
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
A brief daily summary of what is important in cyber security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually about 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter.
Episodes

SANS Stormcast Friday, July 24th, 2026: OpenAI vs. Huggingface; Zimbra Exploited; Notepad++ Abuse; Browser as C2
When the "Autonomous Attacker" Is Your Own AI Model
https://isc.sans.edu/diary/When%20the%20%22Autonomous%20Attacker%22%20Is%20Your%20Own%20AI%20Model/33180
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra
https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a
https://cert.gov.ua/article/6318634
https://cybersecuritynews.com/hackers-abuse-notep

SANS Stormcast Thursday, July 23rd, 2026: Rondo and Geoserver; Oracle Patches; Checkpoint 0-day; OpenAI vs Huggingface
Rondo Meets Geoserver
https://isc.sans.edu/diary/Rondo%20Meets%20Geoserver/33176
Oracle July Patch Update
https://www.oracle.com/security-alerts/cpujul2026.html
OpenAI and Hugging Face partner to address security incident during model evaluation
https://openai.com/index/hugging-face-model-evaluation-security-incident/
Checkpoint July 2026 Security Advisory (CVE-2026-16232)
https://blog.checkpoint

SANS Stormcast Wednesday, July 22nd, 2026: Captive Portals; Critical Serv-U and Zimbra Update; Apple Hide-My-Email fix
Captive Portal Detection
https://isc.sans.edu/diary/Captive%20Portal%20Detection/33172
Critical SolarWinds Serv-U Update
https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm
Zimbra Update with Critical Security Fixes
https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/
Apple Fixed Hide My E-Mail Leak
https://www.404media

SANS Stormcast Tuesday, July 21st, 2026: More Wordpress Details; HOLLOWGRAPH MSFT Calendar Abuse; Gitea Vulnerability
WordPress Exploitation Underway (CVE-2026-63030)
https://isc.sans.edu/diary/WordPress%20Exploitation%20Underway%20%28CVE-2026-63030%29/33168
HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels
https://www.group-ib.com/blog/hollowgraph-microsoft-365/
Gitea Vulnerablity CVE-2026-58443
https://github.com/go-gitea/gitea/security/advisories/GHSA-xxjv-752h-3vp2
My

SANS Stormcast Monday, July 20th, 2026: Hikvision Scans; LG Spyware; Huggingface Hack; Wordpress Core RCE
Scans for Hikvision Intelligent Security API
https://isc.sans.edu/diary/Scans%20for%20Hikvision%20Intelligent%20Security%20API/33164
LG Monitor Spyware
https://www.techradar.com/televisions/lgs-gaming-monitors-and-tvs-are-facing-a-user-revolt https://www.youtube.com/watch?v=Q9uefFYe6bM
Huggingface Hack
https://huggingface.co/blog/security-incident-july-2026
Wordpress Core RCE
https://wp2shell.com

SANS Stormcast Friday, July 17th, 2026: Windows Hello for Business; NGINX Vuln; 7-zip vuln
German Federal Information Security Office Analyzes Windows Hello for Business
https://www.heise.de/en/news/BSI-dissects-Windows-Hello-Where-Microsoft-s-login-reaches-its-limits-11366125.html
https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/Studies/Windows_dissected/AP1_Windows-Hello-for-Business.pdf?__blob=publicationFile&v=7
NGINX Vulnerability
https://my.f5.com/manage/s/art

SANS Stormcast Thursday, July 16th, 2026: DShield SIEM Update; MSFT Patches vs. Intel IPF; Zoom Patch; Forgotten UEFI Shims
DShield SIEM Update
https://isc.sans.edu/diary/Recent%20DShield%20SIEM%20Update/33156
Microsoft Patch Tuesday vs. Dell Intel Innovation Platform Framework (IPF) drivers
https://support.microsoft.com/en-us/servicing/os/windows-11/2026/07/july-14-2026-kb5101650-os-builds-26200-8875-and-26100-8875
Zoom Account Takeover Patch
https://www.zoom.com/en/trust/security-bulletin/zsb-26014/
Forgotten UEFI s

SANS Stormcast Wednesday, July 15th, 2026: Microsoft Patches; New MSFT Priv Escalation; Progress ShareFile 0-Day; Grok Exfiltration
Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20July%202026%20-%20The%20AI%20Acopolypse%20is%20Here%20/33154
LegacyHive : Windows user profile service arbitrary hive load elevation of privileges vulnerability
https://git.projectnightcrawler.dev/NightmareEclipse/LegacyHive
Progress confirms ShareFile zero-day flaw behind Storag

SANS Stormcast Tuesday, July 14th, 2026: MCP/AI Related Scans; Improve Router Hygiene; OAuth Client ID Spoofing; Veeam Vuln;
Someone Is Scanning for Your MCP Servers and AI Assistant Credentials
https://isc.sans.edu/diary/Someone%20Is%20Scanning%20for%20Your%20MCP%20Servers%20and%20AI%20Assistant%20Credentials/33150
Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting
https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a
OAuth Client ID Spoofing
https://www.proofpoint.com/us/blog/th

