dropped%20Through%20MSIX%20Package/30404" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Redline%20Dropped%20Through%20MSIX%20Package/30404</a><br /> ChatGPT Code Interpreter Security Hole<br /><a href="https://www.tomshardware.com/news/chatgpt-code-interpreter-security-hole" target="_blank" rel="noreferrer noopener">https://www.tomshardware.com/news/chatgpt-code-interpreter-security-hole</a><br /> Directory Traversal in Reactor Netty CVE-2023-34062<br /><a href="https://spring.io/security/cve-2023-34062" target="_blank" rel="noreferrer noopener">https://spring.io/security/cve-2023-34062</a><br /> Aruba Networking Product Vulnerabilities<br /><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-017.txt" target="_blank" rel="noreferrer noopener">https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-017.txt</a><br /> HARArmor<br /><a href="https://harmor.dev/" target="_blank" rel="noreferrer noopener">https://harmor.dev/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8748.mp3</guid><pubDate>Thu, 16 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57655648/8748.mp3" length="5305468" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Redline Dropped Through MSIX Package
https://isc.sans.edu/diary/Redline%20Dropped%20Through%20MSIX%20Package/30404
 ChatGPT Code Interpreter Security Hole
https://www.tomshardware.com/news/chatgpt-code-interpreter-security-hole
 Directory Traversal in...</itunes:subtitle><itunes:summary><![CDATA[Redline Dropped Through MSIX Package<br /><a href="https://isc.sans.edu/diary/Redline%20Dropped%20Through%20MSIX%20Package/30404" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Redline%20Dropped%20Through%20MSIX%20Package/30404</a><br /> ChatGPT Code Interpreter Security Hole<br /><a href="https://www.tomshardware.com/news/chatgpt-code-interpreter-security-hole" target="_blank" rel="noreferrer noopener">https://www.tomshardware.com/news/chatgpt-code-interpreter-security-hole</a><br /> Directory Traversal in Reactor Netty CVE-2023-34062<br /><a href="https://spring.io/security/cve-2023-34062" target="_blank" rel="noreferrer noopener">https://spring.io/security/cve-2023-34062</a><br /> Aruba Networking Product Vulnerabilities<br /><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-017.txt" target="_blank" rel="noreferrer noopener">https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-017.txt</a><br /> HARArmor<br /><a href="https://harmor.dev/" target="_blank" rel="noreferrer noopener">https://harmor.dev/</a><br />]]></itunes:summary><itunes:duration>357</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,harmor; aruba; netty; reactor;,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8748</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, November 15th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-november-15th-2023--62130962</link><description><![CDATA[Microsoft Patches<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20November%202023/30400" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20November%202023/30400</a><br /> Adobe Updates<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> Intel CPU Glitch State Patch<br /><a href="https://lock.cmpxchg8b.com/reptar.html" target="_blank" rel="noreferrer noopener">https://lock.cmpxchg8b.com/reptar.html</a><br /><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00950.html" target="_blank" rel="noreferrer noopener">https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00950.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8746.mp3</guid><pubDate>Wed, 15 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62130962/8746.mp3" length="6333004" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft Patches
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20November%202023/30400
 Adobe Updates
https://helpx.adobe.com/security/security-bulletin.html
 Intel CPU Glitch State Patch
https://lock.cmpxchg8b.com/reptar.html...</itunes:subtitle><itunes:summary><![CDATA[Microsoft Patches<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20November%202023/30400" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20November%202023/30400</a><br /> Adobe Updates<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> Intel CPU Glitch State Patch<br /><a href="https://lock.cmpxchg8b.com/reptar.html" target="_blank" rel="noreferrer noopener">https://lock.cmpxchg8b.com/reptar.html</a><br /><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00950.html" target="_blank" rel="noreferrer noopener">https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00950.html</a><br />]]></itunes:summary><itunes:duration>431</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,intel; cpu; glitch; adobe; mic,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8746</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, November 15th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-november-15th-2023--57637009</link><description><![CDATA[Microsoft Patches<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20November%202023/30400" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20November%202023/30400</a><br /> Adobe Updates<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> Intel CPU Glitch State Patch<br /><a href="https://lock.cmpxchg8b.com/reptar.html" target="_blank" rel="noreferrer noopener">https://lock.cmpxchg8b.com/reptar.html</a><br /><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00950.html" target="_blank" rel="noreferrer noopener">https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00950.html</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8746.mp3</guid><pubDate>Wed, 15 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57637009/8746.mp3" length="6333004" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft Patches
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20November%202023/30400
 Adobe Updates
https://helpx.adobe.com/security/security-bulletin.html
 Intel CPU Glitch State Patch
https://lock.cmpxchg8b.com/reptar.html...</itunes:subtitle><itunes:summary><![CDATA[Microsoft Patches<br /><a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20November%202023/30400" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20November%202023/30400</a><br /> Adobe Updates<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br /> Intel CPU Glitch State Patch<br /><a href="https://lock.cmpxchg8b.com/reptar.html" target="_blank" rel="noreferrer noopener">https://lock.cmpxchg8b.com/reptar.html</a><br /><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00950.html" target="_blank" rel="noreferrer noopener">https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00950.html</a><br />]]></itunes:summary><itunes:duration>431</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,intel; cpu; glitch; adobe; mic,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8746</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, November 14th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-november-14th-2023--62130957</link><description><![CDATA[Noticing command control channels by reviewing DNS protocols<br /><a href="https://isc.sans.edu/diary/Noticing%20command%20and%20control%20channels%20by%20reviewing%20DNS%20protocols/30396" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Noticing%20command%20and%20control%20channels%20by%20reviewing%20DNS%20protocols/30396</a><br /> Passive SSH Key Compromise via Lattices<br /><a href="https://eprint.iacr.org/2023/1711.pdf" target="_blank" rel="noreferrer noopener">https://eprint.iacr.org/2023/1711.pdf</a><br /> Juniper Vulnerabilities Exploited<br /><a href="https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8744.mp3</guid><pubDate>Tue, 14 Nov 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62130957/8744.mp3" length="4570338" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Noticing command control channels by reviewing DNS protocols
https://isc.sans.edu/diary/Noticing%20command%20and%20control%20channels%20by%20reviewing%20DNS%20protocols/30396
 Passive SSH Key Compromise via Lattices...</itunes:subtitle><itunes:summary><![CDATA[Noticing command control channels by reviewing DNS protocols<br /><a href="https://isc.sans.edu/diary/Noticing%20command%20and%20control%20channels%20by%20reviewing%20DNS%20protocols/30396" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Noticing%20command%20and%20control%20channels%20by%20reviewing%20DNS%20protocols/30396</a><br /> Passive SSH Key Compromise via Lattices<br /><a href="https://eprint.iacr.org/2023/1711.pdf" target="_blank" rel="noreferrer noopener">https://eprint.iacr.org/2023/1711.pdf</a><br /> Juniper Vulnerabilities Exploited<br /><a href="https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US</a><br />]]></itunes:summary><itunes:duration>305</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,juniper; passive; ssh; dns; se,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8744</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, November 14th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-november-14th-2023--57625275</link><description><![CDATA[Noticing command control channels by reviewing DNS protocols<br /><a href="https://isc.sans.edu/diary/Noticing%20command%20and%20control%20channels%20by%20reviewing%20DNS%20protocols/30396" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Noticing%20command%20and%20control%20channels%20by%20reviewing%20DNS%20protocols/30396</a><br /> Passive SSH Key Compromise via Lattices<br /><a href="https://eprint.iacr.org/2023/1711.pdf" target="_blank" rel="noreferrer noopener">https://eprint.iacr.org/2023/1711.pdf</a><br /> Juniper Vulnerabilities Exploited<br /><a href="https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8744.mp3</guid><pubDate>Tue, 14 Nov 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57625275/8744.mp3" length="4570338" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Noticing command control channels by reviewing DNS protocols
https://isc.sans.edu/diary/Noticing%20command%20and%20control%20channels%20by%20reviewing%20DNS%20protocols/30396
 Passive SSH Key Compromise via Lattices...</itunes:subtitle><itunes:summary><![CDATA[Noticing command control channels by reviewing DNS protocols<br /><a href="https://isc.sans.edu/diary/Noticing%20command%20and%20control%20channels%20by%20reviewing%20DNS%20protocols/30396" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Noticing%20command%20and%20control%20channels%20by%20reviewing%20DNS%20protocols/30396</a><br /> Passive SSH Key Compromise via Lattices<br /><a href="https://eprint.iacr.org/2023/1711.pdf" target="_blank" rel="noreferrer noopener">https://eprint.iacr.org/2023/1711.pdf</a><br /> Juniper Vulnerabilities Exploited<br /><a href="https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US</a><br />]]></itunes:summary><itunes:duration>305</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,juniper; passive; ssh; dns; se,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8744</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, November 13th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-november-13th-2023--62130958</link><description><![CDATA[Routers Targeted for Gafgyt Botnet<br /><a href="https://isc.sans.edu/forums/diary/Routers%20Targeted%20for%20Gafgyt%20Botnet%20%5BGuest%20Diary%5D/30390/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Routers%20Targeted%20for%20Gafgyt%20Botnet%20%5BGuest%20Diary%5D/30390/</a><br /> ScreenConnect used to Attack Healthcare<br /><a href="https://www.huntress.com/blog/third-party-pharmaceutical-vendor-linked-to-pharmacy-and-health-clinic-cyberattack" target="_blank" rel="noreferrer noopener">https://www.huntress.com/blog/third-party-pharmaceutical-vendor-linked-to-pharmacy-and-health-clinic-cyberattack</a><br /> Fake Skills Assessment Portals Associated with Sapphire Sleet<br /><a href="https://twitter.com/MsftSecIntel/status/1722316019920728437" target="_blank" rel="noreferrer noopener">https://twitter.com/MsftSecIntel/status/1722316019920728437</a><br /> OpenVPN Access Server Vulnerabilities<br /><a href="https://openvpn.net/security-advisory/access-server-security-update-cve-2023-46849-cve-2023-46850/" target="_blank" rel="noreferrer noopener">https://openvpn.net/security-advisory/access-server-security-update-cve-2023-46849-cve-2023-46850/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8742.mp3</guid><pubDate>Mon, 13 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62130958/8742.mp3" length="5155125" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Routers Targeted for Gafgyt Botnet
https://isc.sans.edu/forums/diary/Routers%20Targeted%20for%20Gafgyt%20Botnet%20%5BGuest%20Diary%5D/30390/
 ScreenConnect used to Attack Healthcare...</itunes:subtitle><itunes:summary><![CDATA[Routers Targeted for Gafgyt Botnet<br /><a href="https://isc.sans.edu/forums/diary/Routers%20Targeted%20for%20Gafgyt%20Botnet%20%5BGuest%20Diary%5D/30390/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Routers%20Targeted%20for%20Gafgyt%20Botnet%20%5BGuest%20Diary%5D/30390/</a><br /> ScreenConnect used to Attack Healthcare<br /><a href="https://www.huntress.com/blog/third-party-pharmaceutical-vendor-linked-to-pharmacy-and-health-clinic-cyberattack" target="_blank" rel="noreferrer noopener">https://www.huntress.com/blog/third-party-pharmaceutical-vendor-linked-to-pharmacy-and-health-clinic-cyberattack</a><br /> Fake Skills Assessment Portals Associated with Sapphire Sleet<br /><a href="https://twitter.com/MsftSecIntel/status/1722316019920728437" target="_blank" rel="noreferrer noopener">https://twitter.com/MsftSecIntel/status/1722316019920728437</a><br /> OpenVPN Access Server Vulnerabilities<br /><a href="https://openvpn.net/security-advisory/access-server-security-update-cve-2023-46849-cve-2023-46850/" target="_blank" rel="noreferrer noopener">https://openvpn.net/security-advisory/access-server-security-update-cve-2023-46849-cve-2023-46850/</a><br />]]></itunes:summary><itunes:duration>347</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,openvpn; saphire sleet; job po,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8742</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, November 13th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-november-13th-2023--57608758</link><description><![CDATA[Routers Targeted for Gafgyt Botnet<br /><a href="https://isc.sans.edu/forums/diary/Routers%20Targeted%20for%20Gafgyt%20Botnet%20%5BGuest%20Diary%5D/30390/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Routers%20Targeted%20for%20Gafgyt%20Botnet%20%5BGuest%20Diary%5D/30390/</a><br /> ScreenConnect used to Attack Healthcare<br /><a href="https://www.huntress.com/blog/third-party-pharmaceutical-vendor-linked-to-pharmacy-and-health-clinic-cyberattack" target="_blank" rel="noreferrer noopener">https://www.huntress.com/blog/third-party-pharmaceutical-vendor-linked-to-pharmacy-and-health-clinic-cyberattack</a><br /> Fake Skills Assessment Portals Associated with Sapphire Sleet<br /><a href="https://twitter.com/MsftSecIntel/status/1722316019920728437" target="_blank" rel="noreferrer noopener">https://twitter.com/MsftSecIntel/status/1722316019920728437</a><br /> OpenVPN Access Server Vulnerabilities<br /><a href="https://openvpn.net/security-advisory/access-server-security-update-cve-2023-46849-cve-2023-46850/" target="_blank" rel="noreferrer noopener">https://openvpn.net/security-advisory/access-server-security-update-cve-2023-46849-cve-2023-46850/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8742.mp3</guid><pubDate>Mon, 13 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57608758/8742.mp3" length="5155125" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Routers Targeted for Gafgyt Botnet
https://isc.sans.edu/forums/diary/Routers%20Targeted%20for%20Gafgyt%20Botnet%20%5BGuest%20Diary%5D/30390/
 ScreenConnect used to Attack Healthcare...</itunes:subtitle><itunes:summary><![CDATA[Routers Targeted for Gafgyt Botnet<br /><a href="https://isc.sans.edu/forums/diary/Routers%20Targeted%20for%20Gafgyt%20Botnet%20%5BGuest%20Diary%5D/30390/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Routers%20Targeted%20for%20Gafgyt%20Botnet%20%5BGuest%20Diary%5D/30390/</a><br /> ScreenConnect used to Attack Healthcare<br /><a href="https://www.huntress.com/blog/third-party-pharmaceutical-vendor-linked-to-pharmacy-and-health-clinic-cyberattack" target="_blank" rel="noreferrer noopener">https://www.huntress.com/blog/third-party-pharmaceutical-vendor-linked-to-pharmacy-and-health-clinic-cyberattack</a><br /> Fake Skills Assessment Portals Associated with Sapphire Sleet<br /><a href="https://twitter.com/MsftSecIntel/status/1722316019920728437" target="_blank" rel="noreferrer noopener">https://twitter.com/MsftSecIntel/status/1722316019920728437</a><br /> OpenVPN Access Server Vulnerabilities<br /><a href="https://openvpn.net/security-advisory/access-server-security-update-cve-2023-46849-cve-2023-46850/" target="_blank" rel="noreferrer noopener">https://openvpn.net/security-advisory/access-server-security-update-cve-2023-46849-cve-2023-46850/</a><br />]]></itunes:summary><itunes:duration>347</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,openvpn; saphire sleet; job po,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8742</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, November 10th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-november-10th-2023--62130960</link><description><![CDATA[Visual Examples of Code Injection<br /><a href="https://isc.sans.edu/diary/Visual%20Examples%20of%20Code%20Injection/30388" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Visual%20Examples%20of%20Code%20Injection/30388</a><br /> SysAid Exploited by Cl0p Ransomware (CVE-2023-47246)<br /><a href="https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification" target="_blank" rel="noreferrer noopener">https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification</a><br /> WS_FTP Server Update CVE-2023-42659<br /><a href="https://community.progress.com/s/article/WS-FTP-Server-Service-Pack-November-2023" target="_blank" rel="noreferrer noopener">https://community.progress.com/s/article/WS-FTP-Server-Service-Pack-November-2023</a><br /> Malvertiser copies PC news site to delivery infostealer<br /><a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/11/malvertiser-copies-pc-news-site-to-deliver-infostealer" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/threat-intelligence/2023/11/malvertiser-copies-pc-news-site-to-deliver-infostealer</a><br /> pyArrow/Apache Arrow Vulnerability<br /><a href="https://lists.apache.org/thread/yhy7tdfjf9hrl9vfrtzo8p2cyjq87v7n" target="_blank" rel="noreferrer noopener">https://lists.apache.org/thread/yhy7tdfjf9hrl9vfrtzo8p2cyjq87v7n</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8740.mp3</guid><pubDate>Fri, 10 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62130960/8740.mp3" length="4861531" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Visual Examples of Code Injection
https://isc.sans.edu/diary/Visual%20Examples%20of%20Code%20Injection/30388
 SysAid Exploited by Cl0p Ransomware (CVE-2023-47246)...</itunes:subtitle><itunes:summary><![CDATA[Visual Examples of Code Injection<br /><a href="https://isc.sans.edu/diary/Visual%20Examples%20of%20Code%20Injection/30388" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Visual%20Examples%20of%20Code%20Injection/30388</a><br /> SysAid Exploited by Cl0p Ransomware (CVE-2023-47246)<br /><a href="https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification" target="_blank" rel="noreferrer noopener">https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification</a><br /> WS_FTP Server Update CVE-2023-42659<br /><a href="https://community.progress.com/s/article/WS-FTP-Server-Service-Pack-November-2023" target="_blank" rel="noreferrer noopener">https://community.progress.com/s/article/WS-FTP-Server-Service-Pack-November-2023</a><br /> Malvertiser copies PC news site to delivery infostealer<br /><a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/11/malvertiser-copies-pc-news-site-to-deliver-infostealer" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/threat-intelligence/2023/11/malvertiser-copies-pc-news-site-to-deliver-infostealer</a><br /> pyArrow/Apache Arrow Vulnerability<br /><a href="https://lists.apache.org/thread/yhy7tdfjf9hrl9vfrtzo8p2cyjq87v7n" target="_blank" rel="noreferrer noopener">https://lists.apache.org/thread/yhy7tdfjf9hrl9vfrtzo8p2cyjq87v7n</a><br />]]></itunes:summary><itunes:duration>326</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,pyarrow; apache; arrow; cpu-z;,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8740</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, November 10th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-november-10th-2023--57584991</link><description><![CDATA[Visual Examples of Code Injection<br /><a href="https://isc.sans.edu/diary/Visual%20Examples%20of%20Code%20Injection/30388" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Visual%20Examples%20of%20Code%20Injection/30388</a><br /> SysAid Exploited by Cl0p Ransomware (CVE-2023-47246)<br /><a href="https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification" target="_blank" rel="noreferrer noopener">https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification</a><br /> WS_FTP Server Update CVE-2023-42659<br /><a href="https://community.progress.com/s/article/WS-FTP-Server-Service-Pack-November-2023" target="_blank" rel="noreferrer noopener">https://community.progress.com/s/article/WS-FTP-Server-Service-Pack-November-2023</a><br /> Malvertiser copies PC news site to delivery infostealer<br /><a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/11/malvertiser-copies-pc-news-site-to-deliver-infostealer" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/threat-intelligence/2023/11/malvertiser-copies-pc-news-site-to-deliver-infostealer</a><br /> pyArrow/Apache Arrow Vulnerability<br /><a href="https://lists.apache.org/thread/yhy7tdfjf9hrl9vfrtzo8p2cyjq87v7n" target="_blank" rel="noreferrer noopener">https://lists.apache.org/thread/yhy7tdfjf9hrl9vfrtzo8p2cyjq87v7n</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8740.mp3</guid><pubDate>Fri, 10 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57584991/8740.mp3" length="4861531" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Visual Examples of Code Injection
https://isc.sans.edu/diary/Visual%20Examples%20of%20Code%20Injection/30388
 SysAid Exploited by Cl0p Ransomware (CVE-2023-47246)...</itunes:subtitle><itunes:summary><![CDATA[Visual Examples of Code Injection<br /><a href="https://isc.sans.edu/diary/Visual%20Examples%20of%20Code%20Injection/30388" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Visual%20Examples%20of%20Code%20Injection/30388</a><br /> SysAid Exploited by Cl0p Ransomware (CVE-2023-47246)<br /><a href="https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification" target="_blank" rel="noreferrer noopener">https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification</a><br /> WS_FTP Server Update CVE-2023-42659<br /><a href="https://community.progress.com/s/article/WS-FTP-Server-Service-Pack-November-2023" target="_blank" rel="noreferrer noopener">https://community.progress.com/s/article/WS-FTP-Server-Service-Pack-November-2023</a><br /> Malvertiser copies PC news site to delivery infostealer<br /><a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/11/malvertiser-copies-pc-news-site-to-deliver-infostealer" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/threat-intelligence/2023/11/malvertiser-copies-pc-news-site-to-deliver-infostealer</a><br /> pyArrow/Apache Arrow Vulnerability<br /><a href="https://lists.apache.org/thread/yhy7tdfjf9hrl9vfrtzo8p2cyjq87v7n" target="_blank" rel="noreferrer noopener">https://lists.apache.org/thread/yhy7tdfjf9hrl9vfrtzo8p2cyjq87v7n</a><br />]]></itunes:summary><itunes:duration>326</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,pyarrow; apache; arrow; cpu-z;,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8740</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, November 9th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-november-9th-2023--62130959</link><description><![CDATA[Example of a Phishing Campaing Project File<br /><a href="https://isc.sans.edu/diary/Example%20of%20Phishing%20Campaign%20Project%20File/30384" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Example%20of%20Phishing%20Campaign%20Project%20File/30384</a><br /> Cryptomining with Microsoft Azure Automation Services<br /><a href="https://www.safebreach.com/blog/cryptocurrency-miner-microsoft-azure" target="_blank" rel="noreferrer noopener">https://www.safebreach.com/blog/cryptocurrency-miner-microsoft-azure</a><br /> Windows 11 Insider Changing Firewall Behaviour<br /><a href="https://blogs.windows.com/windows-insider/2023/11/08/announcing-windows-11-insider-preview-build-25992-canary-channel/" target="_blank" rel="noreferrer noopener">https://blogs.windows.com/windows-insider/2023/11/08/announcing-windows-11-insider-preview-build-25992-canary-channel/</a><br /> CISA Adds SLP Vulnerability to Known Exploited Vulnerabilty List<br /><a href="https://www.cisa.gov/news-events/alerts/2023/11/08/cisa-adds-one-known-exploited-vulnerability-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2023/11/08/cisa-adds-one-known-exploited-vulnerability-catalog</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8738.mp3</guid><pubDate>Thu, 09 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62130959/8738.mp3" length="4801354" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Example of a Phishing Campaing Project File
https://isc.sans.edu/diary/Example%20of%20Phishing%20Campaign%20Project%20File/30384
 Cryptomining with Microsoft Azure Automation Services...</itunes:subtitle><itunes:summary><![CDATA[Example of a Phishing Campaing Project File<br /><a href="https://isc.sans.edu/diary/Example%20of%20Phishing%20Campaign%20Project%20File/30384" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Example%20of%20Phishing%20Campaign%20Project%20File/30384</a><br /> Cryptomining with Microsoft Azure Automation Services<br /><a href="https://www.safebreach.com/blog/cryptocurrency-miner-microsoft-azure" target="_blank" rel="noreferrer noopener">https://www.safebreach.com/blog/cryptocurrency-miner-microsoft-azure</a><br /> Windows 11 Insider Changing Firewall Behaviour<br /><a href="https://blogs.windows.com/windows-insider/2023/11/08/announcing-windows-11-insider-preview-build-25992-canary-channel/" target="_blank" rel="noreferrer noopener">https://blogs.windows.com/windows-insider/2023/11/08/announcing-windows-11-insider-preview-build-25992-canary-channel/</a><br /> CISA Adds SLP Vulnerability to Known Exploited Vulnerabilty List<br /><a href="https://www.cisa.gov/news-events/alerts/2023/11/08/cisa-adds-one-known-exploited-vulnerability-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2023/11/08/cisa-adds-one-known-exploited-vulnerability-catalog</a><br />]]></itunes:summary><itunes:duration>321</itunes:duration><itunes:keywords>business,cisa; slp; windows 11; smb; nt,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8738</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, November 9th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-november-9th-2023--57567985</link><description><![CDATA[Example of a Phishing Campaing Project File<br /><a href="https://isc.sans.edu/diary/Example%20of%20Phishing%20Campaign%20Project%20File/30384" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Example%20of%20Phishing%20Campaign%20Project%20File/30384</a><br /> Cryptomining with Microsoft Azure Automation Services<br /><a href="https://www.safebreach.com/blog/cryptocurrency-miner-microsoft-azure" target="_blank" rel="noreferrer noopener">https://www.safebreach.com/blog/cryptocurrency-miner-microsoft-azure</a><br /> Windows 11 Insider Changing Firewall Behaviour<br /><a href="https://blogs.windows.com/windows-insider/2023/11/08/announcing-windows-11-insider-preview-build-25992-canary-channel/" target="_blank" rel="noreferrer noopener">https://blogs.windows.com/windows-insider/2023/11/08/announcing-windows-11-insider-preview-build-25992-canary-channel/</a><br /> CISA Adds SLP Vulnerability to Known Exploited Vulnerabilty List<br /><a href="https://www.cisa.gov/news-events/alerts/2023/11/08/cisa-adds-one-known-exploited-vulnerability-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2023/11/08/cisa-adds-one-known-exploited-vulnerability-catalog</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8738.mp3</guid><pubDate>Thu, 09 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57567985/8738.mp3" length="4801354" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Example of a Phishing Campaing Project File
https://isc.sans.edu/diary/Example%20of%20Phishing%20Campaign%20Project%20File/30384
 Cryptomining with Microsoft Azure Automation Services...</itunes:subtitle><itunes:summary><![CDATA[Example of a Phishing Campaing Project File<br /><a href="https://isc.sans.edu/diary/Example%20of%20Phishing%20Campaign%20Project%20File/30384" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Example%20of%20Phishing%20Campaign%20Project%20File/30384</a><br /> Cryptomining with Microsoft Azure Automation Services<br /><a href="https://www.safebreach.com/blog/cryptocurrency-miner-microsoft-azure" target="_blank" rel="noreferrer noopener">https://www.safebreach.com/blog/cryptocurrency-miner-microsoft-azure</a><br /> Windows 11 Insider Changing Firewall Behaviour<br /><a href="https://blogs.windows.com/windows-insider/2023/11/08/announcing-windows-11-insider-preview-build-25992-canary-channel/" target="_blank" rel="noreferrer noopener">https://blogs.windows.com/windows-insider/2023/11/08/announcing-windows-11-insider-preview-build-25992-canary-channel/</a><br /> CISA Adds SLP Vulnerability to Known Exploited Vulnerabilty List<br /><a href="https://www.cisa.gov/news-events/alerts/2023/11/08/cisa-adds-one-known-exploited-vulnerability-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2023/11/08/cisa-adds-one-known-exploited-vulnerability-catalog</a><br />]]></itunes:summary><itunes:duration>321</itunes:duration><itunes:keywords>business,cisa; slp; windows 11; smb; nt,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8738</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, November 8th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-november-8th-2023--62130963</link><description><![CDATA[What's Normal: New uses of DNS, Discovery of Designated Resolvers (DDR)<br /><a href="https://isc.sans.edu/diary/What%27s%20Normal%3A%20New%20uses%20of%20DNS%2C%20Discovery%20of%20Designated%20Resolvers%20%28DDR%29/30380" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%27s%20Normal%3A%20New%20uses%20of%20DNS%2C%20Discovery%20of%20Designated%20Resolvers%20%28DDR%29/30380</a><br /> BlueNoroff macOS Malware<br /><a href="https://www.jamf.com/blog/bluenoroff-strikes-again-with-new-macos-malware/" target="_blank" rel="noreferrer noopener">https://www.jamf.com/blog/bluenoroff-strikes-again-with-new-macos-malware/</a><br /> Emphasizing Security by Default wiht Advanced Microsoft Authenticator Features<br /><a href="https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/emphasizing-security-by-default-with-advanced-microsoft/ba-p/3773130" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/emphasizing-security-by-default-with-advanced-microsoft/ba-p/3773130</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8736.mp3</guid><pubDate>Wed, 08 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62130963/8736.mp3" length="5657862" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>What's Normal: New uses of DNS, Discovery of Designated Resolvers (DDR)
https://isc.sans.edu/diary/What%27s%20Normal%3A%20New%20uses%20of%20DNS%2C%20Discovery%20of%20Designated%20Resolvers%20%28DDR%29/30380
 BlueNoroff macOS Malware...</itunes:subtitle><itunes:summary><![CDATA[What's Normal: New uses of DNS, Discovery of Designated Resolvers (DDR)<br /><a href="https://isc.sans.edu/diary/What%27s%20Normal%3A%20New%20uses%20of%20DNS%2C%20Discovery%20of%20Designated%20Resolvers%20%28DDR%29/30380" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%27s%20Normal%3A%20New%20uses%20of%20DNS%2C%20Discovery%20of%20Designated%20Resolvers%20%28DDR%29/30380</a><br /> BlueNoroff macOS Malware<br /><a href="https://www.jamf.com/blog/bluenoroff-strikes-again-with-new-macos-malware/" target="_blank" rel="noreferrer noopener">https://www.jamf.com/blog/bluenoroff-strikes-again-with-new-macos-malware/</a><br /> Emphasizing Security by Default wiht Advanced Microsoft Authenticator Features<br /><a href="https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/emphasizing-security-by-default-with-advanced-microsoft/ba-p/3773130" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/emphasizing-security-by-default-with-advanced-microsoft/ba-p/3773130</a><br />]]></itunes:summary><itunes:duration>383</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microsoft; authenticator; maco,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8736</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, November 8th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-november-8th-2023--57550431</link><description><![CDATA[What's Normal: New uses of DNS, Discovery of Designated Resolvers (DDR)<br /><a href="https://isc.sans.edu/diary/What%27s%20Normal%3A%20New%20uses%20of%20DNS%2C%20Discovery%20of%20Designated%20Resolvers%20%28DDR%29/30380" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%27s%20Normal%3A%20New%20uses%20of%20DNS%2C%20Discovery%20of%20Designated%20Resolvers%20%28DDR%29/30380</a><br /> BlueNoroff macOS Malware<br /><a href="https://www.jamf.com/blog/bluenoroff-strikes-again-with-new-macos-malware/" target="_blank" rel="noreferrer noopener">https://www.jamf.com/blog/bluenoroff-strikes-again-with-new-macos-malware/</a><br /> Emphasizing Security by Default wiht Advanced Microsoft Authenticator Features<br /><a href="https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/emphasizing-security-by-default-with-advanced-microsoft/ba-p/3773130" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/emphasizing-security-by-default-with-advanced-microsoft/ba-p/3773130</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8736.mp3</guid><pubDate>Wed, 08 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57550431/8736.mp3" length="5657862" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>What's Normal: New uses of DNS, Discovery of Designated Resolvers (DDR)
https://isc.sans.edu/diary/What%27s%20Normal%3A%20New%20uses%20of%20DNS%2C%20Discovery%20of%20Designated%20Resolvers%20%28DDR%29/30380
 BlueNoroff macOS Malware...</itunes:subtitle><itunes:summary><![CDATA[What's Normal: New uses of DNS, Discovery of Designated Resolvers (DDR)<br /><a href="https://isc.sans.edu/diary/What%27s%20Normal%3A%20New%20uses%20of%20DNS%2C%20Discovery%20of%20Designated%20Resolvers%20%28DDR%29/30380" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%27s%20Normal%3A%20New%20uses%20of%20DNS%2C%20Discovery%20of%20Designated%20Resolvers%20%28DDR%29/30380</a><br /> BlueNoroff macOS Malware<br /><a href="https://www.jamf.com/blog/bluenoroff-strikes-again-with-new-macos-malware/" target="_blank" rel="noreferrer noopener">https://www.jamf.com/blog/bluenoroff-strikes-again-with-new-macos-malware/</a><br /> Emphasizing Security by Default wiht Advanced Microsoft Authenticator Features<br /><a href="https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/emphasizing-security-by-default-with-advanced-microsoft/ba-p/3773130" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/emphasizing-security-by-default-with-advanced-microsoft/ba-p/3773130</a><br />]]></itunes:summary><itunes:duration>383</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microsoft; authenticator; maco,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8736</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, November 7th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-november-7th-2023--62130964</link><description><![CDATA[Confluence CVe-2023-22518 Exploited<br /><a href="https://isc.sans.edu/diary/Exploit%20Activity%20for%20CVE-2023-22518%2C%20Atlassian%20Confluence%20Data%20Center%20and%20Server/30376" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit%20Activity%20for%20CVE-2023-22518%2C%20Atlassian%20Confluence%20Data%20Center%20and%20Server/30376</a><br /> Google Threat Horizons Report<br /><a href="https://services.google.com/fh/files/blogs/gcat_threathorizons_full_oct2023.pdf" target="_blank" rel="noreferrer noopener">https://services.google.com/fh/files/blogs/gcat_threathorizons_full_oct2023.pdf</a><br /><a href="https://www.sans.edu/cyber-research/bookmark-bruggling-novel-data-exfiltration-with-brugglemark/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/bookmark-bruggling-novel-data-exfiltration-with-brugglemark/</a><br /> Veeam Update<br /><a href="https://www.veeam.com/kb4508" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4508</a><br /> QNAP Update<br /><a href="https://www.qnap.com/de-de/security-advisory/qsa-23-35" target="_blank" rel="noreferrer noopener">https://www.qnap.com/de-de/security-advisory/qsa-23-35</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8734.mp3</guid><pubDate>Tue, 07 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/62130964/8734.mp3" length="5506916" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Confluence CVe-2023-22518 Exploited
https://isc.sans.edu/diary/Exploit%20Activity%20for%20CVE-2023-22518%2C%20Atlassian%20Confluence%20Data%20Center%20and%20Server/30376
 Google Threat Horizons Report...</itunes:subtitle><itunes:summary><![CDATA[Confluence CVe-2023-22518 Exploited<br /><a href="https://isc.sans.edu/diary/Exploit%20Activity%20for%20CVE-2023-22518%2C%20Atlassian%20Confluence%20Data%20Center%20and%20Server/30376" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit%20Activity%20for%20CVE-2023-22518%2C%20Atlassian%20Confluence%20Data%20Center%20and%20Server/30376</a><br /> Google Threat Horizons Report<br /><a href="https://services.google.com/fh/files/blogs/gcat_threathorizons_full_oct2023.pdf" target="_blank" rel="noreferrer noopener">https://services.google.com/fh/files/blogs/gcat_threathorizons_full_oct2023.pdf</a><br /><a href="https://www.sans.edu/cyber-research/bookmark-bruggling-novel-data-exfiltration-with-brugglemark/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/bookmark-bruggling-novel-data-exfiltration-with-brugglemark/</a><br /> Veeam Update<br /><a href="https://www.veeam.com/kb4508" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4508</a><br /> QNAP Update<br /><a href="https://www.qnap.com/de-de/security-advisory/qsa-23-35" target="_blank" rel="noreferrer noopener">https://www.qnap.com/de-de/security-advisory/qsa-23-35</a><br />]]></itunes:summary><itunes:duration>372</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,qnap; veeam; google; horizons;,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8734</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, November 7th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-november-7th-2023--57537701</link><description><![CDATA[Confluence CVe-2023-22518 Exploited<br /><a href="https://isc.sans.edu/diary/Exploit%20Activity%20for%20CVE-2023-22518%2C%20Atlassian%20Confluence%20Data%20Center%20and%20Server/30376" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit%20Activity%20for%20CVE-2023-22518%2C%20Atlassian%20Confluence%20Data%20Center%20and%20Server/30376</a><br /> Google Threat Horizons Report<br /><a href="https://services.google.com/fh/files/blogs/gcat_threathorizons_full_oct2023.pdf" target="_blank" rel="noreferrer noopener">https://services.google.com/fh/files/blogs/gcat_threathorizons_full_oct2023.pdf</a><br /><a href="https://www.sans.edu/cyber-research/bookmark-bruggling-novel-data-exfiltration-with-brugglemark/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/bookmark-bruggling-novel-data-exfiltration-with-brugglemark/</a><br /> Veeam Update<br /><a href="https://www.veeam.com/kb4508" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4508</a><br /> QNAP Update<br /><a href="https://www.qnap.com/de-de/security-advisory/qsa-23-35" target="_blank" rel="noreferrer noopener">https://www.qnap.com/de-de/security-advisory/qsa-23-35</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8734.mp3</guid><pubDate>Tue, 07 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537701/8734.mp3" length="5506916" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Confluence CVe-2023-22518 Exploited
https://isc.sans.edu/diary/Exploit%20Activity%20for%20CVE-2023-22518%2C%20Atlassian%20Confluence%20Data%20Center%20and%20Server/30376
 Google Threat Horizons Report...</itunes:subtitle><itunes:summary><![CDATA[Confluence CVe-2023-22518 Exploited<br /><a href="https://isc.sans.edu/diary/Exploit%20Activity%20for%20CVE-2023-22518%2C%20Atlassian%20Confluence%20Data%20Center%20and%20Server/30376" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Exploit%20Activity%20for%20CVE-2023-22518%2C%20Atlassian%20Confluence%20Data%20Center%20and%20Server/30376</a><br /> Google Threat Horizons Report<br /><a href="https://services.google.com/fh/files/blogs/gcat_threathorizons_full_oct2023.pdf" target="_blank" rel="noreferrer noopener">https://services.google.com/fh/files/blogs/gcat_threathorizons_full_oct2023.pdf</a><br /><a href="https://www.sans.edu/cyber-research/bookmark-bruggling-novel-data-exfiltration-with-brugglemark/" target="_blank" rel="noreferrer noopener">https://www.sans.edu/cyber-research/bookmark-bruggling-novel-data-exfiltration-with-brugglemark/</a><br /> Veeam Update<br /><a href="https://www.veeam.com/kb4508" target="_blank" rel="noreferrer noopener">https://www.veeam.com/kb4508</a><br /> QNAP Update<br /><a href="https://www.qnap.com/de-de/security-advisory/qsa-23-35" target="_blank" rel="noreferrer noopener">https://www.qnap.com/de-de/security-advisory/qsa-23-35</a><br />]]></itunes:summary><itunes:duration>372</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,qnap; veeam; google; horizons;,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8734</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, November 6th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-november-6th-2023--57537702</link><description><![CDATA[New Microsoft Exchange Zero Days<br /><a href="https://www.bleepingcomputer.com/news/microsoft/new-microsoft-exchange-zero-days-allow-rce-data-theft-attacks/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/microsoft/new-microsoft-exchange-zero-days-allow-rce-data-theft-attacks/</a><br /> StripedFly: Perennially Flying under the Radar<br /><a href="https://securelist.com/stripedfly-perennially-flying-under-the-radar/110903/" target="_blank" rel="noreferrer noopener">https://securelist.com/stripedfly-perennially-flying-under-the-radar/110903/</a><br /> Send My: Sending Data over Apple's Find My Network<br /><a href="https://github.com/positive-security/send-my" target="_blank" rel="noreferrer noopener">https://github.com/positive-security/send-my</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8732.mp3</guid><pubDate>Mon, 06 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537702/8732.mp3" length="6288937" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>New Microsoft Exchange Zero Days
https://www.bleepingcomputer.com/news/microsoft/new-microsoft-exchange-zero-days-allow-rce-data-theft-attacks/
 StripedFly: Perennially Flying under the Radar...</itunes:subtitle><itunes:summary><![CDATA[New Microsoft Exchange Zero Days<br /><a href="https://www.bleepingcomputer.com/news/microsoft/new-microsoft-exchange-zero-days-allow-rce-data-theft-attacks/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/microsoft/new-microsoft-exchange-zero-days-allow-rce-data-theft-attacks/</a><br /> StripedFly: Perennially Flying under the Radar<br /><a href="https://securelist.com/stripedfly-perennially-flying-under-the-radar/110903/" target="_blank" rel="noreferrer noopener">https://securelist.com/stripedfly-perennially-flying-under-the-radar/110903/</a><br /> Send My: Sending Data over Apple's Find My Network<br /><a href="https://github.com/positive-security/send-my" target="_blank" rel="noreferrer noopener">https://github.com/positive-security/send-my</a><br />]]></itunes:summary><itunes:duration>428</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,send my; apple; find my; strip</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8732</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, November 6th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-november-6th-2023--57526566</link><description><![CDATA[New Microsoft Exchange Zero Days<br /><a href="https://www.bleepingcomputer.com/news/microsoft/new-microsoft-exchange-zero-days-allow-rce-data-theft-attacks/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/microsoft/new-microsoft-exchange-zero-days-allow-rce-data-theft-attacks/</a><br /> StripedFly: Perennially Flying under the Radar<br /><a href="https://securelist.com/stripedfly-perennially-flying-under-the-radar/110903/" target="_blank" rel="noreferrer noopener">https://securelist.com/stripedfly-perennially-flying-under-the-radar/110903/</a><br /> Send My: Sending Data over Apple's Find My Network<br /><a href="https://github.com/positive-security/send-my" target="_blank" rel="noreferrer noopener">https://github.com/positive-security/send-my</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8732.mp3</guid><pubDate>Mon, 06 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57526566/8732.mp3" length="6288937" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>New Microsoft Exchange Zero Days
https://www.bleepingcomputer.com/news/microsoft/new-microsoft-exchange-zero-days-allow-rce-data-theft-attacks/
 StripedFly: Perennially Flying under the Radar...</itunes:subtitle><itunes:summary><![CDATA[New Microsoft Exchange Zero Days<br /><a href="https://www.bleepingcomputer.com/news/microsoft/new-microsoft-exchange-zero-days-allow-rce-data-theft-attacks/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/microsoft/new-microsoft-exchange-zero-days-allow-rce-data-theft-attacks/</a><br /> StripedFly: Perennially Flying under the Radar<br /><a href="https://securelist.com/stripedfly-perennially-flying-under-the-radar/110903/" target="_blank" rel="noreferrer noopener">https://securelist.com/stripedfly-perennially-flying-under-the-radar/110903/</a><br /> Send My: Sending Data over Apple's Find My Network<br /><a href="https://github.com/positive-security/send-my" target="_blank" rel="noreferrer noopener">https://github.com/positive-security/send-my</a><br />]]></itunes:summary><itunes:duration>428</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,send my; apple; find my; strip</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8732</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, November 3rd, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-november-3rd-2023--57537703</link><description><![CDATA[Quick Tip for Artificially Inflated PE Files<br /><a href="https://isc.sans.edu/diary/Quick%20Tip%20For%20Artificially%20Inflated%20PE%20Files/30370" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Quick%20Tip%20For%20Artificially%20Inflated%20PE%20Files/30370</a><br /> Apache ActiveMQ Flaw Exploited<br /><a href="https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt" target="_blank" rel="noreferrer noopener">https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt</a><br /><a href="https://www.rapid7.com/blog/post/2023/11/01/etr-suspected-exploitation-of-apache-activemq-cve-2023-46604/" target="_blank" rel="noreferrer noopener">https://www.rapid7.com/blog/post/2023/11/01/etr-suspected-exploitation-of-apache-activemq-cve-2023-46604/</a><br /> Critical Firepower Vulnerability<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-29MP49hN" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-29MP49hN</a><br /> Dozens of npm Packages Caught Attempting to Deploy Reverse Shell<br /><a href="https://blog.phylum.io/dozens-of-npm-packages-caught-attempting-to-deploy-reverse-shell/" target="_blank" rel="noreferrer noopener">https://blog.phylum.io/dozens-of-npm-packages-caught-attempting-to-deploy-reverse-shell/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8730.mp3</guid><pubDate>Fri, 03 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537703/8730.mp3" length="4820407" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Quick Tip for Artificially Inflated PE Files
https://isc.sans.edu/diary/Quick%20Tip%20For%20Artificially%20Inflated%20PE%20Files/30370
 Apache ActiveMQ Flaw Exploited
https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt...</itunes:subtitle><itunes:summary><![CDATA[Quick Tip for Artificially Inflated PE Files<br /><a href="https://isc.sans.edu/diary/Quick%20Tip%20For%20Artificially%20Inflated%20PE%20Files/30370" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Quick%20Tip%20For%20Artificially%20Inflated%20PE%20Files/30370</a><br /> Apache ActiveMQ Flaw Exploited<br /><a href="https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt" target="_blank" rel="noreferrer noopener">https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt</a><br /><a href="https://www.rapid7.com/blog/post/2023/11/01/etr-suspected-exploitation-of-apache-activemq-cve-2023-46604/" target="_blank" rel="noreferrer noopener">https://www.rapid7.com/blog/post/2023/11/01/etr-suspected-exploitation-of-apache-activemq-cve-2023-46604/</a><br /> Critical Firepower Vulnerability<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-29MP49hN" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-29MP49hN</a><br /> Dozens of npm Packages Caught Attempting to Deploy Reverse Shell<br /><a href="https://blog.phylum.io/dozens-of-npm-packages-caught-attempting-to-deploy-reverse-shell/" target="_blank" rel="noreferrer noopener">https://blog.phylum.io/dozens-of-npm-packages-caught-attempting-to-deploy-reverse-shell/</a><br />]]></itunes:summary><itunes:duration>323</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,reverse shell; npm; rsh.js; fi,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8730</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, November 3rd, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-november-3rd-2023--57490281</link><description><![CDATA[Quick Tip for Artificially Inflated PE Files<br /><a href="https://isc.sans.edu/diary/Quick%20Tip%20For%20Artificially%20Inflated%20PE%20Files/30370" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Quick%20Tip%20For%20Artificially%20Inflated%20PE%20Files/30370</a><br /> Apache ActiveMQ Flaw Exploited<br /><a href="https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt" target="_blank" rel="noreferrer noopener">https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt</a><br /><a href="https://www.rapid7.com/blog/post/2023/11/01/etr-suspected-exploitation-of-apache-activemq-cve-2023-46604/" target="_blank" rel="noreferrer noopener">https://www.rapid7.com/blog/post/2023/11/01/etr-suspected-exploitation-of-apache-activemq-cve-2023-46604/</a><br /> Critical Firepower Vulnerability<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-29MP49hN" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-29MP49hN</a><br /> Dozens of npm Packages Caught Attempting to Deploy Reverse Shell<br /><a href="https://blog.phylum.io/dozens-of-npm-packages-caught-attempting-to-deploy-reverse-shell/" target="_blank" rel="noreferrer noopener">https://blog.phylum.io/dozens-of-npm-packages-caught-attempting-to-deploy-reverse-shell/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8730.mp3</guid><pubDate>Fri, 03 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57490281/8730.mp3" length="4820407" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Quick Tip for Artificially Inflated PE Files
https://isc.sans.edu/diary/Quick%20Tip%20For%20Artificially%20Inflated%20PE%20Files/30370
 Apache ActiveMQ Flaw Exploited