SANS Stormcast Monday, July 13th, 2026: Progress Sharefile Shutdown; U-Boot Vuln; More Nightmare Eclipse; Cisco AI Response
Progress Sharefile Emergency Shutdown Notice
https://status.sharefile.com
https://www.reddit.com/r/sysadmin/comments/1usohco/psa_shutdown_your_sharefile_storage_zone/
https://www.bleepingcomputer.com/news/security/progress-urges-sharefile-customers-to-shut-down-servers-over-credible-threat/
U-Boot Vulnerabilities
https://www.binarly.io/blog/unfit-to-boot-breaking-u-boots-fit-signature-verificatio

SANS Stormcast Friday, July 10th, 2026: Belarus Graffiti Bot @sans_edu; Discontinuing Mac OS Ext. FS; Chrome Update; Rogue Planet Patch
_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary]
https://isc.sans.edu/diary/_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_%20%5BGuest%20Diary%5D/33130
Apple Discontinuing Support for Encrypted Mac OS Extended disks in macOS 28
https://support.apple.com/en-us/125615
Google Chrome Update
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html
Microsoft Patches Rogue

SANS Stormcast Thursday, July 9th, 2026: Stack Simulator; RootAsRole; Hoymiles; Git Hash Malleability
My Stack Simulator https://isc.sans.edu/diary/My%20Stack%20Simulator/33138
RootAsRole
https://github.com/LeChatP/RootAsRole
Hoymiles Inverter Vulnerability
https://www.ccc.de/system/uploads/382/original/hoymiles_dtu_vuln.pdf
Git Hash Chain Malleability
https://arxiv.org/abs/2607.02820
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich

SANS Stormcast Wednesday, July 8th, 2026: Odd DNS; AnyDesk Phishing; Tenda Backdoor; GitLost
More Odd DNS Records: NIMLOC
https://isc.sans.edu/diary/More%20Odd%20DNS%20Records%3A%20NIMLOC/33128
From Invoice to AnyDesk: Uncovering a Phishing Campaign Targeting Russian Aerospace Organizations
https://www.seqrite.com/blog/from-invoice-to-anydesk-uncovering-a-phishing-campaign-targeting-russian-aerospace-organizations/
Tenda firmware (multiple versions) contains hidden authentication backd

SANS Stormcast Tuesday, July 7th, 2026: RCS and DNS; OpenSSH Update; Beyond Trust Advisory; PolinRider Update
RCS and DNS: The NAPTR Record
https://isc.sans.edu/diary/RCS%20and%20DNS%3A%20The%20NAPTR%20Record/33124
OpenSSH 10.4 released
https://seclists.org/oss-sec/2026/q3/62
Beyond Trust Advisory CVE-2026-40138 CVE-2026-40139
https://www.beyondtrust.com/trust-center/security-advisories/bt26-03
PolinRider: North Korea-Linked Supply Chain Campaign
https://socket.dev/blog/polinrider-north-korea-linked-supp

SANS Stormcast Monday, July 6th, 2026: Apple Patch Policy; FatFS Vulns; OpenWRT; Multi-Agent Offensive AI;
Apple Updated Patch Policy
https://www.reuters.com/business/apple-says-it-is-releasing-updates-early-response-ai-cybersecurity-concerns-2026-06-29/
T3MP3ST multi-agent offensive-security framework
https://github.com/elder-plinius/T3MP3ST
Seven FatFs bugs, one very large blast radius
https://www.runzero.com/blog/fatfs-bugs/
OpenWRT Releases v25.12.5
https://github.com/openwrt/openwrt/releases
My U

SANS Stormcast Thursday, July 2nd, 2026: MetaMask Phishing; Adobe Patches; Google Chrome Patches; Apple Hide-My-Email Vuln
Why Ask Credentials If There Are Secret Codes?
https://isc.sans.edu/diary/Why%20Ask%20Credentials%20If%20There%20Are%20Secret%20Codes%3F/33118
Adobe Patches and Updated Patch Release Policy
https://helpx.adobe.com/security/Home.html
https://blog.adobe.com/security/protecting-customers-faster-how-adobe-is-responding-to-ai-accelerated-vulnerability-discovery
Google Chrome Update (link had issues lo

SANS Stormcast Wednesday, July 1st, 2026: Apple Patches; SimpleHelp Exploit; Git DNS Tricks;
June 2026 Apple Updates
https://isc.sans.edu/diary/June%202026%20Apple%20Updates/33114
SimpleHelp Exploit used to reply TaskWeaver
https://blackpointcyber.com/blog/a-djinn-in-the-machine-taskweavers-node-js-intrusion-chain/
DNS Tricks to Load Malware into Cloned Repository
https://0din.ai/blog/clone-this-repo-and-i-own-your-machine
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ull

SANS Stormcast Tuesday, June 30th, 2026: Favicon Recon Automation; Targeting Messaging; Gemini CLI vuln; IPv6 Frag Escape
Adding some Automation to the favicon.ico method of Host Recon
https://isc.sans.edu/diary/Adding%20some%20Automation%20to%20the%20favicon.ico%20method%20of%20Host%20Recon/33110
Russian Intelligence Services Continue to Target Commercial Messaging Applications
https://www.ic3.gov/PSA/2026/PSA260626
Google Gemini CLI Vulnerability CVE-2026-12537
https://github.com/advisories/GHSA-jj69-4grx-fqj5
IPv

SANS Stormcast Monday, June 29th, 2026: Automated Cybercrime; Linux Process Names; Amazon Q VS Code
What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime
https://isc.sans.edu/diary/What%20do%20Ports%20Hear%20When%20Nobody%27s%20Listening%3F%20An%20Assessment%20of%20Automated%20Cybercrime%20%5BGuest%20Diary%5D/33104
Linux Process Name Masquerading
https://isc.sans.edu/diary/Linux+Process+Name+Masquerading/33102
Amazon Q VS Code Extension Vulnerability
https://www.wiz.

SANS Stormcast Wednesday, June 24th, 2026: Patching vs. Configurations Updates; libssh2 and ffmpeg vuln;
CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration.
https://isc.sans.edu/diary/CVE-2024-40766%3A%20The%20Patch%20Fixed%20the%20Bug.%20Nobody%20Fixed%20the%20Configuration./33094
libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
https://www.vulncheck.com/advisories/libssh2-out-of-bounds-write-via-unchecked-packet-length-in-transport-c
PixelSmash Critic

SANS Stormcast Tuesday, June 23rd, 2026: Webshells; GitHub Actions Update; Fortibleed Update; Private Access Control Tokens
Webshells Remain Popular
https://isc.sans.edu/diary/Webshells%20Remain%20Popular/33096
Safer pull_request_target defaults for GitHub Actions checkout
https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/
Private Access Control Tokens
https://cloudflare.net/news/news-details/2026/Cloudflare-Collaborates-With-Leading-Browsers-to-Develop-a-Privacy-F

SANS Stormcast Monday, June 22nd, 2026: IPv4 Mapped Phish; nginx bug; squid bleeds; AMD encryption fix
eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address
https://isc.sans.edu/diary/eBanking%20Phishing%20Delivered%20Through%20IPv4-Mapped%20IPv6%20Address/33090
NGINX ngx_http_v3_module vulnerability CVE-2026-42530
https://my.f5.com/manage/s/article/K000161616
Squidbleed (CVE-2026-47729)
https://blog.calif.io/p/squidbleed-cve-2026-47729
AMD will reinstate memory encryption on Ryzen 9000 CPU

SANS Stormcast Thursday, June 18th, 2026: QUIC Challenge; Android 17; Oracle CSPU; JetBrains Plugins;
The browser blind spot: Why your security tool may not be blocking what you think it is [Guest Diary]
https://isc.sans.edu/diary/The%20browser%20blind%20spot%3A%20Why%20your%20security%20tool%20may%20not%20be%20blocking%20what%20you%20think%20it%20is%20%5BGuest%20Diary%5D/33084
Android 17 Security Patches
https://source.android.com/docs/security/bulletin/android-17
Oracle Critical Security Patch

SANS Stormcast Wednesday, June 17th, 2026: VHDX to Remocs RAT; Fake Job Offer; OpenBSD Vuln; Copilot M365 Leakage
From a VHDX File to a Remcos RAT
https://isc.sans.edu/diary/From%20a%20VHDX%20File%20to%20a%20Remcos%20RAT/33080
A backdoor in a LinkedIn job offer
https://roman.pt/posts/linkedin-backdoor/
A 27-Year-Old Authentication Bypass in OpenBSD's PPP Stack
https://blog.argus-systems.ai/blog/openbsd-pap-27-year-auth-bypass.html
Copilot M365 Data Leakage
https://www.varonis.com/blog/searchleak
My Upcoming

SANS Stormcast Tuesday, June 16th, 2026: BASE64 Statistics; Cisco SD-WAN Exploited; AMD TSME Disabled; Poisoning Deep Research Agents
Evil MSI Background: BASE64 Statistical Analysis
https://isc.sans.edu/diary/Evil%20MSI%20Background%3A%20BASE64%20Statistical%20Analysis/33072
Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ
TSME/SME not activating on Ryzen 7 9700X
https://github.com/AMDESE/AMDSEV/issues/292

SANS Stormcast Monday, June 15th, 2026: Arch Linux Malicious User Packages; Splunk Vuln and Exploit; Exploiting AI Coding Agents
Atomic Arch: Attackers Hijack Trusted AUR Packages to Deliver Rootkit-Like Malware
https://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency
Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE) https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/
A Fake B

SANS Stormcast Friday, June 12th, 2026: Bitlocker Trouble; Ivanti and Oracle Exploited; macOS Malicious Installers
More Bitlocker Issues: GreatXML
https://git.churchofmalware.org/Nightmare_Eclipse/GreatXML
Security Advisory Ivanti Sentry (CVE-2026-10520, CVE-2026-10523)
https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US
Oracle Security Alert Advisory - CVE-2026-35273
https://www.oracle.com/security-alerts/alert-cve-2026-35273.html
https://www.bleeping

SANS Stormcast Thursday, June 11th, 2026: Framing Protections; npm improvements; Adobe Patches; New Defender 0-day
How has use of framing protection security headers changed in the past 3 years?
https://isc.sans.edu/diary/How%20has%20use%20of%20framing%20protection%20security%20headers%20changed%20in%20the%20past%203%20years%3F/33068
Preparing for npm v12: install scripts and non-registry sources become opt-in
https://github.com/orgs/community/discussions/198547
Adobe Patches
https://helpx.adobe.com/security.