https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt...</itunes:subtitle><itunes:summary><![CDATA[Quick Tip for Artificially Inflated PE Files<br /><a href="https://isc.sans.edu/diary/Quick%20Tip%20For%20Artificially%20Inflated%20PE%20Files/30370" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Quick%20Tip%20For%20Artificially%20Inflated%20PE%20Files/30370</a><br /> Apache ActiveMQ Flaw Exploited<br /><a href="https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt" target="_blank" rel="noreferrer noopener">https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt</a><br /><a href="https://www.rapid7.com/blog/post/2023/11/01/etr-suspected-exploitation-of-apache-activemq-cve-2023-46604/" target="_blank" rel="noreferrer noopener">https://www.rapid7.com/blog/post/2023/11/01/etr-suspected-exploitation-of-apache-activemq-cve-2023-46604/</a><br /> Critical Firepower Vulnerability<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-29MP49hN" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-29MP49hN</a><br /> Dozens of npm Packages Caught Attempting to Deploy Reverse Shell<br /><a href="https://blog.phylum.io/dozens-of-npm-packages-caught-attempting-to-deploy-reverse-shell/" target="_blank" rel="noreferrer noopener">https://blog.phylum.io/dozens-of-npm-packages-caught-attempting-to-deploy-reverse-shell/</a><br />]]></itunes:summary><itunes:duration>323</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,reverse shell; npm; rsh.js; fi,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8730</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, November 2nd, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-november-2nd-2023--57537708</link><description><![CDATA[Malware Dropped Through a ZPAQ Archive<br /><a href="https://isc.sans.edu/forums/diary/Malware%20Dropped%20Through%20a%20ZPAQ%20Archive/30366/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Malware%20Dropped%20Through%20a%20ZPAQ%20Archive/30366/</a><br /> CVSS 4.0 Now Official<br /><a href="https://www.first.org/cvss/v4-0/index.html" target="_blank" rel="noreferrer noopener">https://www.first.org/cvss/v4-0/index.html</a><br /> MOZI Botnet Killswitch<br /><a href="https://www.welivesecurity.com/en/eset-research/who-killed-mozi-finally-putting-the-iot-zombie-botnet-in-its-grave/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/who-killed-mozi-finally-putting-the-iot-zombie-botnet-in-its-grave/</a><br /> URL Shorteners in .us<br /><a href="https://securityonline.info/infoblox-uncovers-malicious-wave-in-us-domain-registrations/" target="_blank" rel="noreferrer noopener">https://securityonline.info/infoblox-uncovers-malicious-wave-in-us-domain-registrations/</a><br /> Impersonating Slack Users<br /><a href="https://falconspy.org/redteam/tradecraft/2023/10/05/2023-10-05-Slack-Impersonation.html" target="_blank" rel="noreferrer noopener">https://falconspy.org/redteam/tradecraft/2023/10/05/2023-10-05-Slack-Impersonation.html</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8728.mp3</guid><pubDate>Thu, 02 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537708/8728.mp3" length="5108588" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Malware Dropped Through a ZPAQ Archive
https://isc.sans.edu/forums/diary/Malware%20Dropped%20Through%20a%20ZPAQ%20Archive/30366/
 CVSS 4.0 Now Official
https://www.first.org/cvss/v4-0/index.html
 MOZI Botnet Killswitch...</itunes:subtitle><itunes:summary><![CDATA[Malware Dropped Through a ZPAQ Archive<br /><a href="https://isc.sans.edu/forums/diary/Malware%20Dropped%20Through%20a%20ZPAQ%20Archive/30366/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Malware%20Dropped%20Through%20a%20ZPAQ%20Archive/30366/</a><br /> CVSS 4.0 Now Official<br /><a href="https://www.first.org/cvss/v4-0/index.html" target="_blank" rel="noreferrer noopener">https://www.first.org/cvss/v4-0/index.html</a><br /> MOZI Botnet Killswitch<br /><a href="https://www.welivesecurity.com/en/eset-research/who-killed-mozi-finally-putting-the-iot-zombie-botnet-in-its-grave/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/who-killed-mozi-finally-putting-the-iot-zombie-botnet-in-its-grave/</a><br /> URL Shorteners in .us<br /><a href="https://securityonline.info/infoblox-uncovers-malicious-wave-in-us-domain-registrations/" target="_blank" rel="noreferrer noopener">https://securityonline.info/infoblox-uncovers-malicious-wave-in-us-domain-registrations/</a><br /> Impersonating Slack Users<br /><a href="https://falconspy.org/redteam/tradecraft/2023/10/05/2023-10-05-Slack-Impersonation.html" target="_blank" rel="noreferrer noopener">https://falconspy.org/redteam/tradecraft/2023/10/05/2023-10-05-Slack-Impersonation.html</a><br />]]></itunes:summary><itunes:duration>343</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,slack; url; us; mozi; botnet; </itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8728</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, November 2nd, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-november-2nd-2023--57479887</link><description><![CDATA[Malware Dropped Through a ZPAQ Archive<br /><a href="https://isc.sans.edu/forums/diary/Malware%20Dropped%20Through%20a%20ZPAQ%20Archive/30366/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Malware%20Dropped%20Through%20a%20ZPAQ%20Archive/30366/</a><br /> CVSS 4.0 Now Official<br /><a href="https://www.first.org/cvss/v4-0/index.html" target="_blank" rel="noreferrer noopener">https://www.first.org/cvss/v4-0/index.html</a><br /> MOZI Botnet Killswitch<br /><a href="https://www.welivesecurity.com/en/eset-research/who-killed-mozi-finally-putting-the-iot-zombie-botnet-in-its-grave/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/who-killed-mozi-finally-putting-the-iot-zombie-botnet-in-its-grave/</a><br /> URL Shorteners in .us<br /><a href="https://securityonline.info/infoblox-uncovers-malicious-wave-in-us-domain-registrations/" target="_blank" rel="noreferrer noopener">https://securityonline.info/infoblox-uncovers-malicious-wave-in-us-domain-registrations/</a><br /> Impersonating Slack Users<br /><a href="https://falconspy.org/redteam/tradecraft/2023/10/05/2023-10-05-Slack-Impersonation.html" target="_blank" rel="noreferrer noopener">https://falconspy.org/redteam/tradecraft/2023/10/05/2023-10-05-Slack-Impersonation.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8728.mp3</guid><pubDate>Thu, 02 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57479887/8728.mp3" length="5108588" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Malware Dropped Through a ZPAQ Archive
https://isc.sans.edu/forums/diary/Malware%20Dropped%20Through%20a%20ZPAQ%20Archive/30366/
 CVSS 4.0 Now Official
https://www.first.org/cvss/v4-0/index.html
 MOZI Botnet Killswitch...</itunes:subtitle><itunes:summary><![CDATA[Malware Dropped Through a ZPAQ Archive<br /><a href="https://isc.sans.edu/forums/diary/Malware%20Dropped%20Through%20a%20ZPAQ%20Archive/30366/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Malware%20Dropped%20Through%20a%20ZPAQ%20Archive/30366/</a><br /> CVSS 4.0 Now Official<br /><a href="https://www.first.org/cvss/v4-0/index.html" target="_blank" rel="noreferrer noopener">https://www.first.org/cvss/v4-0/index.html</a><br /> MOZI Botnet Killswitch<br /><a href="https://www.welivesecurity.com/en/eset-research/who-killed-mozi-finally-putting-the-iot-zombie-botnet-in-its-grave/" target="_blank" rel="noreferrer noopener">https://www.welivesecurity.com/en/eset-research/who-killed-mozi-finally-putting-the-iot-zombie-botnet-in-its-grave/</a><br /> URL Shorteners in .us<br /><a href="https://securityonline.info/infoblox-uncovers-malicious-wave-in-us-domain-registrations/" target="_blank" rel="noreferrer noopener">https://securityonline.info/infoblox-uncovers-malicious-wave-in-us-domain-registrations/</a><br /> Impersonating Slack Users<br /><a href="https://falconspy.org/redteam/tradecraft/2023/10/05/2023-10-05-Slack-Impersonation.html" target="_blank" rel="noreferrer noopener">https://falconspy.org/redteam/tradecraft/2023/10/05/2023-10-05-Slack-Impersonation.html</a><br />]]></itunes:summary><itunes:duration>343</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,slack; url; us; mozi; botnet; </itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8728</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, November 1st, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-november-1st-2023--57537707</link><description><![CDATA[Multiple Layers of Anti-Sandboxing Techniques<br /><a href="https://isc.sans.edu/diary/Multiple%20Layers%20of%20Anti-Sandboxing%20Techniques/30362" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Multiple%20Layers%20of%20Anti-Sandboxing%20Techniques/30362</a><br /> CVE-2023-22518 Improper Authorization Vulnerability in Confluence Data Center and Server<br /><a href="https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html" target="_blank" rel="noreferrer noopener">https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html</a><br /> Malvertisement Promotes Malicious PyCharm Version<br /><a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/10/malvertising-via-dynamic-search-ads-delivers-malware-bonanza" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/threat-intelligence/2023/10/malvertising-via-dynamic-search-ads-delivers-malware-bonanza</a><br /> Thorn SFTP Gateway Java Deserialization RCE CVE-2016-1000027 CVE-2023-47174<br /><a href="https://help.thorntech.com/docs/sftp-gateway-gcp-3.0/gcp-java-deserialization-rce/" target="_blank" rel="noreferrer noopener">https://help.thorntech.com/docs/sftp-gateway-gcp-3.0/gcp-java-deserialization-rce/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8726.mp3</guid><pubDate>Wed, 01 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537707/8726.mp3" length="3828456" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Multiple Layers of Anti-Sandboxing Techniques
https://isc.sans.edu/diary/Multiple%20Layers%20of%20Anti-Sandboxing%20Techniques/30362
 CVE-2023-22518 Improper Authorization Vulnerability in Confluence Data Center and Server...</itunes:subtitle><itunes:summary><![CDATA[Multiple Layers of Anti-Sandboxing Techniques<br /><a href="https://isc.sans.edu/diary/Multiple%20Layers%20of%20Anti-Sandboxing%20Techniques/30362" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Multiple%20Layers%20of%20Anti-Sandboxing%20Techniques/30362</a><br /> CVE-2023-22518 Improper Authorization Vulnerability in Confluence Data Center and Server<br /><a href="https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html" target="_blank" rel="noreferrer noopener">https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html</a><br /> Malvertisement Promotes Malicious PyCharm Version<br /><a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/10/malvertising-via-dynamic-search-ads-delivers-malware-bonanza" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/threat-intelligence/2023/10/malvertising-via-dynamic-search-ads-delivers-malware-bonanza</a><br /> Thorn SFTP Gateway Java Deserialization RCE CVE-2016-1000027 CVE-2023-47174<br /><a href="https://help.thorntech.com/docs/sftp-gateway-gcp-3.0/gcp-java-deserialization-rce/" target="_blank" rel="noreferrer noopener">https://help.thorntech.com/docs/sftp-gateway-gcp-3.0/gcp-java-deserialization-rce/</a><br />]]></itunes:summary><itunes:duration>252</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,thron; sftp; pycharm; malverti</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8726</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, November 1st, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-november-1st-2023--57463726</link><description><![CDATA[Multiple Layers of Anti-Sandboxing Techniques<br /><a href="https://isc.sans.edu/diary/Multiple%20Layers%20of%20Anti-Sandboxing%20Techniques/30362" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Multiple%20Layers%20of%20Anti-Sandboxing%20Techniques/30362</a><br /> CVE-2023-22518 Improper Authorization Vulnerability in Confluence Data Center and Server<br /><a href="https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html" target="_blank" rel="noreferrer noopener">https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html</a><br /> Malvertisement Promotes Malicious PyCharm Version<br /><a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/10/malvertising-via-dynamic-search-ads-delivers-malware-bonanza" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/threat-intelligence/2023/10/malvertising-via-dynamic-search-ads-delivers-malware-bonanza</a><br /> Thorn SFTP Gateway Java Deserialization RCE CVE-2016-1000027 CVE-2023-47174<br /><a href="https://help.thorntech.com/docs/sftp-gateway-gcp-3.0/gcp-java-deserialization-rce/" target="_blank" rel="noreferrer noopener">https://help.thorntech.com/docs/sftp-gateway-gcp-3.0/gcp-java-deserialization-rce/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8726.mp3</guid><pubDate>Wed, 01 Nov 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57463726/8726.mp3" length="3828456" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Multiple Layers of Anti-Sandboxing Techniques
https://isc.sans.edu/diary/Multiple%20Layers%20of%20Anti-Sandboxing%20Techniques/30362
 CVE-2023-22518 Improper Authorization Vulnerability in Confluence Data Center and Server...</itunes:subtitle><itunes:summary><![CDATA[Multiple Layers of Anti-Sandboxing Techniques<br /><a href="https://isc.sans.edu/diary/Multiple%20Layers%20of%20Anti-Sandboxing%20Techniques/30362" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Multiple%20Layers%20of%20Anti-Sandboxing%20Techniques/30362</a><br /> CVE-2023-22518 Improper Authorization Vulnerability in Confluence Data Center and Server<br /><a href="https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html" target="_blank" rel="noreferrer noopener">https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html</a><br /> Malvertisement Promotes Malicious PyCharm Version<br /><a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/10/malvertising-via-dynamic-search-ads-delivers-malware-bonanza" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/threat-intelligence/2023/10/malvertising-via-dynamic-search-ads-delivers-malware-bonanza</a><br /> Thorn SFTP Gateway Java Deserialization RCE CVE-2016-1000027 CVE-2023-47174<br /><a href="https://help.thorntech.com/docs/sftp-gateway-gcp-3.0/gcp-java-deserialization-rce/" target="_blank" rel="noreferrer noopener">https://help.thorntech.com/docs/sftp-gateway-gcp-3.0/gcp-java-deserialization-rce/</a><br />]]></itunes:summary><itunes:duration>252</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,thron; sftp; pycharm; malverti</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8726</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, October 31st, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-october-31st-2023--57537705</link><description><![CDATA[Flying under the Radar: The Privacy Impact of Mulicast DNS<br /><a href="https://isc.sans.edu/forums/diary/Flying%20under%20the%20Radar%3A%20The%20Privacy%20Impact%20of%20multicast%20DNS/30358/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Flying%20under%20the%20Radar%3A%20The%20Privacy%20Impact%20of%20multicast%20DNS/30358/</a><br /> Kubernetes ingress-nginx vulnerability<br /><a href="https://github.com/kubernetes/ingress-nginx/issues/10571" target="_blank" rel="noreferrer noopener">https://github.com/kubernetes/ingress-nginx/issues/10571</a><br /> Google Chrome HTTPS Upgrade<br /><a href="https://github.com/dadrian/https-upgrade/blob/main/explainer.md" target="_blank" rel="noreferrer noopener">https://github.com/dadrian/https-upgrade/blob/main/explainer.md</a><br /> Wordpad POC CVE-2023-36563<br /><a href="https://www.dillonfrankesecurity.com/posts/cve-2023-36563-wordpad-analysis/" target="_blank" rel="noreferrer noopener">https://www.dillonfrankesecurity.com/posts/cve-2023-36563-wordpad-analysis/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8724.mp3</guid><pubDate>Tue, 31 Oct 2023 00:05:28 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537705/8724.mp3" length="5544151" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Flying under the Radar: The Privacy Impact of Mulicast DNS
https://isc.sans.edu/forums/diary/Flying%20under%20the%20Radar%3A%20The%20Privacy%20Impact%20of%20multicast%20DNS/30358/
 Kubernetes ingress-nginx vulnerability...</itunes:subtitle><itunes:summary><![CDATA[Flying under the Radar: The Privacy Impact of Mulicast DNS<br /><a href="https://isc.sans.edu/forums/diary/Flying%20under%20the%20Radar%3A%20The%20Privacy%20Impact%20of%20multicast%20DNS/30358/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Flying%20under%20the%20Radar%3A%20The%20Privacy%20Impact%20of%20multicast%20DNS/30358/</a><br /> Kubernetes ingress-nginx vulnerability<br /><a href="https://github.com/kubernetes/ingress-nginx/issues/10571" target="_blank" rel="noreferrer noopener">https://github.com/kubernetes/ingress-nginx/issues/10571</a><br /> Google Chrome HTTPS Upgrade<br /><a href="https://github.com/dadrian/https-upgrade/blob/main/explainer.md" target="_blank" rel="noreferrer noopener">https://github.com/dadrian/https-upgrade/blob/main/explainer.md</a><br /> Wordpad POC CVE-2023-36563<br /><a href="https://www.dillonfrankesecurity.com/posts/cve-2023-36563-wordpad-analysis/" target="_blank" rel="noreferrer noopener">https://www.dillonfrankesecurity.com/posts/cve-2023-36563-wordpad-analysis/</a><br />]]></itunes:summary><itunes:duration>374</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,wordpad; google; chrome; https</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8724</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, October 31st, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-october-31st-2023--57447783</link><description><![CDATA[Flying under the Radar: The Privacy Impact of Mulicast DNS<br /><a href="https://isc.sans.edu/forums/diary/Flying%20under%20the%20Radar%3A%20The%20Privacy%20Impact%20of%20multicast%20DNS/30358/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Flying%20under%20the%20Radar%3A%20The%20Privacy%20Impact%20of%20multicast%20DNS/30358/</a><br /> Kubernetes ingress-nginx vulnerability<br /><a href="https://github.com/kubernetes/ingress-nginx/issues/10571" target="_blank" rel="noreferrer noopener">https://github.com/kubernetes/ingress-nginx/issues/10571</a><br /> Google Chrome HTTPS Upgrade<br /><a href="https://github.com/dadrian/https-upgrade/blob/main/explainer.md" target="_blank" rel="noreferrer noopener">https://github.com/dadrian/https-upgrade/blob/main/explainer.md</a><br /> Wordpad POC CVE-2023-36563<br /><a href="https://www.dillonfrankesecurity.com/posts/cve-2023-36563-wordpad-analysis/" target="_blank" rel="noreferrer noopener">https://www.dillonfrankesecurity.com/posts/cve-2023-36563-wordpad-analysis/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8724.mp3</guid><pubDate>Tue, 31 Oct 2023 00:05:28 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57447783/8724.mp3" length="5544151" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Flying under the Radar: The Privacy Impact of Mulicast DNS
https://isc.sans.edu/forums/diary/Flying%20under%20the%20Radar%3A%20The%20Privacy%20Impact%20of%20multicast%20DNS/30358/
 Kubernetes ingress-nginx vulnerability...</itunes:subtitle><itunes:summary><![CDATA[Flying under the Radar: The Privacy Impact of Mulicast DNS<br /><a href="https://isc.sans.edu/forums/diary/Flying%20under%20the%20Radar%3A%20The%20Privacy%20Impact%20of%20multicast%20DNS/30358/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Flying%20under%20the%20Radar%3A%20The%20Privacy%20Impact%20of%20multicast%20DNS/30358/</a><br /> Kubernetes ingress-nginx vulnerability<br /><a href="https://github.com/kubernetes/ingress-nginx/issues/10571" target="_blank" rel="noreferrer noopener">https://github.com/kubernetes/ingress-nginx/issues/10571</a><br /> Google Chrome HTTPS Upgrade<br /><a href="https://github.com/dadrian/https-upgrade/blob/main/explainer.md" target="_blank" rel="noreferrer noopener">https://github.com/dadrian/https-upgrade/blob/main/explainer.md</a><br /> Wordpad POC CVE-2023-36563<br /><a href="https://www.dillonfrankesecurity.com/posts/cve-2023-36563-wordpad-analysis/" target="_blank" rel="noreferrer noopener">https://www.dillonfrankesecurity.com/posts/cve-2023-36563-wordpad-analysis/</a><br />]]></itunes:summary><itunes:duration>374</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,wordpad; google; chrome; https</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8724</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, October 30th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-october-30th-2023--57537710</link><description><![CDATA[Size Matters for Many Security Controls<br /><a href="https://isc.sans.edu/diary/Size%20Matters%20for%20Many%20Security%20Controls/30352" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Size%20Matters%20for%20Many%20Security%20Controls/30352</a><br /> Spam or Phishing? Looking for Credentials and Passwords<br /><a href="https://isc.sans.edu/diary/Spam%20or%20Phishing%3F%20Looking%20for%20Credentials%20%26%20Passwords/30354" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Spam%20or%20Phishing%3F%20Looking%20for%20Credentials%20%26%20Passwords/30354</a><br /> iOS Leaks MAC Address<br /><a href="https://www.youtube.com/watch?v=T3XABxNogTA" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=T3XABxNogTA</a><br /> Zero Day Initiative Pwn2Own Summary<br /><a href="https://www.zerodayinitiative.com/blog/2023/10/24/pwn2own-toronto-2023-day-one-results" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/blog/2023/10/24/pwn2own-toronto-2023-day-one-results</a><br /><a href="https://www.zerodayinitiative.com/blog/2023/10/25/pwn2own-toronto-2023-day-two-results" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/blog/2023/10/25/pwn2own-toronto-2023-day-two-results</a><br /><a href="https://www.zerodayinitiative.com/blog/2023/10/26/pwn2own-toronto-2023-day-three-results" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/blog/2023/10/26/pwn2own-toronto-2023-day-three-results</a><br /> Microsoft Octo Tempest Writeup<br /><a href="https://www.microsoft.com/en-us/security/blog/2023/10/25/octo-tempest-crosses-boundaries-to-facilitate-extortion-encryption-and-destruction/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2023/10/25/octo-tempest-crosses-boundaries-to-facilitate-extortion-encryption-and-destruction/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8722.mp3</guid><pubDate>Mon, 30 Oct 2023 01:43:13 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537710/8722.mp3" length="5443287" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Size Matters for Many Security Controls
https://isc.sans.edu/diary/Size%20Matters%20for%20Many%20Security%20Controls/30352
 Spam or Phishing? Looking for Credentials and Passwords...</itunes:subtitle><itunes:summary><![CDATA[Size Matters for Many Security Controls<br /><a href="https://isc.sans.edu/diary/Size%20Matters%20for%20Many%20Security%20Controls/30352" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Size%20Matters%20for%20Many%20Security%20Controls/30352</a><br /> Spam or Phishing? Looking for Credentials and Passwords<br /><a href="https://isc.sans.edu/diary/Spam%20or%20Phishing%3F%20Looking%20for%20Credentials%20%26%20Passwords/30354" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Spam%20or%20Phishing%3F%20Looking%20for%20Credentials%20%26%20Passwords/30354</a><br /> iOS Leaks MAC Address<br /><a href="https://www.youtube.com/watch?v=T3XABxNogTA" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=T3XABxNogTA</a><br /> Zero Day Initiative Pwn2Own Summary<br /><a href="https://www.zerodayinitiative.com/blog/2023/10/24/pwn2own-toronto-2023-day-one-results" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/blog/2023/10/24/pwn2own-toronto-2023-day-one-results</a><br /><a href="https://www.zerodayinitiative.com/blog/2023/10/25/pwn2own-toronto-2023-day-two-results" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/blog/2023/10/25/pwn2own-toronto-2023-day-two-results</a><br /><a href="https://www.zerodayinitiative.com/blog/2023/10/26/pwn2own-toronto-2023-day-three-results" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/blog/2023/10/26/pwn2own-toronto-2023-day-three-results</a><br /> Microsoft Octo Tempest Writeup<br /><a href="https://www.microsoft.com/en-us/security/blog/2023/10/25/octo-tempest-crosses-boundaries-to-facilitate-extortion-encryption-and-destruction/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2023/10/25/octo-tempest-crosses-boundaries-to-facilitate-extortion-encryption-and-destruction/</a><br />]]></itunes:summary><itunes:duration>367</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,octo; tempest; microsoft; zdi;,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8722</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, October 30th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-october-30th-2023--57437446</link><description><![CDATA[Size Matters for Many Security Controls<br /><a href="https://isc.sans.edu/diary/Size%20Matters%20for%20Many%20Security%20Controls/30352" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Size%20Matters%20for%20Many%20Security%20Controls/30352</a><br /> Spam or Phishing? Looking for Credentials and Passwords<br /><a href="https://isc.sans.edu/diary/Spam%20or%20Phishing%3F%20Looking%20for%20Credentials%20%26%20Passwords/30354" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Spam%20or%20Phishing%3F%20Looking%20for%20Credentials%20%26%20Passwords/30354</a><br /> iOS Leaks MAC Address<br /><a href="https://www.youtube.com/watch?v=T3XABxNogTA" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=T3XABxNogTA</a><br /> Zero Day Initiative Pwn2Own Summary<br /><a href="https://www.zerodayinitiative.com/blog/2023/10/24/pwn2own-toronto-2023-day-one-results" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/blog/2023/10/24/pwn2own-toronto-2023-day-one-results</a><br /><a href="https://www.zerodayinitiative.com/blog/2023/10/25/pwn2own-toronto-2023-day-two-results" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/blog/2023/10/25/pwn2own-toronto-2023-day-two-results</a><br /><a href="https://www.zerodayinitiative.com/blog/2023/10/26/pwn2own-toronto-2023-day-three-results" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/blog/2023/10/26/pwn2own-toronto-2023-day-three-results</a><br /> Microsoft Octo Tempest Writeup<br /><a href="https://www.microsoft.com/en-us/security/blog/2023/10/25/octo-tempest-crosses-boundaries-to-facilitate-extortion-encryption-and-destruction/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2023/10/25/octo-tempest-crosses-boundaries-to-facilitate-extortion-encryption-and-destruction/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8722.mp3</guid><pubDate>Mon, 30 Oct 2023 01:43:13 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57437446/8722.mp3" length="5443287" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Size Matters for Many Security Controls
https://isc.sans.edu/diary/Size%20Matters%20for%20Many%20Security%20Controls/30352
 Spam or Phishing? Looking for Credentials and Passwords...</itunes:subtitle><itunes:summary><![CDATA[Size Matters for Many Security Controls<br /><a href="https://isc.sans.edu/diary/Size%20Matters%20for%20Many%20Security%20Controls/30352" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Size%20Matters%20for%20Many%20Security%20Controls/30352</a><br /> Spam or Phishing? Looking for Credentials and Passwords<br /><a href="https://isc.sans.edu/diary/Spam%20or%20Phishing%3F%20Looking%20for%20Credentials%20%26%20Passwords/30354" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Spam%20or%20Phishing%3F%20Looking%20for%20Credentials%20%26%20Passwords/30354</a><br /> iOS Leaks MAC Address<br /><a href="https://www.youtube.com/watch?v=T3XABxNogTA" target="_blank" rel="noreferrer noopener">https://www.youtube.com/watch?v=T3XABxNogTA</a><br /> Zero Day Initiative Pwn2Own Summary<br /><a href="https://www.zerodayinitiative.com/blog/2023/10/24/pwn2own-toronto-2023-day-one-results" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/blog/2023/10/24/pwn2own-toronto-2023-day-one-results</a><br /><a href="https://www.zerodayinitiative.com/blog/2023/10/25/pwn2own-toronto-2023-day-two-results" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/blog/2023/10/25/pwn2own-toronto-2023-day-two-results</a><br /><a href="https://www.zerodayinitiative.com/blog/2023/10/26/pwn2own-toronto-2023-day-three-results" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/blog/2023/10/26/pwn2own-toronto-2023-day-three-results</a><br /> Microsoft Octo Tempest Writeup<br /><a href="https://www.microsoft.com/en-us/security/blog/2023/10/25/octo-tempest-crosses-boundaries-to-facilitate-extortion-encryption-and-destruction/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2023/10/25/octo-tempest-crosses-boundaries-to-facilitate-extortion-encryption-and-destruction/</a><br />]]></itunes:summary><itunes:duration>367</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,octo; tempest; microsoft; zdi;,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8722</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, October 27th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-october-27th-2023--57537706</link><description><![CDATA[Adventures in Validating IPv4 Addresses<br /><a href="https://isc.sans.edu/forums/diary/Adventures%20in%20Validating%20IPv4%20Addresses/30348/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Adventures%20in%20Validating%20IPv4%20Addresses/30348/</a><br /> BIG-IP Configuration Utility Unauthenticated Remote Code Execution<br /><a href="https://my.f5.com/manage/s/article/K000137353" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000137353</a><br /><a href="https://www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747/" target="_blank" rel="noreferrer noopener">https://www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747/</a><br /> iLeakage Vulnerability<br /><a href="https://ileakage.com/" target="_blank" rel="noreferrer noopener">https://ileakage.com/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8720.mp3</guid><pubDate>Fri, 27 Oct 2023 10:45:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537706/8720.mp3" length="5384979" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Adventures in Validating IPv4 Addresses
https://isc.sans.edu/forums/diary/Adventures%20in%20Validating%20IPv4%20Addresses/30348/
 BIG-IP Configuration Utility Unauthenticated Remote Code Execution
https://my.f5.com/manage/s/article/K000137353...</itunes:subtitle><itunes:summary><![CDATA[Adventures in Validating IPv4 Addresses<br /><a href="https://isc.sans.edu/forums/diary/Adventures%20in%20Validating%20IPv4%20Addresses/30348/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Adventures%20in%20Validating%20IPv4%20Addresses/30348/</a><br /> BIG-IP Configuration Utility Unauthenticated Remote Code Execution<br /><a href="https://my.f5.com/manage/s/article/K000137353" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000137353</a><br /><a href="https://www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747/" target="_blank" rel="noreferrer noopener">https://www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747/</a><br /> iLeakage Vulnerability<br /><a href="https://ileakage.com/" target="_blank" rel="noreferrer noopener">https://ileakage.com/</a><br />]]></itunes:summary><itunes:duration>363</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,ileakage; big-ip; f5; ipv4; ad,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8720</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, October 27th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-october-27th-2023--57407096</link><description><![CDATA[Adventures in Validating IPv4 Addresses<br /><a href="https://isc.sans.edu/forums/diary/Adventures%20in%20Validating%20IPv4%20Addresses/30348/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Adventures%20in%20Validating%20IPv4%20Addresses/30348/</a><br /> BIG-IP Configuration Utility Unauthenticated Remote Code Execution<br /><a href="https://my.f5.com/manage/s/article/K000137353" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000137353</a><br /><a href="https://www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747/" target="_blank" rel="noreferrer noopener">https://www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747/</a><br /> iLeakage Vulnerability<br /><a href="https://ileakage.com/" target="_blank" rel="noreferrer noopener">https://ileakage.com/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8720.mp3</guid><pubDate>Fri, 27 Oct 2023 10:45:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57407096/8720.mp3" length="5384979" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Adventures in Validating IPv4 Addresses
https://isc.sans.edu/forums/diary/Adventures%20in%20Validating%20IPv4%20Addresses/30348/
 BIG-IP Configuration Utility Unauthenticated Remote Code Execution
https://my.f5.com/manage/s/article/K000137353...</itunes:subtitle><itunes:summary><![CDATA[Adventures in Validating IPv4 Addresses<br /><a href="https://isc.sans.edu/forums/diary/Adventures%20in%20Validating%20IPv4%20Addresses/30348/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Adventures%20in%20Validating%20IPv4%20Addresses/30348/</a><br /> BIG-IP Configuration Utility Unauthenticated Remote Code Execution<br /><a href="https://my.f5.com/manage/s/article/K000137353" target="_blank" rel="noreferrer noopener">https://my.f5.com/manage/s/article/K000137353</a><br /><a href="https://www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747/" target="_blank" rel="noreferrer noopener">https://www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747/</a><br /> iLeakage Vulnerability<br /><a href="https://ileakage.com/" target="_blank" rel="noreferrer noopener">https://ileakage.com/</a><br />]]></itunes:summary><itunes:duration>363</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,ileakage; big-ip; f5; ipv4; ad,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8720</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, October 26th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-october-26th-2023--57537704</link><description><![CDATA[Apple Updates<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20Releases%20iOS%2017.1%2C%20MacOS%2014.1%20and%20updates%20for%20older%20versions%20fixing%20exploited%20vulnerability/30344" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20Releases%20iOS%2017.1%2C%20MacOS%2014.1%20and%20updates%20for%20older%20versions%20fixing%20exploited%20vulnerability/30344</a><br /> Confluence Server Scans CVE-2023-22515<br /><a href="https://isc.sans.edu/diary/30342" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/30342</a><br /> Critical VMVware vCenter Patch CVE-2023-34048<br /><a href="https://www.vmware.com/security/advisories/VMSA-2023-0023.html" target="_blank" rel="noreferrer noopener">https://www.vmware.com/security/advisories/VMSA-2023-0023.html</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8718.mp3</guid><pubDate>Thu, 26 Oct 2023 00:56:27 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537704/8718.mp3" length="5436878" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Apple Updates
https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20Releases%20iOS%2017.1%2C%20MacOS%2014.1%20and%20updates%20for%20older%20versions%20fixing%20exploited%20vulnerability/30344
 Confluence Server Scans CVE-2023-22515...</itunes:subtitle><itunes:summary><![CDATA[Apple Updates<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20Releases%20iOS%2017.1%2C%20MacOS%2014.1%20and%20updates%20for%20older%20versions%20fixing%20exploited%20vulnerability/30344" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20Releases%20iOS%2017.1%2C%20MacOS%2014.1%20and%20updates%20for%20older%20versions%20fixing%20exploited%20vulnerability/30344</a><br /> Confluence Server Scans CVE-2023-22515<br /><a href="https://isc.sans.edu/diary/30342" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/30342</a><br /> Critical VMVware vCenter Patch CVE-2023-34048<br /><a href="https://www.vmware.com/security/advisories/VMSA-2023-0023.html" target="_blank" rel="noreferrer noopener">https://www.vmware.com/security/advisories/VMSA-2023-0023.html</a><br />]]></itunes:summary><itunes:duration>367</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,vmware; vcenter; confluence; s</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8718</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, October 26th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-october-26th-2023--57387890</link><description><![CDATA[Apple Updates<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20Releases%20iOS%2017.1%2C%20MacOS%2014.1%20and%20updates%20for%20older%20versions%20fixing%20exploited%20vulnerability/30344" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20Releases%20iOS%2017.1%2C%20MacOS%2014.1%20and%20updates%20for%20older%20versions%20fixing%20exploited%20vulnerability/30344</a><br /> Confluence Server Scans CVE-2023-22515<br /><a href="https://isc.sans.edu/diary/30342" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/30342</a><br /> Critical VMVware vCenter Patch CVE-2023-34048<br /><a href="https://www.vmware.com/security/advisories/VMSA-2023-0023.html" target="_blank" rel="noreferrer noopener">https://www.vmware.com/security/advisories/VMSA-2023-0023.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8718.mp3</guid><pubDate>Thu, 26 Oct 2023 00:56:27 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57387890/8718.mp3" length="5436878" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Apple Updates
https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20Releases%20iOS%2017.1%2C%20MacOS%2014.1%20and%20updates%20for%20older%20versions%20fixing%20exploited%20vulnerability/30344
 Confluence Server Scans CVE-2023-22515...</itunes:subtitle><itunes:summary><![CDATA[Apple Updates<br /><a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20Releases%20iOS%2017.1%2C%20MacOS%2014.1%20and%20updates%20for%20older%20versions%20fixing%20exploited%20vulnerability/30344" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20Releases%20iOS%2017.1%2C%20MacOS%2014.1%20and%20updates%20for%20older%20versions%20fixing%20exploited%20vulnerability/30344</a><br /> Confluence Server Scans CVE-2023-22515<br /><a href="https://isc.sans.edu/diary/30342" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/30342</a><br /> Critical VMVware vCenter Patch CVE-2023-34048<br /><a href="https://www.vmware.com/security/advisories/VMSA-2023-0023.html" target="_blank" rel="noreferrer noopener">https://www.vmware.com/security/advisories/VMSA-2023-0023.html</a><br />]]></itunes:summary><itunes:duration>367</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,vmware; vcenter; confluence; s</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8718</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, October 25th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-october-25th-2023--57537717</link><description><![CDATA[Samsung Messages and Samsung Wallet briefly marked as 'harmful' by Google<br /><a href="https://9to5google.com/2023/10/23/samsung-messages-wallet-harmful-app-google/" target="_blank" rel="noreferrer noopener">https://9to5google.com/2023/10/23/samsung-messages-wallet-harmful-app-google/</a><br /> OAuth Hijacking<br /><a href="https://salt.security/blog/oh-auth-abusing-oauth-to-take-over-millions-of-accounts" target="_blank" rel="noreferrer noopener">https://salt.security/blog/oh-auth-abusing-oauth-to-take-over-millions-of-accounts</a><br /> Microsoft Exchange Server CVe-2023-36745 PoC<br /><a href="https://n1k0la-t.github.io/2023/10/24/Microsoft-Exchange-Server-CVE-2023-36745/" target="_blank" rel="noreferrer noopener">https://n1k0la-t.github.io/2023/10/24/Microsoft-Exchange-Server-CVE-2023-36745/</a><br /> Citrix Bleed PoC CVe-2023-4966<br /><a href="https://www.assetnote.io/resources/research/citrix-bleed-leaking-session-tokens-with-cve-2023-4966" target="_blank" rel="noreferrer noopener">https://www.assetnote.io/resources/research/citrix-bleed-leaking-session-tokens-with-cve-2023-4966</a><br /> VMWare VRealize Exploit CVE-2023-34051 CVE0-2023-34052<br /><a href="https://www.vmware.com/security/advisories/VMSA-2023-0021.html" target="_blank" rel="noreferrer noopener">https://www.vmware.com/security/advisories/VMSA-2023-0021.html</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8716.mp3</guid><pubDate>Wed, 25 Oct 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537717/8716.mp3" length="5422227" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Samsung Messages and Samsung Wallet briefly marked as 'harmful' by Google
https://9to5google.com/2023/10/23/samsung-messages-wallet-harmful-app-google/
 OAuth Hijacking
https://salt.security/blog/oh-auth-abusing-oauth-to-take-over-millions-of-accounts...</itunes:subtitle><itunes:summary><![CDATA[Samsung Messages and Samsung Wallet briefly marked as 'harmful' by Google<br /><a href="https://9to5google.com/2023/10/23/samsung-messages-wallet-harmful-app-google/" target="_blank" rel="noreferrer noopener">https://9to5google.com/2023/10/23/samsung-messages-wallet-harmful-app-google/</a><br /> OAuth Hijacking<br /><a href="https://salt.security/blog/oh-auth-abusing-oauth-to-take-over-millions-of-accounts" target="_blank" rel="noreferrer noopener">https://salt.security/blog/oh-auth-abusing-oauth-to-take-over-millions-of-accounts</a><br /> Microsoft Exchange Server CVe-2023-36745 PoC<br /><a href="https://n1k0la-t.github.io/2023/10/24/Microsoft-Exchange-Server-CVE-2023-36745/" target="_blank" rel="noreferrer noopener">https://n1k0la-t.github.io/2023/10/24/Microsoft-Exchange-Server-CVE-2023-36745/</a><br /> Citrix Bleed PoC CVe-2023-4966<br /><a href="https://www.assetnote.io/resources/research/citrix-bleed-leaking-session-tokens-with-cve-2023-4966" target="_blank" rel="noreferrer noopener">https://www.assetnote.io/resources/research/citrix-bleed-leaking-session-tokens-with-cve-2023-4966</a><br /> VMWare VRealize Exploit CVE-2023-34051 CVE0-2023-34052<br /><a href="https://www.vmware.com/security/advisories/VMSA-2023-0021.html" target="_blank" rel="noreferrer noopener">https://www.vmware.com/security/advisories/VMSA-2023-0021.html</a><br />]]></itunes:summary><itunes:duration>339</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,vmware; vrealize; exploit; poc</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8716</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, October 25th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-october-25th-2023--57376331</link><description><![CDATA[Samsung Messages and Samsung Wallet briefly marked as 'harmful' by Google<br /><a href="https://9to5google.com/2023/10/23/samsung-messages-wallet-harmful-app-google/" target="_blank" rel="noreferrer noopener">https://9to5google.com/2023/10/23/samsung-messages-wallet-harmful-app-google/</a><br /> OAuth Hijacking<br /><a href="https://salt.security/blog/oh-auth-abusing-oauth-to-take-over-millions-of-accounts" target="_blank" rel="noreferrer noopener">https://salt.security/blog/oh-auth-abusing-oauth-to-take-over-millions-of-accounts</a><br /> Microsoft Exchange Server CVe-2023-36745 PoC<br /><a href="https://n1k0la-t.github.io/2023/10/24/Microsoft-Exchange-Server-CVE-2023-36745/" target="_blank" rel="noreferrer noopener">https://n1k0la-t.github.io/2023/10/24/Microsoft-Exchange-Server-CVE-2023-36745/</a><br /> Citrix Bleed PoC CVe-2023-4966<br /><a href="https://www.assetnote.io/resources/research/citrix-bleed-leaking-session-tokens-with-cve-2023-4966" target="_blank" rel="noreferrer noopener">https://www.assetnote.io/resources/research/citrix-bleed-leaking-session-tokens-with-cve-2023-4966</a><br /> VMWare VRealize Exploit CVE-2023-34051 CVE0-2023-34052<br /><a href="https://www.vmware.com/security/advisories/VMSA-2023-0021.html" target="_blank" rel="noreferrer noopener">https://www.vmware.com/security/advisories/VMSA-2023-0021.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8716.mp3</guid><pubDate>Wed, 25 Oct 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57376331/8716.mp3" length="5690345" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Samsung Messages and Samsung Wallet briefly marked as 'harmful' by Google
https://9to5google.com/2023/10/23/samsung-messages-wallet-harmful-app-google/
 OAuth Hijacking
https://salt.security/blog/oh-auth-abusing-oauth-to-take-over-millions-of-accounts...</itunes:subtitle><itunes:summary><![CDATA[Samsung Messages and Samsung Wallet briefly marked as 'harmful' by Google<br /><a href="https://9to5google.com/2023/10/23/samsung-messages-wallet-harmful-app-google/" target="_blank" rel="noreferrer noopener">https://9to5google.com/2023/10/23/samsung-messages-wallet-harmful-app-google/</a><br /> OAuth Hijacking<br /><a href="https://salt.security/blog/oh-auth-abusing-oauth-to-take-over-millions-of-accounts" target="_blank" rel="noreferrer noopener">https://salt.security/blog/oh-auth-abusing-oauth-to-take-over-millions-of-accounts</a><br /> Microsoft Exchange Server CVe-2023-36745 PoC<br /><a href="https://n1k0la-t.github.io/2023/10/24/Microsoft-Exchange-Server-CVE-2023-36745/" target="_blank" rel="noreferrer noopener">https://n1k0la-t.github.io/2023/10/24/Microsoft-Exchange-Server-CVE-2023-36745/</a><br /> Citrix Bleed PoC CVe-2023-4966<br /><a href="https://www.assetnote.io/resources/research/citrix-bleed-leaking-session-tokens-with-cve-2023-4966" target="_blank" rel="noreferrer noopener">https://www.assetnote.io/resources/research/citrix-bleed-leaking-session-tokens-with-cve-2023-4966</a><br /> VMWare VRealize Exploit CVE-2023-34051 CVE0-2023-34052<br /><a href="https://www.vmware.com/security/advisories/VMSA-2023-0021.html" target="_blank" rel="noreferrer noopener">https://www.vmware.com/security/advisories/VMSA-2023-0021.html</a><br />]]></itunes:summary><itunes:duration>385</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,vmware; vrealize; exploit; poc</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8716</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, October 24th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-october-24th-2023--57537712</link><description><![CDATA[Apple TV IPv6 DoS<br /><a href="https://isc.sans.edu/diary/How%20an%20AppleTV%20may%20take%20down%20your%20%28%23IPv6%29%20network/30336" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20an%20AppleTV%20may%20take%20down%20your%20%28%23IPv6%29%20network/30336</a><br /> Squid Patches<br /><a href="https://github.com/squid-cache/squid/security/advisories" target="_blank" rel="noreferrer noopener">https://github.com/squid-cache/squid/security/advisories</a><br /> Critical Citrix Update<br /><a href="https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/" target="_blank" rel="noreferrer noopener">https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/</a><br /> Cisco Vulnerablity Updates CVE-2023-20198<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8714.mp3</guid><pubDate>Tue, 24 Oct 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537712/8714.mp3" length="5689893" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Apple TV IPv6 DoS
https://isc.sans.edu/diary/How%20an%20AppleTV%20may%20take%20down%20your%20%28%23IPv6%29%20network/30336
 Squid Patches
https://github.com/squid-cache/squid/security/advisories
 Critical Citrix Update...</itunes:subtitle><itunes:summary><![CDATA[Apple TV IPv6 DoS<br /><a href="https://isc.sans.edu/diary/How%20an%20AppleTV%20may%20take%20down%20your%20%28%23IPv6%29%20network/30336" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20an%20AppleTV%20may%20take%20down%20your%20%28%23IPv6%29%20network/30336</a><br /> Squid Patches<br /><a href="https://github.com/squid-cache/squid/security/advisories" target="_blank" rel="noreferrer noopener">https://github.com/squid-cache/squid/security/advisories</a><br /> Critical Citrix Update<br /><a href="https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/" target="_blank" rel="noreferrer noopener">https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/</a><br /> Cisco Vulnerablity Updates CVE-2023-20198<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z</a><br />]]></itunes:summary><itunes:duration>385</itunes:duration><itunes:keywords>business,cisco; ios xe; apple; tv; ipv6,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8714</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, October 24th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-october-24th-2023--57361460</link><description><![CDATA[Apple TV IPv6 DoS<br /><a href="https://isc.sans.edu/diary/How%20an%20AppleTV%20may%20take%20down%20your%20%28%23IPv6%29%20network/30336" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20an%20AppleTV%20may%20take%20down%20your%20%28%23IPv6%29%20network/30336</a><br /> Squid Patches<br /><a href="https://github.com/squid-cache/squid/security/advisories" target="_blank" rel="noreferrer noopener">https://github.com/squid-cache/squid/security/advisories</a><br /> Critical Citrix Update<br /><a href="https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/" target="_blank" rel="noreferrer noopener">https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/</a><br /> Cisco Vulnerablity Updates CVE-2023-20198<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8714.mp3</guid><pubDate>Tue, 24 Oct 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57361460/8714.mp3" length="5689893" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Apple TV IPv6 DoS
https://isc.sans.edu/diary/How%20an%20AppleTV%20may%20take%20down%20your%20%28%23IPv6%29%20network/30336
 Squid Patches
https://github.com/squid-cache/squid/security/advisories
 Critical Citrix Update...</itunes:subtitle><itunes:summary><![CDATA[Apple TV IPv6 DoS<br /><a href="https://isc.sans.edu/diary/How%20an%20AppleTV%20may%20take%20down%20your%20%28%23IPv6%29%20network/30336" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20an%20AppleTV%20may%20take%20down%20your%20%28%23IPv6%29%20network/30336</a><br /> Squid Patches<br /><a href="https://github.com/squid-cache/squid/security/advisories" target="_blank" rel="noreferrer noopener">https://github.com/squid-cache/squid/security/advisories</a><br /> Critical Citrix Update<br /><a href="https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/" target="_blank" rel="noreferrer noopener">https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/</a><br /> Cisco Vulnerablity Updates CVE-2023-20198<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z</a><br />]]></itunes:summary><itunes:duration>385</itunes:duration><itunes:keywords>business,cisco; ios xe; apple; tv; ipv6,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8714</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, October 23rd, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-october-23rd-2023--57537714</link><description><![CDATA[base64dump.py Handles More Encodings Than Just BASE64<br /><a href="https://isc.sans.edu/diary/base64dump.py%20Handles%20More%20Encodings%20Than%20Just%20BASE64/30332" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/base64dump.py%20Handles%20More%20Encodings%20Than%20Just%20BASE64/30332</a><br /> Stealing OAuth Tokens via Open Redirects<br /><a href="https://eval.blog/research/microsoft-account-token-leaks-in-harvest/" target="_blank" rel="noreferrer noopener">https://eval.blog/research/microsoft-account-token-leaks-in-harvest/</a><br /> VMWare Patches<br /><a href="https://www.vmware.com/security/advisories.html" target="_blank" rel="noreferrer noopener">https://www.vmware.com/security/advisories.html</a><br /> Solarwinds Patches<br /><a href="https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-1_release_notes.htm" target="_blank" rel="noreferrer noopener">https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-1_release_notes.htm</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8712.mp3</guid><pubDate>Mon, 23 Oct 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537714/8712.mp3" length="5899196" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>base64dump.py Handles More Encodings Than Just BASE64
https://isc.sans.edu/diary/base64dump.py%20Handles%20More%20Encodings%20Than%20Just%20BASE64/30332