SANS Stormcast Wednesday, June 10th, 2026: Microsoft Patch Tuesday; Miasma Source Published; Fortinet Patches
Microsoft June 2026 Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20June%202026%20Patch%20Tuesday/33064
Miasma Software Supply Chain Attack Toolkit Source Published
https://safedep.io/inside-the-miasma-supply-chain-attack-toolkit/
Fortinet FortiSandbox Vulnerability
https://fortiguard.fortinet.com/psirt/FG-IR-26-141
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullric

SANS Stormcast Tuesday, June 9th, 2026: Azure Repos Infected; Checkpoint VPN 0-Day; Verizon VoLTE missing IPSec integrity prot.
Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack
https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents
Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751)
https://blog.checkpoint.com/security/check-point-releases-im

SANS Stormcast Monday, June 8th, 2026: Wetransfer Phish; Spying Smart TV; Dashlane Brute Force
The Evil MSI Background is Back!
https://isc.sans.edu/diary/The%20Evil%20MSI%20Background%20is%20Back!/33054
The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy
https://blog.includesecurity.com/2026/06/the-smart-tv-in-your-livingroom-is-a-node-in-the-aiscraping-economy/
UPDATE: For the story above, we received a notice from Bright Data's PR team. Please refer to the URL above for

SANS Stormcast Friday, June 5th, 2026: Coreutils for Windows; Cisco Unified Comm Manager Fix and Exploit; OAuth Orphans
Microsoft's Coreutils for Windows
https://isc.sans.edu/diary/Microsoft%27s%20Coreutils%20for%20Windows/33048
Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability CVE-2026-20230
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW
Firmware Update for Acer Connect W6x Router
https://community.acer.com/en/kb/articles/1967

SANS Stormcast Thursday, June 4th, 2026: swagger.json Scans; Android Fake Call Detection; Anthropic Dashboard
Continuing Scans for swagger.json
https://isc.sans.edu/diary/Continuing+Scans+for+swaggerjson/33044/#comments
Fake call detection on Android
https://blog.google/security/android-fake-call-detection/
Anthropic's coordinated vulnerability disclosure dashboard
https://red.anthropic.com/2026/cvd/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich

SANS Stormcast Wednesday, June 3rd, 2026: SVG Phishing; Android Patches; Poly Voice Vuln; Ivanti Neurons Priv Escelation
New Wave Of Phishing Emails with SVG Files
https://isc.sans.edu/diary/New%20Wave%20Of%20Phishing%20Emails%20with%20SVG%20Files/33040
Android 2026-06-01 security patch level vulnerability details
https://source.android.com/docs/security/bulletin/2026/2026-06-01
Poly Voice Possible Remote Control of Certain Poly Devices CVE-2026-0826
https://support.hp.com/us-en/document/ish_15052661-15052687-16/

SANS Stormcast Tuesday, June 2nd, 2026: Netlogon Exploit; Unidentified RAT; Windows Netlogon Exploited; RedHat npm Affected; Dashlane Bruteforce Attach
Unidentified RAT pushes NetSupport RAT
https://isc.sans.edu/diary/Unidentified%20RAT%20pushes%20NetSupport%20RAT/33034
CVE-2026-41089: Windows Netlogon Vulnerability Exploited
https://ccb.belgium.be/advisories/warning-microsoft-patch-tuesday-may-2026-patches-118-vulnerabilities-16-critical-102
RedHat npm Packages Affected
https://www.aikido.dev/blog/red-hat-npm-packages-compromised-credential-stea

SANS Stormcast Monday, June 1st, 2026: Bitskrieg; Gogs Unpatched Vuln; Oracle Critical Updates; PAN-OS Exploited;
Announcing Bitskrieg
https://deadeclipse666.blogspot.com/2026/05/announcing-bitskrieg.html
Vulnerability in Gogs
https://www.rapid7.com/blog/post/ve-authenticated-rce-via-argument-injection-gogs-unfixed/
Oracle Critical Security Patch Update Advisory - May 2026
https://www.oracle.com/security-alerts/cspumay2026.html
GlobalProtect Authentication Bypass Vulnerabilities CVE-2026-0257
https://securit

SANS Stormcast Friday, May 29th, 2026: @sans_edu research; Honeypot Log; VPN “Toad”; Silent Ransom Group
Research Review Journal
https://assets.contentstack.io/v3/assets/blt83c410d686aa5f84/blt3cff46f63887f83e/research-review-journal
https://www.sans.edu/cyber-research
Analysis of a Year of Files Uploaded to DShield Sensors
https://isc.sans.edu/diary/Analysis%20of%20a%20Year%20of%20Files%20Uploaded%20to%20DShield%20Sensors/33026
The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular

SANS Stormcast Thursday, May 28th, 2026: Akira Ransomware; Vaultjacking; Poisoned Chatbot and Search Results;
Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs
https://isc.sans.edu/diary/Reconstructing%20an%20Akira%20Ransomware%20Kill%20Chain%20from%20Perimeter%20and%20Endpoint%20Logs/33024
Vaultjacking: One Captured PIN, the Entire Google Password Manager Vault
https://phishu.net/blogs/blog-vaultjacking-phishing-the-google-password-manager-vault-in-the-phishu-framework.html