 Stealing OAuth Tokens via Open Redirects...</itunes:subtitle><itunes:summary><![CDATA[base64dump.py Handles More Encodings Than Just BASE64<br /><a href="https://isc.sans.edu/diary/base64dump.py%20Handles%20More%20Encodings%20Than%20Just%20BASE64/30332" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/base64dump.py%20Handles%20More%20Encodings%20Than%20Just%20BASE64/30332</a><br /> Stealing OAuth Tokens via Open Redirects<br /><a href="https://eval.blog/research/microsoft-account-token-leaks-in-harvest/" target="_blank" rel="noreferrer noopener">https://eval.blog/research/microsoft-account-token-leaks-in-harvest/</a><br /> VMWare Patches<br /><a href="https://www.vmware.com/security/advisories.html" target="_blank" rel="noreferrer noopener">https://www.vmware.com/security/advisories.html</a><br /> Solarwinds Patches<br /><a href="https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-1_release_notes.htm" target="_blank" rel="noreferrer noopener">https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-1_release_notes.htm</a><br />]]></itunes:summary><itunes:duration>400</itunes:duration><itunes:keywords>base64,business,computer,cyber,cybersecurity,daily,hacking,harvest,infosec,internet,it,microsoft,network,news,oauth,security,solarwinds,vmware</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8712</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, October 23rd, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-october-23rd-2023--57348922</link><description><![CDATA[base64dump.py Handles More Encodings Than Just BASE64<br /><a href="https://isc.sans.edu/diary/base64dump.py%20Handles%20More%20Encodings%20Than%20Just%20BASE64/30332" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/base64dump.py%20Handles%20More%20Encodings%20Than%20Just%20BASE64/30332</a><br /> Stealing OAuth Tokens via Open Redirects<br /><a href="https://eval.blog/research/microsoft-account-token-leaks-in-harvest/" target="_blank" rel="noreferrer noopener">https://eval.blog/research/microsoft-account-token-leaks-in-harvest/</a><br /> VMWare Patches<br /><a href="https://www.vmware.com/security/advisories.html" target="_blank" rel="noreferrer noopener">https://www.vmware.com/security/advisories.html</a><br /> Solarwinds Patches<br /><a href="https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-1_release_notes.htm" target="_blank" rel="noreferrer noopener">https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-1_release_notes.htm</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8712.mp3</guid><pubDate>Mon, 23 Oct 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57348922/8712.mp3" length="5899196" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>base64dump.py Handles More Encodings Than Just BASE64
https://isc.sans.edu/diary/base64dump.py%20Handles%20More%20Encodings%20Than%20Just%20BASE64/30332
 Stealing OAuth Tokens via Open Redirects...</itunes:subtitle><itunes:summary><![CDATA[base64dump.py Handles More Encodings Than Just BASE64<br /><a href="https://isc.sans.edu/diary/base64dump.py%20Handles%20More%20Encodings%20Than%20Just%20BASE64/30332" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/base64dump.py%20Handles%20More%20Encodings%20Than%20Just%20BASE64/30332</a><br /> Stealing OAuth Tokens via Open Redirects<br /><a href="https://eval.blog/research/microsoft-account-token-leaks-in-harvest/" target="_blank" rel="noreferrer noopener">https://eval.blog/research/microsoft-account-token-leaks-in-harvest/</a><br /> VMWare Patches<br /><a href="https://www.vmware.com/security/advisories.html" target="_blank" rel="noreferrer noopener">https://www.vmware.com/security/advisories.html</a><br /> Solarwinds Patches<br /><a href="https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-1_release_notes.htm" target="_blank" rel="noreferrer noopener">https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-1_release_notes.htm</a><br />]]></itunes:summary><itunes:duration>400</itunes:duration><itunes:keywords>base64,business,computer,cyber,cybersecurity,daily,hacking,harvest,infosec,internet,it,microsoft,network,news,oauth,security,solarwinds,vmware</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8712</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, October 20th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-october-20th-2023--57537718</link><description><![CDATA[Honeypot Update<br /><a href="https://github.com/DShield-ISC/dshield/blob/main/README.md" target="_blank" rel="noreferrer noopener">https://github.com/DShield-ISC/dshield/blob/main/README.md</a><br /> Malicious Keepass Ads<br /><a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/10/clever-malvertising-attack-uses-punycode-to-look-like-legitimate-website" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/threat-intelligence/2023/10/clever-malvertising-attack-uses-punycode-to-look-like-legitimate-website</a><br /> Malicious JavaScript in Smart Contracts<br /><a href="https://labs.guard.io/etherhiding-hiding-web2-malicious-code-in-web3-smart-contracts-65ea78efad16" target="_blank" rel="noreferrer noopener">https://labs.guard.io/etherhiding-hiding-web2-malicious-code-in-web3-smart-contracts-65ea78efad16</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8710.mp3</guid><pubDate>Fri, 20 Oct 2023 00:37:38 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537718/8710.mp3" length="5864784" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Honeypot Update
https://github.com/DShield-ISC/dshield/blob/main/README.md
 Malicious Keepass Ads
https://www.malwarebytes.com/blog/threat-intelligence/2023/10/clever-malvertising-attack-uses-punycode-to-look-like-legitimate-website
 Malicious...</itunes:subtitle><itunes:summary><![CDATA[Honeypot Update<br /><a href="https://github.com/DShield-ISC/dshield/blob/main/README.md" target="_blank" rel="noreferrer noopener">https://github.com/DShield-ISC/dshield/blob/main/README.md</a><br /> Malicious Keepass Ads<br /><a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/10/clever-malvertising-attack-uses-punycode-to-look-like-legitimate-website" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/threat-intelligence/2023/10/clever-malvertising-attack-uses-punycode-to-look-like-legitimate-website</a><br /> Malicious JavaScript in Smart Contracts<br /><a href="https://labs.guard.io/etherhiding-hiding-web2-malicious-code-in-web3-smart-contracts-65ea78efad16" target="_blank" rel="noreferrer noopener">https://labs.guard.io/etherhiding-hiding-web2-malicious-code-in-web3-smart-contracts-65ea78efad16</a><br />]]></itunes:summary><itunes:duration>397</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,javascript; binance; smart con,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8710</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, October 20th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-october-20th-2023--57313071</link><description><![CDATA[Honeypot Update<br /><a href="https://github.com/DShield-ISC/dshield/blob/main/README.md" target="_blank" rel="noreferrer noopener">https://github.com/DShield-ISC/dshield/blob/main/README.md</a><br /> Malicious Keepass Ads<br /><a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/10/clever-malvertising-attack-uses-punycode-to-look-like-legitimate-website" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/threat-intelligence/2023/10/clever-malvertising-attack-uses-punycode-to-look-like-legitimate-website</a><br /> Malicious JavaScript in Smart Contracts<br /><a href="https://labs.guard.io/etherhiding-hiding-web2-malicious-code-in-web3-smart-contracts-65ea78efad16" target="_blank" rel="noreferrer noopener">https://labs.guard.io/etherhiding-hiding-web2-malicious-code-in-web3-smart-contracts-65ea78efad16</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8710.mp3</guid><pubDate>Fri, 20 Oct 2023 00:37:38 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57313071/8710.mp3" length="5864784" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Honeypot Update
https://github.com/DShield-ISC/dshield/blob/main/README.md
 Malicious Keepass Ads
https://www.malwarebytes.com/blog/threat-intelligence/2023/10/clever-malvertising-attack-uses-punycode-to-look-like-legitimate-website
 Malicious...</itunes:subtitle><itunes:summary><![CDATA[Honeypot Update<br /><a href="https://github.com/DShield-ISC/dshield/blob/main/README.md" target="_blank" rel="noreferrer noopener">https://github.com/DShield-ISC/dshield/blob/main/README.md</a><br /> Malicious Keepass Ads<br /><a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/10/clever-malvertising-attack-uses-punycode-to-look-like-legitimate-website" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/threat-intelligence/2023/10/clever-malvertising-attack-uses-punycode-to-look-like-legitimate-website</a><br /> Malicious JavaScript in Smart Contracts<br /><a href="https://labs.guard.io/etherhiding-hiding-web2-malicious-code-in-web3-smart-contracts-65ea78efad16" target="_blank" rel="noreferrer noopener">https://labs.guard.io/etherhiding-hiding-web2-malicious-code-in-web3-smart-contracts-65ea78efad16</a><br />]]></itunes:summary><itunes:duration>397</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,javascript; binance; smart con,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8710</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, October 19th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-october-19th-2023--57537713</link><description><![CDATA[Hiding in Hex<br /><a href="https://isc.sans.edu/diary/Hiding%20in%20Hex/30322" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Hiding%20in%20Hex/30322</a><br /> Oracle Quarterly Critical Patch Update<br /><a href="https://www.oracle.com/security-alerts/cpuoct2023.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpuoct2023.html</a><br /> Citrix Vulnerability Exploited CVE-2023-4966<br /><a href="https://www.mandiant.com/resources/blog/remediation-netscaler-adc-gateway-cve-2023-4966" target="_blank" rel="noreferrer noopener">https://www.mandiant.com/resources/blog/remediation-netscaler-adc-gateway-cve-2023-4966</a><br /> Exposed Jupyter Notebooks Exploited<br /><a href="https://www.cadosecurity.com/qubitstrike-an-emerging-malware-campaign-targeting-jupyter-notebooks/" target="_blank" rel="noreferrer noopener">https://www.cadosecurity.com/qubitstrike-an-emerging-malware-campaign-targeting-jupyter-notebooks/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8708.mp3</guid><pubDate>Thu, 19 Oct 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537713/8708.mp3" length="5075777" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Hiding in Hex
https://isc.sans.edu/diary/Hiding%20in%20Hex/30322
 Oracle Quarterly Critical Patch Update
https://www.oracle.com/security-alerts/cpuoct2023.html
 Citrix Vulnerability Exploited CVE-2023-4966...</itunes:subtitle><itunes:summary><![CDATA[Hiding in Hex<br /><a href="https://isc.sans.edu/diary/Hiding%20in%20Hex/30322" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Hiding%20in%20Hex/30322</a><br /> Oracle Quarterly Critical Patch Update<br /><a href="https://www.oracle.com/security-alerts/cpuoct2023.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpuoct2023.html</a><br /> Citrix Vulnerability Exploited CVE-2023-4966<br /><a href="https://www.mandiant.com/resources/blog/remediation-netscaler-adc-gateway-cve-2023-4966" target="_blank" rel="noreferrer noopener">https://www.mandiant.com/resources/blog/remediation-netscaler-adc-gateway-cve-2023-4966</a><br /> Exposed Jupyter Notebooks Exploited<br /><a href="https://www.cadosecurity.com/qubitstrike-an-emerging-malware-campaign-targeting-jupyter-notebooks/" target="_blank" rel="noreferrer noopener">https://www.cadosecurity.com/qubitstrike-an-emerging-malware-campaign-targeting-jupyter-notebooks/</a><br />]]></itunes:summary><itunes:duration>341</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,jupyter; citrix; oracle; cpu; ,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8708</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, October 19th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-october-19th-2023--57298870</link><description><![CDATA[Hiding in Hex<br /><a href="https://isc.sans.edu/diary/Hiding%20in%20Hex/30322" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Hiding%20in%20Hex/30322</a><br /> Oracle Quarterly Critical Patch Update<br /><a href="https://www.oracle.com/security-alerts/cpuoct2023.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpuoct2023.html</a><br /> Citrix Vulnerability Exploited CVE-2023-4966<br /><a href="https://www.mandiant.com/resources/blog/remediation-netscaler-adc-gateway-cve-2023-4966" target="_blank" rel="noreferrer noopener">https://www.mandiant.com/resources/blog/remediation-netscaler-adc-gateway-cve-2023-4966</a><br /> Exposed Jupyter Notebooks Exploited<br /><a href="https://www.cadosecurity.com/qubitstrike-an-emerging-malware-campaign-targeting-jupyter-notebooks/" target="_blank" rel="noreferrer noopener">https://www.cadosecurity.com/qubitstrike-an-emerging-malware-campaign-targeting-jupyter-notebooks/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8708.mp3</guid><pubDate>Thu, 19 Oct 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57298870/8708.mp3" length="5075777" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Hiding in Hex
https://isc.sans.edu/diary/Hiding%20in%20Hex/30322
 Oracle Quarterly Critical Patch Update
https://www.oracle.com/security-alerts/cpuoct2023.html
 Citrix Vulnerability Exploited CVE-2023-4966...</itunes:subtitle><itunes:summary><![CDATA[Hiding in Hex<br /><a href="https://isc.sans.edu/diary/Hiding%20in%20Hex/30322" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Hiding%20in%20Hex/30322</a><br /> Oracle Quarterly Critical Patch Update<br /><a href="https://www.oracle.com/security-alerts/cpuoct2023.html" target="_blank" rel="noreferrer noopener">https://www.oracle.com/security-alerts/cpuoct2023.html</a><br /> Citrix Vulnerability Exploited CVE-2023-4966<br /><a href="https://www.mandiant.com/resources/blog/remediation-netscaler-adc-gateway-cve-2023-4966" target="_blank" rel="noreferrer noopener">https://www.mandiant.com/resources/blog/remediation-netscaler-adc-gateway-cve-2023-4966</a><br /> Exposed Jupyter Notebooks Exploited<br /><a href="https://www.cadosecurity.com/qubitstrike-an-emerging-malware-campaign-targeting-jupyter-notebooks/" target="_blank" rel="noreferrer noopener">https://www.cadosecurity.com/qubitstrike-an-emerging-malware-campaign-targeting-jupyter-notebooks/</a><br />]]></itunes:summary><itunes:duration>341</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,jupyter; citrix; oracle; cpu; ,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8708</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, October 18th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-october-18th-2023--57537711</link><description><![CDATA[Changes to SMS Delivery and How it Effects MFA and Phishing<br /><a href="https://isc.sans.edu/diary/Changes%20to%20SMS%20Delivery%20and%20How%20it%20Effects%20MFA%20and%20Phishing/30320" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Changes%20to%20SMS%20Delivery%20and%20How%20it%20Effects%20MFA%20and%20Phishing/30320</a><br /> Fake Traffic Tickets with QR Code<br /><a href="https://twitter.com/polizeiberlin/status/1713867011837567411" target="_blank" rel="noreferrer noopener">https://twitter.com/polizeiberlin/status/1713867011837567411</a><br /> Synology NAS DSM Account Takeover: Not Random Randomnumbers<br /><a href="https://claroty.com/team82/research/synology-nas-dsm-account-takeover-when-random-is-not-secure" target="_blank" rel="noreferrer noopener">https://claroty.com/team82/research/synology-nas-dsm-account-takeover-when-random-is-not-secure</a><br /> Milesight Routers CVe-2023-43261<br /><a href="https://github.com/win3zz/CVE-2023-43261" target="_blank" rel="noreferrer noopener">https://github.com/win3zz/CVE-2023-43261</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8706.mp3</guid><pubDate>Wed, 18 Oct 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537711/8706.mp3" length="5987335" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Changes to SMS Delivery and How it Effects MFA and Phishing
https://isc.sans.edu/diary/Changes%20to%20SMS%20Delivery%20and%20How%20it%20Effects%20MFA%20and%20Phishing/30320
 Fake Traffic Tickets with QR Code...</itunes:subtitle><itunes:summary><![CDATA[Changes to SMS Delivery and How it Effects MFA and Phishing<br /><a href="https://isc.sans.edu/diary/Changes%20to%20SMS%20Delivery%20and%20How%20it%20Effects%20MFA%20and%20Phishing/30320" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Changes%20to%20SMS%20Delivery%20and%20How%20it%20Effects%20MFA%20and%20Phishing/30320</a><br /> Fake Traffic Tickets with QR Code<br /><a href="https://twitter.com/polizeiberlin/status/1713867011837567411" target="_blank" rel="noreferrer noopener">https://twitter.com/polizeiberlin/status/1713867011837567411</a><br /> Synology NAS DSM Account Takeover: Not Random Randomnumbers<br /><a href="https://claroty.com/team82/research/synology-nas-dsm-account-takeover-when-random-is-not-secure" target="_blank" rel="noreferrer noopener">https://claroty.com/team82/research/synology-nas-dsm-account-takeover-when-random-is-not-secure</a><br /> Milesight Routers CVe-2023-43261<br /><a href="https://github.com/win3zz/CVE-2023-43261" target="_blank" rel="noreferrer noopener">https://github.com/win3zz/CVE-2023-43261</a><br />]]></itunes:summary><itunes:duration>406</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,milesight; routers; synology; ,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8706</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, October 18th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-october-18th-2023--57281045</link><description><![CDATA[Changes to SMS Delivery and How it Effects MFA and Phishing<br /><a href="https://isc.sans.edu/diary/Changes%20to%20SMS%20Delivery%20and%20How%20it%20Effects%20MFA%20and%20Phishing/30320" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Changes%20to%20SMS%20Delivery%20and%20How%20it%20Effects%20MFA%20and%20Phishing/30320</a><br /> Fake Traffic Tickets with QR Code<br /><a href="https://twitter.com/polizeiberlin/status/1713867011837567411" target="_blank" rel="noreferrer noopener">https://twitter.com/polizeiberlin/status/1713867011837567411</a><br /> Synology NAS DSM Account Takeover: Not Random Randomnumbers<br /><a href="https://claroty.com/team82/research/synology-nas-dsm-account-takeover-when-random-is-not-secure" target="_blank" rel="noreferrer noopener">https://claroty.com/team82/research/synology-nas-dsm-account-takeover-when-random-is-not-secure</a><br /> Milesight Routers CVe-2023-43261<br /><a href="https://github.com/win3zz/CVE-2023-43261" target="_blank" rel="noreferrer noopener">https://github.com/win3zz/CVE-2023-43261</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8706.mp3</guid><pubDate>Wed, 18 Oct 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57281045/8706.mp3" length="5987335" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Changes to SMS Delivery and How it Effects MFA and Phishing
https://isc.sans.edu/diary/Changes%20to%20SMS%20Delivery%20and%20How%20it%20Effects%20MFA%20and%20Phishing/30320
 Fake Traffic Tickets with QR Code...</itunes:subtitle><itunes:summary><![CDATA[Changes to SMS Delivery and How it Effects MFA and Phishing<br /><a href="https://isc.sans.edu/diary/Changes%20to%20SMS%20Delivery%20and%20How%20it%20Effects%20MFA%20and%20Phishing/30320" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Changes%20to%20SMS%20Delivery%20and%20How%20it%20Effects%20MFA%20and%20Phishing/30320</a><br /> Fake Traffic Tickets with QR Code<br /><a href="https://twitter.com/polizeiberlin/status/1713867011837567411" target="_blank" rel="noreferrer noopener">https://twitter.com/polizeiberlin/status/1713867011837567411</a><br /> Synology NAS DSM Account Takeover: Not Random Randomnumbers<br /><a href="https://claroty.com/team82/research/synology-nas-dsm-account-takeover-when-random-is-not-secure" target="_blank" rel="noreferrer noopener">https://claroty.com/team82/research/synology-nas-dsm-account-takeover-when-random-is-not-secure</a><br /> Milesight Routers CVe-2023-43261<br /><a href="https://github.com/win3zz/CVE-2023-43261" target="_blank" rel="noreferrer noopener">https://github.com/win3zz/CVE-2023-43261</a><br />]]></itunes:summary><itunes:duration>406</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,milesight; routers; synology; ,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8706</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, October 17th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-october-17th-2023--57537721</link><description><![CDATA[Are Typos Still relevant As An Indicator of Phishing<br /><a href="https://isc.sans.edu/diary/Are+typos+still+relevant+as+an+indicator+of+phishing/30316" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Are+typos+still+relevant+as+an+indicator+of+phishing/30316</a><br /> Active Exploitation of Cisco ISO XE Software Web Management User Interface Vuln<br /><a href="https://blog.talosintelligence.com/active-exploitation-of-cisco-ios-xe-software/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/active-exploitation-of-cisco-ios-xe-software/</a><br /> Mail traffic to cancelled domain names<br /><a href="https://www.sidn.nl/en/nl-domain-name/mail-traffic-to-cancelled-domain-names" target="_blank" rel="noreferrer noopener">https://www.sidn.nl/en/nl-domain-name/mail-traffic-to-cancelled-domain-names</a><br /> SAMBA Update<br /><a href="https://www.samba.org/samba/history/security.html" target="_blank" rel="noreferrer noopener">https://www.samba.org/samba/history/security.html</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8704.mp3</guid><pubDate>Tue, 17 Oct 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537721/8704.mp3" length="4906060" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Are Typos Still relevant As An Indicator of Phishing
https://isc.sans.edu/diary/Are+typos+still+relevant+as+an+indicator+of+phishing/30316
 Active Exploitation of Cisco ISO XE Software Web Management User Interface Vuln...</itunes:subtitle><itunes:summary><![CDATA[Are Typos Still relevant As An Indicator of Phishing<br /><a href="https://isc.sans.edu/diary/Are+typos+still+relevant+as+an+indicator+of+phishing/30316" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Are+typos+still+relevant+as+an+indicator+of+phishing/30316</a><br /> Active Exploitation of Cisco ISO XE Software Web Management User Interface Vuln<br /><a href="https://blog.talosintelligence.com/active-exploitation-of-cisco-ios-xe-software/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/active-exploitation-of-cisco-ios-xe-software/</a><br /> Mail traffic to cancelled domain names<br /><a href="https://www.sidn.nl/en/nl-domain-name/mail-traffic-to-cancelled-domain-names" target="_blank" rel="noreferrer noopener">https://www.sidn.nl/en/nl-domain-name/mail-traffic-to-cancelled-domain-names</a><br /> SAMBA Update<br /><a href="https://www.samba.org/samba/history/security.html" target="_blank" rel="noreferrer noopener">https://www.samba.org/samba/history/security.html</a><br />]]></itunes:summary><itunes:duration>329</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,samba; email; domains; netherl,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8704</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, October 17th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-october-17th-2023--57263780</link><description><![CDATA[Are Typos Still relevant As An Indicator of Phishing<br /><a href="https://isc.sans.edu/diary/Are+typos+still+relevant+as+an+indicator+of+phishing/30316" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Are+typos+still+relevant+as+an+indicator+of+phishing/30316</a><br /> Active Exploitation of Cisco ISO XE Software Web Management User Interface Vuln<br /><a href="https://blog.talosintelligence.com/active-exploitation-of-cisco-ios-xe-software/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/active-exploitation-of-cisco-ios-xe-software/</a><br /> Mail traffic to cancelled domain names<br /><a href="https://www.sidn.nl/en/nl-domain-name/mail-traffic-to-cancelled-domain-names" target="_blank" rel="noreferrer noopener">https://www.sidn.nl/en/nl-domain-name/mail-traffic-to-cancelled-domain-names</a><br /> SAMBA Update<br /><a href="https://www.samba.org/samba/history/security.html" target="_blank" rel="noreferrer noopener">https://www.samba.org/samba/history/security.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8704.mp3</guid><pubDate>Tue, 17 Oct 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57263780/8704.mp3" length="4906060" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Are Typos Still relevant As An Indicator of Phishing
https://isc.sans.edu/diary/Are+typos+still+relevant+as+an+indicator+of+phishing/30316
 Active Exploitation of Cisco ISO XE Software Web Management User Interface Vuln...</itunes:subtitle><itunes:summary><![CDATA[Are Typos Still relevant As An Indicator of Phishing<br /><a href="https://isc.sans.edu/diary/Are+typos+still+relevant+as+an+indicator+of+phishing/30316" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Are+typos+still+relevant+as+an+indicator+of+phishing/30316</a><br /> Active Exploitation of Cisco ISO XE Software Web Management User Interface Vuln<br /><a href="https://blog.talosintelligence.com/active-exploitation-of-cisco-ios-xe-software/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/active-exploitation-of-cisco-ios-xe-software/</a><br /> Mail traffic to cancelled domain names<br /><a href="https://www.sidn.nl/en/nl-domain-name/mail-traffic-to-cancelled-domain-names" target="_blank" rel="noreferrer noopener">https://www.sidn.nl/en/nl-domain-name/mail-traffic-to-cancelled-domain-names</a><br /> SAMBA Update<br /><a href="https://www.samba.org/samba/history/security.html" target="_blank" rel="noreferrer noopener">https://www.samba.org/samba/history/security.html</a><br />]]></itunes:summary><itunes:duration>329</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,samba; email; domains; netherl,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8704</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, October 16th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-october-16th-2023--57537729</link><description><![CDATA[What's Normal: Odd Mac Addresses<br /><a href="https://isc.sans.edu/forums/diary/What's%20Normal%3A%20MAC%20Addresses/30310/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/What's%20Normal%3A%20MAC%20Addresses/30310/</a><br /> Domain Name Used as Password Captured by DShield Sensor<br /><a href="https://isc.sans.edu/forums/diary/Domain%20Name%20Used%20as%20Password%20Captured%20by%20DShield%20Sensor/30312/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Domain%20Name%20Used%20as%20Password%20Captured%20by%20DShield%20Sensor/30312/</a><br /> PoC Exploit for CVE-2023-41993<br /><a href="https://github.com/po6ix/POC-for-CVE-2023-41993" target="_blank" rel="noreferrer noopener">https://github.com/po6ix/POC-for-CVE-2023-41993</a><br /> AvosLocker Ransomware Details<br /><a href="https://www.cisa.gov/sites/default/files/2023-10/aa23-284a-joint-csa-stopransomware-avoslocker-ransomware-update.pdf" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/sites/default/files/2023-10/aa23-284a-joint-csa-stopransomware-avoslocker-ransomware-update.pdf</a><br /> DarkGate Spreading via Skype and Teams<br /><a href="https://www.trendmicro.com/en_ph/research/23/j/darkgate-opens-organizations-for-attack-via-skype-teams.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_ph/research/23/j/darkgate-opens-organizations-for-attack-via-skype-teams.html</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8702.mp3</guid><pubDate>Mon, 16 Oct 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537729/8702.mp3" length="4863320" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>What's Normal: Odd Mac Addresses
https://isc.sans.edu/forums/diary/What's%20Normal%3A%20MAC%20Addresses/30310/
 Domain Name Used as Password Captured by DShield Sensor...</itunes:subtitle><itunes:summary><![CDATA[What's Normal: Odd Mac Addresses<br /><a href="https://isc.sans.edu/forums/diary/What's%20Normal%3A%20MAC%20Addresses/30310/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/What's%20Normal%3A%20MAC%20Addresses/30310/</a><br /> Domain Name Used as Password Captured by DShield Sensor<br /><a href="https://isc.sans.edu/forums/diary/Domain%20Name%20Used%20as%20Password%20Captured%20by%20DShield%20Sensor/30312/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Domain%20Name%20Used%20as%20Password%20Captured%20by%20DShield%20Sensor/30312/</a><br /> PoC Exploit for CVE-2023-41993<br /><a href="https://github.com/po6ix/POC-for-CVE-2023-41993" target="_blank" rel="noreferrer noopener">https://github.com/po6ix/POC-for-CVE-2023-41993</a><br /> AvosLocker Ransomware Details<br /><a href="https://www.cisa.gov/sites/default/files/2023-10/aa23-284a-joint-csa-stopransomware-avoslocker-ransomware-update.pdf" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/sites/default/files/2023-10/aa23-284a-joint-csa-stopransomware-avoslocker-ransomware-update.pdf</a><br /> DarkGate Spreading via Skype and Teams<br /><a href="https://www.trendmicro.com/en_ph/research/23/j/darkgate-opens-organizations-for-attack-via-skype-teams.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_ph/research/23/j/darkgate-opens-organizations-for-attack-via-skype-teams.html</a><br />]]></itunes:summary><itunes:duration>326</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,darkcate; avoslocker; poc; ios,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8702</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, October 16th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-october-16th-2023--57244954</link><description><![CDATA[What's Normal: Odd Mac Addresses<br /><a href="https://isc.sans.edu/forums/diary/What's%20Normal%3A%20MAC%20Addresses/30310/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/What's%20Normal%3A%20MAC%20Addresses/30310/</a><br /> Domain Name Used as Password Captured by DShield Sensor<br /><a href="https://isc.sans.edu/forums/diary/Domain%20Name%20Used%20as%20Password%20Captured%20by%20DShield%20Sensor/30312/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Domain%20Name%20Used%20as%20Password%20Captured%20by%20DShield%20Sensor/30312/</a><br /> PoC Exploit for CVE-2023-41993<br /><a href="https://github.com/po6ix/POC-for-CVE-2023-41993" target="_blank" rel="noreferrer noopener">https://github.com/po6ix/POC-for-CVE-2023-41993</a><br /> AvosLocker Ransomware Details<br /><a href="https://www.cisa.gov/sites/default/files/2023-10/aa23-284a-joint-csa-stopransomware-avoslocker-ransomware-update.pdf" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/sites/default/files/2023-10/aa23-284a-joint-csa-stopransomware-avoslocker-ransomware-update.pdf</a><br /> DarkGate Spreading via Skype and Teams<br /><a href="https://www.trendmicro.com/en_ph/research/23/j/darkgate-opens-organizations-for-attack-via-skype-teams.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_ph/research/23/j/darkgate-opens-organizations-for-attack-via-skype-teams.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8702.mp3</guid><pubDate>Mon, 16 Oct 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57244954/8702.mp3" length="4863320" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>What's Normal: Odd Mac Addresses
https://isc.sans.edu/forums/diary/What's%20Normal%3A%20MAC%20Addresses/30310/
 Domain Name Used as Password Captured by DShield Sensor...</itunes:subtitle><itunes:summary><![CDATA[What's Normal: Odd Mac Addresses<br /><a href="https://isc.sans.edu/forums/diary/What's%20Normal%3A%20MAC%20Addresses/30310/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/What's%20Normal%3A%20MAC%20Addresses/30310/</a><br /> Domain Name Used as Password Captured by DShield Sensor<br /><a href="https://isc.sans.edu/forums/diary/Domain%20Name%20Used%20as%20Password%20Captured%20by%20DShield%20Sensor/30312/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Domain%20Name%20Used%20as%20Password%20Captured%20by%20DShield%20Sensor/30312/</a><br /> PoC Exploit for CVE-2023-41993<br /><a href="https://github.com/po6ix/POC-for-CVE-2023-41993" target="_blank" rel="noreferrer noopener">https://github.com/po6ix/POC-for-CVE-2023-41993</a><br /> AvosLocker Ransomware Details<br /><a href="https://www.cisa.gov/sites/default/files/2023-10/aa23-284a-joint-csa-stopransomware-avoslocker-ransomware-update.pdf" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/sites/default/files/2023-10/aa23-284a-joint-csa-stopransomware-avoslocker-ransomware-update.pdf</a><br /> DarkGate Spreading via Skype and Teams<br /><a href="https://www.trendmicro.com/en_ph/research/23/j/darkgate-opens-organizations-for-attack-via-skype-teams.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_ph/research/23/j/darkgate-opens-organizations-for-attack-via-skype-teams.html</a><br />]]></itunes:summary><itunes:duration>326</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,darkcate; avoslocker; poc; ios,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8702</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, October 13th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-october-13th-2023--57537733</link><description><![CDATA[SeroXen RAT in Typosquatted NuGet Packages<br /><a href="https://blog.phylum.io/phylum-discovers-seroxen-rat-in-typosquatted-nuget-package/" target="_blank" rel="noreferrer noopener">https://blog.phylum.io/phylum-discovers-seroxen-rat-in-typosquatted-nuget-package/</a><br /> Hexadecimal IP Addresses<br /><a href="https://asec.ahnlab.com/en/57635/" target="_blank" rel="noreferrer noopener">https://asec.ahnlab.com/en/57635/</a><br /> Juniper Vulnerabilities<br /><a href="https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;numberOfResults=50&amp;f:ctype=%5BSecurity%20Advisories%5D" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;numberOfResults=50&amp;f:ctype=[Security%20Advisories]</a><br /> Unpatched Squid Vulnerabilities<br /><a href="https://joshua.hu/squid-security-audit-35-0days-45-exploits" target="_blank" rel="noreferrer noopener">https://joshua.hu/squid-security-audit-35-0days-45-exploits</a><br /> BSIDES Jacksonville<br /><a href="https://bsidesjax.org" target="_blank" rel="noreferrer noopener">https://bsidesjax.org</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8700.mp3</guid><pubDate>Fri, 13 Oct 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537733/8700.mp3" length="5537201" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>SeroXen RAT in Typosquatted NuGet Packages
https://blog.phylum.io/phylum-discovers-seroxen-rat-in-typosquatted-nuget-package/
 Hexadecimal IP Addresses
https://asec.ahnlab.com/en/57635/
 Juniper Vulnerabilities...</itunes:subtitle><itunes:summary><![CDATA[SeroXen RAT in Typosquatted NuGet Packages<br /><a href="https://blog.phylum.io/phylum-discovers-seroxen-rat-in-typosquatted-nuget-package/" target="_blank" rel="noreferrer noopener">https://blog.phylum.io/phylum-discovers-seroxen-rat-in-typosquatted-nuget-package/</a><br /> Hexadecimal IP Addresses<br /><a href="https://asec.ahnlab.com/en/57635/" target="_blank" rel="noreferrer noopener">https://asec.ahnlab.com/en/57635/</a><br /> Juniper Vulnerabilities<br /><a href="https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;numberOfResults=50&amp;f:ctype=%5BSecurity%20Advisories%5D" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;numberOfResults=50&amp;f:ctype=[Security%20Advisories]</a><br /> Unpatched Squid Vulnerabilities<br /><a href="https://joshua.hu/squid-security-audit-35-0days-45-exploits" target="_blank" rel="noreferrer noopener">https://joshua.hu/squid-security-audit-35-0days-45-exploits</a><br /> BSIDES Jacksonville<br /><a href="https://bsidesjax.org" target="_blank" rel="noreferrer noopener">https://bsidesjax.org</a><br />]]></itunes:summary><itunes:duration>374</itunes:duration><itunes:keywords>bsides; jacksonville; squid; j,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8700</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, October 13th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-october-13th-2023--57217774</link><description><![CDATA[SeroXen RAT in Typosquatted NuGet Packages<br /><a href="https://blog.phylum.io/phylum-discovers-seroxen-rat-in-typosquatted-nuget-package/" target="_blank" rel="noreferrer noopener">https://blog.phylum.io/phylum-discovers-seroxen-rat-in-typosquatted-nuget-package/</a><br /> Hexadecimal IP Addresses<br /><a href="https://asec.ahnlab.com/en/57635/" target="_blank" rel="noreferrer noopener">https://asec.ahnlab.com/en/57635/</a><br /> Juniper Vulnerabilities<br /><a href="https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;numberOfResults=50&amp;f:ctype=%5BSecurity%20Advisories%5D" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;numberOfResults=50&amp;f:ctype=[Security%20Advisories]</a><br /> Unpatched Squid Vulnerabilities<br /><a href="https://joshua.hu/squid-security-audit-35-0days-45-exploits" target="_blank" rel="noreferrer noopener">https://joshua.hu/squid-security-audit-35-0days-45-exploits</a><br /> BSIDES Jacksonville<br /><a href="https://bsidesjax.org" target="_blank" rel="noreferrer noopener">https://bsidesjax.org</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8700.mp3</guid><pubDate>Fri, 13 Oct 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57217774/8700.mp3" length="5537201" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>SeroXen RAT in Typosquatted NuGet Packages
https://blog.phylum.io/phylum-discovers-seroxen-rat-in-typosquatted-nuget-package/
 Hexadecimal IP Addresses
https://asec.ahnlab.com/en/57635/
 Juniper Vulnerabilities...</itunes:subtitle><itunes:summary><![CDATA[SeroXen RAT in Typosquatted NuGet Packages<br /><a href="https://blog.phylum.io/phylum-discovers-seroxen-rat-in-typosquatted-nuget-package/" target="_blank" rel="noreferrer noopener">https://blog.phylum.io/phylum-discovers-seroxen-rat-in-typosquatted-nuget-package/</a><br /> Hexadecimal IP Addresses<br /><a href="https://asec.ahnlab.com/en/57635/" target="_blank" rel="noreferrer noopener">https://asec.ahnlab.com/en/57635/</a><br /> Juniper Vulnerabilities<br /><a href="https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;numberOfResults=50&amp;f:ctype=%5BSecurity%20Advisories%5D" target="_blank" rel="noreferrer noopener">https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;numberOfResults=50&amp;f:ctype=[Security%20Advisories]</a><br /> Unpatched Squid Vulnerabilities<br /><a href="https://joshua.hu/squid-security-audit-35-0days-45-exploits" target="_blank" rel="noreferrer noopener">https://joshua.hu/squid-security-audit-35-0days-45-exploits</a><br /> BSIDES Jacksonville<br /><a href="https://bsidesjax.org" target="_blank" rel="noreferrer noopener">https://bsidesjax.org</a><br />]]></itunes:summary><itunes:duration>374</itunes:duration><itunes:keywords>bsides; jacksonville; squid; j,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8700</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, October 12th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-october-12th-2023--57537727</link><description><![CDATA[CVE-2023-22515 Activately Exploited<br /><a href="https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html" target="_blank" rel="noreferrer noopener">https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html</a><br /> curl SOCKS5 oversized hostname vulnerability CVe-2023-38545<br /><a href="https://isc.sans.edu/diary/CVE-2023-38545%3A%20curl%20SOCKS5%20oversized%20hostname%20vulnerability.%20How%20bad%20is%20it%3F/30304" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CVE-2023-38545%3A%20curl%20SOCKS5%20oversized%20hostname%20vulnerability.%20How%20bad%20is%20it%3F/30304</a><br /> Adobe Acrobat Vulnerablity Actively Exploited CVE-2023-21608<br /><a href="https://www.cisa.gov/news-events/alerts/2023/10/10/cisa-adds-five-known-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2023/10/10/cisa-adds-five-known-vulnerabilities-catalog</a><br /> Google Makes Passkey the Default<br /><a href="https://blog.google/technology/safety-security/passkeys-default-google-accounts/" target="_blank" rel="noreferrer noopener">https://blog.google/technology/safety-security/passkeys-default-google-accounts/</a><br /> VBScript Deprecated from Windows<br /><a href="https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8698.mp3</guid><pubDate>Thu, 12 Oct 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537727/8698.mp3" length="4897989" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>CVE-2023-22515 Activately Exploited
https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html
 curl SOCKS5 oversized hostname vulnerability CVe-2023-38545...</itunes:subtitle><itunes:summary><![CDATA[CVE-2023-22515 Activately Exploited<br /><a href="https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html" target="_blank" rel="noreferrer noopener">https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html</a><br /> curl SOCKS5 oversized hostname vulnerability CVe-2023-38545<br /><a href="https://isc.sans.edu/diary/CVE-2023-38545%3A%20curl%20SOCKS5%20oversized%20hostname%20vulnerability.%20How%20bad%20is%20it%3F/30304" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CVE-2023-38545%3A%20curl%20SOCKS5%20oversized%20hostname%20vulnerability.%20How%20bad%20is%20it%3F/30304</a><br /> Adobe Acrobat Vulnerablity Actively Exploited CVE-2023-21608<br /><a href="https://www.cisa.gov/news-events/alerts/2023/10/10/cisa-adds-five-known-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2023/10/10/cisa-adds-five-known-vulnerabilities-catalog</a><br /> Google Makes Passkey the Default<br /><a href="https://blog.google/technology/safety-security/passkeys-default-google-accounts/" target="_blank" rel="noreferrer noopener">https://blog.google/technology/safety-security/passkeys-default-google-accounts/</a><br /> VBScript Deprecated from Windows<br /><a href="https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features</a><br />]]></itunes:summary><itunes:duration>328</itunes:duration><itunes:keywords>atlassian; curl; vbscript adob,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8698</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, October 12th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-october-12th-2023--57202415</link><description><![CDATA[CVE-2023-22515 Activately Exploited<br /><a href="https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html" target="_blank" rel="noreferrer noopener">https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html</a><br /> curl SOCKS5 oversized hostname vulnerability CVe-2023-38545<br /><a href="https://isc.sans.edu/diary/CVE-2023-38545%3A%20curl%20SOCKS5%20oversized%20hostname%20vulnerability.%20How%20bad%20is%20it%3F/30304" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CVE-2023-38545%3A%20curl%20SOCKS5%20oversized%20hostname%20vulnerability.%20How%20bad%20is%20it%3F/30304</a><br /> Adobe Acrobat Vulnerablity Actively Exploited CVE-2023-21608<br /><a href="https://www.cisa.gov/news-events/alerts/2023/10/10/cisa-adds-five-known-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2023/10/10/cisa-adds-five-known-vulnerabilities-catalog</a><br /> Google Makes Passkey the Default<br /><a href="https://blog.google/technology/safety-security/passkeys-default-google-accounts/" target="_blank" rel="noreferrer noopener">https://blog.google/technology/safety-security/passkeys-default-google-accounts/</a><br /> VBScript Deprecated from Windows<br /><a href="https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8698.mp3</guid><pubDate>Thu, 12 Oct 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57202415/8698.mp3" length="4897989" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>CVE-2023-22515 Activately Exploited
https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html
 curl SOCKS5 oversized hostname vulnerability CVe-2023-38545...</itunes:subtitle><itunes:summary><![CDATA[CVE-2023-22515 Activately Exploited<br /><a href="https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html" target="_blank" rel="noreferrer noopener">https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html</a><br /> curl SOCKS5 oversized hostname vulnerability CVe-2023-38545<br /><a href="https://isc.sans.edu/diary/CVE-2023-38545%3A%20curl%20SOCKS5%20oversized%20hostname%20vulnerability.%20How%20bad%20is%20it%3F/30304" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/CVE-2023-38545%3A%20curl%20SOCKS5%20oversized%20hostname%20vulnerability.%20How%20bad%20is%20it%3F/30304</a><br /> Adobe Acrobat Vulnerablity Actively Exploited CVE-2023-21608<br /><a href="https://www.cisa.gov/news-events/alerts/2023/10/10/cisa-adds-five-known-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/alerts/2023/10/10/cisa-adds-five-known-vulnerabilities-catalog</a><br /> Google Makes Passkey the Default<br /><a href="https://blog.google/technology/safety-security/passkeys-default-google-accounts/" target="_blank" rel="noreferrer noopener">https://blog.google/technology/safety-security/passkeys-default-google-accounts/</a><br /> VBScript Deprecated from Windows<br /><a href="https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features</a><br />]]></itunes:summary><itunes:duration>328</itunes:duration><itunes:keywords>atlassian; curl; vbscript adob,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8698</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, October 11th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-october-11th-2023--57537730</link><description><![CDATA[http2 rapid reset<br /><a href="https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/" target="_blank" rel="noreferrer noopener">https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/</a><br /> microsoft patch tuesday<br /><a href="https://isc.sans.edu/diary/October%202023%20Microsoft%20Patch%20Tuesday%20Summary/30300" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/October%202023%20Microsoft%20Patch%20Tuesday%20Summary/30300</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8696.mp3</guid><pubDate>Wed, 11 Oct 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537730/8696.mp3" length="6952370" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>http2 rapid reset
https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/
 microsoft patch tuesday
https://isc.sans.edu/diary/October%202023%20Microsoft%20Patch%20Tuesday%20Summary/30300
</itunes:subtitle><itunes:summary><![CDATA[http2 rapid reset<br /><a href="https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/" target="_blank" rel="noreferrer noopener">https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/</a><br /> microsoft patch tuesday<br /><a href="https://isc.sans.edu/diary/October%202023%20Microsoft%20Patch%20Tuesday%20Summary/30300" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/October%202023%20Microsoft%20Patch%20Tuesday%20Summary/30300</a><br />]]></itunes:summary><itunes:duration>475</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microsoft; patch; tuesday; htt,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8696</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, October 11th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-october-11th-2023--57187281</link><description><![CDATA[http2 rapid reset<br /><a href="https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/" target="_blank" rel="noreferrer noopener">https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/</a><br /> microsoft patch tuesday<br /><a href="https://isc.sans.edu/diary/October%202023%20Microsoft%20Patch%20Tuesday%20Summary/30300" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/October%202023%20Microsoft%20Patch%20Tuesday%20Summary/30300</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8696.mp3</guid><pubDate>Wed, 11 Oct 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57187281/8696.mp3" length="6952370" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>http2 rapid reset
https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/
 microsoft patch tuesday
https://isc.sans.edu/diary/October%202023%20Microsoft%20Patch%20Tuesday%20Summary/30300
</itunes:subtitle><itunes:summary><![CDATA[http2 rapid reset<br /><a href="https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/" target="_blank" rel="noreferrer noopener">https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/</a><br /> microsoft patch tuesday<br /><a href="https://isc.sans.edu/diary/October%202023%20Microsoft%20Patch%20Tuesday%20Summary/30300" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/October%202023%20Microsoft%20Patch%20Tuesday%20Summary/30300</a><br />]]></itunes:summary><itunes:duration>475</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microsoft; patch; tuesday; htt,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8696</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, October 10th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-october-10th-2023--57537731</link><description><![CDATA[ZIP's DOSTIME and DOSDATE Formats<br /><a href="https://isc.sans.edu/diary/ZIP%27s%20DOSTIME%20%26%20DOSDATE%20Formats/30296" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/ZIP%27s%20DOSTIME%20%26%20DOSDATE%20Formats/30296</a><br /> New Magecart Campaign Abusing 404 Pages<br /><a href="https://www.akamai.com/blog/security-research/magecart-new-technique-404-pages-skimmer" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/magecart-new-technique-404-pages-skimmer</a><br /> Sophos Effected by Exim Flaw<br /><a href="https://www.sophos.com/en-us/security-advisories/sophos-sa-20231005-exim-vuln" target="_blank" rel="noreferrer noopener">https://www.sophos.com/en-us/security-advisories/sophos-sa-20231005-exim-vuln</a><br /> Turn OFF This WatchGuard Feature: GuardLapse<br /><a href="https://projectblack.io/blog/turn-off-this-watchguard-feature-guardlapse/" target="_blank" rel="noreferrer noopener">https://projectblack.io/blog/turn-off-this-watchguard-feature-guardlapse/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8694.mp3</guid><pubDate>Tue, 10 Oct 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537731/8694.mp3" length="4826712" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>ZIP's DOSTIME and DOSDATE Formats
https://isc.sans.edu/diary/ZIP%27s%20DOSTIME%20%26%20DOSDATE%20Formats/30296
 New Magecart Campaign Abusing 404 Pages
https://www.akamai.com/blog/security-research/magecart-new-technique-404-pages-skimmer
 Sophos...</itunes:subtitle><itunes:summary><![CDATA[ZIP's DOSTIME and DOSDATE Formats<br /><a href="https://isc.sans.edu/diary/ZIP%27s%20DOSTIME%20%26%20DOSDATE%20Formats/30296" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/ZIP%27s%20DOSTIME%20%26%20DOSDATE%20Formats/30296</a><br /> New Magecart Campaign Abusing 404 Pages<br /><a href="https://www.akamai.com/blog/security-research/magecart-new-technique-404-pages-skimmer" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/magecart-new-technique-404-pages-skimmer</a><br /> Sophos Effected by Exim Flaw<br /><a href="https://www.sophos.com/en-us/security-advisories/sophos-sa-20231005-exim-vuln" target="_blank" rel="noreferrer noopener">https://www.sophos.com/en-us/security-advisories/sophos-sa-20231005-exim-vuln</a><br /> Turn OFF This WatchGuard Feature: GuardLapse<br /><a href="https://projectblack.io/blog/turn-off-this-watchguard-feature-guardlapse/" target="_blank" rel="noreferrer noopener">https://projectblack.io/blog/turn-off-this-watchguard-feature-guardlapse/</a><br />]]></itunes:summary><itunes:duration>323</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,watchguard; guardlaps; sophos;</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8694</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, October 10th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-october-10th-2023--57174445</link><description><![CDATA[ZIP's DOSTIME and DOSDATE Formats<br /><a href="https://isc.sans.edu/diary/ZIP%27s%20DOSTIME%20%26%20DOSDATE%20Formats/30296" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/ZIP%27s%20DOSTIME%20%26%20DOSDATE%20Formats/30296</a><br /> New Magecart Campaign Abusing 404 Pages<br /><a href="https://www.akamai.com/blog/security-research/magecart-new-technique-404-pages-skimmer" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/magecart-new-technique-404-pages-skimmer</a><br /> Sophos Effected by Exim Flaw<br /><a href="https://www.sophos.com/en-us/security-advisories/sophos-sa-20231005-exim-vuln" target="_blank" rel="noreferrer noopener">https://www.sophos.com/en-us/security-advisories/sophos-sa-20231005-exim-vuln</a><br /> Turn OFF This WatchGuard Feature: GuardLapse<br /><a href="https://projectblack.io/blog/turn-off-this-watchguard-feature-guardlapse/" target="_blank" rel="noreferrer noopener">https://projectblack.io/blog/turn-off-this-watchguard-feature-guardlapse/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8694.mp3</guid><pubDate>Tue, 10 Oct 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57174445/8694.mp3" length="4826712" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>ZIP's DOSTIME and DOSDATE Formats
https://isc.sans.edu/diary/ZIP%27s%20DOSTIME%20%26%20DOSDATE%20Formats/30296
 New Magecart Campaign Abusing 404 Pages
https://www.akamai.com/blog/security-research/magecart-new-technique-404-pages-skimmer
 Sophos...</itunes:subtitle><itunes:summary><![CDATA[ZIP's DOSTIME and DOSDATE Formats<br /><a href="https://isc.sans.edu/diary/ZIP%27s%20DOSTIME%20%26%20DOSDATE%20Formats/30296" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/ZIP%27s%20DOSTIME%20%26%20DOSDATE%20Formats/30296</a><br /> New Magecart Campaign Abusing 404 Pages<br /><a href="https://www.akamai.com/blog/security-research/magecart-new-technique-404-pages-skimmer" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/magecart-new-technique-404-pages-skimmer</a><br /> Sophos Effected by Exim Flaw<br /><a href="https://www.sophos.com/en-us/security-advisories/sophos-sa-20231005-exim-vuln" target="_blank" rel="noreferrer noopener">https://www.sophos.com/en-us/security-advisories/sophos-sa-20231005-exim-vuln</a><br /> Turn OFF This WatchGuard Feature: GuardLapse<br /><a href="https://projectblack.io/blog/turn-off-this-watchguard-feature-guardlapse/" target="_blank" rel="noreferrer noopener">https://projectblack.io/blog/turn-off-this-watchguard-feature-guardlapse/</a><br />]]></itunes:summary><itunes:duration>323</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,watchguard; guardlaps; sophos;</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8694</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, October 9th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-october-9th-2023--57537720</link><description><![CDATA[Binary IPv6 Address Conversion<br /><a href="https://isc.sans.edu/diary/Binary%20IPv6%20Addresses/30290" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Binary%20IPv6%20Addresses/30290</a><br /> Wireshark Updates<br /><a href="https://www.wireshark.org/" target="_blank" rel="noreferrer noopener">https://www.wireshark.org/</a><br /><br /> Improved GitHub Secret Scanning<br /><a href="https://github.blog/2023-10-04-introducing-secret-scanning-validity-checks-for-major-cloud-services/" target="_blank" rel="noreferrer noopener">https://github.blog/2023-10-04-introducing-secret-scanning-validity-checks-for-major-cloud-services/</a><br /> Prerooted Android Devices<br /><a href="https://arstechnica.com/security/2023/10/thousands-of-android-devices-come-with-unkillable-backdoor-preinstalled/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2023/10/thousands-of-android-devices-come-with-unkillable-backdoor-preinstalled/</a><br /> curl update<br /><a href="https://github.com/curl/curl/discussions/12026" target="_blank" rel="noreferrer noopener">https://github.com/curl/curl/discussions/12026</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8692.mp3</guid><pubDate>Mon, 09 Oct 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537720/8692.mp3" length="5502897" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Binary IPv6 Address Conversion
https://isc.sans.edu/diary/Binary%20IPv6%20Addresses/30290
 Wireshark Updates
https://www.wireshark.org/

 Improved GitHub Secret Scanning...</itunes:subtitle><itunes:summary><![CDATA[Binary IPv6 Address Conversion<br /><a href="https://isc.sans.edu/diary/Binary%20IPv6%20Addresses/30290" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Binary%20IPv6%20Addresses/30290</a><br /> Wireshark Updates<br /><a href="https://www.wireshark.org/" target="_blank" rel="noreferrer noopener">https://www.wireshark.org/</a><br /><br /> Improved GitHub Secret Scanning<br /><a href="https://github.blog/2023-10-04-introducing-secret-scanning-validity-checks-for-major-cloud-services/" target="_blank" rel="noreferrer noopener">https://github.blog/2023-10-04-introducing-secret-scanning-validity-checks-for-major-cloud-services/</a><br /> Prerooted Android Devices<br /><a href="https://arstechnica.com/security/2023/10/thousands-of-android-devices-come-with-unkillable-backdoor-preinstalled/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2023/10/thousands-of-android-devices-come-with-unkillable-backdoor-preinstalled/</a><br /> curl update<br /><a href="https://github.com/curl/curl/discussions/12026" target="_blank" rel="noreferrer noopener">https://github.com/curl/curl/discussions/12026</a><br />]]></itunes:summary><itunes:duration>371</itunes:duration><itunes:keywords>business,computer,curl; android; github; secrets,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8692</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, October 9th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-october-9th-2023--57158134</link><description><![CDATA[Binary IPv6 Address Conversion<br /><a href="https://isc.sans.edu/diary/Binary%20IPv6%20Addresses/30290" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Binary%20IPv6%20Addresses/30290</a><br /> Wireshark Updates<br /><a href="https://www.wireshark.org/" target="_blank" rel="noreferrer noopener">https://www.wireshark.org/</a><br /><br /> Improved GitHub Secret Scanning<br /><a href="https://github.blog/2023-10-04-introducing-secret-scanning-validity-checks-for-major-cloud-services/" target="_blank" rel="noreferrer noopener">https://github.blog/2023-10-04-introducing-secret-scanning-validity-checks-for-major-cloud-services/</a><br /> Prerooted Android Devices<br /><a href="https://arstechnica.com/security/2023/10/thousands-of-android-devices-come-with-unkillable-backdoor-preinstalled/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2023/10/thousands-of-android-devices-come-with-unkillable-backdoor-preinstalled/</a><br /> curl update<br /><a href="https://github.com/curl/curl/discussions/12026" target="_blank" rel="noreferrer noopener">https://github.com/curl/curl/discussions/12026</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8692.mp3</guid><pubDate>Mon, 09 Oct 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57158134/8692.mp3" length="5502897" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Binary IPv6 Address Conversion
https://isc.sans.edu/diary/Binary%20IPv6%20Addresses/30290
 Wireshark Updates
https://www.wireshark.org/

 Improved GitHub Secret Scanning...</itunes:subtitle><itunes:summary><![CDATA[Binary IPv6 Address Conversion<br /><a href="https://isc.sans.edu/diary/Binary%20IPv6%20Addresses/30290" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Binary%20IPv6%20Addresses/30290</a><br /> Wireshark Updates<br /><a href="https://www.wireshark.org/" target="_blank" rel="noreferrer noopener">https://www.wireshark.org/</a><br /><br /> Improved GitHub Secret Scanning<br /><a href="https://github.blog/2023-10-04-introducing-secret-scanning-validity-checks-for-major-cloud-services/" target="_blank" rel="noreferrer noopener">https://github.blog/2023-10-04-introducing-secret-scanning-validity-checks-for-major-cloud-services/</a><br /> Prerooted Android Devices<br /><a href="https://arstechnica.com/security/2023/10/thousands-of-android-devices-come-with-unkillable-backdoor-preinstalled/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2023/10/thousands-of-android-devices-come-with-unkillable-backdoor-preinstalled/</a><br /> curl update<br /><a href="https://github.com/curl/curl/discussions/12026" target="_blank" rel="noreferrer noopener">https://github.com/curl/curl/discussions/12026</a><br />]]></itunes:summary><itunes:duration>371</itunes:duration><itunes:keywords>business,computer,curl; android; github; secrets,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8692</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, October 6th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-october-6th-2023--57537722</link><description><![CDATA[New tool: le-hex-to-ip.py<br /><a href="https://isc.sans.edu/diary/New%20tool%3A%20le-hex-to-ip.py/30284" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/New%20tool%3A%20le-hex-to-ip.py/30284</a><br /> Cisco Emergency Responder Static Credentials Vulnerability<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cer-priv-esc-B9t3hqk9" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cer-priv-esc-B9t3hqk9</a><br /> Loony Tunables PoC CVE-2023-4911<br /><a href="https://haxx.in/files/gnu-acme.py" target="_blank" rel="noreferrer noopener">https://haxx.in/files/gnu-acme.py</a><br /> Malicious Python Packages<br /><a href="https://checkmarx.com/blog/the-evolutionary-tale-of-a-persistent-python-threat/" target="_blank" rel="noreferrer noopener">https://checkmarx.com/blog/the-evolutionary-tale-of-a-persistent-python-threat/</a><br /> Supermicro BMC Vulnerability<br /><a href="https://binarly.io/posts/Binarly_REsearch_Uncovers_Major_Vulnerabilities_in_Supermicro_BMCs/index.html" target="_blank" rel="noreferrer noopener">https://binarly.io/posts/Binarly_REsearch_Uncovers_Major_Vulnerabilities_in_Supermicro_BMCs/index.html</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8690.mp3</guid><pubDate>Fri, 06 Oct 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537722/8690.mp3" length="4827831" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>New tool: le-hex-to-ip.py
https://isc.sans.edu/diary/New%20tool%3A%20le-hex-to-ip.py/30284
 Cisco Emergency Responder Static Credentials Vulnerability...</itunes:subtitle><itunes:summary><![CDATA[New tool: le-hex-to-ip.py<br /><a href="https://isc.sans.edu/diary/New%20tool%3A%20le-hex-to-ip.py/30284" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/New%20tool%3A%20le-hex-to-ip.py/30284</a><br /> Cisco Emergency Responder Static Credentials Vulnerability<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cer-priv-esc-B9t3hqk9" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cer-priv-esc-B9t3hqk9</a><br /> Loony Tunables PoC CVE-2023-4911<br /><a href="https://haxx.in/files/gnu-acme.py" target="_blank" rel="noreferrer noopener">https://haxx.in/files/gnu-acme.py</a><br /> Malicious Python Packages<br /><a href="https://checkmarx.com/blog/the-evolutionary-tale-of-a-persistent-python-threat/" target="_blank" rel="noreferrer noopener">https://checkmarx.com/blog/the-evolutionary-tale-of-a-persistent-python-threat/</a><br /> Supermicro BMC Vulnerability<br /><a href="https://binarly.io/posts/Binarly_REsearch_Uncovers_Major_Vulnerabilities_in_Supermicro_BMCs/index.html" target="_blank" rel="noreferrer noopener">https://binarly.io/posts/Binarly_REsearch_Uncovers_Major_Vulnerabilities_in_Supermicro_BMCs/index.html</a><br />]]></itunes:summary><itunes:duration>323</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,supermicro; bmc; python; loony</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8690</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, October 6th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-october-6th-2023--57104016</link><description><![CDATA[New tool: le-hex-to-ip.py<br /><a href="https://isc.sans.edu/diary/New%20tool%3A%20le-hex-to-ip.py/30284" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/New%20tool%3A%20le-hex-to-ip.py/30284</a><br /> Cisco Emergency Responder Static Credentials Vulnerability<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cer-priv-esc-B9t3hqk9" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cer-priv-esc-B9t3hqk9</a><br /> Loony Tunables PoC CVE-2023-4911<br /><a href="https://haxx.in/files/gnu-acme.py" target="_blank" rel="noreferrer noopener">https://haxx.in/files/gnu-acme.py</a><br /> Malicious Python Packages<br /><a href="https://checkmarx.com/blog/the-evolutionary-tale-of-a-persistent-python-threat/" target="_blank" rel="noreferrer noopener">https://checkmarx.com/blog/the-evolutionary-tale-of-a-persistent-python-threat/</a><br /> Supermicro BMC Vulnerability<br /><a href="https://binarly.io/posts/Binarly_REsearch_Uncovers_Major_Vulnerabilities_in_Supermicro_BMCs/index.html" target="_blank" rel="noreferrer noopener">https://binarly.io/posts/Binarly_REsearch_Uncovers_Major_Vulnerabilities_in_Supermicro_BMCs/index.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8690.mp3</guid><pubDate>Fri, 06 Oct 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57104016/8690.mp3" length="4827831" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>New tool: le-hex-to-ip.py
https://isc.sans.edu/diary/New%20tool%3A%20le-hex-to-ip.py/30284
 Cisco Emergency Responder Static Credentials Vulnerability...</itunes:subtitle><itunes:summary><![CDATA[New tool: le-hex-to-ip.py<br /><a href="https://isc.sans.edu/diary/New%20tool%3A%20le-hex-to-ip.py/30284" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/New%20tool%3A%20le-hex-to-ip.py/30284</a><br /> Cisco Emergency Responder Static Credentials Vulnerability<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cer-priv-esc-B9t3hqk9" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cer-priv-esc-B9t3hqk9</a><br /> Loony Tunables PoC CVE-2023-4911<br /><a href="https://haxx.in/files/gnu-acme.py" target="_blank" rel="noreferrer noopener">https://haxx.in/files/gnu-acme.py</a><br /> Malicious Python Packages<br /><a href="https://checkmarx.com/blog/the-evolutionary-tale-of-a-persistent-python-threat/" target="_blank" rel="noreferrer noopener">https://checkmarx.com/blog/the-evolutionary-tale-of-a-persistent-python-threat/</a><br /> Supermicro BMC Vulnerability<br /><a href="https://binarly.io/posts/Binarly_REsearch_Uncovers_Major_Vulnerabilities_in_Supermicro_BMCs/index.html" target="_blank" rel="noreferrer noopener">https://binarly.io/posts/Binarly_REsearch_Uncovers_Major_Vulnerabilities_in_Supermicro_BMCs/index.html</a><br />]]></itunes:summary><itunes:duration>323</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,supermicro; bmc; python; loony</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8690</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, October 5th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-october-5th-2023--57537742</link><description><![CDATA[Normal Connections<br /><a href="https://isc.sans.edu/diary/Whats+Normal+Connection+Sizes/30278/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Whats+Normal+Connection+Sizes/30278/</a><br /> Apple Patches<br /><a href="https://isc.sans.edu/diary/Apple%20fixes%20vulnerabilities%20in%20iOS%20and%20iPadOS./30280" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20fixes%20vulnerabilities%20in%20iOS%20and%20iPadOS./30280</a><br /> Looney Tunables Linux Privilege Escalation<br /><a href="https://blog.qualys.com/vulnerabilities-threat-research/2023/10/03/cve-2023-4911-looney-tunables-local-privilege-escalation-in-the-glibcs-ld-so" target="_blank" rel="noreferrer noopener">https://blog.qualys.com/vulnerabilities-threat-research/2023/10/03/cve-2023-4911-looney-tunables-local-privilege-escalation-in-the-glibcs-ld-so</a><br /> Atlasian Confluence Server Vulnerability<br /><a href="https://jira.atlassian.com/browse/CONFSERVER-92475" target="_blank" rel="noreferrer noopener">https://jira.atlassian.com/browse/CONFSERVER-92475</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8688.mp3</guid><pubDate>Thu, 05 Oct 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537742/8688.mp3" length="4929144" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Normal Connections
https://isc.sans.edu/diary/Whats+Normal+Connection+Sizes/30278/
 Apple Patches
https://isc.sans.edu/diary/Apple%20fixes%20vulnerabilities%20in%20iOS%20and%20iPadOS./30280
 Looney Tunables Linux Privilege Escalation...</itunes:subtitle><itunes:summary><![CDATA[Normal Connections<br /><a href="https://isc.sans.edu/diary/Whats+Normal+Connection+Sizes/30278/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Whats+Normal+Connection+Sizes/30278/</a><br /> Apple Patches<br /><a href="https://isc.sans.edu/diary/Apple%20fixes%20vulnerabilities%20in%20iOS%20and%20iPadOS./30280" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20fixes%20vulnerabilities%20in%20iOS%20and%20iPadOS./30280</a><br /> Looney Tunables Linux Privilege Escalation<br /><a href="https://blog.qualys.com/vulnerabilities-threat-research/2023/10/03/cve-2023-4911-looney-tunables-local-privilege-escalation-in-the-glibcs-ld-so" target="_blank" rel="noreferrer noopener">https://blog.qualys.com/vulnerabilities-threat-research/2023/10/03/cve-2023-4911-looney-tunables-local-privilege-escalation-in-the-glibcs-ld-so</a><br /> Atlasian Confluence Server Vulnerability<br /><a href="https://jira.atlassian.com/browse/CONFSERVER-92475" target="_blank" rel="noreferrer noopener">https://jira.atlassian.com/browse/CONFSERVER-92475</a><br />]]></itunes:summary><itunes:duration>330</itunes:duration><itunes:keywords>atlasian; confluence; 0-day; l,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8688</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, October 5th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-october-5th-2023--57070280</link><description><![CDATA[Normal Connections<br /><a href="https://isc.sans.edu/diary/Whats+Normal+Connection+Sizes/30278/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Whats+Normal+Connection+Sizes/30278/</a><br /> Apple Patches<br /><a href="https://isc.sans.edu/diary/Apple%20fixes%20vulnerabilities%20in%20iOS%20and%20iPadOS./30280" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20fixes%20vulnerabilities%20in%20iOS%20and%20iPadOS./30280</a><br /> Looney Tunables Linux Privilege Escalation<br /><a href="https://blog.qualys.com/vulnerabilities-threat-research/2023/10/03/cve-2023-4911-looney-tunables-local-privilege-escalation-in-the-glibcs-ld-so" target="_blank" rel="noreferrer noopener">https://blog.qualys.com/vulnerabilities-threat-research/2023/10/03/cve-2023-4911-looney-tunables-local-privilege-escalation-in-the-glibcs-ld-so</a><br /> Atlasian Confluence Server Vulnerability<br /><a href="https://jira.atlassian.com/browse/CONFSERVER-92475" target="_blank" rel="noreferrer noopener">https://jira.atlassian.com/browse/CONFSERVER-92475</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8688.mp3</guid><pubDate>Thu, 05 Oct 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57070280/8688.mp3" length="4929144" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Normal Connections
https://isc.sans.edu/diary/Whats+Normal+Connection+Sizes/30278/
 Apple Patches
https://isc.sans.edu/diary/Apple%20fixes%20vulnerabilities%20in%20iOS%20and%20iPadOS./30280
 Looney Tunables Linux Privilege Escalation...</itunes:subtitle><itunes:summary><![CDATA[Normal Connections<br /><a href="https://isc.sans.edu/diary/Whats+Normal+Connection+Sizes/30278/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Whats+Normal+Connection+Sizes/30278/</a><br /> Apple Patches<br /><a href="https://isc.sans.edu/diary/Apple%20fixes%20vulnerabilities%20in%20iOS%20and%20iPadOS./30280" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20fixes%20vulnerabilities%20in%20iOS%20and%20iPadOS./30280</a><br /> Looney Tunables Linux Privilege Escalation<br /><a href="https://blog.qualys.com/vulnerabilities-threat-research/2023/10/03/cve-2023-4911-looney-tunables-local-privilege-escalation-in-the-glibcs-ld-so" target="_blank" rel="noreferrer noopener">https://blog.qualys.com/vulnerabilities-threat-research/2023/10/03/cve-2023-4911-looney-tunables-local-privilege-escalation-in-the-glibcs-ld-so</a><br /> Atlasian Confluence Server Vulnerability<br /><a href="https://jira.atlassian.com/browse/CONFSERVER-92475" target="_blank" rel="noreferrer noopener">https://jira.atlassian.com/browse/CONFSERVER-92475</a><br />]]></itunes:summary><itunes:duration>330</itunes:duration><itunes:keywords>atlasian; confluence; 0-day; l,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8688</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, October 4th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-october-4th-2023--57537732</link><description><![CDATA[Are Local LLMs Useful in Incident Response?<br /><a href="https://isc.sans.edu/diary/Are%20Local%20LLMs%20Useful%20in%20Incident%20Response%3F/30274" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Are%20Local%20LLMs%20Useful%20in%20Incident%20Response%3F/30274</a><br /> Pytorch Vulnerability<br /><a href="https://github.com/advisories/GHSA-4mqg-h5jf-j9m7" target="_blank" rel="noreferrer noopener">https://github.com/advisories/GHSA-4mqg-h5jf-j9m7</a><br /> BING Reads Captchas<br /><a href="https://twitter.com/literallydenis/status/1708283962399846459" target="_blank" rel="noreferrer noopener">https://twitter.com/literallydenis/status/1708283962399846459</a><br /> Evilproxy vs. Microsoft 365<br /><a href="https://www.menlosecurity.com/blog/evilproxy-phishing-attack-strikes-indeed/" target="_blank" rel="noreferrer noopener">https://www.menlosecurity.com/blog/evilproxy-phishing-attack-strikes-indeed/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8686.mp3</guid><pubDate>Wed, 04 Oct 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537732/8686.mp3" length="5019453" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Are Local LLMs Useful in Incident Response?
https://isc.sans.edu/diary/Are%20Local%20LLMs%20Useful%20in%20Incident%20Response%3F/30274
 Pytorch Vulnerability
https://github.com/advisories/GHSA-4mqg-h5jf-j9m7
 BING Reads Captchas...</itunes:subtitle><itunes:summary><![CDATA[Are Local LLMs Useful in Incident Response?<br /><a href="https://isc.sans.edu/diary/Are%20Local%20LLMs%20Useful%20in%20Incident%20Response%3F/30274" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Are%20Local%20LLMs%20Useful%20in%20Incident%20Response%3F/30274</a><br /> Pytorch Vulnerability<br /><a href="https://github.com/advisories/GHSA-4mqg-h5jf-j9m7" target="_blank" rel="noreferrer noopener">https://github.com/advisories/GHSA-4mqg-h5jf-j9m7</a><br /> BING Reads Captchas<br /><a href="https://twitter.com/literallydenis/status/1708283962399846459" target="_blank" rel="noreferrer noopener">https://twitter.com/literallydenis/status/1708283962399846459</a><br /> Evilproxy vs. Microsoft 365<br /><a href="https://www.menlosecurity.com/blog/evilproxy-phishing-attack-strikes-indeed/" target="_blank" rel="noreferrer noopener">https://www.menlosecurity.com/blog/evilproxy-phishing-attack-strikes-indeed/</a><br />]]></itunes:summary><itunes:duration>337</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,evilproxy; microsoft; indeed; ,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8686</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, October 4th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-october-4th-2023--57052551</link><description><![CDATA[Are Local LLMs Useful in Incident Response?<br /><a href="https://isc.sans.edu/diary/Are%20Local%20LLMs%20Useful%20in%20Incident%20Response%3F/30274" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Are%20Local%20LLMs%20Useful%20in%20Incident%20Response%3F/30274</a><br /> Pytorch Vulnerability<br /><a href="https://github.com/advisories/GHSA-4mqg-h5jf-j9m7" target="_blank" rel="noreferrer noopener">https://github.com/advisories/GHSA-4mqg-h5jf-j9m7</a><br /> BING Reads Captchas<br /><a href="https://twitter.com/literallydenis/status/1708283962399846459" target="_blank" rel="noreferrer noopener">https://twitter.com/literallydenis/status/1708283962399846459</a><br /> Evilproxy vs. Microsoft 365<br /><a href="https://www.menlosecurity.com/blog/evilproxy-phishing-attack-strikes-indeed/" target="_blank" rel="noreferrer noopener">https://www.menlosecurity.com/blog/evilproxy-phishing-attack-strikes-indeed/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8686.mp3</guid><pubDate>Wed, 04 Oct 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57052551/8686.mp3" length="5019453" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Are Local LLMs Useful in Incident Response?
https://isc.sans.edu/diary/Are%20Local%20LLMs%20Useful%20in%20Incident%20Response%3F/30274
 Pytorch Vulnerability
https://github.com/advisories/GHSA-4mqg-h5jf-j9m7
 BING Reads Captchas...</itunes:subtitle><itunes:summary><![CDATA[Are Local LLMs Useful in Incident Response?<br /><a href="https://isc.sans.edu/diary/Are%20Local%20LLMs%20Useful%20in%20Incident%20Response%3F/30274" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Are%20Local%20LLMs%20Useful%20in%20Incident%20Response%3F/30274</a><br /> Pytorch Vulnerability<br /><a href="https://github.com/advisories/GHSA-4mqg-h5jf-j9m7" target="_blank" rel="noreferrer noopener">https://github.com/advisories/GHSA-4mqg-h5jf-j9m7</a><br /> BING Reads Captchas<br /><a href="https://twitter.com/literallydenis/status/1708283962399846459" target="_blank" rel="noreferrer noopener">https://twitter.com/literallydenis/status/1708283962399846459</a><br /> Evilproxy vs. Microsoft 365<br /><a href="https://www.menlosecurity.com/blog/evilproxy-phishing-attack-strikes-indeed/" target="_blank" rel="noreferrer noopener">https://www.menlosecurity.com/blog/evilproxy-phishing-attack-strikes-indeed/</a><br />]]></itunes:summary><itunes:duration>337</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,evilproxy; microsoft; indeed; ,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8686</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, October 3rd, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-october-3rd-2023--57537735</link><description><![CDATA[Friendly Reminder: ZIP Metadata is Not Encrypted<br /><a href="https://isc.sans.edu/diary/Friendly%20Reminder%3A%20ZIP%20Metadata%20is%20Not%20Encrypted/30268" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Friendly%20Reminder%3A%20ZIP%20Metadata%20is%20Not%20Encrypted/30268</a><br /> EXIM New Version Released<br /><a href="https://www.exim.org/static/doc/security/CVE-2023-zdi.txt" target="_blank" rel="noreferrer noopener">https://www.exim.org/static/doc/security/CVE-2023-zdi.txt</a><br /> Mail GPU Kernel Driver Allows Improper GPU Memory Processing Operations<br /><a href="https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities" target="_blank" rel="noreferrer noopener">https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities</a><br /> Bing AI Serves Malicous Ads<br /><a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/09/malicious-ad-served-inside-bing-ai-chatbot" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/threat-intelligence/2023/09/malicious-ad-served-inside-bing-ai-chatbot</a><br /> Google Announces Robots.txt Ad-Restrictions<br /><a href="https://developers.google.com/search/docs/crawling-indexing/overview-google-crawlers#adsbot-mobile-web-android" target="_blank" rel="noreferrer noopener">https://developers.google.com/search/docs/crawling-indexing/overview-google-crawlers#adsbot-mobile-web-android</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8684.mp3</guid><pubDate>Tue, 03 Oct 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537735/8684.mp3" length="5081429" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Friendly Reminder: ZIP Metadata is Not Encrypted
https://isc.sans.edu/diary/Friendly%20Reminder%3A%20ZIP%20Metadata%20is%20Not%20Encrypted/30268
 EXIM New Version Released
https://www.exim.org/static/doc/security/CVE-2023-zdi.txt
 Mail GPU Kernel...</itunes:subtitle><itunes:summary><![CDATA[Friendly Reminder: ZIP Metadata is Not Encrypted<br /><a href="https://isc.sans.edu/diary/Friendly%20Reminder%3A%20ZIP%20Metadata%20is%20Not%20Encrypted/30268" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Friendly%20Reminder%3A%20ZIP%20Metadata%20is%20Not%20Encrypted/30268</a><br /> EXIM New Version Released<br /><a href="https://www.exim.org/static/doc/security/CVE-2023-zdi.txt" target="_blank" rel="noreferrer noopener">https://www.exim.org/static/doc/security/CVE-2023-zdi.txt</a><br /> Mail GPU Kernel Driver Allows Improper GPU Memory Processing Operations<br /><a href="https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities" target="_blank" rel="noreferrer noopener">https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities</a><br /> Bing AI Serves Malicous Ads<br /><a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/09/malicious-ad-served-inside-bing-ai-chatbot" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/threat-intelligence/2023/09/malicious-ad-served-inside-bing-ai-chatbot</a><br /> Google Announces Robots.txt Ad-Restrictions<br /><a href="https://developers.google.com/search/docs/crawling-indexing/overview-google-crawlers#adsbot-mobile-web-android" target="_blank" rel="noreferrer noopener">https://developers.google.com/search/docs/crawling-indexing/overview-google-crawlers#adsbot-mobile-web-android</a><br />]]></itunes:summary><itunes:duration>341</itunes:duration><itunes:keywords>arm; gpu; mali; exim; bing; go,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8684</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, October 3rd, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-october-3rd-2023--57037248</link><description><![CDATA[Friendly Reminder: ZIP Metadata is Not Encrypted<br /><a href="https://isc.sans.edu/diary/Friendly%20Reminder%3A%20ZIP%20Metadata%20is%20Not%20Encrypted/30268" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Friendly%20Reminder%3A%20ZIP%20Metadata%20is%20Not%20Encrypted/30268</a><br /> EXIM New Version Released<br /><a href="https://www.exim.org/static/doc/security/CVE-2023-zdi.txt" target="_blank" rel="noreferrer noopener">https://www.exim.org/static/doc/security/CVE-2023-zdi.txt</a><br /> Mail GPU Kernel Driver Allows Improper GPU Memory Processing Operations<br /><a href="https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities" target="_blank" rel="noreferrer noopener">https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities</a><br /> Bing AI Serves Malicous Ads<br /><a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/09/malicious-ad-served-inside-bing-ai-chatbot" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/threat-intelligence/2023/09/malicious-ad-served-inside-bing-ai-chatbot</a><br /> Google Announces Robots.txt Ad-Restrictions<br /><a href="https://developers.google.com/search/docs/crawling-indexing/overview-google-crawlers#adsbot-mobile-web-android" target="_blank" rel="noreferrer noopener">https://developers.google.com/search/docs/crawling-indexing/overview-google-crawlers#adsbot-mobile-web-android</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8684.mp3</guid><pubDate>Tue, 03 Oct 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57037248/8684.mp3" length="5081429" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Friendly Reminder: ZIP Metadata is Not Encrypted
https://isc.sans.edu/diary/Friendly%20Reminder%3A%20ZIP%20Metadata%20is%20Not%20Encrypted/30268
 EXIM New Version Released
https://www.exim.org/static/doc/security/CVE-2023-zdi.txt
 Mail GPU Kernel...</itunes:subtitle><itunes:summary><![CDATA[Friendly Reminder: ZIP Metadata is Not Encrypted<br /><a href="https://isc.sans.edu/diary/Friendly%20Reminder%3A%20ZIP%20Metadata%20is%20Not%20Encrypted/30268" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Friendly%20Reminder%3A%20ZIP%20Metadata%20is%20Not%20Encrypted/30268</a><br /> EXIM New Version Released<br /><a href="https://www.exim.org/static/doc/security/CVE-2023-zdi.txt" target="_blank" rel="noreferrer noopener">https://www.exim.org/static/doc/security/CVE-2023-zdi.txt</a><br /> Mail GPU Kernel Driver Allows Improper GPU Memory Processing Operations<br /><a href="https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities" target="_blank" rel="noreferrer noopener">https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities</a><br /> Bing AI Serves Malicous Ads<br /><a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/09/malicious-ad-served-inside-bing-ai-chatbot" target="_blank" rel="noreferrer noopener">https://www.malwarebytes.com/blog/threat-intelligence/2023/09/malicious-ad-served-inside-bing-ai-chatbot</a><br /> Google Announces Robots.txt Ad-Restrictions<br /><a href="https://developers.google.com/search/docs/crawling-indexing/overview-google-crawlers#adsbot-mobile-web-android" target="_blank" rel="noreferrer noopener">https://developers.google.com/search/docs/crawling-indexing/overview-google-crawlers#adsbot-mobile-web-android</a><br />]]></itunes:summary><itunes:duration>341</itunes:duration><itunes:keywords>arm; gpu; mali; exim; bing; go,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8684</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, October 2nd, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-october-2nd-2023--57537744</link><description><![CDATA[Analyzing MIME Files: a Quick Tip<br /><a href="https://isc.sans.edu/diary/Analyzing%20MIME%20Files%3A%20a%20Quick%20Tip/30266" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analyzing%20MIME%20Files%3A%20a%20Quick%20Tip/30266</a><br /> Infostealers Looking for Password Files<br /><a href="https://isc.sans.edu/diary/Are+You+Still+Storing+Passwords+In+Plain+Text+Files/30262/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Are+You+Still+Storing+Passwords+In+Plain+Text+Files/30262/</a><br /> Simple Netcat Backdoor<br /><a href="https://isc.sans.edu/diary/Simple+Netcat+Backdoor+in+Python+Script/30264/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Simple+Netcat+Backdoor+in+Python+Script/30264/</a><br /> EXIM Response to the ZDI Release<br /><a href="https://exim.org/static/doc/security/CVE-2023-zdi.txt" target="_blank" rel="noreferrer noopener">https://exim.org/static/doc/security/CVE-2023-zdi.txt</a><br /> Exploit for WS_FTP Vulnerability<br /><a href="https://www.assetnote.io/resources/research/rce-in-progress-ws-ftp-ad-hoc-via-iis-http-modules-cve-2023-40044" target="_blank" rel="noreferrer noopener">https://www.assetnote.io/resources/research/rce-in-progress-ws-ftp-ad-hoc-via-iis-http-modules-cve-2023-40044</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8682.mp3</guid><pubDate>Mon, 02 Oct 2023 10:10:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537744/8682.mp3" length="4636470" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Analyzing MIME Files: a Quick Tip
https://isc.sans.edu/diary/Analyzing%20MIME%20Files%3A%20a%20Quick%20Tip/30266
 Infostealers Looking for Password Files
https://isc.sans.edu/diary/Are+You+Still+Storing+Passwords+In+Plain+Text+Files/30262/
 Simple...</itunes:subtitle><itunes:summary><![CDATA[Analyzing MIME Files: a Quick Tip<br /><a href="https://isc.sans.edu/diary/Analyzing%20MIME%20Files%3A%20a%20Quick%20Tip/30266" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analyzing%20MIME%20Files%3A%20a%20Quick%20Tip/30266</a><br /> Infostealers Looking for Password Files<br /><a href="https://isc.sans.edu/diary/Are+You+Still+Storing+Passwords+In+Plain+Text+Files/30262/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Are+You+Still+Storing+Passwords+In+Plain+Text+Files/30262/</a><br /> Simple Netcat Backdoor<br /><a href="https://isc.sans.edu/diary/Simple+Netcat+Backdoor+in+Python+Script/30264/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Simple+Netcat+Backdoor+in+Python+Script/30264/</a><br /> EXIM Response to the ZDI Release<br /><a href="https://exim.org/static/doc/security/CVE-2023-zdi.txt" target="_blank" rel="noreferrer noopener">https://exim.org/static/doc/security/CVE-2023-zdi.txt</a><br /> Exploit for WS_FTP Vulnerability<br /><a href="https://www.assetnote.io/resources/research/rce-in-progress-ws-ftp-ad-hoc-via-iis-http-modules-cve-2023-40044" target="_blank" rel="noreferrer noopener">https://www.assetnote.io/resources/research/rce-in-progress-ws-ftp-ad-hoc-via-iis-http-modules-cve-2023-40044</a><br />]]></itunes:summary><itunes:duration>310</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,ws_ftp; exploit; exim; vulnera</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8682</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, October 2nd, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-october-2nd-2023--57025889</link><description><![CDATA[Analyzing MIME Files: a Quick Tip<br /><a href="https://isc.sans.edu/diary/Analyzing%20MIME%20Files%3A%20a%20Quick%20Tip/30266" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analyzing%20MIME%20Files%3A%20a%20Quick%20Tip/30266</a><br /> Infostealers Looking for Password Files<br /><a href="https://isc.sans.edu/diary/Are+You+Still+Storing+Passwords+In+Plain+Text+Files/30262/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Are+You+Still+Storing+Passwords+In+Plain+Text+Files/30262/</a><br /> Simple Netcat Backdoor<br /><a href="https://isc.sans.edu/diary/Simple+Netcat+Backdoor+in+Python+Script/30264/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Simple+Netcat+Backdoor+in+Python+Script/30264/</a><br /> EXIM Response to the ZDI Release<br /><a href="https://exim.org/static/doc/security/CVE-2023-zdi.txt" target="_blank" rel="noreferrer noopener">https://exim.org/static/doc/security/CVE-2023-zdi.txt</a><br /> Exploit for WS_FTP Vulnerability<br /><a href="https://www.assetnote.io/resources/research/rce-in-progress-ws-ftp-ad-hoc-via-iis-http-modules-cve-2023-40044" target="_blank" rel="noreferrer noopener">https://www.assetnote.io/resources/research/rce-in-progress-ws-ftp-ad-hoc-via-iis-http-modules-cve-2023-40044</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8682.mp3</guid><pubDate>Mon, 02 Oct 2023 10:10:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57025889/8682.mp3" length="4636470" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Analyzing MIME Files: a Quick Tip
https://isc.sans.edu/diary/Analyzing%20MIME%20Files%3A%20a%20Quick%20Tip/30266
 Infostealers Looking for Password Files
https://isc.sans.edu/diary/Are+You+Still+Storing+Passwords+In+Plain+Text+Files/30262/
 Simple...</itunes:subtitle><itunes:summary><![CDATA[Analyzing MIME Files: a Quick Tip<br /><a href="https://isc.sans.edu/diary/Analyzing%20MIME%20Files%3A%20a%20Quick%20Tip/30266" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analyzing%20MIME%20Files%3A%20a%20Quick%20Tip/30266</a><br /> Infostealers Looking for Password Files<br /><a href="https://isc.sans.edu/diary/Are+You+Still+Storing+Passwords+In+Plain+Text+Files/30262/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Are+You+Still+Storing+Passwords+In+Plain+Text+Files/30262/</a><br /> Simple Netcat Backdoor<br /><a href="https://isc.sans.edu/diary/Simple+Netcat+Backdoor+in+Python+Script/30264/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Simple+Netcat+Backdoor+in+Python+Script/30264/</a><br /> EXIM Response to the ZDI Release<br /><a href="https://exim.org/static/doc/security/CVE-2023-zdi.txt" target="_blank" rel="noreferrer noopener">https://exim.org/static/doc/security/CVE-2023-zdi.txt</a><br /> Exploit for WS_FTP Vulnerability<br /><a href="https://www.assetnote.io/resources/research/rce-in-progress-ws-ftp-ad-hoc-via-iis-http-modules-cve-2023-40044" target="_blank" rel="noreferrer noopener">https://www.assetnote.io/resources/research/rce-in-progress-ws-ftp-ad-hoc-via-iis-http-modules-cve-2023-40044</a><br />]]></itunes:summary><itunes:duration>310</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,ws_ftp; exploit; exim; vulnera</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8682</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, September 29th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-september-29th-2023--57537725</link><description><![CDATA[IPv4 Addresses in Little Endian Decimal Format<br /><a href="https://isc.sans.edu/diary/IPv4%20Addresses%20in%20Little%20Endian%20Decimal%20Format/30256" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/IPv4%20Addresses%20in%20Little%20Endian%20Decimal%20Format/30256</a><br /> Chrome Update fixes 0-day Vulnerability<br /><a href="https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html</a><br /> Unpatched EXIM Vulnerabilities<br /><a href="https://www.zerodayinitiative.com/advisories/ZDI-23-1469/" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/advisories/ZDI-23-1469/</a><br /> WS_FTP Vulnerabilities<br /><a href="https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023" target="_blank" rel="noreferrer noopener">https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8680.mp3</guid><pubDate>Fri, 29 Sep 2023 02:15:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537725/8680.mp3" length="4316690" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>IPv4 Addresses in Little Endian Decimal Format
https://isc.sans.edu/diary/IPv4%20Addresses%20in%20Little%20Endian%20Decimal%20Format/30256
 Chrome Update fixes 0-day Vulnerability...</itunes:subtitle><itunes:summary><![CDATA[IPv4 Addresses in Little Endian Decimal Format<br /><a href="https://isc.sans.edu/diary/IPv4%20Addresses%20in%20Little%20Endian%20Decimal%20Format/30256" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/IPv4%20Addresses%20in%20Little%20Endian%20Decimal%20Format/30256</a><br /> Chrome Update fixes 0-day Vulnerability<br /><a href="https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html</a><br /> Unpatched EXIM Vulnerabilities<br /><a href="https://www.zerodayinitiative.com/advisories/ZDI-23-1469/" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/advisories/ZDI-23-1469/</a><br /> WS_FTP Vulnerabilities<br /><a href="https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023" target="_blank" rel="noreferrer noopener">https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023</a><br />]]></itunes:summary><itunes:duration>287</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,ws-ftp; exim; chrome; 0-day; i</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8680</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, September 29th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-september-29th-2023--56985054</link><description><![CDATA[IPv4 Addresses in Little Endian Decimal Format<br /><a href="https://isc.sans.edu/diary/IPv4%20Addresses%20in%20Little%20Endian%20Decimal%20Format/30256" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/IPv4%20Addresses%20in%20Little%20Endian%20Decimal%20Format/30256</a><br /> Chrome Update fixes 0-day Vulnerability<br /><a href="https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html</a><br /> Unpatched EXIM Vulnerabilities<br /><a href="https://www.zerodayinitiative.com/advisories/ZDI-23-1469/" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/advisories/ZDI-23-1469/</a><br /> WS_FTP Vulnerabilities<br /><a href="https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023" target="_blank" rel="noreferrer noopener">https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8680.mp3</guid><pubDate>Fri, 29 Sep 2023 02:15:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56985054/8680.mp3" length="4316690" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>IPv4 Addresses in Little Endian Decimal Format
https://isc.sans.edu/diary/IPv4%20Addresses%20in%20Little%20Endian%20Decimal%20Format/30256
 Chrome Update fixes 0-day Vulnerability...</itunes:subtitle><itunes:summary><![CDATA[IPv4 Addresses in Little Endian Decimal Format<br /><a href="https://isc.sans.edu/diary/IPv4%20Addresses%20in%20Little%20Endian%20Decimal%20Format/30256" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/IPv4%20Addresses%20in%20Little%20Endian%20Decimal%20Format/30256</a><br /> Chrome Update fixes 0-day Vulnerability<br /><a href="https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html</a><br /> Unpatched EXIM Vulnerabilities<br /><a href="https://www.zerodayinitiative.com/advisories/ZDI-23-1469/" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/advisories/ZDI-23-1469/</a><br /> WS_FTP Vulnerabilities<br /><a href="https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023" target="_blank" rel="noreferrer noopener">https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023</a><br />]]></itunes:summary><itunes:duration>287</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,ws-ftp; exim; chrome; 0-day; i</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8680</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, September 28th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-september-28th-2023--57537745</link><description><![CDATA[GPU Sidechannel Attack<br /><a href="https://www.hertzbleed.com/gpu.zip/GPU-zip.pdf" target="_blank" rel="noreferrer noopener">https://www.hertzbleed.com/gpu.zip/GPU-zip.pdf</a><br /> Router Firmware Compromised for Persistent Access<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csa-cyber-report-sept-2023" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csa-cyber-report-sept-2023</a><br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-270a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-270a</a><br /> More libwebp vulnerability confusion<br /><a href="https://www.cve.org/CVERecord?id=CVE-2023-5129" target="_blank" rel="noreferrer noopener">https://www.cve.org/CVERecord?id=CVE-2023-5129</a><br /><a href="https://arstechnica.com/security/2023/09/google-quietly-corrects-previously-submitted-disclosure-for-critical-webp-0-day/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2023/09/google-quietly-corrects-previously-submitted-disclosure-for-critical-webp-0-day/</a><br /> Fake Dependabot Commits<br /><a href="https://checkmarx.com/blog/surprise-when-dependabot-contributes-malicious-code/" target="_blank" rel="noreferrer noopener">https://checkmarx.com/blog/surprise-when-dependabot-contributes-malicious-code/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8678.mp3</guid><pubDate>Thu, 28 Sep 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537745/8678.mp3" length="6139093" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>GPU Sidechannel Attack
https://www.hertzbleed.com/gpu.zip/GPU-zip.pdf
 Router Firmware Compromised for Persistent Access
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csa-cyber-report-sept-2023...</itunes:subtitle><itunes:summary><![CDATA[GPU Sidechannel Attack<br /><a href="https://www.hertzbleed.com/gpu.zip/GPU-zip.pdf" target="_blank" rel="noreferrer noopener">https://www.hertzbleed.com/gpu.zip/GPU-zip.pdf</a><br /> Router Firmware Compromised for Persistent Access<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csa-cyber-report-sept-2023" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csa-cyber-report-sept-2023</a><br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-270a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-270a</a><br /> More libwebp vulnerability confusion<br /><a href="https://www.cve.org/CVERecord?id=CVE-2023-5129" target="_blank" rel="noreferrer noopener">https://www.cve.org/CVERecord?id=CVE-2023-5129</a><br /><a href="https://arstechnica.com/security/2023/09/google-quietly-corrects-previously-submitted-disclosure-for-critical-webp-0-day/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2023/09/google-quietly-corrects-previously-submitted-disclosure-for-critical-webp-0-day/</a><br /> Fake Dependabot Commits<br /><a href="https://checkmarx.com/blog/surprise-when-dependabot-contributes-malicious-code/" target="_blank" rel="noreferrer noopener">https://checkmarx.com/blog/surprise-when-dependabot-contributes-malicious-code/</a><br />]]></itunes:summary><itunes:duration>417</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dependabot; libwebp; router; p,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8678</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, September 28th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-september-28th-2023--56968091</link><description><![CDATA[GPU Sidechannel Attack<br /><a href="https://www.hertzbleed.com/gpu.zip/GPU-zip.pdf" target="_blank" rel="noreferrer noopener">https://www.hertzbleed.com/gpu.zip/GPU-zip.pdf</a><br /> Router Firmware Compromised for Persistent Access<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csa-cyber-report-sept-2023" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csa-cyber-report-sept-2023</a><br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-270a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-270a</a><br /> More libwebp vulnerability confusion<br /><a href="https://www.cve.org/CVERecord?id=CVE-2023-5129" target="_blank" rel="noreferrer noopener">https://www.cve.org/CVERecord?id=CVE-2023-5129</a><br /><a href="https://arstechnica.com/security/2023/09/google-quietly-corrects-previously-submitted-disclosure-for-critical-webp-0-day/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2023/09/google-quietly-corrects-previously-submitted-disclosure-for-critical-webp-0-day/</a><br /> Fake Dependabot Commits<br /><a href="https://checkmarx.com/blog/surprise-when-dependabot-contributes-malicious-code/" target="_blank" rel="noreferrer noopener">https://checkmarx.com/blog/surprise-when-dependabot-contributes-malicious-code/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8678.mp3</guid><pubDate>Thu, 28 Sep 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56968091/8678.mp3" length="6139093" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>GPU Sidechannel Attack
https://www.hertzbleed.com/gpu.zip/GPU-zip.pdf
 Router Firmware Compromised for Persistent Access
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csa-cyber-report-sept-2023...</itunes:subtitle><itunes:summary><![CDATA[GPU Sidechannel Attack<br /><a href="https://www.hertzbleed.com/gpu.zip/GPU-zip.pdf" target="_blank" rel="noreferrer noopener">https://www.hertzbleed.com/gpu.zip/GPU-zip.pdf</a><br /> Router Firmware Compromised for Persistent Access<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csa-cyber-report-sept-2023" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csa-cyber-report-sept-2023</a><br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-270a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-270a</a><br /> More libwebp vulnerability confusion<br /><a href="https://www.cve.org/CVERecord?id=CVE-2023-5129" target="_blank" rel="noreferrer noopener">https://www.cve.org/CVERecord?id=CVE-2023-5129</a><br /><a href="https://arstechnica.com/security/2023/09/google-quietly-corrects-previously-submitted-disclosure-for-critical-webp-0-day/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2023/09/google-quietly-corrects-previously-submitted-disclosure-for-critical-webp-0-day/</a><br /> Fake Dependabot Commits<br /><a href="https://checkmarx.com/blog/surprise-when-dependabot-contributes-malicious-code/" target="_blank" rel="noreferrer noopener">https://checkmarx.com/blog/surprise-when-dependabot-contributes-malicious-code/</a><br />]]></itunes:summary><itunes:duration>417</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dependabot; libwebp; router; p,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8678</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, September 27th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-september-27th-2023--57537734</link><description><![CDATA[A new spint on the ZeroFont phishing technique<br /><a href="https://isc.sans.edu/diary/A%20new%20spin%20on%20the%20ZeroFont%20phishing%20technique/30248" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20new%20spin%20on%20the%20ZeroFont%20phishing%20technique/30248</a><br /> macOS Sonoma Updates<br /><a href="https://isc.sans.edu/diary/Apple%20Releases%20MacOS%20Sonoma%20Including%20Numerous%20Security%20Patches/30252" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Releases%20MacOS%20Sonoma%20Including%20Numerous%20Security%20Patches/30252</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8676.mp3</guid><pubDate>Wed, 27 Sep 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537734/8676.mp3" length="5785210" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>A new spint on the ZeroFont phishing technique
https://isc.sans.edu/diary/A%20new%20spin%20on%20the%20ZeroFont%20phishing%20technique/30248
 macOS Sonoma Updates...</itunes:subtitle><itunes:summary><![CDATA[A new spint on the ZeroFont phishing technique<br /><a href="https://isc.sans.edu/diary/A%20new%20spin%20on%20the%20ZeroFont%20phishing%20technique/30248" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20new%20spin%20on%20the%20ZeroFont%20phishing%20technique/30248</a><br /> macOS Sonoma Updates<br /><a href="https://isc.sans.edu/diary/Apple%20Releases%20MacOS%20Sonoma%20Including%20Numerous%20Security%20Patches/30252" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Releases%20MacOS%20Sonoma%20Including%20Numerous%20Security%20Patches/30252</a><br />]]></itunes:summary><itunes:duration>392</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,macos; sonoma; zerofont; phish,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8676</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, September 27th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-september-27th-2023--56950690</link><description><![CDATA[A new spint on the ZeroFont phishing technique<br /><a href="https://isc.sans.edu/diary/A%20new%20spin%20on%20the%20ZeroFont%20phishing%20technique/30248" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20new%20spin%20on%20the%20ZeroFont%20phishing%20technique/30248</a><br /> macOS Sonoma Updates<br /><a href="https://isc.sans.edu/diary/Apple%20Releases%20MacOS%20Sonoma%20Including%20Numerous%20Security%20Patches/30252" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Releases%20MacOS%20Sonoma%20Including%20Numerous%20Security%20Patches/30252</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8676.mp3</guid><pubDate>Wed, 27 Sep 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56950690/8676.mp3" length="5785210" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>A new spint on the ZeroFont phishing technique
https://isc.sans.edu/diary/A%20new%20spin%20on%20the%20ZeroFont%20phishing%20technique/30248