SANS Stormcast Wednesday, May 27th, 2026: Fake Claude Ads; SharePoint Vuln; Angular Vulnerabilities
Possible ACR Stealer From Page Impersonating Claude
https://isc.sans.edu/diary/Possible%20ACR%20Stealer%20From%20Page%20Impersonating%20Claude/33018
Microsoft SharePoint Remote Code Execution Vulnerability CVE-2026-45659
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659
Multiple Vulnerabilities in Angular Language Service VS Code Extension
https://github.com/angular/angular/sec

SANS Stormcast Tuesday, May 26th, 2026: VBA in MSFT Access; NPM Stealer; PHP Laravel Compromise; Google API Key Lag;
Microsoft Access VBA
https://isc.sans.edu/diary/Microsoft%20Access%20VBA/33012
An Example of Stack String in High Level Language
https://isc.sans.edu/diary/An%20Example%20of%20Stack%20String%20in%20High%20Level%20Language/33008
Cross-Platform NPM Stealer
https://isc.sans.edu/diary/Cross-Platform%20NPM%20Stealer/33006
Laravel Lang Compromised with RCE Backdoor Across
https://socket.dev/blog/larave

SANS Stormcast Friday, May 22nd, 2026: Selective HTTP Proxying; More GitHub Repo Trouble; MSFT Defender Patches;
Selective HTTP Proxying in Linux
https://isc.sans.edu/diary/Selective%20HTTP%20Proxying%20in%20Linux/33002
Megalodon: Mass GitHub Repo Backdooring via CI Workflows
https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows/
MSFT Patches Recent Windows Defender Flaws CVE-2026-41091, CVE-2026-45498, CVE-2026-45584
https://x.com/fabian_bader/status/2057198207243804881
Cisco Secure Worklo

SANS Stormcast Thursday, May 21st, 2026: GitHub Breach; Agentic Threat Intel Feed; NGINX Vuln; YellowKey Fix; Incomplete SonicWall Patch
GitHub Breach
https://x.com/github/status/2056949168208552080
Agentic Threat Intelligence Feed - VS Code Extensions
https://agentmesh.knostic.ai/extensions
More NGINX Vulnerabilities
https://x.com/nebusecurity/status/2057071579876753643
https://my.f5.com/manage/s/article/K000161307
Microsoft Publishes YellowKey Mitigation CVE-2026-45585
https://msrc.microsoft.com/update-guide/vulnerability/CVE-20

SANS Stormcast Wednesday, May 20th, 2026: Assume Supply Chain Compromise; GitHub Action Compromise;
TeamPCP Supply Chain Campaign: Activity Through 2026-05-17
https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Activity%20Through%202026-05-17/32994
https://slsa.dev/spec/v0.1/levels
Github Action Compromise
https://www.stepsecurity.io/blog/actions-cool-issues-helper-github-action-compromised-all-tags-point-to-imposter-commit-that-exfiltrates-ci-cd-credentials
How Storm-2949 turne

SANS Stormcast Tuesday, May 19th, 2026: New libssh in Malware; Exchange 0-Day; MSFT Authenticator Update
New Malware Libraries means New Signatures
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20%20New%20Malware%20Libraries%20means%20New%20Signatures/32986
Addressing Exchange Server May 2026 vulnerability CVE-2026-42897
https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498
Microsoft Authenticator Update CVE-2026-41615
https://msr

SANS Stormcast Friday, May 15th, 2026: Website Fraud; Outlook Link Preview Bug; NGINX Vuln; Cisco 0-Day
Tearing apart website fraud to see how it works. (@sans_edu)
https://isc.sans.edu/diary/%5BGUEST%20DIARY%5D%20Tearing%20apart%20website%20fraud%20to%20see%20how%20it%20works./32958
Simple bypass of the link preview function in Outlook Junk folder
https://isc.sans.edu/diary/Simple%20bypass%20of%20the%20link%20preview%20function%20in%20Outlook%20Junk%20folder/32990
NGINX Vulnerability
https://depth

SANS Stormcast Thursday, May 14th, 2026: Flexbile Windows Proxy; News from Nightmare Eclipse; Adobe Patches
Proxying the Unproxyable? Sending EXE traffic to a Proxy
https://isc.sans.edu/diary/Proxying%20the%20Unproxyable%3F%20Sending%20EXE%20traffic%20to%20a%20Proxy/32982
New Nightmare Eclipse Vulnerabilities Disclosed
https://github.com/Nightmare-Eclipse/YellowKey
https://github.com/Nightmare-Eclipse/GreenPlasma
Adobe Patches
https://helpx.adobe.com/security.html

SANS Stormcast Wednesday, May 13th, 2026: Microsoft Patch Tuesday; Large npm/pypi Compromise; Rubygems Attack
Microsoft Patch Tuesday
https://isc.sans.edu/diary/32980
Tanstack npm and others compromised
https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack
Ruby Gems Attack
https://x.com/maciejmensfeld/status/2054164602577940619

SANS Stormcast Tuesday, May 12th, 2026: Apple Patches; Encrypted RCS; CAPTCHAs; Checkmarx vs TeamPCP;
Apple Patches Everything
https://isc.sans.edu/diary/Apple%20Patches%20Everything/32976
End-to-End Encrypted RCS Messages
https://www.apple.com/newsroom/2026/05/end-to-end-encrypted-rcs-messaging-begins-rolling-out-today-in-beta/
Why we use CAPTCHAs
https://isc.sans.edu/diary/Why%20we%20use%20CAPTCHAs/32974
Checkmarx Jenkins AST plugin compromise
https://checkmarx.com/blog/ongoing-security-updates

SANS Stormcast Monday, May 11th, 2026: New Linux Priv Escalation; PAM Backdoors; CPanel Updates; Let’s Encrypt
Another Universal Linux Local Privilege Escalation (LPE) Vulnerability: Dirty Frag
https://isc.sans.edu/diary/Another%20Universal%20Linux%20Local%20Privilege%20Escalation%20%28LPE%29%20Vulnerability%3A%20Dirty%20Frag/32968
PAM Backdoors Steel Passwords
https://flare.io/learn/resources/blog/pamdoora-new-linux-pam-based-backdoor-sale-dark-web
CPanel Updates
https://support.cpanel.net/hc/en-us/secti

SANS Stormcast Friday, May 8th, 2026: AI Generated Dashboard; Ivanti Patches; Redis Vuln; @sans_edu Marcio Enriquez
An Adaptive Cyber Analytics UI for Web Honeypot Logs
https://isc.sans.edu/diary/An%20Adaptive%20Cyber%20Analytics%20UI%20for%20Web%20Honeypot%20Logs%20%5BGuest%20Diary%5D/32962
Ivanti May Patchday
https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs
Redis Security advisory: [CVE 2026 23479] [CVE 2026 25243] [CVE-2026-25588] [CVE 2026 25589]

SANS Stormcast Thursday, May 7th, 2026: .DE DNSEC Fail; PAN OS 0-Day Patched;
Technical issue with .de domains
https://blog.denic.de/en/technical-issue-with-de-domains-resolved/
CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID Authentication Portal
https://security.paloaltonetworks.com/CVE-2026-0300
Android Security Bulletin May 2026 CVE-2026-0073
https://source.android.com/docs/security/bulletin/2026/2026-05-01

SANS Stormcast Wednesday, May 6th, 2026: Cleartext Passwords in Edge; SSL.com Root Rotation; DAEMONTOOLS Backdoor;
Cleartext Passwords in MS Edge? In 2026?
https://isc.sans.edu/diary/Cleartext%20Passwords%20in%20MS%20Edge%3F%20In%202026%3F/32954
SSL.com rotates its root certificate today
https://isc.sans.edu/diary/SSL.com%20rotates%20their%20root%20certificate%20today/32956
DEAMONTOOLS Compromise
https://securelist.com/tr/daemon-tools-backdoor/119654/

SANS Stormcast Tuesday, May 5th, 2026: Honeypot Update; MOVEit Patches; Apache http2 Vuln;
DShield Honeypot Update
https://isc.sans.edu/diary/DShield%20Honeypot%20Update/32948
MOVEit Automation Critical Security Alert Bulletin April 2026 (CVE-2026-4670, CVE-2026-5174)
https://community.progress.com/s/article/MOVEit-Automation-Critical-Security-Alert-Bulletin-April-2026-CVE-2026-4670-CVE-2026-5174
Apache httpd http2 vulnerability
https://seclists.org/oss-sec/2026/q2/387

SANS Stormcast Monday, May 4th, 2026: Malicious Homebrew Ads; Wireshark Update; Digicert False Positive; cPanel Exploited
Malicious Ad for Homebrew Leads to MacSync Stealer
https://isc.sans.edu/diary/Malicious%20Ad%20for%20Homebrew%20Leads%20to%20MacSync%20Stealer/32942
Wireshark Update
https://www.wireshark.org/docs/relnotes/wireshark-4.6.5.html
Digicert Microsoft Defender False Positive
https://www.reddit.com/r/cybersecurity/comments/1t2hfsh/mde_flagging_digi_cert_certificate_as_malicious/
https://bugzilla.mozilla

SANS Stormcast Friday, May 1st, 2026: Libredtail; FreeBSD dhclient vuln; Linux Copy-Fail; @sans_edu Detecting AI Pickling
Danger of Libredtail
https://isc.sans.edu/diary/Danger%20of%20Libredtail%20%5BGuest%20Diary%5D/32936
FreeBSD dhclient vulnerability
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:12.dhclient.asc
Linux Copy-Fail Vulnerability CVE-2026-31431
https://copy.fail
Bryan Nice Research Paper
https://www.linkedin.com/in/bryannice/
https://www.sans.edu/cyber-research/detecting-ai-pickling

SANS Stormcast Thursday, April 30th, 2026: Odd Requests; MSFT LNK Bug Exploited; Secure Boot Fix; TLS Updates; SAP npm malware
Today's Odd Web Requests
https://isc.sans.edu/diary/Today%27s%20Odd%20Web%20Requests/32934
Incomplete Patch of APT28's Zero-Day Leads to CVE-2026-32202
https://www.akamai.com/blog/security-research/2026/apr/incomplete-patch-apt28s-zero-day-cve-2026-32202
Assess Secure Boot status with Microsoft Defender
https://techcommunity.microsoft.com/blog/MicrosoftDefenderATPBlog/assess-secure-boot-status-wi