 macOS Sonoma Updates...</itunes:subtitle><itunes:summary><![CDATA[A new spint on the ZeroFont phishing technique<br /><a href="https://isc.sans.edu/diary/A%20new%20spin%20on%20the%20ZeroFont%20phishing%20technique/30248" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/A%20new%20spin%20on%20the%20ZeroFont%20phishing%20technique/30248</a><br /> macOS Sonoma Updates<br /><a href="https://isc.sans.edu/diary/Apple%20Releases%20MacOS%20Sonoma%20Including%20Numerous%20Security%20Patches/30252" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20Releases%20MacOS%20Sonoma%20Including%20Numerous%20Security%20Patches/30252</a><br />]]></itunes:summary><itunes:duration>392</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,macos; sonoma; zerofont; phish,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8676</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, September 26th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-september-26th-2023--57537749</link><description><![CDATA[LuaJIT Malware<br /><a href="https://www.sentinelone.com/labs/sandman-apt-a-mystery-group-targeting-telcos-with-a-luajit-toolkit/" target="_blank" rel="noreferrer noopener">https://www.sentinelone.com/labs/sandman-apt-a-mystery-group-targeting-telcos-with-a-luajit-toolkit/</a><br /> NPM systeminformation flaw<br /><a href="https://systeminformation.io/security.html" target="_blank" rel="noreferrer noopener">https://systeminformation.io/security.html</a><br /> Team City Authentication Bypass<br /><a href="https://twitter.com/ptswarm/status/1706223917008834748" target="_blank" rel="noreferrer noopener">https://twitter.com/ptswarm/status/1706223917008834748</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8674.mp3</guid><pubDate>Tue, 26 Sep 2023 12:10:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537749/8674.mp3" length="4597208" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>LuaJIT Malware
https://www.sentinelone.com/labs/sandman-apt-a-mystery-group-targeting-telcos-with-a-luajit-toolkit/
 NPM systeminformation flaw
https://systeminformation.io/security.html
 Team City Authentication Bypass...</itunes:subtitle><itunes:summary><![CDATA[LuaJIT Malware<br /><a href="https://www.sentinelone.com/labs/sandman-apt-a-mystery-group-targeting-telcos-with-a-luajit-toolkit/" target="_blank" rel="noreferrer noopener">https://www.sentinelone.com/labs/sandman-apt-a-mystery-group-targeting-telcos-with-a-luajit-toolkit/</a><br /> NPM systeminformation flaw<br /><a href="https://systeminformation.io/security.html" target="_blank" rel="noreferrer noopener">https://systeminformation.io/security.html</a><br /> Team City Authentication Bypass<br /><a href="https://twitter.com/ptswarm/status/1706223917008834748" target="_blank" rel="noreferrer noopener">https://twitter.com/ptswarm/status/1706223917008834748</a><br />]]></itunes:summary><itunes:duration>307</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,team city; jetbrains; npm; sys</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8674</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, September 26th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-september-26th-2023--56941312</link><description><![CDATA[LuaJIT Malware<br /><a href="https://www.sentinelone.com/labs/sandman-apt-a-mystery-group-targeting-telcos-with-a-luajit-toolkit/" target="_blank" rel="noreferrer noopener">https://www.sentinelone.com/labs/sandman-apt-a-mystery-group-targeting-telcos-with-a-luajit-toolkit/</a><br /> NPM systeminformation flaw<br /><a href="https://systeminformation.io/security.html" target="_blank" rel="noreferrer noopener">https://systeminformation.io/security.html</a><br /> Team City Authentication Bypass<br /><a href="https://twitter.com/ptswarm/status/1706223917008834748" target="_blank" rel="noreferrer noopener">https://twitter.com/ptswarm/status/1706223917008834748</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8674.mp3</guid><pubDate>Tue, 26 Sep 2023 12:10:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56941312/8674.mp3" length="4597208" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>LuaJIT Malware
https://www.sentinelone.com/labs/sandman-apt-a-mystery-group-targeting-telcos-with-a-luajit-toolkit/
 NPM systeminformation flaw
https://systeminformation.io/security.html
 Team City Authentication Bypass...</itunes:subtitle><itunes:summary><![CDATA[LuaJIT Malware<br /><a href="https://www.sentinelone.com/labs/sandman-apt-a-mystery-group-targeting-telcos-with-a-luajit-toolkit/" target="_blank" rel="noreferrer noopener">https://www.sentinelone.com/labs/sandman-apt-a-mystery-group-targeting-telcos-with-a-luajit-toolkit/</a><br /> NPM systeminformation flaw<br /><a href="https://systeminformation.io/security.html" target="_blank" rel="noreferrer noopener">https://systeminformation.io/security.html</a><br /> Team City Authentication Bypass<br /><a href="https://twitter.com/ptswarm/status/1706223917008834748" target="_blank" rel="noreferrer noopener">https://twitter.com/ptswarm/status/1706223917008834748</a><br />]]></itunes:summary><itunes:duration>307</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,team city; jetbrains; npm; sys</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8674</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, September 25th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-september-25th-2023--57537715</link><description><![CDATA[Scanning for Laravel - a PHP Framework for Web Artisants<br /><a href="https://isc.sans.edu/forums/diary/Scanning%20for%20Laravel%20-%20a%20PHP%20Framework%20for%20Web%20Artisants/30242/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Scanning%20for%20Laravel%20-%20a%20PHP%20Framework%20for%20Web%20Artisants/30242/</a><br /> Fake CVE-2023-40477 Proof of Concept Leads to VenomRAT<br /><a href="https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/</a><br /> Unmasking a Sophistiacted Phishing Campaign That Targets Hotel Guests<br /><a href="https://www.akamai.com/blog/security-research/sophisticated-phishing-campaign-targeting-hospitality" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/sophisticated-phishing-campaign-targeting-hospitality</a><br /> BSides JAX October 14th<br /><a href="https://www.bsidesjax.org/" target="_blank" rel="noreferrer noopener">https://www.bsidesjax.org/</a><br />  tickets: <a href="https://www.eventbrite.com/e/bsides-jacksonville-2023-registration-566463807497?aff=oddtdtcreator" target="_blank" rel="noreferrer noopener">https://www.eventbrite.com/e/bsides-jacksonville-2023-registration-566463807497?aff=oddtdtcreator</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8672.mp3</guid><pubDate>Mon, 25 Sep 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537715/8672.mp3" length="6306232" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Scanning for Laravel - a PHP Framework for Web Artisants
https://isc.sans.edu/forums/diary/Scanning%20for%20Laravel%20-%20a%20PHP%20Framework%20for%20Web%20Artisants/30242/
 Fake CVE-2023-40477 Proof of Concept Leads to VenomRAT...</itunes:subtitle><itunes:summary><![CDATA[Scanning for Laravel - a PHP Framework for Web Artisants<br /><a href="https://isc.sans.edu/forums/diary/Scanning%20for%20Laravel%20-%20a%20PHP%20Framework%20for%20Web%20Artisants/30242/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Scanning%20for%20Laravel%20-%20a%20PHP%20Framework%20for%20Web%20Artisants/30242/</a><br /> Fake CVE-2023-40477 Proof of Concept Leads to VenomRAT<br /><a href="https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/</a><br /> Unmasking a Sophistiacted Phishing Campaign That Targets Hotel Guests<br /><a href="https://www.akamai.com/blog/security-research/sophisticated-phishing-campaign-targeting-hospitality" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/sophisticated-phishing-campaign-targeting-hospitality</a><br /> BSides JAX October 14th<br /><a href="https://www.bsidesjax.org/" target="_blank" rel="noreferrer noopener">https://www.bsidesjax.org/</a><br />  tickets: <a href="https://www.eventbrite.com/e/bsides-jacksonville-2023-registration-566463807497?aff=oddtdtcreator" target="_blank" rel="noreferrer noopener">https://www.eventbrite.com/e/bsides-jacksonville-2023-registration-566463807497?aff=oddtdtcreator</a><br />]]></itunes:summary><itunes:duration>429</itunes:duration><itunes:keywords>bsides; jax; phishing; hotels;,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8672</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, September 25th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-september-25th-2023--56920544</link><description><![CDATA[Scanning for Laravel - a PHP Framework for Web Artisants<br /><a href="https://isc.sans.edu/forums/diary/Scanning%20for%20Laravel%20-%20a%20PHP%20Framework%20for%20Web%20Artisants/30242/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Scanning%20for%20Laravel%20-%20a%20PHP%20Framework%20for%20Web%20Artisants/30242/</a><br /> Fake CVE-2023-40477 Proof of Concept Leads to VenomRAT<br /><a href="https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/</a><br /> Unmasking a Sophistiacted Phishing Campaign That Targets Hotel Guests<br /><a href="https://www.akamai.com/blog/security-research/sophisticated-phishing-campaign-targeting-hospitality" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/sophisticated-phishing-campaign-targeting-hospitality</a><br /> BSides JAX October 14th<br /><a href="https://www.bsidesjax.org/" target="_blank" rel="noreferrer noopener">https://www.bsidesjax.org/</a><br />  tickets: <a href="https://www.eventbrite.com/e/bsides-jacksonville-2023-registration-566463807497?aff=oddtdtcreator" target="_blank" rel="noreferrer noopener">https://www.eventbrite.com/e/bsides-jacksonville-2023-registration-566463807497?aff=oddtdtcreator</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8672.mp3</guid><pubDate>Mon, 25 Sep 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56920544/8672.mp3" length="6306232" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Scanning for Laravel - a PHP Framework for Web Artisants
https://isc.sans.edu/forums/diary/Scanning%20for%20Laravel%20-%20a%20PHP%20Framework%20for%20Web%20Artisants/30242/
 Fake CVE-2023-40477 Proof of Concept Leads to VenomRAT...</itunes:subtitle><itunes:summary><![CDATA[Scanning for Laravel - a PHP Framework for Web Artisants<br /><a href="https://isc.sans.edu/forums/diary/Scanning%20for%20Laravel%20-%20a%20PHP%20Framework%20for%20Web%20Artisants/30242/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Scanning%20for%20Laravel%20-%20a%20PHP%20Framework%20for%20Web%20Artisants/30242/</a><br /> Fake CVE-2023-40477 Proof of Concept Leads to VenomRAT<br /><a href="https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/" target="_blank" rel="noreferrer noopener">https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/</a><br /> Unmasking a Sophistiacted Phishing Campaign That Targets Hotel Guests<br /><a href="https://www.akamai.com/blog/security-research/sophisticated-phishing-campaign-targeting-hospitality" target="_blank" rel="noreferrer noopener">https://www.akamai.com/blog/security-research/sophisticated-phishing-campaign-targeting-hospitality</a><br /> BSides JAX October 14th<br /><a href="https://www.bsidesjax.org/" target="_blank" rel="noreferrer noopener">https://www.bsidesjax.org/</a><br />  tickets: <a href="https://www.eventbrite.com/e/bsides-jacksonville-2023-registration-566463807497?aff=oddtdtcreator" target="_blank" rel="noreferrer noopener">https://www.eventbrite.com/e/bsides-jacksonville-2023-registration-566463807497?aff=oddtdtcreator</a><br />]]></itunes:summary><itunes:duration>429</itunes:duration><itunes:keywords>bsides; jax; phishing; hotels;,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8672</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, September 22nd, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-september-22nd-2023--57537752</link><description><![CDATA[Apple Patches Three 0-Days<br /><a href="https://isc.sans.edu/diary/Apple+Patches+Three+New+0Day+Vulnerabilities+Affecting+iOSiPadOSwatchOSmacOS/30238" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple+Patches+Three+New+0Day+Vulnerabilities+Affecting+iOSiPadOSwatchOSmacOS/30238</a><br /> WebP Vulnerability<br /><a href="https://blog.isosceles.com/the-webp-0day/" target="_blank" rel="noreferrer noopener">https://blog.isosceles.com/the-webp-0day/</a><br /> MOVEit Transfer Service Pack<br /><a href="https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-September-2023" target="_blank" rel="noreferrer noopener">https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-September-2023</a><br /> Improved Passkey Support in Windows 11<br /><a href="https://www.microsoft.com/en-us/security/blog/2023/09/21/new-microsoft-security-tools-to-protect-families-and-businesses/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2023/09/21/new-microsoft-security-tools-to-protect-families-and-businesses/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8670.mp3</guid><pubDate>Fri, 22 Sep 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537752/8670.mp3" length="5384640" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Apple Patches Three 0-Days
https://isc.sans.edu/diary/Apple+Patches+Three+New+0Day+Vulnerabilities+Affecting+iOSiPadOSwatchOSmacOS/30238
 WebP Vulnerability
https://blog.isosceles.com/the-webp-0day/
 MOVEit Transfer Service Pack...</itunes:subtitle><itunes:summary><![CDATA[Apple Patches Three 0-Days<br /><a href="https://isc.sans.edu/diary/Apple+Patches+Three+New+0Day+Vulnerabilities+Affecting+iOSiPadOSwatchOSmacOS/30238" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple+Patches+Three+New+0Day+Vulnerabilities+Affecting+iOSiPadOSwatchOSmacOS/30238</a><br /> WebP Vulnerability<br /><a href="https://blog.isosceles.com/the-webp-0day/" target="_blank" rel="noreferrer noopener">https://blog.isosceles.com/the-webp-0day/</a><br /> MOVEit Transfer Service Pack<br /><a href="https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-September-2023" target="_blank" rel="noreferrer noopener">https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-September-2023</a><br /> Improved Passkey Support in Windows 11<br /><a href="https://www.microsoft.com/en-us/security/blog/2023/09/21/new-microsoft-security-tools-to-protect-families-and-businesses/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2023/09/21/new-microsoft-security-tools-to-protect-families-and-businesses/</a><br />]]></itunes:summary><itunes:duration>363</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,moveit; windows 11; passkeys; ,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8670</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, September 22nd, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-september-22nd-2023--56891347</link><description><![CDATA[Apple Patches Three 0-Days<br /><a href="https://isc.sans.edu/diary/Apple+Patches+Three+New+0Day+Vulnerabilities+Affecting+iOSiPadOSwatchOSmacOS/30238" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple+Patches+Three+New+0Day+Vulnerabilities+Affecting+iOSiPadOSwatchOSmacOS/30238</a><br /> WebP Vulnerability<br /><a href="https://blog.isosceles.com/the-webp-0day/" target="_blank" rel="noreferrer noopener">https://blog.isosceles.com/the-webp-0day/</a><br /> MOVEit Transfer Service Pack<br /><a href="https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-September-2023" target="_blank" rel="noreferrer noopener">https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-September-2023</a><br /> Improved Passkey Support in Windows 11<br /><a href="https://www.microsoft.com/en-us/security/blog/2023/09/21/new-microsoft-security-tools-to-protect-families-and-businesses/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2023/09/21/new-microsoft-security-tools-to-protect-families-and-businesses/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8670.mp3</guid><pubDate>Fri, 22 Sep 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56891347/8670.mp3" length="5384640" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Apple Patches Three 0-Days
https://isc.sans.edu/diary/Apple+Patches+Three+New+0Day+Vulnerabilities+Affecting+iOSiPadOSwatchOSmacOS/30238
 WebP Vulnerability
https://blog.isosceles.com/the-webp-0day/
 MOVEit Transfer Service Pack...</itunes:subtitle><itunes:summary><![CDATA[Apple Patches Three 0-Days<br /><a href="https://isc.sans.edu/diary/Apple+Patches+Three+New+0Day+Vulnerabilities+Affecting+iOSiPadOSwatchOSmacOS/30238" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple+Patches+Three+New+0Day+Vulnerabilities+Affecting+iOSiPadOSwatchOSmacOS/30238</a><br /> WebP Vulnerability<br /><a href="https://blog.isosceles.com/the-webp-0day/" target="_blank" rel="noreferrer noopener">https://blog.isosceles.com/the-webp-0day/</a><br /> MOVEit Transfer Service Pack<br /><a href="https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-September-2023" target="_blank" rel="noreferrer noopener">https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-September-2023</a><br /> Improved Passkey Support in Windows 11<br /><a href="https://www.microsoft.com/en-us/security/blog/2023/09/21/new-microsoft-security-tools-to-protect-families-and-businesses/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2023/09/21/new-microsoft-security-tools-to-protect-families-and-businesses/</a><br />]]></itunes:summary><itunes:duration>363</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,moveit; windows 11; passkeys; ,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8670</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, September 21st, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-september-21st-2023--57537716</link><description><![CDATA[What's Normal: DNS TTL Values<br /><a href="https://isc.sans.edu/forums/diary/What's%20Normal%3F%20DNS%20TTL%20Values/30234/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/What's%20Normal%3F%20DNS%20TTL%20Values/30234/</a><br /> CISA Highlights Snatch Ransomware<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-263a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-263a</a><br /> npm packages caught exfiltrating Kubernetes config, SSH keys<br /><a href="https://blog.sonatype.com/npm-packages-caught-exfiltrating-kubernetes-config-ssh-keys" target="_blank" rel="noreferrer noopener">https://blog.sonatype.com/npm-packages-caught-exfiltrating-kubernetes-config-ssh-keys</a><br /> Nagios XI Vulnerabilities<br /><a href="https://outpost24.com/blog/nagios-xi-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://outpost24.com/blog/nagios-xi-vulnerabilities/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8668.mp3</guid><pubDate>Thu, 21 Sep 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537716/8668.mp3" length="5317132" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>What's Normal: DNS TTL Values
https://isc.sans.edu/forums/diary/What's%20Normal%3F%20DNS%20TTL%20Values/30234/
 CISA Highlights Snatch Ransomware
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-263a
 npm packages caught exfiltrating...</itunes:subtitle><itunes:summary><![CDATA[What's Normal: DNS TTL Values<br /><a href="https://isc.sans.edu/forums/diary/What's%20Normal%3F%20DNS%20TTL%20Values/30234/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/What's%20Normal%3F%20DNS%20TTL%20Values/30234/</a><br /> CISA Highlights Snatch Ransomware<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-263a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-263a</a><br /> npm packages caught exfiltrating Kubernetes config, SSH keys<br /><a href="https://blog.sonatype.com/npm-packages-caught-exfiltrating-kubernetes-config-ssh-keys" target="_blank" rel="noreferrer noopener">https://blog.sonatype.com/npm-packages-caught-exfiltrating-kubernetes-config-ssh-keys</a><br /> Nagios XI Vulnerabilities<br /><a href="https://outpost24.com/blog/nagios-xi-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://outpost24.com/blog/nagios-xi-vulnerabilities/</a><br />]]></itunes:summary><itunes:duration>358</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,nagios; npm; kubernetes; ssh;,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8668</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, September 21st, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-september-21st-2023--56876411</link><description><![CDATA[What's Normal: DNS TTL Values<br /><a href="https://isc.sans.edu/forums/diary/What's%20Normal%3F%20DNS%20TTL%20Values/30234/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/What's%20Normal%3F%20DNS%20TTL%20Values/30234/</a><br /> CISA Highlights Snatch Ransomware<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-263a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-263a</a><br /> npm packages caught exfiltrating Kubernetes config, SSH keys<br /><a href="https://blog.sonatype.com/npm-packages-caught-exfiltrating-kubernetes-config-ssh-keys" target="_blank" rel="noreferrer noopener">https://blog.sonatype.com/npm-packages-caught-exfiltrating-kubernetes-config-ssh-keys</a><br /> Nagios XI Vulnerabilities<br /><a href="https://outpost24.com/blog/nagios-xi-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://outpost24.com/blog/nagios-xi-vulnerabilities/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8668.mp3</guid><pubDate>Thu, 21 Sep 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56876411/8668.mp3" length="5317132" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>What's Normal: DNS TTL Values
https://isc.sans.edu/forums/diary/What's%20Normal%3F%20DNS%20TTL%20Values/30234/
 CISA Highlights Snatch Ransomware
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-263a
 npm packages caught exfiltrating...</itunes:subtitle><itunes:summary><![CDATA[What's Normal: DNS TTL Values<br /><a href="https://isc.sans.edu/forums/diary/What's%20Normal%3F%20DNS%20TTL%20Values/30234/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/What's%20Normal%3F%20DNS%20TTL%20Values/30234/</a><br /> CISA Highlights Snatch Ransomware<br /><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-263a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-263a</a><br /> npm packages caught exfiltrating Kubernetes config, SSH keys<br /><a href="https://blog.sonatype.com/npm-packages-caught-exfiltrating-kubernetes-config-ssh-keys" target="_blank" rel="noreferrer noopener">https://blog.sonatype.com/npm-packages-caught-exfiltrating-kubernetes-config-ssh-keys</a><br /> Nagios XI Vulnerabilities<br /><a href="https://outpost24.com/blog/nagios-xi-vulnerabilities/" target="_blank" rel="noreferrer noopener">https://outpost24.com/blog/nagios-xi-vulnerabilities/</a><br />]]></itunes:summary><itunes:duration>358</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,nagios; npm; kubernetes; ssh;,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8668</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, September 20th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-september-20th-2023--57537760</link><description><![CDATA[Obfuscated Scans For Older Adobe Experience Manager Vulnerabilities<br /><a href="https://isc.sans.edu/diary/Obfuscated%20Scans%20for%20Older%20Adobe%20Experience%20Manager%20Vulnerabilities/30230" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Obfuscated%20Scans%20for%20Older%20Adobe%20Experience%20Manager%20Vulnerabilities/30230</a><br /> Trend Micro Apex One 0-day<br /><a href="https://success.trendmicro.com/dcx/s/solution/000294994?language=en_US" target="_blank" rel="noreferrer noopener">https://success.trendmicro.com/dcx/s/solution/000294994?language=en_US</a><br /> SprySOCKS Backdoor<br /><a href="https://www.trendmicro.com/en_us/research/23/i/earth-lusca-employs-new-linux-backdoor.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_us/research/23/i/earth-lusca-employs-new-linux-backdoor.html</a><br /> GitLab Patches<br /><a href="https://about.gitlab.com/releases/2023/09/18/security-release-gitlab-16-3-4-released/" target="_blank" rel="noreferrer noopener">https://about.gitlab.com/releases/2023/09/18/security-release-gitlab-16-3-4-released/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8666.mp3</guid><pubDate>Wed, 20 Sep 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537760/8666.mp3" length="4825381" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Obfuscated Scans For Older Adobe Experience Manager Vulnerabilities
https://isc.sans.edu/diary/Obfuscated%20Scans%20for%20Older%20Adobe%20Experience%20Manager%20Vulnerabilities/30230
 Trend Micro Apex One 0-day...</itunes:subtitle><itunes:summary><![CDATA[Obfuscated Scans For Older Adobe Experience Manager Vulnerabilities<br /><a href="https://isc.sans.edu/diary/Obfuscated%20Scans%20for%20Older%20Adobe%20Experience%20Manager%20Vulnerabilities/30230" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Obfuscated%20Scans%20for%20Older%20Adobe%20Experience%20Manager%20Vulnerabilities/30230</a><br /> Trend Micro Apex One 0-day<br /><a href="https://success.trendmicro.com/dcx/s/solution/000294994?language=en_US" target="_blank" rel="noreferrer noopener">https://success.trendmicro.com/dcx/s/solution/000294994?language=en_US</a><br /> SprySOCKS Backdoor<br /><a href="https://www.trendmicro.com/en_us/research/23/i/earth-lusca-employs-new-linux-backdoor.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_us/research/23/i/earth-lusca-employs-new-linux-backdoor.html</a><br /> GitLab Patches<br /><a href="https://about.gitlab.com/releases/2023/09/18/security-release-gitlab-16-3-4-released/" target="_blank" rel="noreferrer noopener">https://about.gitlab.com/releases/2023/09/18/security-release-gitlab-16-3-4-released/</a><br />]]></itunes:summary><itunes:duration>323</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,gitlab; sprysocks; backdoor; t,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8666</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, September 20th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-september-20th-2023--56866547</link><description><![CDATA[Obfuscated Scans For Older Adobe Experience Manager Vulnerabilities<br /><a href="https://isc.sans.edu/diary/Obfuscated%20Scans%20for%20Older%20Adobe%20Experience%20Manager%20Vulnerabilities/30230" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Obfuscated%20Scans%20for%20Older%20Adobe%20Experience%20Manager%20Vulnerabilities/30230</a><br /> Trend Micro Apex One 0-day<br /><a href="https://success.trendmicro.com/dcx/s/solution/000294994?language=en_US" target="_blank" rel="noreferrer noopener">https://success.trendmicro.com/dcx/s/solution/000294994?language=en_US</a><br /> SprySOCKS Backdoor<br /><a href="https://www.trendmicro.com/en_us/research/23/i/earth-lusca-employs-new-linux-backdoor.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_us/research/23/i/earth-lusca-employs-new-linux-backdoor.html</a><br /> GitLab Patches<br /><a href="https://about.gitlab.com/releases/2023/09/18/security-release-gitlab-16-3-4-released/" target="_blank" rel="noreferrer noopener">https://about.gitlab.com/releases/2023/09/18/security-release-gitlab-16-3-4-released/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8666.mp3</guid><pubDate>Wed, 20 Sep 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56866547/8666.mp3" length="4825381" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Obfuscated Scans For Older Adobe Experience Manager Vulnerabilities
https://isc.sans.edu/diary/Obfuscated%20Scans%20for%20Older%20Adobe%20Experience%20Manager%20Vulnerabilities/30230
 Trend Micro Apex One 0-day...</itunes:subtitle><itunes:summary><![CDATA[Obfuscated Scans For Older Adobe Experience Manager Vulnerabilities<br /><a href="https://isc.sans.edu/diary/Obfuscated%20Scans%20for%20Older%20Adobe%20Experience%20Manager%20Vulnerabilities/30230" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Obfuscated%20Scans%20for%20Older%20Adobe%20Experience%20Manager%20Vulnerabilities/30230</a><br /> Trend Micro Apex One 0-day<br /><a href="https://success.trendmicro.com/dcx/s/solution/000294994?language=en_US" target="_blank" rel="noreferrer noopener">https://success.trendmicro.com/dcx/s/solution/000294994?language=en_US</a><br /> SprySOCKS Backdoor<br /><a href="https://www.trendmicro.com/en_us/research/23/i/earth-lusca-employs-new-linux-backdoor.html" target="_blank" rel="noreferrer noopener">https://www.trendmicro.com/en_us/research/23/i/earth-lusca-employs-new-linux-backdoor.html</a><br /> GitLab Patches<br /><a href="https://about.gitlab.com/releases/2023/09/18/security-release-gitlab-16-3-4-released/" target="_blank" rel="noreferrer noopener">https://about.gitlab.com/releases/2023/09/18/security-release-gitlab-16-3-4-released/</a><br />]]></itunes:summary><itunes:duration>323</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,gitlab; sprysocks; backdoor; t,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8666</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, September 19th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-september-19th-2023--57537738</link><description><![CDATA[Internet Wide Multi VPN Search from Single /24 Network<br /><a href="https://isc.sans.edu/diary/Internet%20Wide%20Multi%20VPN%20Search%20From%20Single%20%2024%20Network/30226" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Internet%20Wide%20Multi%20VPN%20Search%20From%20Single%20%2024%20Network/30226</a><br /> iOS/iPadOS/tvOS/WatchOS Updates<br /><a href="https://support.apple.com/en-us/HT201222" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/HT201222</a><br /> Juniper Vuln Details/Exploit CVE-2023-36845<br /><a href="https://vulncheck.com/blog/juniper-cve-2023-36845" target="_blank" rel="noreferrer noopener">https://vulncheck.com/blog/juniper-cve-2023-36845</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8664.mp3</guid><pubDate>Tue, 19 Sep 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537738/8664.mp3" length="4868302" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Internet Wide Multi VPN Search from Single /24 Network
https://isc.sans.edu/diary/Internet%20Wide%20Multi%20VPN%20Search%20From%20Single%20%2024%20Network/30226
 iOS/iPadOS/tvOS/WatchOS Updates
https://support.apple.com/en-us/HT201222
 Juniper Vuln...</itunes:subtitle><itunes:summary><![CDATA[Internet Wide Multi VPN Search from Single /24 Network<br /><a href="https://isc.sans.edu/diary/Internet%20Wide%20Multi%20VPN%20Search%20From%20Single%20%2024%20Network/30226" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Internet%20Wide%20Multi%20VPN%20Search%20From%20Single%20%2024%20Network/30226</a><br /> iOS/iPadOS/tvOS/WatchOS Updates<br /><a href="https://support.apple.com/en-us/HT201222" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/HT201222</a><br /> Juniper Vuln Details/Exploit CVE-2023-36845<br /><a href="https://vulncheck.com/blog/juniper-cve-2023-36845" target="_blank" rel="noreferrer noopener">https://vulncheck.com/blog/juniper-cve-2023-36845</a><br />]]></itunes:summary><itunes:duration>326</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,juniper; exploit; ios; apple; ,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8664</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, September 19th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-september-19th-2023--56848955</link><description><![CDATA[Internet Wide Multi VPN Search from Single /24 Network<br /><a href="https://isc.sans.edu/diary/Internet%20Wide%20Multi%20VPN%20Search%20From%20Single%20%2024%20Network/30226" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Internet%20Wide%20Multi%20VPN%20Search%20From%20Single%20%2024%20Network/30226</a><br /> iOS/iPadOS/tvOS/WatchOS Updates<br /><a href="https://support.apple.com/en-us/HT201222" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/HT201222</a><br /> Juniper Vuln Details/Exploit CVE-2023-36845<br /><a href="https://vulncheck.com/blog/juniper-cve-2023-36845" target="_blank" rel="noreferrer noopener">https://vulncheck.com/blog/juniper-cve-2023-36845</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8664.mp3</guid><pubDate>Tue, 19 Sep 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56848955/8664.mp3" length="4868302" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Internet Wide Multi VPN Search from Single /24 Network
https://isc.sans.edu/diary/Internet%20Wide%20Multi%20VPN%20Search%20From%20Single%20%2024%20Network/30226
 iOS/iPadOS/tvOS/WatchOS Updates
https://support.apple.com/en-us/HT201222
 Juniper Vuln...</itunes:subtitle><itunes:summary><![CDATA[Internet Wide Multi VPN Search from Single /24 Network<br /><a href="https://isc.sans.edu/diary/Internet%20Wide%20Multi%20VPN%20Search%20From%20Single%20%2024%20Network/30226" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Internet%20Wide%20Multi%20VPN%20Search%20From%20Single%20%2024%20Network/30226</a><br /> iOS/iPadOS/tvOS/WatchOS Updates<br /><a href="https://support.apple.com/en-us/HT201222" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/HT201222</a><br /> Juniper Vuln Details/Exploit CVE-2023-36845<br /><a href="https://vulncheck.com/blog/juniper-cve-2023-36845" target="_blank" rel="noreferrer noopener">https://vulncheck.com/blog/juniper-cve-2023-36845</a><br />]]></itunes:summary><itunes:duration>326</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,juniper; exploit; ios; apple; ,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8664</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, September 18th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-september-18th-2023--57537748</link><description><![CDATA[When MFA isn't actually MFA<br /><a href="https://retool.com/blog/mfa-isnt-mfa/" target="_blank" rel="noreferrer noopener">https://retool.com/blog/mfa-isnt-mfa/</a><br /> QNAP Patches<br /><a href="https://www.qnap.com/en/security-advisories?ref=security_advisory_details" target="_blank" rel="noreferrer noopener">https://www.qnap.com/en/security-advisories?ref=security_advisory_details</a><br /> Chrome able to use Apple Keychain Passkeys<br /><a href="https://9to5google.com/2023/09/14/chrome-118-icloud-passkey/" target="_blank" rel="noreferrer noopener">https://9to5google.com/2023/09/14/chrome-118-icloud-passkey/</a><br /> Fortinet XSS<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-23-106" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-23-106</a><br /> vBulletin XSS<br /><a href="https://gist.github.com/GiongfNef/8fe658dce4c7fcf3a7b4e6387e50141c" target="_blank" rel="noreferrer noopener">https://gist.github.com/GiongfNef/8fe658dce4c7fcf3a7b4e6387e50141c</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8662.mp3</guid><pubDate>Mon, 18 Sep 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537748/8662.mp3" length="5166148" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>When MFA isn't actually MFA
https://retool.com/blog/mfa-isnt-mfa/
 QNAP Patches
https://www.qnap.com/en/security-advisories?ref=security_advisory_details
 Chrome able to use Apple Keychain Passkeys...</itunes:subtitle><itunes:summary><![CDATA[When MFA isn't actually MFA<br /><a href="https://retool.com/blog/mfa-isnt-mfa/" target="_blank" rel="noreferrer noopener">https://retool.com/blog/mfa-isnt-mfa/</a><br /> QNAP Patches<br /><a href="https://www.qnap.com/en/security-advisories?ref=security_advisory_details" target="_blank" rel="noreferrer noopener">https://www.qnap.com/en/security-advisories?ref=security_advisory_details</a><br /> Chrome able to use Apple Keychain Passkeys<br /><a href="https://9to5google.com/2023/09/14/chrome-118-icloud-passkey/" target="_blank" rel="noreferrer noopener">https://9to5google.com/2023/09/14/chrome-118-icloud-passkey/</a><br /> Fortinet XSS<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-23-106" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-23-106</a><br /> vBulletin XSS<br /><a href="https://gist.github.com/GiongfNef/8fe658dce4c7fcf3a7b4e6387e50141c" target="_blank" rel="noreferrer noopener">https://gist.github.com/GiongfNef/8fe658dce4c7fcf3a7b4e6387e50141c</a><br />]]></itunes:summary><itunes:duration>347</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,vbulletin; fortinet; xss; chro</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8662</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, September 18th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-september-18th-2023--56835311</link><description><![CDATA[When MFA isn't actually MFA<br /><a href="https://retool.com/blog/mfa-isnt-mfa/" target="_blank" rel="noreferrer noopener">https://retool.com/blog/mfa-isnt-mfa/</a><br /> QNAP Patches<br /><a href="https://www.qnap.com/en/security-advisories?ref=security_advisory_details" target="_blank" rel="noreferrer noopener">https://www.qnap.com/en/security-advisories?ref=security_advisory_details</a><br /> Chrome able to use Apple Keychain Passkeys<br /><a href="https://9to5google.com/2023/09/14/chrome-118-icloud-passkey/" target="_blank" rel="noreferrer noopener">https://9to5google.com/2023/09/14/chrome-118-icloud-passkey/</a><br /> Fortinet XSS<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-23-106" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-23-106</a><br /> vBulletin XSS<br /><a href="https://gist.github.com/GiongfNef/8fe658dce4c7fcf3a7b4e6387e50141c" target="_blank" rel="noreferrer noopener">https://gist.github.com/GiongfNef/8fe658dce4c7fcf3a7b4e6387e50141c</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8662.mp3</guid><pubDate>Mon, 18 Sep 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56835311/8662.mp3" length="5166148" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>When MFA isn't actually MFA
https://retool.com/blog/mfa-isnt-mfa/
 QNAP Patches
https://www.qnap.com/en/security-advisories?ref=security_advisory_details
 Chrome able to use Apple Keychain Passkeys...</itunes:subtitle><itunes:summary><![CDATA[When MFA isn't actually MFA<br /><a href="https://retool.com/blog/mfa-isnt-mfa/" target="_blank" rel="noreferrer noopener">https://retool.com/blog/mfa-isnt-mfa/</a><br /> QNAP Patches<br /><a href="https://www.qnap.com/en/security-advisories?ref=security_advisory_details" target="_blank" rel="noreferrer noopener">https://www.qnap.com/en/security-advisories?ref=security_advisory_details</a><br /> Chrome able to use Apple Keychain Passkeys<br /><a href="https://9to5google.com/2023/09/14/chrome-118-icloud-passkey/" target="_blank" rel="noreferrer noopener">https://9to5google.com/2023/09/14/chrome-118-icloud-passkey/</a><br /> Fortinet XSS<br /><a href="https://fortiguard.fortinet.com/psirt/FG-IR-23-106" target="_blank" rel="noreferrer noopener">https://fortiguard.fortinet.com/psirt/FG-IR-23-106</a><br /> vBulletin XSS<br /><a href="https://gist.github.com/GiongfNef/8fe658dce4c7fcf3a7b4e6387e50141c" target="_blank" rel="noreferrer noopener">https://gist.github.com/GiongfNef/8fe658dce4c7fcf3a7b4e6387e50141c</a><br />]]></itunes:summary><itunes:duration>347</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,vbulletin; fortinet; xss; chro</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8662</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, September 15th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-september-15th-2023--57537737</link><description><![CDATA[DShield and eqmu Sitting in a Tree: L-O-G-G-I-N-G<br /><a href="https://isc.sans.edu/diary/DShield%20and%20qemu%20Sitting%20in%20a%20Tree%3A%20L-O-G-G-I-N-G/30216" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/DShield%20and%20qemu%20Sitting%20in%20a%20Tree%3A%20L-O-G-G-I-N-G/30216</a><br /> Uncursing the ncurses memory corruption vulnerabilities<br /><a href="https://www.microsoft.com/en-us/security/blog/2023/09/14/uncursing-the-ncurses-memory-corruption-vulnerabilities-found-in-library/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2023/09/14/uncursing-the-ncurses-memory-corruption-vulnerabilities-found-in-library/</a><br /> Arbitrary code execution via Windows Themes (CVE-2023-38146)<br /><a href="https://exploits.forsale/themebleed/" target="_blank" rel="noreferrer noopener">https://exploits.forsale/themebleed/</a><br /> 3AM Ransomware used if LockBit Fails<br /><a href="https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/3am-ransomware-lockbit" target="_blank" rel="noreferrer noopener">https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/3am-ransomware-lockbit</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8660.mp3</guid><pubDate>Fri, 15 Sep 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537737/8660.mp3" length="5030003" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>DShield and eqmu Sitting in a Tree: L-O-G-G-I-N-G
https://isc.sans.edu/diary/DShield%20and%20qemu%20Sitting%20in%20a%20Tree%3A%20L-O-G-G-I-N-G/30216
 Uncursing the ncurses memory corruption vulnerabilities...</itunes:subtitle><itunes:summary><![CDATA[DShield and eqmu Sitting in a Tree: L-O-G-G-I-N-G<br /><a href="https://isc.sans.edu/diary/DShield%20and%20qemu%20Sitting%20in%20a%20Tree%3A%20L-O-G-G-I-N-G/30216" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/DShield%20and%20qemu%20Sitting%20in%20a%20Tree%3A%20L-O-G-G-I-N-G/30216</a><br /> Uncursing the ncurses memory corruption vulnerabilities<br /><a href="https://www.microsoft.com/en-us/security/blog/2023/09/14/uncursing-the-ncurses-memory-corruption-vulnerabilities-found-in-library/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2023/09/14/uncursing-the-ncurses-memory-corruption-vulnerabilities-found-in-library/</a><br /> Arbitrary code execution via Windows Themes (CVE-2023-38146)<br /><a href="https://exploits.forsale/themebleed/" target="_blank" rel="noreferrer noopener">https://exploits.forsale/themebleed/</a><br /> 3AM Ransomware used if LockBit Fails<br /><a href="https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/3am-ransomware-lockbit" target="_blank" rel="noreferrer noopener">https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/3am-ransomware-lockbit</a><br />]]></itunes:summary><itunes:duration>338</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dshield; qemu; raspberry pi; n,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8660</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, September 15th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-september-15th-2023--56806815</link><description><![CDATA[DShield and eqmu Sitting in a Tree: L-O-G-G-I-N-G<br /><a href="https://isc.sans.edu/diary/DShield%20and%20qemu%20Sitting%20in%20a%20Tree%3A%20L-O-G-G-I-N-G/30216" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/DShield%20and%20qemu%20Sitting%20in%20a%20Tree%3A%20L-O-G-G-I-N-G/30216</a><br /> Uncursing the ncurses memory corruption vulnerabilities<br /><a href="https://www.microsoft.com/en-us/security/blog/2023/09/14/uncursing-the-ncurses-memory-corruption-vulnerabilities-found-in-library/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2023/09/14/uncursing-the-ncurses-memory-corruption-vulnerabilities-found-in-library/</a><br /> Arbitrary code execution via Windows Themes (CVE-2023-38146)<br /><a href="https://exploits.forsale/themebleed/" target="_blank" rel="noreferrer noopener">https://exploits.forsale/themebleed/</a><br /> 3AM Ransomware used if LockBit Fails<br /><a href="https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/3am-ransomware-lockbit" target="_blank" rel="noreferrer noopener">https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/3am-ransomware-lockbit</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8660.mp3</guid><pubDate>Fri, 15 Sep 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56806815/8660.mp3" length="5030003" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>DShield and eqmu Sitting in a Tree: L-O-G-G-I-N-G
https://isc.sans.edu/diary/DShield%20and%20qemu%20Sitting%20in%20a%20Tree%3A%20L-O-G-G-I-N-G/30216
 Uncursing the ncurses memory corruption vulnerabilities...</itunes:subtitle><itunes:summary><![CDATA[DShield and eqmu Sitting in a Tree: L-O-G-G-I-N-G<br /><a href="https://isc.sans.edu/diary/DShield%20and%20qemu%20Sitting%20in%20a%20Tree%3A%20L-O-G-G-I-N-G/30216" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/DShield%20and%20qemu%20Sitting%20in%20a%20Tree%3A%20L-O-G-G-I-N-G/30216</a><br /> Uncursing the ncurses memory corruption vulnerabilities<br /><a href="https://www.microsoft.com/en-us/security/blog/2023/09/14/uncursing-the-ncurses-memory-corruption-vulnerabilities-found-in-library/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2023/09/14/uncursing-the-ncurses-memory-corruption-vulnerabilities-found-in-library/</a><br /> Arbitrary code execution via Windows Themes (CVE-2023-38146)<br /><a href="https://exploits.forsale/themebleed/" target="_blank" rel="noreferrer noopener">https://exploits.forsale/themebleed/</a><br /> 3AM Ransomware used if LockBit Fails<br /><a href="https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/3am-ransomware-lockbit" target="_blank" rel="noreferrer noopener">https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/3am-ransomware-lockbit</a><br />]]></itunes:summary><itunes:duration>338</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,dshield; qemu; raspberry pi; n,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8660</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, September 14th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-september-14th-2023--57537764</link><description><![CDATA[Backdoored Free DownloadManager<br /><a href="https://securelist.com/backdoored-free-download-manager-linux-malware/110465/" target="_blank" rel="noreferrer noopener">https://securelist.com/backdoored-free-download-manager-linux-malware/110465/</a><br /> Foxit PDF Reader Updates<br /><a href="https://www.foxit.com/support/security-bulletins.html" target="_blank" rel="noreferrer noopener">https://www.foxit.com/support/security-bulletins.html</a><br /> macOS MetaStealer: New Family of Obfuscated Go Infostealers<br /><a href="https://www.sentinelone.com/blog/macos-metastealer-new-family-of-obfuscated-go-infostealers-spread-in-targeted-attacks/" target="_blank" rel="noreferrer noopener">https://www.sentinelone.com/blog/macos-metastealer-new-family-of-obfuscated-go-infostealers-spread-in-targeted-attacks/</a><br /> Windows 11 to Support Blocking SMB NTLM Hashes<br /><a href="https://techcommunity.microsoft.com/t5/storage-at-microsoft/smb-ntlm-blocking-now-supported-in-windows-insider/ba-p/3916206" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/storage-at-microsoft/smb-ntlm-blocking-now-supported-in-windows-insider/ba-p/3916206</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8658.mp3</guid><pubDate>Thu, 14 Sep 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537764/8658.mp3" length="5099838" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Backdoored Free DownloadManager
https://securelist.com/backdoored-free-download-manager-linux-malware/110465/
 Foxit PDF Reader Updates
https://www.foxit.com/support/security-bulletins.html
 macOS MetaStealer: New Family of Obfuscated Go Infostealers...</itunes:subtitle><itunes:summary><![CDATA[Backdoored Free DownloadManager<br /><a href="https://securelist.com/backdoored-free-download-manager-linux-malware/110465/" target="_blank" rel="noreferrer noopener">https://securelist.com/backdoored-free-download-manager-linux-malware/110465/</a><br /> Foxit PDF Reader Updates<br /><a href="https://www.foxit.com/support/security-bulletins.html" target="_blank" rel="noreferrer noopener">https://www.foxit.com/support/security-bulletins.html</a><br /> macOS MetaStealer: New Family of Obfuscated Go Infostealers<br /><a href="https://www.sentinelone.com/blog/macos-metastealer-new-family-of-obfuscated-go-infostealers-spread-in-targeted-attacks/" target="_blank" rel="noreferrer noopener">https://www.sentinelone.com/blog/macos-metastealer-new-family-of-obfuscated-go-infostealers-spread-in-targeted-attacks/</a><br /> Windows 11 to Support Blocking SMB NTLM Hashes<br /><a href="https://techcommunity.microsoft.com/t5/storage-at-microsoft/smb-ntlm-blocking-now-supported-in-windows-insider/ba-p/3916206" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/storage-at-microsoft/smb-ntlm-blocking-now-supported-in-windows-insider/ba-p/3916206</a><br />]]></itunes:summary><itunes:duration>343</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,macos; metastealer; windows 11,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8658</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, September 14th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-september-14th-2023--56794674</link><description><![CDATA[Backdoored Free DownloadManager<br /><a href="https://securelist.com/backdoored-free-download-manager-linux-malware/110465/" target="_blank" rel="noreferrer noopener">https://securelist.com/backdoored-free-download-manager-linux-malware/110465/</a><br /> Foxit PDF Reader Updates<br /><a href="https://www.foxit.com/support/security-bulletins.html" target="_blank" rel="noreferrer noopener">https://www.foxit.com/support/security-bulletins.html</a><br /> macOS MetaStealer: New Family of Obfuscated Go Infostealers<br /><a href="https://www.sentinelone.com/blog/macos-metastealer-new-family-of-obfuscated-go-infostealers-spread-in-targeted-attacks/" target="_blank" rel="noreferrer noopener">https://www.sentinelone.com/blog/macos-metastealer-new-family-of-obfuscated-go-infostealers-spread-in-targeted-attacks/</a><br /> Windows 11 to Support Blocking SMB NTLM Hashes<br /><a href="https://techcommunity.microsoft.com/t5/storage-at-microsoft/smb-ntlm-blocking-now-supported-in-windows-insider/ba-p/3916206" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/storage-at-microsoft/smb-ntlm-blocking-now-supported-in-windows-insider/ba-p/3916206</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8658.mp3</guid><pubDate>Thu, 14 Sep 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56794674/8658.mp3" length="5099838" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Backdoored Free DownloadManager
https://securelist.com/backdoored-free-download-manager-linux-malware/110465/
 Foxit PDF Reader Updates
https://www.foxit.com/support/security-bulletins.html
 macOS MetaStealer: New Family of Obfuscated Go Infostealers...</itunes:subtitle><itunes:summary><![CDATA[Backdoored Free DownloadManager<br /><a href="https://securelist.com/backdoored-free-download-manager-linux-malware/110465/" target="_blank" rel="noreferrer noopener">https://securelist.com/backdoored-free-download-manager-linux-malware/110465/</a><br /> Foxit PDF Reader Updates<br /><a href="https://www.foxit.com/support/security-bulletins.html" target="_blank" rel="noreferrer noopener">https://www.foxit.com/support/security-bulletins.html</a><br /> macOS MetaStealer: New Family of Obfuscated Go Infostealers<br /><a href="https://www.sentinelone.com/blog/macos-metastealer-new-family-of-obfuscated-go-infostealers-spread-in-targeted-attacks/" target="_blank" rel="noreferrer noopener">https://www.sentinelone.com/blog/macos-metastealer-new-family-of-obfuscated-go-infostealers-spread-in-targeted-attacks/</a><br /> Windows 11 to Support Blocking SMB NTLM Hashes<br /><a href="https://techcommunity.microsoft.com/t5/storage-at-microsoft/smb-ntlm-blocking-now-supported-in-windows-insider/ba-p/3916206" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/storage-at-microsoft/smb-ntlm-blocking-now-supported-in-windows-insider/ba-p/3916206</a><br />]]></itunes:summary><itunes:duration>343</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,macos; metastealer; windows 11,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8658</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, September 13th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-september-13th-2023--57537740</link><description><![CDATA[Microsoft Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20September%202023%20Patch%20Tuesday/30214" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20September%202023%20Patch%20Tuesday/30214</a><br /> OpenSSL 1.1.1 End of Life<br /><a href="https://www.openssl.org/blog/blog/2023/09/11/eol-111/" target="_blank" rel="noreferrer noopener">https://www.openssl.org/blog/blog/2023/09/11/eol-111/</a><br /> Adobe Updates<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8656.mp3</guid><pubDate>Wed, 13 Sep 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537740/8656.mp3" length="5313872" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20September%202023%20Patch%20Tuesday/30214
 OpenSSL 1.1.1 End of Life
https://www.openssl.org/blog/blog/2023/09/11/eol-111/
 Adobe Updates...</itunes:subtitle><itunes:summary><![CDATA[Microsoft Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20September%202023%20Patch%20Tuesday/30214" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20September%202023%20Patch%20Tuesday/30214</a><br /> OpenSSL 1.1.1 End of Life<br /><a href="https://www.openssl.org/blog/blog/2023/09/11/eol-111/" target="_blank" rel="noreferrer noopener">https://www.openssl.org/blog/blog/2023/09/11/eol-111/</a><br /> Adobe Updates<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br />]]></itunes:summary><itunes:duration>358</itunes:duration><itunes:keywords>adobe; openssl; microsoft; pat,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8656</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, September 13th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-september-13th-2023--56783173</link><description><![CDATA[Microsoft Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20September%202023%20Patch%20Tuesday/30214" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20September%202023%20Patch%20Tuesday/30214</a><br /> OpenSSL 1.1.1 End of Life<br /><a href="https://www.openssl.org/blog/blog/2023/09/11/eol-111/" target="_blank" rel="noreferrer noopener">https://www.openssl.org/blog/blog/2023/09/11/eol-111/</a><br /> Adobe Updates<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8656.mp3</guid><pubDate>Wed, 13 Sep 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56783173/8656.mp3" length="5313872" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20September%202023%20Patch%20Tuesday/30214
 OpenSSL 1.1.1 End of Life
https://www.openssl.org/blog/blog/2023/09/11/eol-111/
 Adobe Updates...</itunes:subtitle><itunes:summary><![CDATA[Microsoft Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20September%202023%20Patch%20Tuesday/30214" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20September%202023%20Patch%20Tuesday/30214</a><br /> OpenSSL 1.1.1 End of Life<br /><a href="https://www.openssl.org/blog/blog/2023/09/11/eol-111/" target="_blank" rel="noreferrer noopener">https://www.openssl.org/blog/blog/2023/09/11/eol-111/</a><br /> Adobe Updates<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br />]]></itunes:summary><itunes:duration>358</itunes:duration><itunes:keywords>adobe; openssl; microsoft; pat,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8656</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, September 12th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-september-12th-2023--57537724</link><description><![CDATA[Apple Patches Older Operating Systems<br /><a href="https://isc.sans.edu/diary/Apple%20fixes%200-Day%20Vulnerability%20in%20Older%20Operating%20Systems/30210" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20fixes%200-Day%20Vulnerability%20in%20Older%20Operating%20Systems/30210</a><br /> Wi-Fi Enabled Practical Keystroke Eavesdropping<br /><a href="https://arxiv.org/pdf/2309.03492.pdf" target="_blank" rel="noreferrer noopener">https://arxiv.org/pdf/2309.03492.pdf</a><br /> Phishing via Google Looker Studio<br /><a href="https://blog.checkpoint.com/security/phishing-via-google-looker-studio" target="_blank" rel="noreferrer noopener">https://blog.checkpoint.com/security/phishing-via-google-looker-studio</a><br /> HPE One View Authentication Bypass<br /><a href="https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;docId=hpesbgn04530en_us" target="_blank" rel="noreferrer noopener">https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;docId=hpesbgn04530en_us</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8654.mp3</guid><pubDate>Tue, 12 Sep 2023 10:10:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537724/8654.mp3" length="5240752" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Apple Patches Older Operating Systems
https://isc.sans.edu/diary/Apple%20fixes%200-Day%20Vulnerability%20in%20Older%20Operating%20Systems/30210
 Wi-Fi Enabled Practical Keystroke Eavesdropping
https://arxiv.org/pdf/2309.03492.pdf
 Phishing via Google...</itunes:subtitle><itunes:summary><![CDATA[Apple Patches Older Operating Systems<br /><a href="https://isc.sans.edu/diary/Apple%20fixes%200-Day%20Vulnerability%20in%20Older%20Operating%20Systems/30210" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20fixes%200-Day%20Vulnerability%20in%20Older%20Operating%20Systems/30210</a><br /> Wi-Fi Enabled Practical Keystroke Eavesdropping<br /><a href="https://arxiv.org/pdf/2309.03492.pdf" target="_blank" rel="noreferrer noopener">https://arxiv.org/pdf/2309.03492.pdf</a><br /> Phishing via Google Looker Studio<br /><a href="https://blog.checkpoint.com/security/phishing-via-google-looker-studio" target="_blank" rel="noreferrer noopener">https://blog.checkpoint.com/security/phishing-via-google-looker-studio</a><br /> HPE One View Authentication Bypass<br /><a href="https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;docId=hpesbgn04530en_us" target="_blank" rel="noreferrer noopener">https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;docId=hpesbgn04530en_us</a><br />]]></itunes:summary><itunes:duration>353</itunes:duration><itunes:keywords>apple; patches; ios; macos; wi,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8654</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, September 12th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-september-12th-2023--56774251</link><description><![CDATA[Apple Patches Older Operating Systems<br /><a href="https://isc.sans.edu/diary/Apple%20fixes%200-Day%20Vulnerability%20in%20Older%20Operating%20Systems/30210" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20fixes%200-Day%20Vulnerability%20in%20Older%20Operating%20Systems/30210</a><br /> Wi-Fi Enabled Practical Keystroke Eavesdropping<br /><a href="https://arxiv.org/pdf/2309.03492.pdf" target="_blank" rel="noreferrer noopener">https://arxiv.org/pdf/2309.03492.pdf</a><br /> Phishing via Google Looker Studio<br /><a href="https://blog.checkpoint.com/security/phishing-via-google-looker-studio" target="_blank" rel="noreferrer noopener">https://blog.checkpoint.com/security/phishing-via-google-looker-studio</a><br /> HPE One View Authentication Bypass<br /><a href="https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;docId=hpesbgn04530en_us" target="_blank" rel="noreferrer noopener">https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;docId=hpesbgn04530en_us</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8654.mp3</guid><pubDate>Tue, 12 Sep 2023 10:10:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56774251/8654.mp3" length="5240752" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Apple Patches Older Operating Systems
https://isc.sans.edu/diary/Apple%20fixes%200-Day%20Vulnerability%20in%20Older%20Operating%20Systems/30210
 Wi-Fi Enabled Practical Keystroke Eavesdropping
https://arxiv.org/pdf/2309.03492.pdf
 Phishing via Google...</itunes:subtitle><itunes:summary><![CDATA[Apple Patches Older Operating Systems<br /><a href="https://isc.sans.edu/diary/Apple%20fixes%200-Day%20Vulnerability%20in%20Older%20Operating%20Systems/30210" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Apple%20fixes%200-Day%20Vulnerability%20in%20Older%20Operating%20Systems/30210</a><br /> Wi-Fi Enabled Practical Keystroke Eavesdropping<br /><a href="https://arxiv.org/pdf/2309.03492.pdf" target="_blank" rel="noreferrer noopener">https://arxiv.org/pdf/2309.03492.pdf</a><br /> Phishing via Google Looker Studio<br /><a href="https://blog.checkpoint.com/security/phishing-via-google-looker-studio" target="_blank" rel="noreferrer noopener">https://blog.checkpoint.com/security/phishing-via-google-looker-studio</a><br /> HPE One View Authentication Bypass<br /><a href="https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;docId=hpesbgn04530en_us" target="_blank" rel="noreferrer noopener">https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;docId=hpesbgn04530en_us</a><br />]]></itunes:summary><itunes:duration>353</itunes:duration><itunes:keywords>apple; patches; ios; macos; wi,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8654</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, September 11th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-september-11th-2023--57537750</link><description><![CDATA[Augmenting Honeypot Logs<br /><a href="https://isc.sans.edu/diary/%3FAnyone%20get%20the%20ASN%20of%20the%20Truck%20that%20Hit%20Me%3F!%3F%3A%20Creating%20a%20PowerShell%20Function%20to%20Make%203rd%20Party%20API%20Calls%20for%20Extending%20Honeypot%20Information%20%5BGuest%20Diary%5D/30204" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%3FAnyone%20get%20the%20ASN%20of%20the%20Truck%20that%20Hit%20Me%3F!%3F%3A%20Creating%20a%20PowerShell%20Function%20to%20Make%203rd%20Party%20API%20Calls%20for%20Extending%20Honeypot%20Information%20%5BGuest%20Diary%5D/30204</a><br /> More details about Apple 0-day<br /><a href="https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild/" target="_blank" rel="noreferrer noopener">https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild/</a><br /> Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote Access VPN Unauthorized Access Vulnerability<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ravpn-auth-8LyfCkeC#fs" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ravpn-auth-8LyfCkeC#fs</a><br /> Odd Password Solution<br /><a href="https://notpickard.com/@rdp/111009868239846779" target="_blank" rel="noreferrer noopener">https://notpickard.com/@rdp/111009868239846779</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8652.mp3</guid><pubDate>Mon, 11 Sep 2023 03:25:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537750/8652.mp3" length="6043796" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Augmenting Honeypot Logs...</itunes:subtitle><itunes:summary><![CDATA[Augmenting Honeypot Logs<br /><a href="https://isc.sans.edu/diary/%3FAnyone%20get%20the%20ASN%20of%20the%20Truck%20that%20Hit%20Me%3F!%3F%3A%20Creating%20a%20PowerShell%20Function%20to%20Make%203rd%20Party%20API%20Calls%20for%20Extending%20Honeypot%20Information%20%5BGuest%20Diary%5D/30204" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%3FAnyone%20get%20the%20ASN%20of%20the%20Truck%20that%20Hit%20Me%3F!%3F%3A%20Creating%20a%20PowerShell%20Function%20to%20Make%203rd%20Party%20API%20Calls%20for%20Extending%20Honeypot%20Information%20%5BGuest%20Diary%5D/30204</a><br /> More details about Apple 0-day<br /><a href="https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild/" target="_blank" rel="noreferrer noopener">https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild/</a><br /> Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote Access VPN Unauthorized Access Vulnerability<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ravpn-auth-8LyfCkeC#fs" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ravpn-auth-8LyfCkeC#fs</a><br /> Odd Password Solution<br /><a href="https://notpickard.com/@rdp/111009868239846779" target="_blank" rel="noreferrer noopener">https://notpickard.com/@rdp/111009868239846779</a><br />]]></itunes:summary><itunes:duration>410</itunes:duration><itunes:keywords>augmentation,business,cisco,computer,cyber,cybersecurity,daily,hacking,honeypot,infosec,internet,it,keyboard,logs,network,news,password,security,taiwan</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8652</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, September 11th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-september-11th-2023--56758010</link><description><![CDATA[Augmenting Honeypot Logs<br /><a href="https://isc.sans.edu/diary/%3FAnyone%20get%20the%20ASN%20of%20the%20Truck%20that%20Hit%20Me%3F!%3F%3A%20Creating%20a%20PowerShell%20Function%20to%20Make%203rd%20Party%20API%20Calls%20for%20Extending%20Honeypot%20Information%20%5BGuest%20Diary%5D/30204" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%3FAnyone%20get%20the%20ASN%20of%20the%20Truck%20that%20Hit%20Me%3F!%3F%3A%20Creating%20a%20PowerShell%20Function%20to%20Make%203rd%20Party%20API%20Calls%20for%20Extending%20Honeypot%20Information%20%5BGuest%20Diary%5D/30204</a><br /> More details about Apple 0-day<br /><a href="https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild/" target="_blank" rel="noreferrer noopener">https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild/</a><br /> Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote Access VPN Unauthorized Access Vulnerability<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ravpn-auth-8LyfCkeC#fs" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ravpn-auth-8LyfCkeC#fs</a><br /> Odd Password Solution<br /><a href="https://notpickard.com/@rdp/111009868239846779" target="_blank" rel="noreferrer noopener">https://notpickard.com/@rdp/111009868239846779</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8652.mp3</guid><pubDate>Mon, 11 Sep 2023 03:25:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56758010/8652.mp3" length="6043796" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Augmenting Honeypot Logs...</itunes:subtitle><itunes:summary><![CDATA[Augmenting Honeypot Logs<br /><a href="https://isc.sans.edu/diary/%3FAnyone%20get%20the%20ASN%20of%20the%20Truck%20that%20Hit%20Me%3F!%3F%3A%20Creating%20a%20PowerShell%20Function%20to%20Make%203rd%20Party%20API%20Calls%20for%20Extending%20Honeypot%20Information%20%5BGuest%20Diary%5D/30204" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/%3FAnyone%20get%20the%20ASN%20of%20the%20Truck%20that%20Hit%20Me%3F!%3F%3A%20Creating%20a%20PowerShell%20Function%20to%20Make%203rd%20Party%20API%20Calls%20for%20Extending%20Honeypot%20Information%20%5BGuest%20Diary%5D/30204</a><br /> More details about Apple 0-day<br /><a href="https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild/" target="_blank" rel="noreferrer noopener">https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild/</a><br /> Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote Access VPN Unauthorized Access Vulnerability<br /><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ravpn-auth-8LyfCkeC#fs" target="_blank" rel="noreferrer noopener">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ravpn-auth-8LyfCkeC#fs</a><br /> Odd Password Solution<br /><a href="https://notpickard.com/@rdp/111009868239846779" target="_blank" rel="noreferrer noopener">https://notpickard.com/@rdp/111009868239846779</a><br />]]></itunes:summary><itunes:duration>410</itunes:duration><itunes:keywords>augmentation,business,cisco,computer,cyber,cybersecurity,daily,hacking,honeypot,infosec,internet,it,keyboard,logs,network,news,password,security,taiwan</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8652</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, September 8th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-september-8th-2023--57537755</link><description><![CDATA[Apple Patches 0-Days<br /><a href="https://isc.sans.edu/diary/30200" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/30200</a><br /><a href="https://support.apple.com/en-us/HT201222" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/HT201222</a><br /> iOS Fleezeware/Scareware<br /><a href="https://isc.sans.edu/diary/Fleezeware%20Scareware%20Advertised%20via%20Facebook%20Tags%3B%20Available%20in%20Apple%20App%20Store/30198" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Fleezeware%20Scareware%20Advertised%20via%20Facebook%20Tags%3B%20Available%20in%20Apple%20App%20Store/30198</a><br /> Aruba Vulnerabilities<br /><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-014.txt" target="_blank" rel="noreferrer noopener">https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-014.txt</a><br /> TP Link Vulnerabilities<br /><a href="https://jvn.jp/en/vu/JVNVU99392903/" target="_blank" rel="noreferrer noopener">https://jvn.jp/en/vu/JVNVU99392903/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8650.mp3</guid><pubDate>Fri, 08 Sep 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537755/8650.mp3" length="4600296" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Apple Patches 0-Days
https://isc.sans.edu/diary/30200
https://support.apple.com/en-us/HT201222
 iOS Fleezeware/Scareware...</itunes:subtitle><itunes:summary><![CDATA[Apple Patches 0-Days<br /><a href="https://isc.sans.edu/diary/30200" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/30200</a><br /><a href="https://support.apple.com/en-us/HT201222" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/HT201222</a><br /> iOS Fleezeware/Scareware<br /><a href="https://isc.sans.edu/diary/Fleezeware%20Scareware%20Advertised%20via%20Facebook%20Tags%3B%20Available%20in%20Apple%20App%20Store/30198" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Fleezeware%20Scareware%20Advertised%20via%20Facebook%20Tags%3B%20Available%20in%20Apple%20App%20Store/30198</a><br /> Aruba Vulnerabilities<br /><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-014.txt" target="_blank" rel="noreferrer noopener">https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-014.txt</a><br /> TP Link Vulnerabilities<br /><a href="https://jvn.jp/en/vu/JVNVU99392903/" target="_blank" rel="noreferrer noopener">https://jvn.jp/en/vu/JVNVU99392903/</a><br />]]></itunes:summary><itunes:duration>307</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,tplink; aruba; ios; fleezeware</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8650</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, September 8th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-september-8th-2023--56730753</link><description><![CDATA[Apple Patches 0-Days<br /><a href="https://isc.sans.edu/diary/30200" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/30200</a><br /><a href="https://support.apple.com/en-us/HT201222" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/HT201222</a><br /> iOS Fleezeware/Scareware<br /><a href="https://isc.sans.edu/diary/Fleezeware%20Scareware%20Advertised%20via%20Facebook%20Tags%3B%20Available%20in%20Apple%20App%20Store/30198" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Fleezeware%20Scareware%20Advertised%20via%20Facebook%20Tags%3B%20Available%20in%20Apple%20App%20Store/30198</a><br /> Aruba Vulnerabilities<br /><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-014.txt" target="_blank" rel="noreferrer noopener">https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-014.txt</a><br /> TP Link Vulnerabilities<br /><a href="https://jvn.jp/en/vu/JVNVU99392903/" target="_blank" rel="noreferrer noopener">https://jvn.jp/en/vu/JVNVU99392903/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8650.mp3</guid><pubDate>Fri, 08 Sep 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56730753/8650.mp3" length="4600296" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Apple Patches 0-Days
https://isc.sans.edu/diary/30200
https://support.apple.com/en-us/HT201222
 iOS Fleezeware/Scareware...</itunes:subtitle><itunes:summary><![CDATA[Apple Patches 0-Days<br /><a href="https://isc.sans.edu/diary/30200" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/30200</a><br /><a href="https://support.apple.com/en-us/HT201222" target="_blank" rel="noreferrer noopener">https://support.apple.com/en-us/HT201222</a><br /> iOS Fleezeware/Scareware<br /><a href="https://isc.sans.edu/diary/Fleezeware%20Scareware%20Advertised%20via%20Facebook%20Tags%3B%20Available%20in%20Apple%20App%20Store/30198" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Fleezeware%20Scareware%20Advertised%20via%20Facebook%20Tags%3B%20Available%20in%20Apple%20App%20Store/30198</a><br /> Aruba Vulnerabilities<br /><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-014.txt" target="_blank" rel="noreferrer noopener">https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-014.txt</a><br /> TP Link Vulnerabilities<br /><a href="https://jvn.jp/en/vu/JVNVU99392903/" target="_blank" rel="noreferrer noopener">https://jvn.jp/en/vu/JVNVU99392903/</a><br />]]></itunes:summary><itunes:duration>307</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,tplink; aruba; ios; fleezeware</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8650</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, September 7th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-september-7th-2023--57537741</link><description><![CDATA[Security Related DNS Records<br /><a href="https://isc.sans.edu/diary/Security%20Relevant%20DNS%20Records/30194" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Security%20Relevant%20DNS%20Records/30194</a><br /> Microsoft Reveleas Details about Key Loss<br /><a href="https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/</a><br /> September Android Updates<br /><a href="https://source.android.com/docs/security/bulletin/2023-09-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2023-09-01</a><br /> Google Chrome Update<br /><a href="https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop.html</a><br /> Atlas VPN Tunnel Termination Vulnerability<br /><a href="https://www.reddit.com/r/cybersecurity/comments/167f16e/atlasvpn_linux_client_103_remote_disconnect/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/cybersecurity/comments/167f16e/atlasvpn_linux_client_103_remote_disconnect/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8648.mp3</guid><pubDate>Thu, 07 Sep 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537741/8648.mp3" length="5112449" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Security Related DNS Records
https://isc.sans.edu/diary/Security%20Relevant%20DNS%20Records/30194
 Microsoft Reveleas Details about Key Loss...</itunes:subtitle><itunes:summary><![CDATA[Security Related DNS Records<br /><a href="https://isc.sans.edu/diary/Security%20Relevant%20DNS%20Records/30194" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Security%20Relevant%20DNS%20Records/30194</a><br /> Microsoft Reveleas Details about Key Loss<br /><a href="https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/</a><br /> September Android Updates<br /><a href="https://source.android.com/docs/security/bulletin/2023-09-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2023-09-01</a><br /> Google Chrome Update<br /><a href="https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop.html</a><br /> Atlas VPN Tunnel Termination Vulnerability<br /><a href="https://www.reddit.com/r/cybersecurity/comments/167f16e/atlasvpn_linux_client_103_remote_disconnect/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/cybersecurity/comments/167f16e/atlasvpn_linux_client_103_remote_disconnect/</a><br />]]></itunes:summary><itunes:duration>344</itunes:duration><itunes:keywords>atlas; vpn; google; chrome; an,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8648</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, September 7th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-september-7th-2023--56719977</link><description><![CDATA[Security Related DNS Records<br /><a href="https://isc.sans.edu/diary/Security%20Relevant%20DNS%20Records/30194" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Security%20Relevant%20DNS%20Records/30194</a><br /> Microsoft Reveleas Details about Key Loss<br /><a href="https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/</a><br /> September Android Updates<br /><a href="https://source.android.com/docs/security/bulletin/2023-09-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2023-09-01</a><br /> Google Chrome Update<br /><a href="https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop.html</a><br /> Atlas VPN Tunnel Termination Vulnerability<br /><a href="https://www.reddit.com/r/cybersecurity/comments/167f16e/atlasvpn_linux_client_103_remote_disconnect/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/cybersecurity/comments/167f16e/atlasvpn_linux_client_103_remote_disconnect/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8648.mp3</guid><pubDate>Thu, 07 Sep 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56719977/8648.mp3" length="5112449" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Security Related DNS Records
https://isc.sans.edu/diary/Security%20Relevant%20DNS%20Records/30194
 Microsoft Reveleas Details about Key Loss...</itunes:subtitle><itunes:summary><![CDATA[Security Related DNS Records<br /><a href="https://isc.sans.edu/diary/Security%20Relevant%20DNS%20Records/30194" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Security%20Relevant%20DNS%20Records/30194</a><br /> Microsoft Reveleas Details about Key Loss<br /><a href="https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/</a><br /> September Android Updates<br /><a href="https://source.android.com/docs/security/bulletin/2023-09-01" target="_blank" rel="noreferrer noopener">https://source.android.com/docs/security/bulletin/2023-09-01</a><br /> Google Chrome Update<br /><a href="https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop.html" target="_blank" rel="noreferrer noopener">https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop.html</a><br /> Atlas VPN Tunnel Termination Vulnerability<br /><a href="https://www.reddit.com/r/cybersecurity/comments/167f16e/atlasvpn_linux_client_103_remote_disconnect/" target="_blank" rel="noreferrer noopener">https://www.reddit.com/r/cybersecurity/comments/167f16e/atlasvpn_linux_client_103_remote_disconnect/</a><br />]]></itunes:summary><itunes:duration>344</itunes:duration><itunes:keywords>atlas; vpn; google; chrome; an,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8648</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, September 6th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-september-6th-2023--57537728</link><description><![CDATA[Common Usernames Submitted to Honeypots<br /><a href="https://isc.sans.edu/diary/Common%20usernames%20submitted%20to%20honeypots/30188" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Common%20usernames%20submitted%20to%20honeypots/30188</a><br /> TPM LUKS Bypass<br /><a href="https://pulsesecurity.co.nz/advisories/tpm-luks-bypass" target="_blank" rel="noreferrer noopener">https://pulsesecurity.co.nz/advisories/tpm-luks-bypass</a><br /> Cross Tenant Impersonation Prevention and Detection<br /><a href="https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection" target="_blank" rel="noreferrer noopener">https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8646.mp3</guid><pubDate>Wed, 06 Sep 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537728/8646.mp3" length="4991430" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Common Usernames Submitted to Honeypots
https://isc.sans.edu/diary/Common%20usernames%20submitted%20to%20honeypots/30188
 TPM LUKS Bypass
https://pulsesecurity.co.nz/advisories/tpm-luks-bypass
 Cross Tenant Impersonation Prevention and Detection...</itunes:subtitle><itunes:summary><![CDATA[Common Usernames Submitted to Honeypots<br /><a href="https://isc.sans.edu/diary/Common%20usernames%20submitted%20to%20honeypots/30188" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Common%20usernames%20submitted%20to%20honeypots/30188</a><br /> TPM LUKS Bypass<br /><a href="https://pulsesecurity.co.nz/advisories/tpm-luks-bypass" target="_blank" rel="noreferrer noopener">https://pulsesecurity.co.nz/advisories/tpm-luks-bypass</a><br /> Cross Tenant Impersonation Prevention and Detection<br /><a href="https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection" target="_blank" rel="noreferrer noopener">https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection</a><br />]]></itunes:summary><itunes:duration>335</itunes:duration><itunes:keywords>2fa; impersonation; social eng,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8646</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, September 6th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-september-6th-2023--56705944</link><description><![CDATA[Common Usernames Submitted to Honeypots<br /><a href="https://isc.sans.edu/diary/Common%20usernames%20submitted%20to%20honeypots/30188" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Common%20usernames%20submitted%20to%20honeypots/30188</a><br /> TPM LUKS Bypass<br /><a href="https://pulsesecurity.co.nz/advisories/tpm-luks-bypass" target="_blank" rel="noreferrer noopener">https://pulsesecurity.co.nz/advisories/tpm-luks-bypass</a><br /> Cross Tenant Impersonation Prevention and Detection<br /><a href="https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection" target="_blank" rel="noreferrer noopener">https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8646.mp3</guid><pubDate>Wed, 06 Sep 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56705944/8646.mp3" length="4991430" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Common Usernames Submitted to Honeypots
https://isc.sans.edu/diary/Common%20usernames%20submitted%20to%20honeypots/30188
 TPM LUKS Bypass
https://pulsesecurity.co.nz/advisories/tpm-luks-bypass
 Cross Tenant Impersonation Prevention and Detection...</itunes:subtitle><itunes:summary><![CDATA[Common Usernames Submitted to Honeypots<br /><a href="https://isc.sans.edu/diary/Common%20usernames%20submitted%20to%20honeypots/30188" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Common%20usernames%20submitted%20to%20honeypots/30188</a><br /> TPM LUKS Bypass<br /><a href="https://pulsesecurity.co.nz/advisories/tpm-luks-bypass" target="_blank" rel="noreferrer noopener">https://pulsesecurity.co.nz/advisories/tpm-luks-bypass</a><br /> Cross Tenant Impersonation Prevention and Detection<br /><a href="https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection" target="_blank" rel="noreferrer noopener">https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection</a><br />]]></itunes:summary><itunes:duration>335</itunes:duration><itunes:keywords>2fa; impersonation; social eng,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8646</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, September 5th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-september-5th-2023--57537719</link><description><![CDATA[What is the Origin of Passwords Submitted to Honeypots<br /><a href="https://isc.sans.edu/diary/What%20is%20the%20origin%20of%20passwords%20submitted%20to%20honeypots%3F/30182" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20is%20the%20origin%20of%20passwords%20submitted%20to%20honeypots%3F/30182</a><br /> Creating a YARA Rule to Detect Obfuscated Strings<br /><a href="https://isc.sans.edu/diary/Creating%20a%20YARA%20Rule%20to%20Detect%20Obfuscated%20Strings/30186" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Creating%20a%20YARA%20Rule%20to%20Detect%20Obfuscated%20Strings/30186</a><br /> VMware Aria Operations for Networks Hardcoded Keys 2023-34039 <br /><a href="https://summoning.team/blog/vmware-vrealize-network-insight-rce-cve-2023-34039/" target="_blank" rel="noreferrer noopener">https://summoning.team/blog/vmware-vrealize-network-insight-rce-cve-2023-34039/</a><br /><a href="https://github.com/sinsinology/CVE-2023-34039/" target="_blank" rel="noreferrer noopener">https://github.com/sinsinology/CVE-2023-34039/</a><br /> Windows will Disable TLS 1.0/1.1<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/windows-message-center" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/windows-message-center</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8644.mp3</guid><pubDate>Tue, 05 Sep 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537719/8644.mp3" length="5581764" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>What is the Origin of Passwords Submitted to Honeypots
https://isc.sans.edu/diary/What%20is%20the%20origin%20of%20passwords%20submitted%20to%20honeypots%3F/30182
 Creating a YARA Rule to Detect Obfuscated Strings...</itunes:subtitle><itunes:summary><![CDATA[What is the Origin of Passwords Submitted to Honeypots<br /><a href="https://isc.sans.edu/diary/What%20is%20the%20origin%20of%20passwords%20submitted%20to%20honeypots%3F/30182" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20is%20the%20origin%20of%20passwords%20submitted%20to%20honeypots%3F/30182</a><br /> Creating a YARA Rule to Detect Obfuscated Strings<br /><a href="https://isc.sans.edu/diary/Creating%20a%20YARA%20Rule%20to%20Detect%20Obfuscated%20Strings/30186" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Creating%20a%20YARA%20Rule%20to%20Detect%20Obfuscated%20Strings/30186</a><br /> VMware Aria Operations for Networks Hardcoded Keys 2023-34039 <br /><a href="https://summoning.team/blog/vmware-vrealize-network-insight-rce-cve-2023-34039/" target="_blank" rel="noreferrer noopener">https://summoning.team/blog/vmware-vrealize-network-insight-rce-cve-2023-34039/</a><br /><a href="https://github.com/sinsinology/CVE-2023-34039/" target="_blank" rel="noreferrer noopener">https://github.com/sinsinology/CVE-2023-34039/</a><br /> Windows will Disable TLS 1.0/1.1<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/windows-message-center" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/windows-message-center</a><br />]]></itunes:summary><itunes:duration>377</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,windows; tls; vmware; aira; ss</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8644</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, September 5th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-september-5th-2023--56694125</link><description><![CDATA[What is the Origin of Passwords Submitted to Honeypots<br /><a href="https://isc.sans.edu/diary/What%20is%20the%20origin%20of%20passwords%20submitted%20to%20honeypots%3F/30182" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20is%20the%20origin%20of%20passwords%20submitted%20to%20honeypots%3F/30182</a><br /> Creating a YARA Rule to Detect Obfuscated Strings<br /><a href="https://isc.sans.edu/diary/Creating%20a%20YARA%20Rule%20to%20Detect%20Obfuscated%20Strings/30186" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Creating%20a%20YARA%20Rule%20to%20Detect%20Obfuscated%20Strings/30186</a><br /> VMware Aria Operations for Networks Hardcoded Keys 2023-34039 <br /><a href="https://summoning.team/blog/vmware-vrealize-network-insight-rce-cve-2023-34039/" target="_blank" rel="noreferrer noopener">https://summoning.team/blog/vmware-vrealize-network-insight-rce-cve-2023-34039/</a><br /><a href="https://github.com/sinsinology/CVE-2023-34039/" target="_blank" rel="noreferrer noopener">https://github.com/sinsinology/CVE-2023-34039/</a><br /> Windows will Disable TLS 1.0/1.1<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/windows-message-center" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/windows-message-center</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8644.mp3</guid><pubDate>Tue, 05 Sep 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56694125/8644.mp3" length="5581764" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>What is the Origin of Passwords Submitted to Honeypots
https://isc.sans.edu/diary/What%20is%20the%20origin%20of%20passwords%20submitted%20to%20honeypots%3F/30182
 Creating a YARA Rule to Detect Obfuscated Strings...</itunes:subtitle><itunes:summary><![CDATA[What is the Origin of Passwords Submitted to Honeypots<br /><a href="https://isc.sans.edu/diary/What%20is%20the%20origin%20of%20passwords%20submitted%20to%20honeypots%3F/30182" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/What%20is%20the%20origin%20of%20passwords%20submitted%20to%20honeypots%3F/30182</a><br /> Creating a YARA Rule to Detect Obfuscated Strings<br /><a href="https://isc.sans.edu/diary/Creating%20a%20YARA%20Rule%20to%20Detect%20Obfuscated%20Strings/30186" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Creating%20a%20YARA%20Rule%20to%20Detect%20Obfuscated%20Strings/30186</a><br /> VMware Aria Operations for Networks Hardcoded Keys 2023-34039 <br /><a href="https://summoning.team/blog/vmware-vrealize-network-insight-rce-cve-2023-34039/" target="_blank" rel="noreferrer noopener">https://summoning.team/blog/vmware-vrealize-network-insight-rce-cve-2023-34039/</a><br /><a href="https://github.com/sinsinology/CVE-2023-34039/" target="_blank" rel="noreferrer noopener">https://github.com/sinsinology/CVE-2023-34039/</a><br /> Windows will Disable TLS 1.0/1.1<br /><a href="https://learn.microsoft.com/en-us/windows/release-health/windows-message-center" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/windows/release-health/windows-message-center</a><br />]]></itunes:summary><itunes:duration>377</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,windows; tls; vmware; aira; ss</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8644</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, September 1st, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-september-1st-2023--57537761</link><description><![CDATA[The low, low cost of (committing) cybercrime<br /><a href="https://isc.sans.edu/forums/diary/The%20low%2C%20low%20cost%20of%20%28committing%29%20cybercrime/30176/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/The%20low%2C%20low%20cost%20of%20%28committing%29%20cybercrime/30176/</a><br /> Unpinnable Github Actions<br /><a href="https://www.paloaltonetworks.com/blog/prisma-cloud/unpinnable-actions-github-security/" target="_blank" rel="noreferrer noopener">https://www.paloaltonetworks.com/blog/prisma-cloud/unpinnable-actions-github-security/</a><br /> Exploitation of Cisco ASA SSL VPNs<br /><a href="https://www.rapid7.com/blog/post/2023/08/29/under-siege-rapid7-observed-exploitation-of-cisco-asa-ssl-vpns/" target="_blank" rel="noreferrer noopener">https://www.rapid7.com/blog/post/2023/08/29/under-siege-rapid7-observed-exploitation-of-cisco-asa-ssl-vpns/</a><br /> Splunk Vulnerabilities<br /><a href="https://advisory.splunk.com/advisories" target="_blank" rel="noreferrer noopener">https://advisory.splunk.com/advisories</a><br /> Top Level Domain Issues<br /><a href="https://blog.talosintelligence.com/whats-in-a-name/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/whats-in-a-name/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8642.mp3</guid><pubDate>Fri, 01 Sep 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537761/8642.mp3" length="5631523" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>The low, low cost of (committing) cybercrime
https://isc.sans.edu/forums/diary/The%20low%2C%20low%20cost%20of%20%28committing%29%20cybercrime/30176/
 Unpinnable Github Actions...</itunes:subtitle><itunes:summary><![CDATA[The low, low cost of (committing) cybercrime<br /><a href="https://isc.sans.edu/forums/diary/The%20low%2C%20low%20cost%20of%20%28committing%29%20cybercrime/30176/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/The%20low%2C%20low%20cost%20of%20%28committing%29%20cybercrime/30176/</a><br /> Unpinnable Github Actions<br /><a href="https://www.paloaltonetworks.com/blog/prisma-cloud/unpinnable-actions-github-security/" target="_blank" rel="noreferrer noopener">https://www.paloaltonetworks.com/blog/prisma-cloud/unpinnable-actions-github-security/</a><br /> Exploitation of Cisco ASA SSL VPNs<br /><a href="https://www.rapid7.com/blog/post/2023/08/29/under-siege-rapid7-observed-exploitation-of-cisco-asa-ssl-vpns/" target="_blank" rel="noreferrer noopener">https://www.rapid7.com/blog/post/2023/08/29/under-siege-rapid7-observed-exploitation-of-cisco-asa-ssl-vpns/</a><br /> Splunk Vulnerabilities<br /><a href="https://advisory.splunk.com/advisories" target="_blank" rel="noreferrer noopener">https://advisory.splunk.com/advisories</a><br /> Top Level Domain Issues<br /><a href="https://blog.talosintelligence.com/whats-in-a-name/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/whats-in-a-name/</a><br />]]></itunes:summary><itunes:duration>381</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,tld; splunk; cisco; asa; ssl v</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8642</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, September 1st, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-september-1st-2023--56655975</link><description><![CDATA[The low, low cost of (committing) cybercrime<br /><a href="https://isc.sans.edu/forums/diary/The%20low%2C%20low%20cost%20of%20%28committing%29%20cybercrime/30176/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/The%20low%2C%20low%20cost%20of%20%28committing%29%20cybercrime/30176/</a><br /> Unpinnable Github Actions<br /><a href="https://www.paloaltonetworks.com/blog/prisma-cloud/unpinnable-actions-github-security/" target="_blank" rel="noreferrer noopener">https://www.paloaltonetworks.com/blog/prisma-cloud/unpinnable-actions-github-security/</a><br /> Exploitation of Cisco ASA SSL VPNs<br /><a href="https://www.rapid7.com/blog/post/2023/08/29/under-siege-rapid7-observed-exploitation-of-cisco-asa-ssl-vpns/" target="_blank" rel="noreferrer noopener">https://www.rapid7.com/blog/post/2023/08/29/under-siege-rapid7-observed-exploitation-of-cisco-asa-ssl-vpns/</a><br /> Splunk Vulnerabilities<br /><a href="https://advisory.splunk.com/advisories" target="_blank" rel="noreferrer noopener">https://advisory.splunk.com/advisories</a><br /> Top Level Domain Issues<br /><a href="https://blog.talosintelligence.com/whats-in-a-name/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/whats-in-a-name/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8642.mp3</guid><pubDate>Fri, 01 Sep 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56655975/8642.mp3" length="5631523" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>The low, low cost of (committing) cybercrime
https://isc.sans.edu/forums/diary/The%20low%2C%20low%20cost%20of%20%28committing%29%20cybercrime/30176/
 Unpinnable Github Actions...</itunes:subtitle><itunes:summary><![CDATA[The low, low cost of (committing) cybercrime<br /><a href="https://isc.sans.edu/forums/diary/The%20low%2C%20low%20cost%20of%20%28committing%29%20cybercrime/30176/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/The%20low%2C%20low%20cost%20of%20%28committing%29%20cybercrime/30176/</a><br /> Unpinnable Github Actions<br /><a href="https://www.paloaltonetworks.com/blog/prisma-cloud/unpinnable-actions-github-security/" target="_blank" rel="noreferrer noopener">https://www.paloaltonetworks.com/blog/prisma-cloud/unpinnable-actions-github-security/</a><br /> Exploitation of Cisco ASA SSL VPNs<br /><a href="https://www.rapid7.com/blog/post/2023/08/29/under-siege-rapid7-observed-exploitation-of-cisco-asa-ssl-vpns/" target="_blank" rel="noreferrer noopener">https://www.rapid7.com/blog/post/2023/08/29/under-siege-rapid7-observed-exploitation-of-cisco-asa-ssl-vpns/</a><br /> Splunk Vulnerabilities<br /><a href="https://advisory.splunk.com/advisories" target="_blank" rel="noreferrer noopener">https://advisory.splunk.com/advisories</a><br /> Top Level Domain Issues<br /><a href="https://blog.talosintelligence.com/whats-in-a-name/" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/whats-in-a-name/</a><br />]]></itunes:summary><itunes:duration>381</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,tld; splunk; cisco; asa; ssl v</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8642</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, August 31st, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-august-31st-2023--57537754</link><description><![CDATA[Home Office/Small Business Hurricane Prep<br /><a href="https://isc.sans.edu/diary/Home%20Office%20%20%20Small%20Business%20Hurricane%20Prep/30166" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Home%20Office%20%20%20Small%20Business%20Hurricane%20Prep/30166</a><br /> Notepad++ Vulnerabilities<br /><a href="https://securitylab.github.com/advisories/GHSL-2023-092_Notepad__/" target="_blank" rel="noreferrer noopener">https://securitylab.github.com/advisories/GHSL-2023-092_Notepad__/</a><br /> 7-Zip Vulnerability<br /><a href="https://www.zerodayinitiative.com/advisories/ZDI-23-1164/" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/advisories/ZDI-23-1164/</a><br /> BGP Error Handling Issues<br /><a href="https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling" target="_blank" rel="noreferrer noopener">https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8640.mp3</guid><pubDate>Thu, 31 Aug 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537754/8640.mp3" length="4991153" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Home Office/Small Business Hurricane Prep
https://isc.sans.edu/diary/Home%20Office%20%20%20Small%20Business%20Hurricane%20Prep/30166
 Notepad++ Vulnerabilities
https://securitylab.github.com/advisories/GHSL-2023-092_Notepad__/
 7-Zip Vulnerability...</itunes:subtitle><itunes:summary><![CDATA[Home Office/Small Business Hurricane Prep<br /><a href="https://isc.sans.edu/diary/Home%20Office%20%20%20Small%20Business%20Hurricane%20Prep/30166" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Home%20Office%20%20%20Small%20Business%20Hurricane%20Prep/30166</a><br /> Notepad++ Vulnerabilities<br /><a href="https://securitylab.github.com/advisories/GHSL-2023-092_Notepad__/" target="_blank" rel="noreferrer noopener">https://securitylab.github.com/advisories/GHSL-2023-092_Notepad__/</a><br /> 7-Zip Vulnerability<br /><a href="https://www.zerodayinitiative.com/advisories/ZDI-23-1164/" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/advisories/ZDI-23-1164/</a><br /> BGP Error Handling Issues<br /><a href="https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling" target="_blank" rel="noreferrer noopener">https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling</a><br />]]></itunes:summary><itunes:duration>335</itunes:duration><itunes:keywords>bgp; 7zip; notepad++; hurrican,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8640</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, August 31st, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-august-31st-2023--56643591</link><description><![CDATA[Home Office/Small Business Hurricane Prep<br /><a href="https://isc.sans.edu/diary/Home%20Office%20%20%20Small%20Business%20Hurricane%20Prep/30166" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Home%20Office%20%20%20Small%20Business%20Hurricane%20Prep/30166</a><br /> Notepad++ Vulnerabilities<br /><a href="https://securitylab.github.com/advisories/GHSL-2023-092_Notepad__/" target="_blank" rel="noreferrer noopener">https://securitylab.github.com/advisories/GHSL-2023-092_Notepad__/</a><br /> 7-Zip Vulnerability<br /><a href="https://www.zerodayinitiative.com/advisories/ZDI-23-1164/" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/advisories/ZDI-23-1164/</a><br /> BGP Error Handling Issues<br /><a href="https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling" target="_blank" rel="noreferrer noopener">https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8640.mp3</guid><pubDate>Thu, 31 Aug 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56643591/8640.mp3" length="4991153" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Home Office/Small Business Hurricane Prep
https://isc.sans.edu/diary/Home%20Office%20%20%20Small%20Business%20Hurricane%20Prep/30166
 Notepad++ Vulnerabilities
https://securitylab.github.com/advisories/GHSL-2023-092_Notepad__/
 7-Zip Vulnerability...</itunes:subtitle><itunes:summary><![CDATA[Home Office/Small Business Hurricane Prep<br /><a href="https://isc.sans.edu/diary/Home%20Office%20%20%20Small%20Business%20Hurricane%20Prep/30166" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Home%20Office%20%20%20Small%20Business%20Hurricane%20Prep/30166</a><br /> Notepad++ Vulnerabilities<br /><a href="https://securitylab.github.com/advisories/GHSL-2023-092_Notepad__/" target="_blank" rel="noreferrer noopener">https://securitylab.github.com/advisories/GHSL-2023-092_Notepad__/</a><br /> 7-Zip Vulnerability<br /><a href="https://www.zerodayinitiative.com/advisories/ZDI-23-1164/" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/advisories/ZDI-23-1164/</a><br /> BGP Error Handling Issues<br /><a href="https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling" target="_blank" rel="noreferrer noopener">https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling</a><br />]]></itunes:summary><itunes:duration>335</itunes:duration><itunes:keywords>bgp; 7zip; notepad++; hurrican,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8640</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, August 30th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-august-30th-2023--57537770</link><description><![CDATA[Survival Time for Web Sites<br /><a href="https://isc.sans.edu/diary/Survival%20time%20for%20web%20sites/30170" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Survival%20time%20for%20web%20sites/30170</a><br /> PDF/ActiveMime Polyglot Maldocs<br /><a href="https://blogs.jpcert.or.jp/en/2023/08/maldocinpdf.html" target="_blank" rel="noreferrer noopener">https://blogs.jpcert.or.jp/en/2023/08/maldocinpdf.html</a><br /><a href="https://blog.didierstevens.com/2023/08/29/quickpost-pdf-activemime-maldocs-yara-rule/" target="_blank" rel="noreferrer noopener">https://blog.didierstevens.com/2023/08/29/quickpost-pdf-activemime-maldocs-yara-rule/</a><br /> RocketMQ Vulnerability Exploited<br /><a href="https://blogs.juniper.net/en-us/threat-research/dreambus-botnet-resurfaces-targets-rocketmq-vulnerability" target="_blank" rel="noreferrer noopener">https://blogs.juniper.net/en-us/threat-research/dreambus-botnet-resurfaces-targets-rocketmq-vulnerability</a><br /> ManageEngine Vulnerabilty<br /><a href="https://www.manageengine.com/security/advisory/CVE/CVE-2023-35785.html" target="_blank" rel="noreferrer noopener">https://www.manageengine.com/security/advisory/CVE/CVE-2023-35785.html</a><br /><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8638.mp3</guid><pubDate>Wed, 30 Aug 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537770/8638.mp3" length="5395050" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Survival Time for Web Sites
https://isc.sans.edu/diary/Survival%20time%20for%20web%20sites/30170
 PDF/ActiveMime Polyglot Maldocs
https://blogs.jpcert.or.jp/en/2023/08/maldocinpdf.html...</itunes:subtitle><itunes:summary><![CDATA[Survival Time for Web Sites<br /><a href="https://isc.sans.edu/diary/Survival%20time%20for%20web%20sites/30170" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Survival%20time%20for%20web%20sites/30170</a><br /> PDF/ActiveMime Polyglot Maldocs<br /><a href="https://blogs.jpcert.or.jp/en/2023/08/maldocinpdf.html" target="_blank" rel="noreferrer noopener">https://blogs.jpcert.or.jp/en/2023/08/maldocinpdf.html</a><br /><a href="https://blog.didierstevens.com/2023/08/29/quickpost-pdf-activemime-maldocs-yara-rule/" target="_blank" rel="noreferrer noopener">https://blog.didierstevens.com/2023/08/29/quickpost-pdf-activemime-maldocs-yara-rule/</a><br /> RocketMQ Vulnerability Exploited<br /><a href="https://blogs.juniper.net/en-us/threat-research/dreambus-botnet-resurfaces-targets-rocketmq-vulnerability" target="_blank" rel="noreferrer noopener">https://blogs.juniper.net/en-us/threat-research/dreambus-botnet-resurfaces-targets-rocketmq-vulnerability</a><br /> ManageEngine Vulnerabilty<br /><a href="https://www.manageengine.com/security/advisory/CVE/CVE-2023-35785.html" target="_blank" rel="noreferrer noopener">https://www.manageengine.com/security/advisory/CVE/CVE-2023-35785.html</a><br /><br />]]></itunes:summary><itunes:duration>364</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,manageengine; zoho; vulnerabil,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8638</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, August 30th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-august-30th-2023--56632109</link><description><![CDATA[Survival Time for Web Sites<br /><a href="https://isc.sans.edu/diary/Survival%20time%20for%20web%20sites/30170" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Survival%20time%20for%20web%20sites/30170</a><br /> PDF/ActiveMime Polyglot Maldocs<br /><a href="https://blogs.jpcert.or.jp/en/2023/08/maldocinpdf.html" target="_blank" rel="noreferrer noopener">https://blogs.jpcert.or.jp/en/2023/08/maldocinpdf.html</a><br /><a href="https://blog.didierstevens.com/2023/08/29/quickpost-pdf-activemime-maldocs-yara-rule/" target="_blank" rel="noreferrer noopener">https://blog.didierstevens.com/2023/08/29/quickpost-pdf-activemime-maldocs-yara-rule/</a><br /> RocketMQ Vulnerability Exploited<br /><a href="https://blogs.juniper.net/en-us/threat-research/dreambus-botnet-resurfaces-targets-rocketmq-vulnerability" target="_blank" rel="noreferrer noopener">https://blogs.juniper.net/en-us/threat-research/dreambus-botnet-resurfaces-targets-rocketmq-vulnerability</a><br /> ManageEngine Vulnerabilty<br /><a href="https://www.manageengine.com/security/advisory/CVE/CVE-2023-35785.html" target="_blank" rel="noreferrer noopener">https://www.manageengine.com/security/advisory/CVE/CVE-2023-35785.html</a><br /><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8638.mp3</guid><pubDate>Wed, 30 Aug 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56632109/8638.mp3" length="5395050" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Survival Time for Web Sites
https://isc.sans.edu/diary/Survival%20time%20for%20web%20sites/30170
 PDF/ActiveMime Polyglot Maldocs