SANS Stormcast Wednesday, April 29th, 2026: Odd Vercel Header Usage; GitHub Vuln Patches; MSFT RDP Notification Bug
HTTP Requests with X-Vercel-Set-Bypass-Cookie Header
https://isc.sans.edu/diary/HTTP%20Requests%20with%20X-Vercel-Set-Bypass-Cookie%20Header/32930
GitHub Vulnerability CVE-2026-3854
https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854
Microsoft RDP Notification Bug
https://support.microsoft.com/en-us/topic/april-14-2026-kb5083768-os-build-28000-1836-839e4a25-d979-4158-b70c-182333045883

SANS Stormcast Tuesday, April 28th, 2026: More TeamPCP; Citrix XenServer Unpatched Vulns; Phantom RPC;
TeamPCP Update
https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Update%20008%20-%2026-Day%20Pause%20Ends%20with%20Three%20Concurrent%20Compromises%20%28Checkmarx%20KICS%2C%20Bitwarden%20CLI%20Cascade%2C%20xinference%20PyPI%29%2C%20CanisterSprawl%20npm%20Worm%20Identified%2C%20and%20Tier%201%20Coverage%20Returns/32926
https://socket.dev/blog/73-open-vsx-sleeper-extensions-glassw

SANS Stormcast Friday April 24rd, 2026: Apple Update; Bitwarden Compromise; ASP.NET Core Patch
Apple Patches Exploited Notification Flaw
https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Notification%20Flaw/32922
Bitwarden CLI Compromised
https://socket.dev/blog/bitwarden-cli-compromised
https://community.bitwarden.com/t/bitwarden-statement-on-checkmarx-supply-chain-incident/96127
Microsoft Security Advisory CVE-2026-40372 ASP.NET Core Elevation of Privilege
https://github.com/dot

SANS Stormcast Thursday, April 23rd, 2026: Stealing Telegram Sessions; Oracle CPU; Firefox Patches
Beyond Cryptojacking: Telegram tdata as a Credential Harvesting Vector, Lessons from a Honeypot Incident
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Beyond%20Cryptojacking%3A%20Telegram%20tdata%20as%20a%20Credential%20Harvesting%20Vector%2C%20Lessons%20from%20a%20Honeypot%20Incident/32888
Checkmarx Compromise
https://socket.dev/blog/checkmarx-supply-chain-compromise
Oracle Quarterly Critical

SANS Stormcast Wednesday, April 22nd, 2026: WAV Malware; GitHub OAUTH Phishing; Perforce Settings
A .WAV With A Payload
https://isc.sans.edu/diary/A%20.WAV%20With%20A%20Payload/32910
The Phishy GitHub Issue Case
https://blog.atsika.ninja/posts/the-phishy-github-issue-case/
P4WNED: How Insecure Defaults in Perforce Expose Source Code Across the Internet
https://morganrobertson.net/p4wned/

SANS Stormcast Tuesday, April 21st, 2026: CVE and EPSS; Windows Server 2025 OOB; QEMU Abuse;
Handling the CVE Flood With EPSS
https://isc.sans.edu/diary/Handling%20the%20CVE%20Flood%20With%20EPSS/32914
Windows Server 2025 Out of Band Patch
https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#4835
QEMU abused to evade detection and enable ransomware delivery
https://www.sophos.com/en-us/blog/qemu-abused-to-evade-detection-and-enable-ransomware-delivery

SANS Stormcast Monday, April 20th, 2026: Lumma Stealer and Sectop RAT; Windows 0-Day Exploited; NIST NVD Update; FortiSandbox PoC
Lumma Stealer infection with Sectop RAT (ArechClient2)
https://isc.sans.edu/diary/Lumma%20Stealer%20infection%20with%20Sectop%20RAT%20%28ArechClient2%29/32904
Three Recent Windows Defender Vulnerabilities Exploited (one 0-day)
https://x.com/HuntressLabs/status/2044882115574091960
FortiSandbox PoC Exploit CVE-2026-39808
https://github.com/samu-delucas/CVE-2026-39808?tab=readme-ov-file
NIST Updates

SANS Stormcast Friday, April 17th, 2026: DVRs Again; Cisco Again; Windows Defender Again; Sonatype
Compromised DVRs and Finding Them in the Wild
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Compromised%20DVRs%20and%20Finding%20Them%20in%20the%20Wild/32886
Cisco ISE RCE Vulnerability and WebEx Auth Bypass CVE-2026-20184 CVE-2026-20180 CVE-2026-20186
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-4fverepv
https://sec.cloudapps.cisco.com/securit

SANS Stormcast Thursday, April 16th, 2026: AI Credential Scans; Microsoft Update Issues; RDP Warnings; GitHub Action Vulns;
Scanning for AI Models
https://isc.sans.edu/diary/Scanning%20for%20AI%20Models/32896
Microsoft Update Problems
https://support.microsoft.com/en-us/topic/april-14-2026-kb5082063-os-build-26100-32690-c57e289d-27c9-47cd-a183-72fabc62c5d7#:~:text=Known%20issues%20in%20this%20update
Microsoft RDP File Warnings
https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remotepc/und