https://blogs.jpcert.or.jp/en/2023/08/maldocinpdf.html...</itunes:subtitle><itunes:summary><![CDATA[Survival Time for Web Sites<br /><a href="https://isc.sans.edu/diary/Survival%20time%20for%20web%20sites/30170" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Survival%20time%20for%20web%20sites/30170</a><br /> PDF/ActiveMime Polyglot Maldocs<br /><a href="https://blogs.jpcert.or.jp/en/2023/08/maldocinpdf.html" target="_blank" rel="noreferrer noopener">https://blogs.jpcert.or.jp/en/2023/08/maldocinpdf.html</a><br /><a href="https://blog.didierstevens.com/2023/08/29/quickpost-pdf-activemime-maldocs-yara-rule/" target="_blank" rel="noreferrer noopener">https://blog.didierstevens.com/2023/08/29/quickpost-pdf-activemime-maldocs-yara-rule/</a><br /> RocketMQ Vulnerability Exploited<br /><a href="https://blogs.juniper.net/en-us/threat-research/dreambus-botnet-resurfaces-targets-rocketmq-vulnerability" target="_blank" rel="noreferrer noopener">https://blogs.juniper.net/en-us/threat-research/dreambus-botnet-resurfaces-targets-rocketmq-vulnerability</a><br /> ManageEngine Vulnerabilty<br /><a href="https://www.manageengine.com/security/advisory/CVE/CVE-2023-35785.html" target="_blank" rel="noreferrer noopener">https://www.manageengine.com/security/advisory/CVE/CVE-2023-35785.html</a><br /><br />]]></itunes:summary><itunes:duration>364</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,manageengine; zoho; vulnerabil,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8638</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, August 29th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-august-29th-2023--57537756</link><description><![CDATA[Analysis of RAR Exploit Files (CVE-2023-38831)<br /><a href="https://isc.sans.edu/diary/Analysis+of+RAR+Exploit+Files+CVE202338831/30164" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analysis+of+RAR+Exploit+Files+CVE202338831/30164</a><br /> Juniper Exploit  CVE-2023-36844 , CVE-2023-36845 , CVE-2023-36846 , CVE-2023-36847<br /><a href="https://labs.watchtowr.com/cve-2023-36844-and-friends-rce-in-juniper-firewalls/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/cve-2023-36844-and-friends-rce-in-juniper-firewalls/</a><br /> Microsoft Will Enabled Extended Protection for Exchange Server by Default<br /><a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/coming-soon-enabling-extended-protection-on-exchange-server-by/ba-p/3911849" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/exchange-team-blog/coming-soon-enabling-extended-protection-on-exchange-server-by/ba-p/3911849</a><br /> Rust Malware Stages on Crates.io<br /><a href="https://blog.phylum.io/rust-malware-staged-on-crates-io/" target="_blank" rel="noreferrer noopener">https://blog.phylum.io/rust-malware-staged-on-crates-io/</a><br /><br /> SANS Community Night London Signup<br /><a href="https://www.sans.org/mlp/community-night-cloud-security-london-september-2023" target="_blank" rel="noreferrer noopener">https://www.sans.org/mlp/community-night-cloud-security-london-september-2023</a>]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8636.mp3</guid><pubDate>Tue, 29 Aug 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537756/8636.mp3" length="5786010" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Analysis of RAR Exploit Files (CVE-2023-38831)
https://isc.sans.edu/diary/Analysis+of+RAR+Exploit+Files+CVE202338831/30164
 Juniper Exploit  CVE-2023-36844 , CVE-2023-36845 , CVE-2023-36846 , CVE-2023-36847...</itunes:subtitle><itunes:summary><![CDATA[Analysis of RAR Exploit Files (CVE-2023-38831)<br /><a href="https://isc.sans.edu/diary/Analysis+of+RAR+Exploit+Files+CVE202338831/30164" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analysis+of+RAR+Exploit+Files+CVE202338831/30164</a><br /> Juniper Exploit  CVE-2023-36844 , CVE-2023-36845 , CVE-2023-36846 , CVE-2023-36847<br /><a href="https://labs.watchtowr.com/cve-2023-36844-and-friends-rce-in-juniper-firewalls/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/cve-2023-36844-and-friends-rce-in-juniper-firewalls/</a><br /> Microsoft Will Enabled Extended Protection for Exchange Server by Default<br /><a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/coming-soon-enabling-extended-protection-on-exchange-server-by/ba-p/3911849" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/exchange-team-blog/coming-soon-enabling-extended-protection-on-exchange-server-by/ba-p/3911849</a><br /> Rust Malware Stages on Crates.io<br /><a href="https://blog.phylum.io/rust-malware-staged-on-crates-io/" target="_blank" rel="noreferrer noopener">https://blog.phylum.io/rust-malware-staged-on-crates-io/</a><br /><br /> SANS Community Night London Signup<br /><a href="https://www.sans.org/mlp/community-night-cloud-security-london-september-2023" target="_blank" rel="noreferrer noopener">https://www.sans.org/mlp/community-night-cloud-security-london-september-2023</a>]]></itunes:summary><itunes:duration>392</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,rar; winrar; exploit; juniper;,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8636</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, August 29th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-august-29th-2023--56621758</link><description><![CDATA[Analysis of RAR Exploit Files (CVE-2023-38831)<br /><a href="https://isc.sans.edu/diary/Analysis+of+RAR+Exploit+Files+CVE202338831/30164" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analysis+of+RAR+Exploit+Files+CVE202338831/30164</a><br /> Juniper Exploit  CVE-2023-36844 , CVE-2023-36845 , CVE-2023-36846 , CVE-2023-36847<br /><a href="https://labs.watchtowr.com/cve-2023-36844-and-friends-rce-in-juniper-firewalls/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/cve-2023-36844-and-friends-rce-in-juniper-firewalls/</a><br /> Microsoft Will Enabled Extended Protection for Exchange Server by Default<br /><a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/coming-soon-enabling-extended-protection-on-exchange-server-by/ba-p/3911849" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/exchange-team-blog/coming-soon-enabling-extended-protection-on-exchange-server-by/ba-p/3911849</a><br /> Rust Malware Stages on Crates.io<br /><a href="https://blog.phylum.io/rust-malware-staged-on-crates-io/" target="_blank" rel="noreferrer noopener">https://blog.phylum.io/rust-malware-staged-on-crates-io/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8636.mp3</guid><pubDate>Tue, 29 Aug 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56621758/8636.mp3" length="5786010" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Analysis of RAR Exploit Files (CVE-2023-38831)
https://isc.sans.edu/diary/Analysis+of+RAR+Exploit+Files+CVE202338831/30164
 Juniper Exploit  CVE-2023-36844 , CVE-2023-36845 , CVE-2023-36846 , CVE-2023-36847...</itunes:subtitle><itunes:summary><![CDATA[Analysis of RAR Exploit Files (CVE-2023-38831)<br /><a href="https://isc.sans.edu/diary/Analysis+of+RAR+Exploit+Files+CVE202338831/30164" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Analysis+of+RAR+Exploit+Files+CVE202338831/30164</a><br /> Juniper Exploit  CVE-2023-36844 , CVE-2023-36845 , CVE-2023-36846 , CVE-2023-36847<br /><a href="https://labs.watchtowr.com/cve-2023-36844-and-friends-rce-in-juniper-firewalls/" target="_blank" rel="noreferrer noopener">https://labs.watchtowr.com/cve-2023-36844-and-friends-rce-in-juniper-firewalls/</a><br /> Microsoft Will Enabled Extended Protection for Exchange Server by Default<br /><a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/coming-soon-enabling-extended-protection-on-exchange-server-by/ba-p/3911849" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/exchange-team-blog/coming-soon-enabling-extended-protection-on-exchange-server-by/ba-p/3911849</a><br /> Rust Malware Stages on Crates.io<br /><a href="https://blog.phylum.io/rust-malware-staged-on-crates-io/" target="_blank" rel="noreferrer noopener">https://blog.phylum.io/rust-malware-staged-on-crates-io/</a><br />]]></itunes:summary><itunes:duration>392</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,rar; winrar; exploit; juniper;,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8636</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, August 28th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-august-28th-2023--57537757</link><description><![CDATA[Python Malware Using Postgresql for C2 Communications<br /><a href="https://isc.sans.edu/diary/Python%20Malware%20Using%20Postgresql%20for%20C2%20Communications/30158" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Python%20Malware%20Using%20Postgresql%20for%20C2%20Communications/30158</a><br /> macOS: Who is Behind This Network Connection?<br /><a href="https://isc.sans.edu/diary/macOS%3A%20Who%3Fs%20Behind%20This%20Network%20Connection%3F/30160" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/macOS%3A%20Who%3Fs%20Behind%20This%20Network%20Connection%3F/30160</a><br /> CVE-2020-19909 Is Everything that is Wrong with CVEs<br /><a href="https://daniel.haxx.se/blog/2023/08/26/cve-2020-19909-is-everything-that-is-wrong-with-cves/" target="_blank" rel="noreferrer noopener">https://daniel.haxx.se/blog/2023/08/26/cve-2020-19909-is-everything-that-is-wrong-with-cves/</a><br /> Windows Certificate Confusion<br /><a href="https://arstechnica.com/security/2023/08/a-renegade-certificate-is-removed-from-windows-then-it-returns-confusion-ensues/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2023/08/a-renegade-certificate-is-removed-from-windows-then-it-returns-confusion-ensues/</a><br /> NPM E-Mail Validator Package Malware<br /><a href="https://blog.phylum.io/npm-emails-validator-package-malware/" target="_blank" rel="noreferrer noopener">https://blog.phylum.io/npm-emails-validator-package-malware/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8634.mp3</guid><pubDate>Mon, 28 Aug 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537757/8634.mp3" length="5869580" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Python Malware Using Postgresql for C2 Communications
https://isc.sans.edu/diary/Python%20Malware%20Using%20Postgresql%20for%20C2%20Communications/30158
 macOS: Who is Behind This Network Connection?...</itunes:subtitle><itunes:summary><![CDATA[Python Malware Using Postgresql for C2 Communications<br /><a href="https://isc.sans.edu/diary/Python%20Malware%20Using%20Postgresql%20for%20C2%20Communications/30158" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Python%20Malware%20Using%20Postgresql%20for%20C2%20Communications/30158</a><br /> macOS: Who is Behind This Network Connection?<br /><a href="https://isc.sans.edu/diary/macOS%3A%20Who%3Fs%20Behind%20This%20Network%20Connection%3F/30160" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/macOS%3A%20Who%3Fs%20Behind%20This%20Network%20Connection%3F/30160</a><br /> CVE-2020-19909 Is Everything that is Wrong with CVEs<br /><a href="https://daniel.haxx.se/blog/2023/08/26/cve-2020-19909-is-everything-that-is-wrong-with-cves/" target="_blank" rel="noreferrer noopener">https://daniel.haxx.se/blog/2023/08/26/cve-2020-19909-is-everything-that-is-wrong-with-cves/</a><br /> Windows Certificate Confusion<br /><a href="https://arstechnica.com/security/2023/08/a-renegade-certificate-is-removed-from-windows-then-it-returns-confusion-ensues/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2023/08/a-renegade-certificate-is-removed-from-windows-then-it-returns-confusion-ensues/</a><br /> NPM E-Mail Validator Package Malware<br /><a href="https://blog.phylum.io/npm-emails-validator-package-malware/" target="_blank" rel="noreferrer noopener">https://blog.phylum.io/npm-emails-validator-package-malware/</a><br />]]></itunes:summary><itunes:duration>398</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,npm; windows; certificate; cve,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8634</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, August 28th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-august-28th-2023--56609579</link><description><![CDATA[Python Malware Using Postgresql for C2 Communications<br /><a href="https://isc.sans.edu/diary/Python%20Malware%20Using%20Postgresql%20for%20C2%20Communications/30158" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Python%20Malware%20Using%20Postgresql%20for%20C2%20Communications/30158</a><br /> macOS: Who is Behind This Network Connection?<br /><a href="https://isc.sans.edu/diary/macOS%3A%20Who%3Fs%20Behind%20This%20Network%20Connection%3F/30160" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/macOS%3A%20Who%3Fs%20Behind%20This%20Network%20Connection%3F/30160</a><br /> CVE-2020-19909 Is Everything that is Wrong with CVEs<br /><a href="https://daniel.haxx.se/blog/2023/08/26/cve-2020-19909-is-everything-that-is-wrong-with-cves/" target="_blank" rel="noreferrer noopener">https://daniel.haxx.se/blog/2023/08/26/cve-2020-19909-is-everything-that-is-wrong-with-cves/</a><br /> Windows Certificate Confusion<br /><a href="https://arstechnica.com/security/2023/08/a-renegade-certificate-is-removed-from-windows-then-it-returns-confusion-ensues/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2023/08/a-renegade-certificate-is-removed-from-windows-then-it-returns-confusion-ensues/</a><br /> NPM E-Mail Validator Package Malware<br /><a href="https://blog.phylum.io/npm-emails-validator-package-malware/" target="_blank" rel="noreferrer noopener">https://blog.phylum.io/npm-emails-validator-package-malware/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8634.mp3</guid><pubDate>Mon, 28 Aug 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56609579/8634.mp3" length="5869580" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Python Malware Using Postgresql for C2 Communications
https://isc.sans.edu/diary/Python%20Malware%20Using%20Postgresql%20for%20C2%20Communications/30158
 macOS: Who is Behind This Network Connection?...</itunes:subtitle><itunes:summary><![CDATA[Python Malware Using Postgresql for C2 Communications<br /><a href="https://isc.sans.edu/diary/Python%20Malware%20Using%20Postgresql%20for%20C2%20Communications/30158" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Python%20Malware%20Using%20Postgresql%20for%20C2%20Communications/30158</a><br /> macOS: Who is Behind This Network Connection?<br /><a href="https://isc.sans.edu/diary/macOS%3A%20Who%3Fs%20Behind%20This%20Network%20Connection%3F/30160" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/macOS%3A%20Who%3Fs%20Behind%20This%20Network%20Connection%3F/30160</a><br /> CVE-2020-19909 Is Everything that is Wrong with CVEs<br /><a href="https://daniel.haxx.se/blog/2023/08/26/cve-2020-19909-is-everything-that-is-wrong-with-cves/" target="_blank" rel="noreferrer noopener">https://daniel.haxx.se/blog/2023/08/26/cve-2020-19909-is-everything-that-is-wrong-with-cves/</a><br /> Windows Certificate Confusion<br /><a href="https://arstechnica.com/security/2023/08/a-renegade-certificate-is-removed-from-windows-then-it-returns-confusion-ensues/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2023/08/a-renegade-certificate-is-removed-from-windows-then-it-returns-confusion-ensues/</a><br /> NPM E-Mail Validator Package Malware<br /><a href="https://blog.phylum.io/npm-emails-validator-package-malware/" target="_blank" rel="noreferrer noopener">https://blog.phylum.io/npm-emails-validator-package-malware/</a><br />]]></itunes:summary><itunes:duration>398</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,npm; windows; certificate; cve,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8634</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, August 25th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-august-25th-2023--57537766</link><description><![CDATA[How I made a "QWERTY" Keyboard Walk Password Generator with ChatGPT<br /><a href="https://isc.sans.edu/diary/How%20I%20made%20a%20qwerty%20%3Fkeyboard%20walk%3F%20password%20generator%20with%20ChatGPT%20%20%5BGuest%20Diary%5D/30152" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20I%20made%20a%20qwerty%20%3Fkeyboard%20walk%3F%20password%20generator%20with%20ChatGPT%20%20%5BGuest%20Diary%5D/30152</a><br /> FBI Warns of Persistent Barracuda Backdoors<br /><a href="https://www.ic3.gov/Media/News/2023/230823.pdf" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/Media/News/2023/230823.pdf</a><br /> Ivanti Sentry Athentication Bypass Deep Diver CVE-2023-38035<br /><a href="https://www.horizon3.ai/ivanti-sentry-authentication-bypass-cve-2023-38035-deep-dive/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/ivanti-sentry-authentication-bypass-cve-2023-38035-deep-dive/</a><br /> Smoke Loader Drops Whiffy Recon WiFi Scanning and Geolocation Malware<br /><a href="https://www.secureworks.com/blog/smoke-loader-drops-whiffy-recon-wi-fi-scanning-and-geolocation-malware" target="_blank" rel="noreferrer noopener">https://www.secureworks.com/blog/smoke-loader-drops-whiffy-recon-wi-fi-scanning-and-geolocation-malware</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8632.mp3</guid><pubDate>Fri, 25 Aug 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537766/8632.mp3" length="5232981" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>How I made a "QWERTY" Keyboard Walk Password Generator with ChatGPT
https://isc.sans.edu/diary/How%20I%20made%20a%20qwerty%20%3Fkeyboard%20walk%3F%20password%20generator%20with%20ChatGPT%20%20%5BGuest%20Diary%5D/30152
 FBI Warns of Persistent...</itunes:subtitle><itunes:summary><![CDATA[How I made a "QWERTY" Keyboard Walk Password Generator with ChatGPT<br /><a href="https://isc.sans.edu/diary/How%20I%20made%20a%20qwerty%20%3Fkeyboard%20walk%3F%20password%20generator%20with%20ChatGPT%20%20%5BGuest%20Diary%5D/30152" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20I%20made%20a%20qwerty%20%3Fkeyboard%20walk%3F%20password%20generator%20with%20ChatGPT%20%20%5BGuest%20Diary%5D/30152</a><br /> FBI Warns of Persistent Barracuda Backdoors<br /><a href="https://www.ic3.gov/Media/News/2023/230823.pdf" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/Media/News/2023/230823.pdf</a><br /> Ivanti Sentry Athentication Bypass Deep Diver CVE-2023-38035<br /><a href="https://www.horizon3.ai/ivanti-sentry-authentication-bypass-cve-2023-38035-deep-dive/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/ivanti-sentry-authentication-bypass-cve-2023-38035-deep-dive/</a><br /> Smoke Loader Drops Whiffy Recon WiFi Scanning and Geolocation Malware<br /><a href="https://www.secureworks.com/blog/smoke-loader-drops-whiffy-recon-wi-fi-scanning-and-geolocation-malware" target="_blank" rel="noreferrer noopener">https://www.secureworks.com/blog/smoke-loader-drops-whiffy-recon-wi-fi-scanning-and-geolocation-malware</a><br />]]></itunes:summary><itunes:duration>352</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,smoke loader; whiffy; recon; w</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8632</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, August 25th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-august-25th-2023--56585374</link><description><![CDATA[How I made a "QWERTY" Keyboard Walk Password Generator with ChatGPT<br /><a href="https://isc.sans.edu/diary/How%20I%20made%20a%20qwerty%20%3Fkeyboard%20walk%3F%20password%20generator%20with%20ChatGPT%20%20%5BGuest%20Diary%5D/30152" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20I%20made%20a%20qwerty%20%3Fkeyboard%20walk%3F%20password%20generator%20with%20ChatGPT%20%20%5BGuest%20Diary%5D/30152</a><br /> FBI Warns of Persistent Barracuda Backdoors<br /><a href="https://www.ic3.gov/Media/News/2023/230823.pdf" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/Media/News/2023/230823.pdf</a><br /> Ivanti Sentry Athentication Bypass Deep Diver CVE-2023-38035<br /><a href="https://www.horizon3.ai/ivanti-sentry-authentication-bypass-cve-2023-38035-deep-dive/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/ivanti-sentry-authentication-bypass-cve-2023-38035-deep-dive/</a><br /> Smoke Loader Drops Whiffy Recon WiFi Scanning and Geolocation Malware<br /><a href="https://www.secureworks.com/blog/smoke-loader-drops-whiffy-recon-wi-fi-scanning-and-geolocation-malware" target="_blank" rel="noreferrer noopener">https://www.secureworks.com/blog/smoke-loader-drops-whiffy-recon-wi-fi-scanning-and-geolocation-malware</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8632.mp3</guid><pubDate>Fri, 25 Aug 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56585374/8632.mp3" length="5232981" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>How I made a "QWERTY" Keyboard Walk Password Generator with ChatGPT
https://isc.sans.edu/diary/How%20I%20made%20a%20qwerty%20%3Fkeyboard%20walk%3F%20password%20generator%20with%20ChatGPT%20%20%5BGuest%20Diary%5D/30152
 FBI Warns of Persistent...</itunes:subtitle><itunes:summary><![CDATA[How I made a "QWERTY" Keyboard Walk Password Generator with ChatGPT<br /><a href="https://isc.sans.edu/diary/How%20I%20made%20a%20qwerty%20%3Fkeyboard%20walk%3F%20password%20generator%20with%20ChatGPT%20%20%5BGuest%20Diary%5D/30152" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/How%20I%20made%20a%20qwerty%20%3Fkeyboard%20walk%3F%20password%20generator%20with%20ChatGPT%20%20%5BGuest%20Diary%5D/30152</a><br /> FBI Warns of Persistent Barracuda Backdoors<br /><a href="https://www.ic3.gov/Media/News/2023/230823.pdf" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/Media/News/2023/230823.pdf</a><br /> Ivanti Sentry Athentication Bypass Deep Diver CVE-2023-38035<br /><a href="https://www.horizon3.ai/ivanti-sentry-authentication-bypass-cve-2023-38035-deep-dive/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/ivanti-sentry-authentication-bypass-cve-2023-38035-deep-dive/</a><br /> Smoke Loader Drops Whiffy Recon WiFi Scanning and Geolocation Malware<br /><a href="https://www.secureworks.com/blog/smoke-loader-drops-whiffy-recon-wi-fi-scanning-and-geolocation-malware" target="_blank" rel="noreferrer noopener">https://www.secureworks.com/blog/smoke-loader-drops-whiffy-recon-wi-fi-scanning-and-geolocation-malware</a><br />]]></itunes:summary><itunes:duration>352</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,smoke loader; whiffy; recon; w</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8632</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, August 24th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-august-24th-2023--57537792</link><description><![CDATA[More Exotic Excel Files Dropping AgentTesla<br /><a href="https://isc.sans.edu/diary/More%20Exotic%20Excel%20Files%20Dropping%20AgentTesla/30150" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/More%20Exotic%20Excel%20Files%20Dropping%20AgentTesla/30150</a><br /> CVE-2023-38831 WinRAR Vulnerability Exploited<br /><a href="https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/" target="_blank" rel="noreferrer noopener">https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/</a><br /> Aruba Vulnerabilities<br /><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-012.txt" target="_blank" rel="noreferrer noopener">https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-012.txt</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8630.mp3</guid><pubDate>Thu, 24 Aug 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537792/8630.mp3" length="4783758" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>More Exotic Excel Files Dropping AgentTesla
https://isc.sans.edu/diary/More%20Exotic%20Excel%20Files%20Dropping%20AgentTesla/30150
 CVE-2023-38831 WinRAR Vulnerability Exploited
https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/
 Aruba...</itunes:subtitle><itunes:summary><![CDATA[More Exotic Excel Files Dropping AgentTesla<br /><a href="https://isc.sans.edu/diary/More%20Exotic%20Excel%20Files%20Dropping%20AgentTesla/30150" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/More%20Exotic%20Excel%20Files%20Dropping%20AgentTesla/30150</a><br /> CVE-2023-38831 WinRAR Vulnerability Exploited<br /><a href="https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/" target="_blank" rel="noreferrer noopener">https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/</a><br /> Aruba Vulnerabilities<br /><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-012.txt" target="_blank" rel="noreferrer noopener">https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-012.txt</a><br />]]></itunes:summary><itunes:duration>320</itunes:duration><itunes:keywords>aruba; winrar; xlam;,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8630</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, August 24th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-august-24th-2023--56572947</link><description><![CDATA[More Exotic Excel Files Dropping AgentTesla<br /><a href="https://isc.sans.edu/diary/More%20Exotic%20Excel%20Files%20Dropping%20AgentTesla/30150" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/More%20Exotic%20Excel%20Files%20Dropping%20AgentTesla/30150</a><br /> CVE-2023-38831 WinRAR Vulnerability Exploited<br /><a href="https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/" target="_blank" rel="noreferrer noopener">https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/</a><br /> Aruba Vulnerabilities<br /><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-012.txt" target="_blank" rel="noreferrer noopener">https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-012.txt</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8630.mp3</guid><pubDate>Thu, 24 Aug 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56572947/8630.mp3" length="4783758" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>More Exotic Excel Files Dropping AgentTesla
https://isc.sans.edu/diary/More%20Exotic%20Excel%20Files%20Dropping%20AgentTesla/30150
 CVE-2023-38831 WinRAR Vulnerability Exploited
https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/
 Aruba...</itunes:subtitle><itunes:summary><![CDATA[More Exotic Excel Files Dropping AgentTesla<br /><a href="https://isc.sans.edu/diary/More%20Exotic%20Excel%20Files%20Dropping%20AgentTesla/30150" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/More%20Exotic%20Excel%20Files%20Dropping%20AgentTesla/30150</a><br /> CVE-2023-38831 WinRAR Vulnerability Exploited<br /><a href="https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/" target="_blank" rel="noreferrer noopener">https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/</a><br /> Aruba Vulnerabilities<br /><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-012.txt" target="_blank" rel="noreferrer noopener">https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-012.txt</a><br />]]></itunes:summary><itunes:duration>320</itunes:duration><itunes:keywords>aruba; winrar; xlam;,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8630</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, August 23rd, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-august-23rd-2023--57537767</link><description><![CDATA[Fernet Encryption in Malware<br /><a href="https://isc.sans.edu/forums/diary/Have%20You%20Ever%20Heard%20of%20the%20Fernet%20Encryption%20Algorithm%3F/30146/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Have%20You%20Ever%20Heard%20of%20the%20Fernet%20Encryption%20Algorithm%3F/30146/</a><br /> Malware Triage With Inotify Tools<br /><a href="https://isc.sans.edu/diary/Quick+Malware+Triage+With+Inotify+Tools/30142/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Quick+Malware+Triage+With+Inotify+Tools/30142/</a><br /> Adobe Coldfusion Exploited<br /><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a><br /> Openfire Admin Console Vulnerability Exploited<br /><a href="https://vulncheck.com/blog/openfire-cve-2023-32315" target="_blank" rel="noreferrer noopener">https://vulncheck.com/blog/openfire-cve-2023-32315</a><br /> XLoader Mac Malware Updates<br /><a href="https://www.sentinelone.com/blog/xloaders-latest-trick-new-macos-variant-disguised-as-signed-officenote-app/" target="_blank" rel="noreferrer noopener">https://www.sentinelone.com/blog/xloaders-latest-trick-new-macos-variant-disguised-as-signed-officenote-app/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8628.mp3</guid><pubDate>Wed, 23 Aug 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537767/8628.mp3" length="5372452" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Fernet Encryption in Malware
https://isc.sans.edu/forums/diary/Have%20You%20Ever%20Heard%20of%20the%20Fernet%20Encryption%20Algorithm%3F/30146/
 Malware Triage With Inotify Tools...</itunes:subtitle><itunes:summary><![CDATA[Fernet Encryption in Malware<br /><a href="https://isc.sans.edu/forums/diary/Have%20You%20Ever%20Heard%20of%20the%20Fernet%20Encryption%20Algorithm%3F/30146/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Have%20You%20Ever%20Heard%20of%20the%20Fernet%20Encryption%20Algorithm%3F/30146/</a><br /> Malware Triage With Inotify Tools<br /><a href="https://isc.sans.edu/diary/Quick+Malware+Triage+With+Inotify+Tools/30142/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Quick+Malware+Triage+With+Inotify+Tools/30142/</a><br /> Adobe Coldfusion Exploited<br /><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a><br /> Openfire Admin Console Vulnerability Exploited<br /><a href="https://vulncheck.com/blog/openfire-cve-2023-32315" target="_blank" rel="noreferrer noopener">https://vulncheck.com/blog/openfire-cve-2023-32315</a><br /> XLoader Mac Malware Updates<br /><a href="https://www.sentinelone.com/blog/xloaders-latest-trick-new-macos-variant-disguised-as-signed-officenote-app/" target="_blank" rel="noreferrer noopener">https://www.sentinelone.com/blog/xloaders-latest-trick-new-macos-variant-disguised-as-signed-officenote-app/</a><br />]]></itunes:summary><itunes:duration>362</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,xloader; mac; openfire; adobe;</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8628</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, August 23rd, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-august-23rd-2023--56561968</link><description><![CDATA[Fernet Encryption in Malware<br /><a href="https://isc.sans.edu/forums/diary/Have%20You%20Ever%20Heard%20of%20the%20Fernet%20Encryption%20Algorithm%3F/30146/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Have%20You%20Ever%20Heard%20of%20the%20Fernet%20Encryption%20Algorithm%3F/30146/</a><br /> Malware Triage With Inotify Tools<br /><a href="https://isc.sans.edu/diary/Quick+Malware+Triage+With+Inotify+Tools/30142/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Quick+Malware+Triage+With+Inotify+Tools/30142/</a><br /> Adobe Coldfusion Exploited<br /><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a><br /> Openfire Admin Console Vulnerability Exploited<br /><a href="https://vulncheck.com/blog/openfire-cve-2023-32315" target="_blank" rel="noreferrer noopener">https://vulncheck.com/blog/openfire-cve-2023-32315</a><br /> XLoader Mac Malware Updates<br /><a href="https://www.sentinelone.com/blog/xloaders-latest-trick-new-macos-variant-disguised-as-signed-officenote-app/" target="_blank" rel="noreferrer noopener">https://www.sentinelone.com/blog/xloaders-latest-trick-new-macos-variant-disguised-as-signed-officenote-app/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8628.mp3</guid><pubDate>Wed, 23 Aug 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56561968/8628.mp3" length="5372452" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Fernet Encryption in Malware
https://isc.sans.edu/forums/diary/Have%20You%20Ever%20Heard%20of%20the%20Fernet%20Encryption%20Algorithm%3F/30146/
 Malware Triage With Inotify Tools...</itunes:subtitle><itunes:summary><![CDATA[Fernet Encryption in Malware<br /><a href="https://isc.sans.edu/forums/diary/Have%20You%20Ever%20Heard%20of%20the%20Fernet%20Encryption%20Algorithm%3F/30146/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/forums/diary/Have%20You%20Ever%20Heard%20of%20the%20Fernet%20Encryption%20Algorithm%3F/30146/</a><br /> Malware Triage With Inotify Tools<br /><a href="https://isc.sans.edu/diary/Quick+Malware+Triage+With+Inotify+Tools/30142/" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Quick+Malware+Triage+With+Inotify+Tools/30142/</a><br /> Adobe Coldfusion Exploited<br /><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a><br /> Openfire Admin Console Vulnerability Exploited<br /><a href="https://vulncheck.com/blog/openfire-cve-2023-32315" target="_blank" rel="noreferrer noopener">https://vulncheck.com/blog/openfire-cve-2023-32315</a><br /> XLoader Mac Malware Updates<br /><a href="https://www.sentinelone.com/blog/xloaders-latest-trick-new-macos-variant-disguised-as-signed-officenote-app/" target="_blank" rel="noreferrer noopener">https://www.sentinelone.com/blog/xloaders-latest-trick-new-macos-variant-disguised-as-signed-officenote-app/</a><br />]]></itunes:summary><itunes:duration>362</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,xloader; mac; openfire; adobe;</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8628</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, August 22nd, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-august-22nd-2023--57537723</link><description><![CDATA[SystemBC Scans and ProxyNation<br /><a href="https://isc.sans.edu/diary/SystemBC%20Malware%20Activity%20/30138" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SystemBC%20Malware%20Activity%20/30138</a><br /><a href="https://cybersecurity.att.com/blogs/labs-research/proxynation-the-dark-nexus-between-proxy-apps-and-malware" target="_blank" rel="noreferrer noopener">https://cybersecurity.att.com/blogs/labs-research/proxynation-the-dark-nexus-between-proxy-apps-and-malware</a><br /> Exchange Server Security Update Re-Release<br /><a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/re-release-of-august-2023-exchange-server-security-update/ba-p/3900025" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/exchange-team-blog/re-release-of-august-2023-exchange-server-security-update/ba-p/3900025</a><br /> Ivanti Sentry Vulnerability Exploited<br /><a href="https://forums.ivanti.com/s/article/CVE-2023-38035-API-Authentication-Bypass-on-Sentry-Administrator-Interface?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/CVE-2023-38035-API-Authentication-Bypass-on-Sentry-Administrator-Interface?language=en_US</a><br /> DUO Security Outage<br /><a href="https://status.duo.com/incidents/rw7g0q7ztj8f" target="_blank" rel="noreferrer noopener">https://status.duo.com/incidents/rw7g0q7ztj8f</a><br /> mTLS Vulnerabilities<br /><a href="https://github.blog/2023-08-17-mtls-when-certificate-authentication-is-done-wrong/" target="_blank" rel="noreferrer noopener">https://github.blog/2023-08-17-mtls-when-certificate-authentication-is-done-wrong/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8626.mp3</guid><pubDate>Tue, 22 Aug 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537723/8626.mp3" length="5444306" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>SystemBC Scans and ProxyNation
https://isc.sans.edu/diary/SystemBC%20Malware%20Activity%20/30138
https://cybersecurity.att.com/blogs/labs-research/proxynation-the-dark-nexus-between-proxy-apps-and-malware
 Exchange Server Security Update Re-Release...</itunes:subtitle><itunes:summary><![CDATA[SystemBC Scans and ProxyNation<br /><a href="https://isc.sans.edu/diary/SystemBC%20Malware%20Activity%20/30138" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SystemBC%20Malware%20Activity%20/30138</a><br /><a href="https://cybersecurity.att.com/blogs/labs-research/proxynation-the-dark-nexus-between-proxy-apps-and-malware" target="_blank" rel="noreferrer noopener">https://cybersecurity.att.com/blogs/labs-research/proxynation-the-dark-nexus-between-proxy-apps-and-malware</a><br /> Exchange Server Security Update Re-Release<br /><a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/re-release-of-august-2023-exchange-server-security-update/ba-p/3900025" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/exchange-team-blog/re-release-of-august-2023-exchange-server-security-update/ba-p/3900025</a><br /> Ivanti Sentry Vulnerability Exploited<br /><a href="https://forums.ivanti.com/s/article/CVE-2023-38035-API-Authentication-Bypass-on-Sentry-Administrator-Interface?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/CVE-2023-38035-API-Authentication-Bypass-on-Sentry-Administrator-Interface?language=en_US</a><br /> DUO Security Outage<br /><a href="https://status.duo.com/incidents/rw7g0q7ztj8f" target="_blank" rel="noreferrer noopener">https://status.duo.com/incidents/rw7g0q7ztj8f</a><br /> mTLS Vulnerabilities<br /><a href="https://github.blog/2023-08-17-mtls-when-certificate-authentication-is-done-wrong/" target="_blank" rel="noreferrer noopener">https://github.blog/2023-08-17-mtls-when-certificate-authentication-is-done-wrong/</a><br />]]></itunes:summary><itunes:duration>367</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,mtls; duo; ivanti; sentry; exc,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8626</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, August 22nd, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-august-22nd-2023--56550656</link><description><![CDATA[SystemBC Scans and ProxyNation<br /><a href="https://isc.sans.edu/diary/SystemBC%20Malware%20Activity%20/30138" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SystemBC%20Malware%20Activity%20/30138</a><br /><a href="https://cybersecurity.att.com/blogs/labs-research/proxynation-the-dark-nexus-between-proxy-apps-and-malware" target="_blank" rel="noreferrer noopener">https://cybersecurity.att.com/blogs/labs-research/proxynation-the-dark-nexus-between-proxy-apps-and-malware</a><br /> Exchange Server Security Update Re-Release<br /><a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/re-release-of-august-2023-exchange-server-security-update/ba-p/3900025" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/exchange-team-blog/re-release-of-august-2023-exchange-server-security-update/ba-p/3900025</a><br /> Ivanti Sentry Vulnerability Exploited<br /><a href="https://forums.ivanti.com/s/article/CVE-2023-38035-API-Authentication-Bypass-on-Sentry-Administrator-Interface?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/CVE-2023-38035-API-Authentication-Bypass-on-Sentry-Administrator-Interface?language=en_US</a><br /> DUO Security Outage<br /><a href="https://status.duo.com/incidents/rw7g0q7ztj8f" target="_blank" rel="noreferrer noopener">https://status.duo.com/incidents/rw7g0q7ztj8f</a><br /> mTLS Vulnerabilities<br /><a href="https://github.blog/2023-08-17-mtls-when-certificate-authentication-is-done-wrong/" target="_blank" rel="noreferrer noopener">https://github.blog/2023-08-17-mtls-when-certificate-authentication-is-done-wrong/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8626.mp3</guid><pubDate>Tue, 22 Aug 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56550656/8626.mp3" length="5444306" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>SystemBC Scans and ProxyNation
https://isc.sans.edu/diary/SystemBC%20Malware%20Activity%20/30138
https://cybersecurity.att.com/blogs/labs-research/proxynation-the-dark-nexus-between-proxy-apps-and-malware
 Exchange Server Security Update Re-Release...</itunes:subtitle><itunes:summary><![CDATA[SystemBC Scans and ProxyNation<br /><a href="https://isc.sans.edu/diary/SystemBC%20Malware%20Activity%20/30138" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/SystemBC%20Malware%20Activity%20/30138</a><br /><a href="https://cybersecurity.att.com/blogs/labs-research/proxynation-the-dark-nexus-between-proxy-apps-and-malware" target="_blank" rel="noreferrer noopener">https://cybersecurity.att.com/blogs/labs-research/proxynation-the-dark-nexus-between-proxy-apps-and-malware</a><br /> Exchange Server Security Update Re-Release<br /><a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/re-release-of-august-2023-exchange-server-security-update/ba-p/3900025" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/exchange-team-blog/re-release-of-august-2023-exchange-server-security-update/ba-p/3900025</a><br /> Ivanti Sentry Vulnerability Exploited<br /><a href="https://forums.ivanti.com/s/article/CVE-2023-38035-API-Authentication-Bypass-on-Sentry-Administrator-Interface?language=en_US" target="_blank" rel="noreferrer noopener">https://forums.ivanti.com/s/article/CVE-2023-38035-API-Authentication-Bypass-on-Sentry-Administrator-Interface?language=en_US</a><br /> DUO Security Outage<br /><a href="https://status.duo.com/incidents/rw7g0q7ztj8f" target="_blank" rel="noreferrer noopener">https://status.duo.com/incidents/rw7g0q7ztj8f</a><br /> mTLS Vulnerabilities<br /><a href="https://github.blog/2023-08-17-mtls-when-certificate-authentication-is-done-wrong/" target="_blank" rel="noreferrer noopener">https://github.blog/2023-08-17-mtls-when-certificate-authentication-is-done-wrong/</a><br />]]></itunes:summary><itunes:duration>367</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,mtls; duo; ivanti; sentry; exc,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8626</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, August 21st, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-august-21st-2023--57537726</link><description><![CDATA[From a Zalando Phish to a RAT<br /><a href="https://isc.sans.edu/diary/From%20a%20Zalando%20Phishing%20to%20a%20RAT/30136" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/From%20a%20Zalando%20Phishing%20to%20a%20RAT/30136</a><br /> RARLAB WinRAR Recovery Volume Vulnerability<br /><a href="https://www.zerodayinitiative.com/advisories/ZDI-23-1152/" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/advisories/ZDI-23-1152/</a><br /> Hotmail SPF Record Error Leads to spam false positives<br /><a href="https://www.bleepingcomputer.com/news/microsoft/hotmail-email-delivery-fails-after-microsoft-misconfigures-dns/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/microsoft/hotmail-email-delivery-fails-after-microsoft-misconfigures-dns/</a><br /> Chinese Entanglement | DLL Hijacking in the Asian Gambling Sector<br /><a href="https://www.sentinelone.com/labs/chinese-entanglement-dll-hijacking-in-the-asian-gambling-sector/" target="_blank" rel="noreferrer noopener">https://www.sentinelone.com/labs/chinese-entanglement-dll-hijacking-in-the-asian-gambling-sector/</a><br /> Google Chrome to Warn Users of Malicious Extensions<br /><a href="https://betanews.com/2023/08/17/google-chrome-to-warn-users-about-problematic-extensions/" target="_blank" rel="noreferrer noopener">https://betanews.com/2023/08/17/google-chrome-to-warn-users-about-problematic-extensions/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8624.mp3</guid><pubDate>Mon, 21 Aug 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537726/8624.mp3" length="5002495" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>From a Zalando Phish to a RAT
https://isc.sans.edu/diary/From%20a%20Zalando%20Phishing%20to%20a%20RAT/30136
 RARLAB WinRAR Recovery Volume Vulnerability
https://www.zerodayinitiative.com/advisories/ZDI-23-1152/
 Hotmail SPF Record Error Leads to spam...</itunes:subtitle><itunes:summary><![CDATA[From a Zalando Phish to a RAT<br /><a href="https://isc.sans.edu/diary/From%20a%20Zalando%20Phishing%20to%20a%20RAT/30136" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/From%20a%20Zalando%20Phishing%20to%20a%20RAT/30136</a><br /> RARLAB WinRAR Recovery Volume Vulnerability<br /><a href="https://www.zerodayinitiative.com/advisories/ZDI-23-1152/" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/advisories/ZDI-23-1152/</a><br /> Hotmail SPF Record Error Leads to spam false positives<br /><a href="https://www.bleepingcomputer.com/news/microsoft/hotmail-email-delivery-fails-after-microsoft-misconfigures-dns/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/microsoft/hotmail-email-delivery-fails-after-microsoft-misconfigures-dns/</a><br /> Chinese Entanglement | DLL Hijacking in the Asian Gambling Sector<br /><a href="https://www.sentinelone.com/labs/chinese-entanglement-dll-hijacking-in-the-asian-gambling-sector/" target="_blank" rel="noreferrer noopener">https://www.sentinelone.com/labs/chinese-entanglement-dll-hijacking-in-the-asian-gambling-sector/</a><br /> Google Chrome to Warn Users of Malicious Extensions<br /><a href="https://betanews.com/2023/08/17/google-chrome-to-warn-users-about-problematic-extensions/" target="_blank" rel="noreferrer noopener">https://betanews.com/2023/08/17/google-chrome-to-warn-users-about-problematic-extensions/</a><br />]]></itunes:summary><itunes:duration>336</itunes:duration><itunes:keywords>business,chrome; extensions; warning; v,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8624</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, August 21st, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-august-21st-2023--56533670</link><description><![CDATA[From a Zalando Phish to a RAT<br /><a href="https://isc.sans.edu/diary/From%20a%20Zalando%20Phishing%20to%20a%20RAT/30136" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/From%20a%20Zalando%20Phishing%20to%20a%20RAT/30136</a><br /> RARLAB WinRAR Recovery Volume Vulnerability<br /><a href="https://www.zerodayinitiative.com/advisories/ZDI-23-1152/" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/advisories/ZDI-23-1152/</a><br /> Hotmail SPF Record Error Leads to spam false positives<br /><a href="https://www.bleepingcomputer.com/news/microsoft/hotmail-email-delivery-fails-after-microsoft-misconfigures-dns/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/microsoft/hotmail-email-delivery-fails-after-microsoft-misconfigures-dns/</a><br /> Chinese Entanglement | DLL Hijacking in the Asian Gambling Sector<br /><a href="https://www.sentinelone.com/labs/chinese-entanglement-dll-hijacking-in-the-asian-gambling-sector/" target="_blank" rel="noreferrer noopener">https://www.sentinelone.com/labs/chinese-entanglement-dll-hijacking-in-the-asian-gambling-sector/</a><br /> Google Chrome to Warn Users of Malicious Extensions<br /><a href="https://betanews.com/2023/08/17/google-chrome-to-warn-users-about-problematic-extensions/" target="_blank" rel="noreferrer noopener">https://betanews.com/2023/08/17/google-chrome-to-warn-users-about-problematic-extensions/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8624.mp3</guid><pubDate>Mon, 21 Aug 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56533670/8624.mp3" length="5002495" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>From a Zalando Phish to a RAT
https://isc.sans.edu/diary/From%20a%20Zalando%20Phishing%20to%20a%20RAT/30136
 RARLAB WinRAR Recovery Volume Vulnerability
https://www.zerodayinitiative.com/advisories/ZDI-23-1152/
 Hotmail SPF Record Error Leads to spam...</itunes:subtitle><itunes:summary><![CDATA[From a Zalando Phish to a RAT<br /><a href="https://isc.sans.edu/diary/From%20a%20Zalando%20Phishing%20to%20a%20RAT/30136" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/From%20a%20Zalando%20Phishing%20to%20a%20RAT/30136</a><br /> RARLAB WinRAR Recovery Volume Vulnerability<br /><a href="https://www.zerodayinitiative.com/advisories/ZDI-23-1152/" target="_blank" rel="noreferrer noopener">https://www.zerodayinitiative.com/advisories/ZDI-23-1152/</a><br /> Hotmail SPF Record Error Leads to spam false positives<br /><a href="https://www.bleepingcomputer.com/news/microsoft/hotmail-email-delivery-fails-after-microsoft-misconfigures-dns/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/microsoft/hotmail-email-delivery-fails-after-microsoft-misconfigures-dns/</a><br /> Chinese Entanglement | DLL Hijacking in the Asian Gambling Sector<br /><a href="https://www.sentinelone.com/labs/chinese-entanglement-dll-hijacking-in-the-asian-gambling-sector/" target="_blank" rel="noreferrer noopener">https://www.sentinelone.com/labs/chinese-entanglement-dll-hijacking-in-the-asian-gambling-sector/</a><br /> Google Chrome to Warn Users of Malicious Extensions<br /><a href="https://betanews.com/2023/08/17/google-chrome-to-warn-users-about-problematic-extensions/" target="_blank" rel="noreferrer noopener">https://betanews.com/2023/08/17/google-chrome-to-warn-users-about-problematic-extensions/</a><br />]]></itunes:summary><itunes:duration>336</itunes:duration><itunes:keywords>business,chrome; extensions; warning; v,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8624</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, August 18th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-august-18th-2023--57537796</link><description><![CDATA[Command Line Parsing - Are These Really Unique Strings?<br /><a href="https://isc.sans.edu/diary/Command%20Line%20Parsing%20-%20Are%20These%20Really%20Unique%20Strings%3F/30126" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Command%20Line%20Parsing%20-%20Are%20These%20Really%20Unique%20Strings%3F/30126</a><br /> iOS 16 Fake Airplane Mode<br /><a href="https://www.jamf.com/blog/fake-airplane-mode-a-mobile-tampering-technique-to-maintain-connectivity/" target="_blank" rel="noreferrer noopener">https://www.jamf.com/blog/fake-airplane-mode-a-mobile-tampering-technique-to-maintain-connectivity/</a><br /> LinkedIn Attacks<br /><a href="https://cyberint.com/blog/research/linkedin-accounts-under-attack-how-to-protect-yourself/" target="_blank" rel="noreferrer noopener">https://cyberint.com/blog/research/linkedin-accounts-under-attack-how-to-protect-yourself/</a><br /> Robot Vacuum Privacy Issues<br /><a href="https://dontvacuum.me/talks/DEFCON31/DEFCON31-vacuum-robots-final.pdf" target="_blank" rel="noreferrer noopener">https://dontvacuum.me/talks/DEFCON31/DEFCON31-vacuum-robots-final.pdf</a><br /><a href="https://dontvacuum.me/" target="_blank" rel="noreferrer noopener">https://dontvacuum.me/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8622.mp3</guid><pubDate>Fri, 18 Aug 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537796/8622.mp3" length="5121971" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Command Line Parsing - Are These Really Unique Strings?
https://isc.sans.edu/diary/Command%20Line%20Parsing%20-%20Are%20These%20Really%20Unique%20Strings%3F/30126
 iOS 16 Fake Airplane Mode...</itunes:subtitle><itunes:summary><![CDATA[Command Line Parsing - Are These Really Unique Strings?<br /><a href="https://isc.sans.edu/diary/Command%20Line%20Parsing%20-%20Are%20These%20Really%20Unique%20Strings%3F/30126" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Command%20Line%20Parsing%20-%20Are%20These%20Really%20Unique%20Strings%3F/30126</a><br /> iOS 16 Fake Airplane Mode<br /><a href="https://www.jamf.com/blog/fake-airplane-mode-a-mobile-tampering-technique-to-maintain-connectivity/" target="_blank" rel="noreferrer noopener">https://www.jamf.com/blog/fake-airplane-mode-a-mobile-tampering-technique-to-maintain-connectivity/</a><br /> LinkedIn Attacks<br /><a href="https://cyberint.com/blog/research/linkedin-accounts-under-attack-how-to-protect-yourself/" target="_blank" rel="noreferrer noopener">https://cyberint.com/blog/research/linkedin-accounts-under-attack-how-to-protect-yourself/</a><br /> Robot Vacuum Privacy Issues<br /><a href="https://dontvacuum.me/talks/DEFCON31/DEFCON31-vacuum-robots-final.pdf" target="_blank" rel="noreferrer noopener">https://dontvacuum.me/talks/DEFCON31/DEFCON31-vacuum-robots-final.pdf</a><br /><a href="https://dontvacuum.me/" target="_blank" rel="noreferrer noopener">https://dontvacuum.me/</a><br />]]></itunes:summary><itunes:duration>344</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,robots; vacuum; privacy; linke,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8622</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, August 18th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-august-18th-2023--56507710</link><description><![CDATA[Command Line Parsing - Are These Really Unique Strings?<br /><a href="https://isc.sans.edu/diary/Command%20Line%20Parsing%20-%20Are%20These%20Really%20Unique%20Strings%3F/30126" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Command%20Line%20Parsing%20-%20Are%20These%20Really%20Unique%20Strings%3F/30126</a><br /> iOS 16 Fake Airplane Mode<br /><a href="https://www.jamf.com/blog/fake-airplane-mode-a-mobile-tampering-technique-to-maintain-connectivity/" target="_blank" rel="noreferrer noopener">https://www.jamf.com/blog/fake-airplane-mode-a-mobile-tampering-technique-to-maintain-connectivity/</a><br /> LinkedIn Attacks<br /><a href="https://cyberint.com/blog/research/linkedin-accounts-under-attack-how-to-protect-yourself/" target="_blank" rel="noreferrer noopener">https://cyberint.com/blog/research/linkedin-accounts-under-attack-how-to-protect-yourself/</a><br /> Robot Vacuum Privacy Issues<br /><a href="https://dontvacuum.me/talks/DEFCON31/DEFCON31-vacuum-robots-final.pdf" target="_blank" rel="noreferrer noopener">https://dontvacuum.me/talks/DEFCON31/DEFCON31-vacuum-robots-final.pdf</a><br /><a href="https://dontvacuum.me/" target="_blank" rel="noreferrer noopener">https://dontvacuum.me/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8622.mp3</guid><pubDate>Fri, 18 Aug 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56507710/8622.mp3" length="5121971" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Command Line Parsing - Are These Really Unique Strings?
https://isc.sans.edu/diary/Command%20Line%20Parsing%20-%20Are%20These%20Really%20Unique%20Strings%3F/30126
 iOS 16 Fake Airplane Mode...</itunes:subtitle><itunes:summary><![CDATA[Command Line Parsing - Are These Really Unique Strings?<br /><a href="https://isc.sans.edu/diary/Command%20Line%20Parsing%20-%20Are%20These%20Really%20Unique%20Strings%3F/30126" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Command%20Line%20Parsing%20-%20Are%20These%20Really%20Unique%20Strings%3F/30126</a><br /> iOS 16 Fake Airplane Mode<br /><a href="https://www.jamf.com/blog/fake-airplane-mode-a-mobile-tampering-technique-to-maintain-connectivity/" target="_blank" rel="noreferrer noopener">https://www.jamf.com/blog/fake-airplane-mode-a-mobile-tampering-technique-to-maintain-connectivity/</a><br /> LinkedIn Attacks<br /><a href="https://cyberint.com/blog/research/linkedin-accounts-under-attack-how-to-protect-yourself/" target="_blank" rel="noreferrer noopener">https://cyberint.com/blog/research/linkedin-accounts-under-attack-how-to-protect-yourself/</a><br /> Robot Vacuum Privacy Issues<br /><a href="https://dontvacuum.me/talks/DEFCON31/DEFCON31-vacuum-robots-final.pdf" target="_blank" rel="noreferrer noopener">https://dontvacuum.me/talks/DEFCON31/DEFCON31-vacuum-robots-final.pdf</a><br /><a href="https://dontvacuum.me/" target="_blank" rel="noreferrer noopener">https://dontvacuum.me/</a><br />]]></itunes:summary><itunes:duration>344</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,robots; vacuum; privacy; linke,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8622</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, August 17th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-august-17th-2023--57537771</link><description><![CDATA[PowerShell Gallery Prone to Typosqatting, Other Sypply Chain Attacks<br /><a href="https://www.darkreading.com/application-security/powershell-gallery-prone-to-typosquatting-other-supply-chain-attacks" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/application-security/powershell-gallery-prone-to-typosquatting-other-supply-chain-attacks</a><br /> Windows Random Time Issues<br /><a href="https://arstechnica.com/security/2023/08/windows-feature-that-resets-system-clocks-based-on-random-data-is-wreaking-havoc/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2023/08/windows-feature-that-resets-system-clocks-based-on-random-data-is-wreaking-havoc/</a><br /> Energy Company Targeted in QR Code Campaign<br /><a href="https://cofense.com/blog/major-energy-company-targeted-in-large-qr-code-campaign/" target="_blank" rel="noreferrer noopener">https://cofense.com/blog/major-energy-company-targeted-in-large-qr-code-campaign/</a><br /> New Citrix Scanner from Mandiant<br /><a href="https://www.mandiant.com/resources/blog/citrix-adc-vulnerability-ioc-scanner" target="_blank" rel="noreferrer noopener">https://www.mandiant.com/resources/blog/citrix-adc-vulnerability-ioc-scanner</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8620.mp3</guid><pubDate>Thu, 17 Aug 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537771/8620.mp3" length="5915799" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>PowerShell Gallery Prone to Typosqatting, Other Sypply Chain Attacks
https://www.darkreading.com/application-security/powershell-gallery-prone-to-typosquatting-other-supply-chain-attacks
 Windows Random Time Issues...</itunes:subtitle><itunes:summary><![CDATA[PowerShell Gallery Prone to Typosqatting, Other Sypply Chain Attacks<br /><a href="https://www.darkreading.com/application-security/powershell-gallery-prone-to-typosquatting-other-supply-chain-attacks" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/application-security/powershell-gallery-prone-to-typosquatting-other-supply-chain-attacks</a><br /> Windows Random Time Issues<br /><a href="https://arstechnica.com/security/2023/08/windows-feature-that-resets-system-clocks-based-on-random-data-is-wreaking-havoc/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2023/08/windows-feature-that-resets-system-clocks-based-on-random-data-is-wreaking-havoc/</a><br /> Energy Company Targeted in QR Code Campaign<br /><a href="https://cofense.com/blog/major-energy-company-targeted-in-large-qr-code-campaign/" target="_blank" rel="noreferrer noopener">https://cofense.com/blog/major-energy-company-targeted-in-large-qr-code-campaign/</a><br /> New Citrix Scanner from Mandiant<br /><a href="https://www.mandiant.com/resources/blog/citrix-adc-vulnerability-ioc-scanner" target="_blank" rel="noreferrer noopener">https://www.mandiant.com/resources/blog/citrix-adc-vulnerability-ioc-scanner</a><br />]]></itunes:summary><itunes:duration>401</itunes:duration><itunes:keywords>business,citrix; energey; qr; time; win,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8620</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, August 17th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-august-17th-2023--56496915</link><description><![CDATA[PowerShell Gallery Prone to Typosqatting, Other Sypply Chain Attacks<br /><a href="https://www.darkreading.com/application-security/powershell-gallery-prone-to-typosquatting-other-supply-chain-attacks" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/application-security/powershell-gallery-prone-to-typosquatting-other-supply-chain-attacks</a><br /> Windows Random Time Issues<br /><a href="https://arstechnica.com/security/2023/08/windows-feature-that-resets-system-clocks-based-on-random-data-is-wreaking-havoc/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2023/08/windows-feature-that-resets-system-clocks-based-on-random-data-is-wreaking-havoc/</a><br /> Energy Company Targeted in QR Code Campaign<br /><a href="https://cofense.com/blog/major-energy-company-targeted-in-large-qr-code-campaign/" target="_blank" rel="noreferrer noopener">https://cofense.com/blog/major-energy-company-targeted-in-large-qr-code-campaign/</a><br /> New Citrix Scanner from Mandiant<br /><a href="https://www.mandiant.com/resources/blog/citrix-adc-vulnerability-ioc-scanner" target="_blank" rel="noreferrer noopener">https://www.mandiant.com/resources/blog/citrix-adc-vulnerability-ioc-scanner</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8620.mp3</guid><pubDate>Thu, 17 Aug 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56496915/8620.mp3" length="5915799" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>PowerShell Gallery Prone to Typosqatting, Other Sypply Chain Attacks
https://www.darkreading.com/application-security/powershell-gallery-prone-to-typosquatting-other-supply-chain-attacks
 Windows Random Time Issues...</itunes:subtitle><itunes:summary><![CDATA[PowerShell Gallery Prone to Typosqatting, Other Sypply Chain Attacks<br /><a href="https://www.darkreading.com/application-security/powershell-gallery-prone-to-typosquatting-other-supply-chain-attacks" target="_blank" rel="noreferrer noopener">https://www.darkreading.com/application-security/powershell-gallery-prone-to-typosquatting-other-supply-chain-attacks</a><br /> Windows Random Time Issues<br /><a href="https://arstechnica.com/security/2023/08/windows-feature-that-resets-system-clocks-based-on-random-data-is-wreaking-havoc/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/security/2023/08/windows-feature-that-resets-system-clocks-based-on-random-data-is-wreaking-havoc/</a><br /> Energy Company Targeted in QR Code Campaign<br /><a href="https://cofense.com/blog/major-energy-company-targeted-in-large-qr-code-campaign/" target="_blank" rel="noreferrer noopener">https://cofense.com/blog/major-energy-company-targeted-in-large-qr-code-campaign/</a><br /> New Citrix Scanner from Mandiant<br /><a href="https://www.mandiant.com/resources/blog/citrix-adc-vulnerability-ioc-scanner" target="_blank" rel="noreferrer noopener">https://www.mandiant.com/resources/blog/citrix-adc-vulnerability-ioc-scanner</a><br />]]></itunes:summary><itunes:duration>401</itunes:duration><itunes:keywords>business,citrix; energey; qr; time; win,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8620</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, August 16th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-august-16th-2023--57537782</link><description><![CDATA[macOS Background Task Manager Bypass<br /><a href="https://www.wired.com/story/apple-mac-background-task-management-flaw/" target="_blank" rel="noreferrer noopener">https://www.wired.com/story/apple-mac-background-task-management-flaw/</a><br /> Ivanti Avalanche Vulnerability<br /><a href="https://www.tenable.com/security/research/tra-2023-27" target="_blank" rel="noreferrer noopener">https://www.tenable.com/security/research/tra-2023-27</a><br /> Exploiting Synology NAS Cloud Connectivity<br /><a href="https://claroty.com/team82/research/a-pain-in-the-nas-exploiting-cloud-connectivity-to-pwn-your-nas-synology-ds920-edition" target="_blank" rel="noreferrer noopener">https://claroty.com/team82/research/a-pain-in-the-nas-exploiting-cloud-connectivity-to-pwn-your-nas-synology-ds920-edition</a><br /> Fake Crypto Currency Apps Offered as "Beta" versions<br /><a href="https://www.ic3.gov/Media/Y2023/PSA230814" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/Media/Y2023/PSA230814</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8618.mp3</guid><pubDate>Wed, 16 Aug 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537782/8618.mp3" length="5255461" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>macOS Background Task Manager Bypass
https://www.wired.com/story/apple-mac-background-task-management-flaw/
 Ivanti Avalanche Vulnerability
https://www.tenable.com/security/research/tra-2023-27
 Exploiting Synology NAS Cloud Connectivity...</itunes:subtitle><itunes:summary><![CDATA[macOS Background Task Manager Bypass<br /><a href="https://www.wired.com/story/apple-mac-background-task-management-flaw/" target="_blank" rel="noreferrer noopener">https://www.wired.com/story/apple-mac-background-task-management-flaw/</a><br /> Ivanti Avalanche Vulnerability<br /><a href="https://www.tenable.com/security/research/tra-2023-27" target="_blank" rel="noreferrer noopener">https://www.tenable.com/security/research/tra-2023-27</a><br /> Exploiting Synology NAS Cloud Connectivity<br /><a href="https://claroty.com/team82/research/a-pain-in-the-nas-exploiting-cloud-connectivity-to-pwn-your-nas-synology-ds920-edition" target="_blank" rel="noreferrer noopener">https://claroty.com/team82/research/a-pain-in-the-nas-exploiting-cloud-connectivity-to-pwn-your-nas-synology-ds920-edition</a><br /> Fake Crypto Currency Apps Offered as "Beta" versions<br /><a href="https://www.ic3.gov/Media/Y2023/PSA230814" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/Media/Y2023/PSA230814</a><br />]]></itunes:summary><itunes:duration>354</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,fbi; crypto; apps; beta; synol,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8618</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, August 16th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-august-16th-2023--56481969</link><description><![CDATA[macOS Background Task Manager Bypass<br /><a href="https://www.wired.com/story/apple-mac-background-task-management-flaw/" target="_blank" rel="noreferrer noopener">https://www.wired.com/story/apple-mac-background-task-management-flaw/</a><br /> Ivanti Avalanche Vulnerability<br /><a href="https://www.tenable.com/security/research/tra-2023-27" target="_blank" rel="noreferrer noopener">https://www.tenable.com/security/research/tra-2023-27</a><br /> Exploiting Synology NAS Cloud Connectivity<br /><a href="https://claroty.com/team82/research/a-pain-in-the-nas-exploiting-cloud-connectivity-to-pwn-your-nas-synology-ds920-edition" target="_blank" rel="noreferrer noopener">https://claroty.com/team82/research/a-pain-in-the-nas-exploiting-cloud-connectivity-to-pwn-your-nas-synology-ds920-edition</a><br /> Fake Crypto Currency Apps Offered as "Beta" versions<br /><a href="https://www.ic3.gov/Media/Y2023/PSA230814" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/Media/Y2023/PSA230814</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8618.mp3</guid><pubDate>Wed, 16 Aug 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56481969/8618.mp3" length="5255461" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>macOS Background Task Manager Bypass
https://www.wired.com/story/apple-mac-background-task-management-flaw/
 Ivanti Avalanche Vulnerability
https://www.tenable.com/security/research/tra-2023-27
 Exploiting Synology NAS Cloud Connectivity...</itunes:subtitle><itunes:summary><![CDATA[macOS Background Task Manager Bypass<br /><a href="https://www.wired.com/story/apple-mac-background-task-management-flaw/" target="_blank" rel="noreferrer noopener">https://www.wired.com/story/apple-mac-background-task-management-flaw/</a><br /> Ivanti Avalanche Vulnerability<br /><a href="https://www.tenable.com/security/research/tra-2023-27" target="_blank" rel="noreferrer noopener">https://www.tenable.com/security/research/tra-2023-27</a><br /> Exploiting Synology NAS Cloud Connectivity<br /><a href="https://claroty.com/team82/research/a-pain-in-the-nas-exploiting-cloud-connectivity-to-pwn-your-nas-synology-ds920-edition" target="_blank" rel="noreferrer noopener">https://claroty.com/team82/research/a-pain-in-the-nas-exploiting-cloud-connectivity-to-pwn-your-nas-synology-ds920-edition</a><br /> Fake Crypto Currency Apps Offered as "Beta" versions<br /><a href="https://www.ic3.gov/Media/Y2023/PSA230814" target="_blank" rel="noreferrer noopener">https://www.ic3.gov/Media/Y2023/PSA230814</a><br />]]></itunes:summary><itunes:duration>354</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,fbi; crypto; apps; beta; synol,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8618</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, August 15th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-august-15th-2023--57537788</link><description><![CDATA[PDFiD False Positives Revisited<br /><a href="https://isc.sans.edu/diary/PDFiD%3A%20False%20Positives%20Revisited/30122" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/PDFiD%3A%20False%20Positives%20Revisited/30122</a><br /> CVE-2023-32019 Fix Enabled by Default;<br /><a href="https://support.microsoft.com/en-us/topic/kb5028407-how-to-manage-the-vulnerability-associated-with-cve-2023-32019-bd6ed35f-48b1-41f6-bd19-d2d97270f080" target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-us/topic/kb5028407-how-to-manage-the-vulnerability-associated-with-cve-2023-32019-bd6ed35f-48b1-41f6-bd19-d2d97270f080</a><br /> CyberPower and Dataprobe Vulnerabilities<br /><a href="https://www.trellix.com/en-us/about/newsroom/stories/research/the-threat-lurking-in-data-centers.html" target="_blank" rel="noreferrer noopener">https://www.trellix.com/en-us/about/newsroom/stories/research/the-threat-lurking-in-data-centers.html</a><br /> Ford WiFi Driver Vulnerability<br /><a href="https://www.ti.com/lit/er/swra773/swra773.pdf?ts=1691717352391&amp;ref_url=https%253A%252F%252Fmedia.ford.com%252F" target="_blank" rel="noreferrer noopener">https://www.ti.com/lit/er/swra773/swra773.pdf?ts=1691717352391&amp;ref_url=https%253A%252F%252Fmedia.ford.com%252F</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8616.mp3</guid><pubDate>Tue, 15 Aug 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537788/8616.mp3" length="5220656" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>PDFiD False Positives Revisited
https://isc.sans.edu/diary/PDFiD%3A%20False%20Positives%20Revisited/30122
 CVE-2023-32019 Fix Enabled by Default;...</itunes:subtitle><itunes:summary><![CDATA[PDFiD False Positives Revisited<br /><a href="https://isc.sans.edu/diary/PDFiD%3A%20False%20Positives%20Revisited/30122" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/PDFiD%3A%20False%20Positives%20Revisited/30122</a><br /> CVE-2023-32019 Fix Enabled by Default;<br /><a href="https://support.microsoft.com/en-us/topic/kb5028407-how-to-manage-the-vulnerability-associated-with-cve-2023-32019-bd6ed35f-48b1-41f6-bd19-d2d97270f080" target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-us/topic/kb5028407-how-to-manage-the-vulnerability-associated-with-cve-2023-32019-bd6ed35f-48b1-41f6-bd19-d2d97270f080</a><br /> CyberPower and Dataprobe Vulnerabilities<br /><a href="https://www.trellix.com/en-us/about/newsroom/stories/research/the-threat-lurking-in-data-centers.html" target="_blank" rel="noreferrer noopener">https://www.trellix.com/en-us/about/newsroom/stories/research/the-threat-lurking-in-data-centers.html</a><br /> Ford WiFi Driver Vulnerability<br /><a href="https://www.ti.com/lit/er/swra773/swra773.pdf?ts=1691717352391&amp;ref_url=https%253A%252F%252Fmedia.ford.com%252F" target="_blank" rel="noreferrer noopener">https://www.ti.com/lit/er/swra773/swra773.pdf?ts=1691717352391&amp;ref_url=https%253A%252F%252Fmedia.ford.com%252F</a><br />]]></itunes:summary><itunes:duration>351</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,ford; wifi; cyberpower; datapr,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8616</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, August 15th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-august-15th-2023--56469772</link><description><![CDATA[PDFiD False Positives Revisited<br /><a href="https://isc.sans.edu/diary/PDFiD%3A%20False%20Positives%20Revisited/30122" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/PDFiD%3A%20False%20Positives%20Revisited/30122</a><br /> CVE-2023-32019 Fix Enabled by Default;<br /><a href="https://support.microsoft.com/en-us/topic/kb5028407-how-to-manage-the-vulnerability-associated-with-cve-2023-32019-bd6ed35f-48b1-41f6-bd19-d2d97270f080" target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-us/topic/kb5028407-how-to-manage-the-vulnerability-associated-with-cve-2023-32019-bd6ed35f-48b1-41f6-bd19-d2d97270f080</a><br /> CyberPower and Dataprobe Vulnerabilities<br /><a href="https://www.trellix.com/en-us/about/newsroom/stories/research/the-threat-lurking-in-data-centers.html" target="_blank" rel="noreferrer noopener">https://www.trellix.com/en-us/about/newsroom/stories/research/the-threat-lurking-in-data-centers.html</a><br /> Ford WiFi Driver Vulnerability<br /><a href="https://www.ti.com/lit/er/swra773/swra773.pdf?ts=1691717352391&amp;ref_url=https%253A%252F%252Fmedia.ford.com%252F" target="_blank" rel="noreferrer noopener">https://www.ti.com/lit/er/swra773/swra773.pdf?ts=1691717352391&amp;ref_url=https%253A%252F%252Fmedia.ford.com%252F</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8616.mp3</guid><pubDate>Tue, 15 Aug 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56469772/8616.mp3" length="5220656" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>PDFiD False Positives Revisited
https://isc.sans.edu/diary/PDFiD%3A%20False%20Positives%20Revisited/30122
 CVE-2023-32019 Fix Enabled by Default;...</itunes:subtitle><itunes:summary><![CDATA[PDFiD False Positives Revisited<br /><a href="https://isc.sans.edu/diary/PDFiD%3A%20False%20Positives%20Revisited/30122" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/PDFiD%3A%20False%20Positives%20Revisited/30122</a><br /> CVE-2023-32019 Fix Enabled by Default;<br /><a href="https://support.microsoft.com/en-us/topic/kb5028407-how-to-manage-the-vulnerability-associated-with-cve-2023-32019-bd6ed35f-48b1-41f6-bd19-d2d97270f080" target="_blank" rel="noreferrer noopener">https://support.microsoft.com/en-us/topic/kb5028407-how-to-manage-the-vulnerability-associated-with-cve-2023-32019-bd6ed35f-48b1-41f6-bd19-d2d97270f080</a><br /> CyberPower and Dataprobe Vulnerabilities<br /><a href="https://www.trellix.com/en-us/about/newsroom/stories/research/the-threat-lurking-in-data-centers.html" target="_blank" rel="noreferrer noopener">https://www.trellix.com/en-us/about/newsroom/stories/research/the-threat-lurking-in-data-centers.html</a><br /> Ford WiFi Driver Vulnerability<br /><a href="https://www.ti.com/lit/er/swra773/swra773.pdf?ts=1691717352391&amp;ref_url=https%253A%252F%252Fmedia.ford.com%252F" target="_blank" rel="noreferrer noopener">https://www.ti.com/lit/er/swra773/swra773.pdf?ts=1691717352391&amp;ref_url=https%253A%252F%252Fmedia.ford.com%252F</a><br />]]></itunes:summary><itunes:duration>351</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,ford; wifi; cyberpower; datapr,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8616</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, August 14th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-august-14th-2023--57537739</link><description><![CDATA[Show Me All Your Windows<br /><a href="https://isc.sans.edu/diary/Show%20me%20All%20Your%20Windows!/30116" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Show%20me%20All%20Your%20Windows!/30116</a><br /> Zero Touch Pwn<br /><a href="https://blog.syss.com/posts/zero-touch-pwn/" target="_blank" rel="noreferrer noopener">https://blog.syss.com/posts/zero-touch-pwn/</a><br /> Maginot DNS Spoofing Attack<br /><a href="https://www.usenix.org/conference/usenixsecurity23/presentation/li-xiang" target="_blank" rel="noreferrer noopener">https://www.usenix.org/conference/usenixsecurity23/presentation/li-xiang</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8614.mp3</guid><pubDate>Mon, 14 Aug 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537739/8614.mp3" length="4931025" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Show Me All Your Windows
https://isc.sans.edu/diary/Show%20me%20All%20Your%20Windows!/30116
 Zero Touch Pwn
https://blog.syss.com/posts/zero-touch-pwn/
 Maginot DNS Spoofing Attack
https://www.usenix.org/conference/usenixsecurity23/presentation/li-xiang
</itunes:subtitle><itunes:summary><![CDATA[Show Me All Your Windows<br /><a href="https://isc.sans.edu/diary/Show%20me%20All%20Your%20Windows!/30116" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Show%20me%20All%20Your%20Windows!/30116</a><br /> Zero Touch Pwn<br /><a href="https://blog.syss.com/posts/zero-touch-pwn/" target="_blank" rel="noreferrer noopener">https://blog.syss.com/posts/zero-touch-pwn/</a><br /> Maginot DNS Spoofing Attack<br /><a href="https://www.usenix.org/conference/usenixsecurity23/presentation/li-xiang" target="_blank" rel="noreferrer noopener">https://www.usenix.org/conference/usenixsecurity23/presentation/li-xiang</a><br />]]></itunes:summary><itunes:duration>331</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,windows; python; anti-debuggin</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8614</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, August 14th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-august-14th-2023--56459641</link><description><![CDATA[Show Me All Your Windows<br /><a href="https://isc.sans.edu/diary/Show%20me%20All%20Your%20Windows!/30116" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Show%20me%20All%20Your%20Windows!/30116</a><br /> Zero Touch Pwn<br /><a href="https://blog.syss.com/posts/zero-touch-pwn/" target="_blank" rel="noreferrer noopener">https://blog.syss.com/posts/zero-touch-pwn/</a><br /> Maginot DNS Spoofing Attack<br /><a href="https://www.usenix.org/conference/usenixsecurity23/presentation/li-xiang" target="_blank" rel="noreferrer noopener">https://www.usenix.org/conference/usenixsecurity23/presentation/li-xiang</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8614.mp3</guid><pubDate>Mon, 14 Aug 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56459641/8614.mp3" length="4931025" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Show Me All Your Windows
https://isc.sans.edu/diary/Show%20me%20All%20Your%20Windows!/30116
 Zero Touch Pwn
https://blog.syss.com/posts/zero-touch-pwn/
 Maginot DNS Spoofing Attack
https://www.usenix.org/conference/usenixsecurity23/presentation/li-xiang
</itunes:subtitle><itunes:summary><![CDATA[Show Me All Your Windows<br /><a href="https://isc.sans.edu/diary/Show%20me%20All%20Your%20Windows!/30116" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Show%20me%20All%20Your%20Windows!/30116</a><br /> Zero Touch Pwn<br /><a href="https://blog.syss.com/posts/zero-touch-pwn/" target="_blank" rel="noreferrer noopener">https://blog.syss.com/posts/zero-touch-pwn/</a><br /> Maginot DNS Spoofing Attack<br /><a href="https://www.usenix.org/conference/usenixsecurity23/presentation/li-xiang" target="_blank" rel="noreferrer noopener">https://www.usenix.org/conference/usenixsecurity23/presentation/li-xiang</a><br />]]></itunes:summary><itunes:duration>331</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,windows; python; anti-debuggin</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8614</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, August 11th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-august-11th-2023--57537772</link><description><![CDATA[Some things never change, such as SQL Authentication "Encryption"<br /><a href="https://isc.sans.edu/diary/Some%20things%20never%20change%20%3F%20such%20as%20SQL%20Authentication%20%3Fencryption%3F/30112" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Some%20things%20never%20change%20%3F%20such%20as%20SQL%20Authentication%20%3Fencryption%3F/30112</a><br /> Defender Pretender: When Windows Defender Updates Become a Security Risk<br /><a href="https://www.blackhat.com/us-23/briefings/schedule/#defender-pretender-when-windows-defender-updates-become-a-security-risk-32706" target="_blank" rel="noreferrer noopener">https://www.blackhat.com/us-23/briefings/schedule/#defender-pretender-when-windows-defender-updates-become-a-security-risk-32706</a><br /> Dell Compellent Hardcoded Key<br /><a href="https://www.dell.com/support/kbdoc/en-us/000216615/dsa-2023-282-security-update-for-dell-storage-integration-tools-for-vmware-dsitv-vulnerabilities" target="_blank" rel="noreferrer noopener">https://www.dell.com/support/kbdoc/en-us/000216615/dsa-2023-282-security-update-for-dell-storage-integration-tools-for-vmware-dsitv-vulnerabilities</a><br /> Vulnerabilities in Sogou Keyboard<br /><a href="https://citizenlab.ca/2023/08/vulnerabilities-in-sogou-keyboard-encryption/" target="_blank" rel="noreferrer noopener">https://citizenlab.ca/2023/08/vulnerabilities-in-sogou-keyboard-encryption/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8612.mp3</guid><pubDate>Fri, 11 Aug 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537772/8612.mp3" length="5360855" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Some things never change, such as SQL Authentication "Encryption"
https://isc.sans.edu/diary/Some%20things%20never%20change%20%3F%20such%20as%20SQL%20Authentication%20%3Fencryption%3F/30112
 Defender Pretender: When Windows Defender Updates Become a...</itunes:subtitle><itunes:summary><![CDATA[Some things never change, such as SQL Authentication "Encryption"<br /><a href="https://isc.sans.edu/diary/Some%20things%20never%20change%20%3F%20such%20as%20SQL%20Authentication%20%3Fencryption%3F/30112" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Some%20things%20never%20change%20%3F%20such%20as%20SQL%20Authentication%20%3Fencryption%3F/30112</a><br /> Defender Pretender: When Windows Defender Updates Become a Security Risk<br /><a href="https://www.blackhat.com/us-23/briefings/schedule/#defender-pretender-when-windows-defender-updates-become-a-security-risk-32706" target="_blank" rel="noreferrer noopener">https://www.blackhat.com/us-23/briefings/schedule/#defender-pretender-when-windows-defender-updates-become-a-security-risk-32706</a><br /> Dell Compellent Hardcoded Key<br /><a href="https://www.dell.com/support/kbdoc/en-us/000216615/dsa-2023-282-security-update-for-dell-storage-integration-tools-for-vmware-dsitv-vulnerabilities" target="_blank" rel="noreferrer noopener">https://www.dell.com/support/kbdoc/en-us/000216615/dsa-2023-282-security-update-for-dell-storage-integration-tools-for-vmware-dsitv-vulnerabilities</a><br /> Vulnerabilities in Sogou Keyboard<br /><a href="https://citizenlab.ca/2023/08/vulnerabilities-in-sogou-keyboard-encryption/" target="_blank" rel="noreferrer noopener">https://citizenlab.ca/2023/08/vulnerabilities-in-sogou-keyboard-encryption/</a><br />]]></itunes:summary><itunes:duration>361</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,sogou; keyboard; dell; compell</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8612</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, August 11th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-august-11th-2023--56434460</link><description><![CDATA[Some things never change, such as SQL Authentication "Encryption"<br /><a href="https://isc.sans.edu/diary/Some%20things%20never%20change%20%3F%20such%20as%20SQL%20Authentication%20%3Fencryption%3F/30112" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Some%20things%20never%20change%20%3F%20such%20as%20SQL%20Authentication%20%3Fencryption%3F/30112</a><br /> Defender Pretender: When Windows Defender Updates Become a Security Risk<br /><a href="https://www.blackhat.com/us-23/briefings/schedule/#defender-pretender-when-windows-defender-updates-become-a-security-risk-32706" target="_blank" rel="noreferrer noopener">https://www.blackhat.com/us-23/briefings/schedule/#defender-pretender-when-windows-defender-updates-become-a-security-risk-32706</a><br /> Dell Compellent Hardcoded Key<br /><a href="https://www.dell.com/support/kbdoc/en-us/000216615/dsa-2023-282-security-update-for-dell-storage-integration-tools-for-vmware-dsitv-vulnerabilities" target="_blank" rel="noreferrer noopener">https://www.dell.com/support/kbdoc/en-us/000216615/dsa-2023-282-security-update-for-dell-storage-integration-tools-for-vmware-dsitv-vulnerabilities</a><br /> Vulnerabilities in Sogou Keyboard<br /><a href="https://citizenlab.ca/2023/08/vulnerabilities-in-sogou-keyboard-encryption/" target="_blank" rel="noreferrer noopener">https://citizenlab.ca/2023/08/vulnerabilities-in-sogou-keyboard-encryption/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8612.mp3</guid><pubDate>Fri, 11 Aug 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56434460/8612.mp3" length="5360855" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Some things never change, such as SQL Authentication "Encryption"
https://isc.sans.edu/diary/Some%20things%20never%20change%20%3F%20such%20as%20SQL%20Authentication%20%3Fencryption%3F/30112
 Defender Pretender: When Windows Defender Updates Become a...</itunes:subtitle><itunes:summary><![CDATA[Some things never change, such as SQL Authentication "Encryption"<br /><a href="https://isc.sans.edu/diary/Some%20things%20never%20change%20%3F%20such%20as%20SQL%20Authentication%20%3Fencryption%3F/30112" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Some%20things%20never%20change%20%3F%20such%20as%20SQL%20Authentication%20%3Fencryption%3F/30112</a><br /> Defender Pretender: When Windows Defender Updates Become a Security Risk<br /><a href="https://www.blackhat.com/us-23/briefings/schedule/#defender-pretender-when-windows-defender-updates-become-a-security-risk-32706" target="_blank" rel="noreferrer noopener">https://www.blackhat.com/us-23/briefings/schedule/#defender-pretender-when-windows-defender-updates-become-a-security-risk-32706</a><br /> Dell Compellent Hardcoded Key<br /><a href="https://www.dell.com/support/kbdoc/en-us/000216615/dsa-2023-282-security-update-for-dell-storage-integration-tools-for-vmware-dsitv-vulnerabilities" target="_blank" rel="noreferrer noopener">https://www.dell.com/support/kbdoc/en-us/000216615/dsa-2023-282-security-update-for-dell-storage-integration-tools-for-vmware-dsitv-vulnerabilities</a><br /> Vulnerabilities in Sogou Keyboard<br /><a href="https://citizenlab.ca/2023/08/vulnerabilities-in-sogou-keyboard-encryption/" target="_blank" rel="noreferrer noopener">https://citizenlab.ca/2023/08/vulnerabilities-in-sogou-keyboard-encryption/</a><br />]]></itunes:summary><itunes:duration>361</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,sogou; keyboard; dell; compell</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8612</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, August 10th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-august-10th-2023--57537743</link><description><![CDATA[Tunnelcrack VPN Vulnerability<br /><a href="https://papers.mathyvanhoef.com/usenix2023-tunnelcrack.pdf" target="_blank" rel="noreferrer noopener">https://papers.mathyvanhoef.com/usenix2023-tunnelcrack.pdf</a><br /> Mozilla VPN Vulnerablity<br /><a href="https://www.openwall.com/lists/oss-security/2023/08/03/1" target="_blank" rel="noreferrer noopener">https://www.openwall.com/lists/oss-security/2023/08/03/1</a><br /> Non English Exchange Server Patch Issues<br /><a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/released-august-2023-exchange-server-security-updates/bc-p/3894481/highlight/true" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/exchange-team-blog/released-august-2023-exchange-server-security-updates/bc-p/3894481/highlight/true</a><br /> VSCode Token Security<br /><a href="https://cycode.com/blog/exposing-vscode-secrets/" target="_blank" rel="noreferrer noopener">https://cycode.com/blog/exposing-vscode-secrets/</a><br /> Weekly Updates for Google Chrome<br /><a href="https://security.googleblog.com/2023/08/an-update-on-chrome-security-updates.html" target="_blank" rel="noreferrer noopener">https://security.googleblog.com/2023/08/an-update-on-chrome-security-updates.html</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8610.mp3</guid><pubDate>Thu, 10 Aug 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537743/8610.mp3" length="5552319" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Tunnelcrack VPN Vulnerability
https://papers.mathyvanhoef.com/usenix2023-tunnelcrack.pdf
 Mozilla VPN Vulnerablity
https://www.openwall.com/lists/oss-security/2023/08/03/1
 Non English Exchange Server Patch Issues...</itunes:subtitle><itunes:summary><![CDATA[Tunnelcrack VPN Vulnerability<br /><a href="https://papers.mathyvanhoef.com/usenix2023-tunnelcrack.pdf" target="_blank" rel="noreferrer noopener">https://papers.mathyvanhoef.com/usenix2023-tunnelcrack.pdf</a><br /> Mozilla VPN Vulnerablity<br /><a href="https://www.openwall.com/lists/oss-security/2023/08/03/1" target="_blank" rel="noreferrer noopener">https://www.openwall.com/lists/oss-security/2023/08/03/1</a><br /> Non English Exchange Server Patch Issues<br /><a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/released-august-2023-exchange-server-security-updates/bc-p/3894481/highlight/true" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/exchange-team-blog/released-august-2023-exchange-server-security-updates/bc-p/3894481/highlight/true</a><br /> VSCode Token Security<br /><a href="https://cycode.com/blog/exposing-vscode-secrets/" target="_blank" rel="noreferrer noopener">https://cycode.com/blog/exposing-vscode-secrets/</a><br /> Weekly Updates for Google Chrome<br /><a href="https://security.googleblog.com/2023/08/an-update-on-chrome-security-updates.html" target="_blank" rel="noreferrer noopener">https://security.googleblog.com/2023/08/an-update-on-chrome-security-updates.html</a><br />]]></itunes:summary><itunes:duration>375</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,google; chrome; updates; vscod,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8610</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Thursday, August 10th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-thursday-august-10th-2023--56418892</link><description><![CDATA[Tunnelcrack VPN Vulnerability<br /><a href="https://papers.mathyvanhoef.com/usenix2023-tunnelcrack.pdf" target="_blank" rel="noreferrer noopener">https://papers.mathyvanhoef.com/usenix2023-tunnelcrack.pdf</a><br /> Mozilla VPN Vulnerablity<br /><a href="https://www.openwall.com/lists/oss-security/2023/08/03/1" target="_blank" rel="noreferrer noopener">https://www.openwall.com/lists/oss-security/2023/08/03/1</a><br /> Non English Exchange Server Patch Issues<br /><a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/released-august-2023-exchange-server-security-updates/bc-p/3894481/highlight/true" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/exchange-team-blog/released-august-2023-exchange-server-security-updates/bc-p/3894481/highlight/true</a><br /> VSCode Token Security<br /><a href="https://cycode.com/blog/exposing-vscode-secrets/" target="_blank" rel="noreferrer noopener">https://cycode.com/blog/exposing-vscode-secrets/</a><br /> Weekly Updates for Google Chrome<br /><a href="https://security.googleblog.com/2023/08/an-update-on-chrome-security-updates.html" target="_blank" rel="noreferrer noopener">https://security.googleblog.com/2023/08/an-update-on-chrome-security-updates.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8610.mp3</guid><pubDate>Thu, 10 Aug 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56418892/8610.mp3" length="5552319" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Tunnelcrack VPN Vulnerability
https://papers.mathyvanhoef.com/usenix2023-tunnelcrack.pdf
 Mozilla VPN Vulnerablity
https://www.openwall.com/lists/oss-security/2023/08/03/1
 Non English Exchange Server Patch Issues...</itunes:subtitle><itunes:summary><![CDATA[Tunnelcrack VPN Vulnerability<br /><a href="https://papers.mathyvanhoef.com/usenix2023-tunnelcrack.pdf" target="_blank" rel="noreferrer noopener">https://papers.mathyvanhoef.com/usenix2023-tunnelcrack.pdf</a><br /> Mozilla VPN Vulnerablity<br /><a href="https://www.openwall.com/lists/oss-security/2023/08/03/1" target="_blank" rel="noreferrer noopener">https://www.openwall.com/lists/oss-security/2023/08/03/1</a><br /> Non English Exchange Server Patch Issues<br /><a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/released-august-2023-exchange-server-security-updates/bc-p/3894481/highlight/true" target="_blank" rel="noreferrer noopener">https://techcommunity.microsoft.com/t5/exchange-team-blog/released-august-2023-exchange-server-security-updates/bc-p/3894481/highlight/true</a><br /> VSCode Token Security<br /><a href="https://cycode.com/blog/exposing-vscode-secrets/" target="_blank" rel="noreferrer noopener">https://cycode.com/blog/exposing-vscode-secrets/</a><br /> Weekly Updates for Google Chrome<br /><a href="https://security.googleblog.com/2023/08/an-update-on-chrome-security-updates.html" target="_blank" rel="noreferrer noopener">https://security.googleblog.com/2023/08/an-update-on-chrome-security-updates.html</a><br />]]></itunes:summary><itunes:duration>375</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,google; chrome; updates; vscod,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8610</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, August 9th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-august-9th-2023--57537736</link><description><![CDATA[Microsoft Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20August%202023%20Patch%20Tuesday/30106" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20August%202023%20Patch%20Tuesday/30106</a><br /> Adobe Updates<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8608.mp3</guid><pubDate>Wed, 09 Aug 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537736/8608.mp3" length="5373505" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20August%202023%20Patch%20Tuesday/30106
 Adobe Updates
https://helpx.adobe.com/security/security-bulletin.html
</itunes:subtitle><itunes:summary><![CDATA[Microsoft Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20August%202023%20Patch%20Tuesday/30106" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20August%202023%20Patch%20Tuesday/30106</a><br /> Adobe Updates<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br />]]></itunes:summary><itunes:duration>362</itunes:duration><itunes:keywords>adobe; adobe commerce; reader;,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8608</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Wednesday, August 9th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-wednesday-august-9th-2023--56409239</link><description><![CDATA[Microsoft Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20August%202023%20Patch%20Tuesday/30106" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20August%202023%20Patch%20Tuesday/30106</a><br /> Adobe Updates<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8608.mp3</guid><pubDate>Wed, 09 Aug 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56409239/8608.mp3" length="5373505" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20August%202023%20Patch%20Tuesday/30106
 Adobe Updates
https://helpx.adobe.com/security/security-bulletin.html
</itunes:subtitle><itunes:summary><![CDATA[Microsoft Patch Tuesday<br /><a href="https://isc.sans.edu/diary/Microsoft%20August%202023%20Patch%20Tuesday/30106" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Microsoft%20August%202023%20Patch%20Tuesday/30106</a><br /> Adobe Updates<br /><a href="https://helpx.adobe.com/security/security-bulletin.html" target="_blank" rel="noreferrer noopener">https://helpx.adobe.com/security/security-bulletin.html</a><br />]]></itunes:summary><itunes:duration>362</itunes:duration><itunes:keywords>adobe; adobe commerce; reader;,business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8608</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, August 8th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-august-8th-2023--57537790</link><description><![CDATA[Update: Researchers Scanning the Internet<br /><a href="https://isc.sans.edu/diary/Update%3A%20Researchers%20scanning%20the%20Internet/30102" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Update%3A%20Researchers%20scanning%20the%20Internet/30102</a><br /> Malicious OpenBullet Configuration Files<br /><a href="https://www.kasada.io/threat-intel-openbullet-malware/" target="_blank" rel="noreferrer noopener">https://www.kasada.io/threat-intel-openbullet-malware/</a><br /> Abusing Cloudflare Tunnels<br /><a href="https://www.guidepointsecurity.com/blog/tunnel-vision-cloudflared-abused-in-the-wild/" target="_blank" rel="noreferrer noopener">https://www.guidepointsecurity.com/blog/tunnel-vision-cloudflared-abused-in-the-wild/</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8606.mp3</guid><pubDate>Tue, 08 Aug 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537790/8606.mp3" length="5723161" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Update: Researchers Scanning the Internet
https://isc.sans.edu/diary/Update%3A%20Researchers%20scanning%20the%20Internet/30102
 Malicious OpenBullet Configuration Files
https://www.kasada.io/threat-intel-openbullet-malware/
 Abusing Cloudflare Tunnels...</itunes:subtitle><itunes:summary><![CDATA[Update: Researchers Scanning the Internet<br /><a href="https://isc.sans.edu/diary/Update%3A%20Researchers%20scanning%20the%20Internet/30102" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Update%3A%20Researchers%20scanning%20the%20Internet/30102</a><br /> Malicious OpenBullet Configuration Files<br /><a href="https://www.kasada.io/threat-intel-openbullet-malware/" target="_blank" rel="noreferrer noopener">https://www.kasada.io/threat-intel-openbullet-malware/</a><br /> Abusing Cloudflare Tunnels<br /><a href="https://www.guidepointsecurity.com/blog/tunnel-vision-cloudflared-abused-in-the-wild/" target="_blank" rel="noreferrer noopener">https://www.guidepointsecurity.com/blog/tunnel-vision-cloudflared-abused-in-the-wild/</a><br />]]></itunes:summary><itunes:duration>387</itunes:duration><itunes:keywords>business,cloudflare; cloudflared; openb,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8606</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Tuesday, August 8th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-tuesday-august-8th-2023--56399229</link><description><![CDATA[Update: Researchers Scanning the Internet<br /><a href="https://isc.sans.edu/diary/Update%3A%20Researchers%20scanning%20the%20Internet/30102" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Update%3A%20Researchers%20scanning%20the%20Internet/30102</a><br /> Malicious OpenBullet Configuration Files<br /><a href="https://www.kasada.io/threat-intel-openbullet-malware/" target="_blank" rel="noreferrer noopener">https://www.kasada.io/threat-intel-openbullet-malware/</a><br /> Abusing Cloudflare Tunnels<br /><a href="https://www.guidepointsecurity.com/blog/tunnel-vision-cloudflared-abused-in-the-wild/" target="_blank" rel="noreferrer noopener">https://www.guidepointsecurity.com/blog/tunnel-vision-cloudflared-abused-in-the-wild/</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8606.mp3</guid><pubDate>Tue, 08 Aug 2023 02:00:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56399229/8606.mp3" length="5723161" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Update: Researchers Scanning the Internet
https://isc.sans.edu/diary/Update%3A%20Researchers%20scanning%20the%20Internet/30102
 Malicious OpenBullet Configuration Files
https://www.kasada.io/threat-intel-openbullet-malware/
 Abusing Cloudflare Tunnels...</itunes:subtitle><itunes:summary><![CDATA[Update: Researchers Scanning the Internet<br /><a href="https://isc.sans.edu/diary/Update%3A%20Researchers%20scanning%20the%20Internet/30102" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Update%3A%20Researchers%20scanning%20the%20Internet/30102</a><br /> Malicious OpenBullet Configuration Files<br /><a href="https://www.kasada.io/threat-intel-openbullet-malware/" target="_blank" rel="noreferrer noopener">https://www.kasada.io/threat-intel-openbullet-malware/</a><br /> Abusing Cloudflare Tunnels<br /><a href="https://www.guidepointsecurity.com/blog/tunnel-vision-cloudflared-abused-in-the-wild/" target="_blank" rel="noreferrer noopener">https://www.guidepointsecurity.com/blog/tunnel-vision-cloudflared-abused-in-the-wild/</a><br />]]></itunes:summary><itunes:duration>387</itunes:duration><itunes:keywords>business,cloudflare; cloudflared; openb,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8606</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, August 7th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-august-7th-2023--57537773</link><description><![CDATA[Are Leaked Credential Dumps Used by Attackers?<br /><a href="https://isc.sans.edu/diary/Are%20Leaked%20Credentials%20Dumps%20Used%20by%20Attackers%3F/30098" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Are%20Leaked%20Credentials%20Dumps%20Used%20by%20Attackers%3F/30098</a><br /> New PaperCut RCE Vulnerability<br /><a href="https://www.horizon3.ai/cve-2023-39143-papercut-path-traversal-file-upload-rce-vulnerability/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/cve-2023-39143-papercut-path-traversal-file-upload-rce-vulnerability/</a><br /> Microsoft mitigates Power Platform Custom Code information disclosure vulnerability<br /><a href="https://msrc.microsoft.com/blog/2023/08/microsoft-mitigates-power-platform-custom-code-information-disclosure-vulnerability/" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/blog/2023/08/microsoft-mitigates-power-platform-custom-code-information-disclosure-vulnerability/</a><br /> Microsoft Publishes Token theft Playbook<br /><a href="https://learn.microsoft.com/en-us/security/operations/token-theft-playbook" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/security/operations/token-theft-playbook</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8604.mp3</guid><pubDate>Mon, 07 Aug 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537773/8604.mp3" length="4727098" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Are Leaked Credential Dumps Used by Attackers?
https://isc.sans.edu/diary/Are%20Leaked%20Credentials%20Dumps%20Used%20by%20Attackers%3F/30098
 New PaperCut RCE Vulnerability...</itunes:subtitle><itunes:summary><![CDATA[Are Leaked Credential Dumps Used by Attackers?<br /><a href="https://isc.sans.edu/diary/Are%20Leaked%20Credentials%20Dumps%20Used%20by%20Attackers%3F/30098" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Are%20Leaked%20Credentials%20Dumps%20Used%20by%20Attackers%3F/30098</a><br /> New PaperCut RCE Vulnerability<br /><a href="https://www.horizon3.ai/cve-2023-39143-papercut-path-traversal-file-upload-rce-vulnerability/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/cve-2023-39143-papercut-path-traversal-file-upload-rce-vulnerability/</a><br /> Microsoft mitigates Power Platform Custom Code information disclosure vulnerability<br /><a href="https://msrc.microsoft.com/blog/2023/08/microsoft-mitigates-power-platform-custom-code-information-disclosure-vulnerability/" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/blog/2023/08/microsoft-mitigates-power-platform-custom-code-information-disclosure-vulnerability/</a><br /> Microsoft Publishes Token theft Playbook<br /><a href="https://learn.microsoft.com/en-us/security/operations/token-theft-playbook" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/security/operations/token-theft-playbook</a><br />]]></itunes:summary><itunes:duration>316</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microsoft; cloud; azure; playb,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8604</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Monday, August 7th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-monday-august-7th-2023--56388328</link><description><![CDATA[Are Leaked Credential Dumps Used by Attackers?<br /><a href="https://isc.sans.edu/diary/Are%20Leaked%20Credentials%20Dumps%20Used%20by%20Attackers%3F/30098" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Are%20Leaked%20Credentials%20Dumps%20Used%20by%20Attackers%3F/30098</a><br /> New PaperCut RCE Vulnerability<br /><a href="https://www.horizon3.ai/cve-2023-39143-papercut-path-traversal-file-upload-rce-vulnerability/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/cve-2023-39143-papercut-path-traversal-file-upload-rce-vulnerability/</a><br /> Microsoft mitigates Power Platform Custom Code information disclosure vulnerability<br /><a href="https://msrc.microsoft.com/blog/2023/08/microsoft-mitigates-power-platform-custom-code-information-disclosure-vulnerability/" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/blog/2023/08/microsoft-mitigates-power-platform-custom-code-information-disclosure-vulnerability/</a><br /> Microsoft Publishes Token theft Playbook<br /><a href="https://learn.microsoft.com/en-us/security/operations/token-theft-playbook" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/security/operations/token-theft-playbook</a><br />]]></description><guid isPermaLink="false">https://traffic.libsyn.com/securitypodcast/8604.mp3</guid><pubDate>Mon, 07 Aug 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/56388328/8604.mp3" length="4727098" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>Are Leaked Credential Dumps Used by Attackers?
https://isc.sans.edu/diary/Are%20Leaked%20Credentials%20Dumps%20Used%20by%20Attackers%3F/30098
 New PaperCut RCE Vulnerability...</itunes:subtitle><itunes:summary><![CDATA[Are Leaked Credential Dumps Used by Attackers?<br /><a href="https://isc.sans.edu/diary/Are%20Leaked%20Credentials%20Dumps%20Used%20by%20Attackers%3F/30098" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/Are%20Leaked%20Credentials%20Dumps%20Used%20by%20Attackers%3F/30098</a><br /> New PaperCut RCE Vulnerability<br /><a href="https://www.horizon3.ai/cve-2023-39143-papercut-path-traversal-file-upload-rce-vulnerability/" target="_blank" rel="noreferrer noopener">https://www.horizon3.ai/cve-2023-39143-papercut-path-traversal-file-upload-rce-vulnerability/</a><br /> Microsoft mitigates Power Platform Custom Code information disclosure vulnerability<br /><a href="https://msrc.microsoft.com/blog/2023/08/microsoft-mitigates-power-platform-custom-code-information-disclosure-vulnerability/" target="_blank" rel="noreferrer noopener">https://msrc.microsoft.com/blog/2023/08/microsoft-mitigates-power-platform-custom-code-information-disclosure-vulnerability/</a><br /> Microsoft Publishes Token theft Playbook<br /><a href="https://learn.microsoft.com/en-us/security/operations/token-theft-playbook" target="_blank" rel="noreferrer noopener">https://learn.microsoft.com/en-us/security/operations/token-theft-playbook</a><br />]]></itunes:summary><itunes:duration>316</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,microsoft; cloud; azure; playb,network,news,security</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8604</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>ISC StormCast for Friday, August 4th, 2023</title><link>https://www.spreaker.com/episode/isc-stormcast-for-friday-august-4th-2023--57537795</link><description><![CDATA[From small LNK to large malicious BAT file with zero VT score<br /><a href="https://isc.sans.edu/diary/From%20small%20LNK%20to%20large%20malicious%20BAT%20file%20with%20zero%20VT%20score/30094" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/From%20small%20LNK%20to%20large%20malicious%20BAT%20file%20with%20zero%20VT%20score/30094</a><br /> Social Engineering via Microsoft Teams<br /><a href="https://www.microsoft.com/en-us/security/blog/2023/08/02/midnight-blizzard-conducts-targeted-social-engineering-over-microsoft-teams/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2023/08/02/midnight-blizzard-conducts-targeted-social-engineering-over-microsoft-teams/</a><br /> Automating the Search for LOLBAS<br /><a href="https://pentera.io/resources/whitepapers/the-lolbas-odyssey-finding-new-lolbas-and-how-you-can-too/" target="_blank" rel="noreferrer noopener">https://pentera.io/resources/whitepapers/the-lolbas-odyssey-finding-new-lolbas-and-how-you-can-too/</a><br /> Sneaky Versioning Used to Bypass Scanners<br /><a href="https://thehackernews.com/2023/08/malicious-apps-use-sneaky-versioning.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2023/08/malicious-apps-use-sneaky-versioning.html</a><br /> Aruba Patches<br /><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-010.txt" target="_blank" rel="noreferrer noopener">https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-010.txt</a><br /> Mitel Patches<br /><a href="https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-23-0008" target="_blank" rel="noreferrer noopener">https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-23-0008</a><br />]]></description><guid isPermaLink="false">https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/8602.mp3</guid><pubDate>Fri, 04 Aug 2023 02:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/57537795/8602.mp3" length="5001034" type="audio/mpeg"/><itunes:author>Johannes Ullrich</itunes:author><itunes:subtitle>From small LNK to large malicious BAT file with zero VT score
https://isc.sans.edu/diary/From%20small%20LNK%20to%20large%20malicious%20BAT%20file%20with%20zero%20VT%20score/30094
 Social Engineering via Microsoft Teams...</itunes:subtitle><itunes:summary><![CDATA[From small LNK to large malicious BAT file with zero VT score<br /><a href="https://isc.sans.edu/diary/From%20small%20LNK%20to%20large%20malicious%20BAT%20file%20with%20zero%20VT%20score/30094" target="_blank" rel="noreferrer noopener">https://isc.sans.edu/diary/From%20small%20LNK%20to%20large%20malicious%20BAT%20file%20with%20zero%20VT%20score/30094</a><br /> Social Engineering via Microsoft Teams<br /><a href="https://www.microsoft.com/en-us/security/blog/2023/08/02/midnight-blizzard-conducts-targeted-social-engineering-over-microsoft-teams/" target="_blank" rel="noreferrer noopener">https://www.microsoft.com/en-us/security/blog/2023/08/02/midnight-blizzard-conducts-targeted-social-engineering-over-microsoft-teams/</a><br /> Automating the Search for LOLBAS<br /><a href="https://pentera.io/resources/whitepapers/the-lolbas-odyssey-finding-new-lolbas-and-how-you-can-too/" target="_blank" rel="noreferrer noopener">https://pentera.io/resources/whitepapers/the-lolbas-odyssey-finding-new-lolbas-and-how-you-can-too/</a><br /> Sneaky Versioning Used to Bypass Scanners<br /><a href="https://thehackernews.com/2023/08/malicious-apps-use-sneaky-versioning.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2023/08/malicious-apps-use-sneaky-versioning.html</a><br /> Aruba Patches<br /><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-010.txt" target="_blank" rel="noreferrer noopener">https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-010.txt</a><br /> Mitel Patches<br /><a href="https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-23-0008" target="_blank" rel="noreferrer noopener">https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-23-0008</a><br />]]></itunes:summary><itunes:duration>336</itunes:duration><itunes:keywords>business,computer,cyber,cybersecurity,daily,hacking,infosec,internet,it,network,news,security,versioning; android; google pl</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/6f5e8f9158eeb754a19fbf5e4e588916.jpg"/><itunes:episode>8602</itunes:episode><itunes:episodeType>full</itunes:episodeType></item></channel></rss>