SANS Stormcast Wednesday, April 15th, 2026: Microsoft, Adobe, Fortinet and others Patches
Microsoft Patch Tuesday April 2026
https://isc.sans.edu/forums/diary/Microsoft%20Patch%20Tuesday%20April%202026./32898/
Adobe Patches
https://helpx.adobe.com/security/Home.html
Fortinet Patches
https://fortiguard.fortinet.com/psirt

SANS Stormcast Tuesday, April 14th, 2026: EncystPHP Webshell; CPUID Compromise; OpenAI Mac Cert Issue; Axios Vulnerability
Scans for EncystPHP Webshell
https://isc.sans.edu/diary/Scans%20for%20EncystPHP%20Webshell/32892
CPUID Compromise
https://securelist.com/tr/cpu-z/119365/
https://x.com/d0cTB/status/2042520961824559150
OpenAI Mac Application Update due to Axios Compromise
https://openai.com/index/axios-developer-tool-compromise/
Axios Vulnerability CVE-2026-40175
https://github.com/axios/axios/security/advisories/

SANS Stormcast Monday, April 13th, 2026: Obfuscated JavaScript; Numbers in Passwords; Adobe Patches 0-Day; ClickFix Fix Bypass
Obfuscated JavaScript or Nothing
https://isc.sans.edu/diary/Obfuscated%20JavaScript%20or%20Nothing/32884
Numbers in Passwords
https://isc.sans.edu/diary/Number%20Usage%20in%20Passwords%3A%20Take%20Two/32866
Adobe 0-Day Patch CVE-2026-34621
https://helpx.adobe.com/security/products/acrobat/apsb26-43.html
ClickFix Bypass via ScriptEditor
https://www.jamf.com/blog/clickfix-macos-script-editor-atomic

SANS Stormcast Thursday, April 9th, 2026: Honeypot Fingerprinting; Microsoft Locks Developer Accounts; ActiveMQ Vuln;
Honeypot Fingerprinting
https://isc.sans.edu/diary/More%20Honeypot%20Fingerprinting%20Scans/32878
Microsoft Locks Accounts for Privacy/Encryption Related Developers
https://sourceforge.net/p/veracrypt/discussion/general/thread/9620d7a4b3/ https://news.ycombinator.com/item?id=47687884 https://x.com/windscribecom/status/2041929519628443943
https://windowsforum.com/threads/april-2026-windows-update-

SANS Stormcast Wednesday, April 8th, 2026: Pivoting for Webshells; WatchGuard Firebox Patch; Project Glasswing; Kubernetes Misconfigurations
A Little Bit Pivoting: What Web Shells are Attackers Looking for Today?
https://isc.sans.edu/diary/A%20Little%20Bit%20Pivoting%3A%20What%20Web%20Shells%20are%20Attackers%20Looking%20for%3F/32874
WatchGuard Firebox Arbitrary File Write via Path Traversal in Fireware Web UI
https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00009
Project Glasswing
https://www.anthropic.com/glasswing
Current T

SANS Stormcast Tuesday, April 7th, 2026: Redirects in Phishing; Internet Bug Bounty Suspended; Bluehammer; Keycloak MFA Bypass
How often are redirects used in phishing in 2026?
https://isc.sans.edu/diary/How%20often%20are%20redirects%20used%20in%20phishing%20in%202026%3F/32870
Hackerone Suspends Internet Bug Bounty
https://hackerone.com/ibb?type=team
https://www.linkedin.com/posts/danielstenberg_hackerone-share-7446667043380076545-RX9b/
Bluehammer Windows 0-day Privilege Escalation
https://github.com/Nightmare-Eclipse/Bl

SANS Stormcast Monday, April 6th, 2026: TeamPCP Update and Axio Post Mortem; Fortinet 0-Day
Team PCP Update and Axios Post Mortem
https://isc.sans.edu/diary/32864
https://github.com/axios/axios/issues/10636
Strapi NPM Packages Compromised
https://safedep.io/malicious-npm-strapi-plugin-events-c2-agent/
Fortinet CVE-2026-35616 exctively exploited
https://fortiguard.fortinet.com/psirt/FG-IR-26-099

SANS Stormcast Friday, April 3rd, 2026: Vite Exploits; OpenSSH 10.3; Claude Code Vuln
Attempts to Exploit Exposed "Vite" Installs (CVE-2025-30208)
https://isc.sans.edu/diary/Attempts%20to%20Exploit%20Exposed%20%22Vite%22%20Installs%20%28CVE-2025-30208%29/32860
OpenSSH 10.3 Release
https://seclists.org/oss-sec/2026/q2/7
Claude Code Vulnerability
https://adversa.ai/claude-code-security-bypass-deny-rules-disabled/

SANS Stormcast Thursday, April 2nd, 2026: Script Removing ADS/MotW; Google Chrome 0-Day; iOS/iPadOS 18 Update;
Malicious Script That Gets Rid of ADS
https://isc.sans.edu/diary/Malicious%20Script%20That%20Gets%20Rid%20of%20ADS/32854
Google Chrome Update fixes 21 Vulnerabilities and 0-Day
https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_31.html
Apple Addresses Darksword Vulnerabilities for older devices
https://support.apple.com/en-us/126793

SANS Stormcast Wednesday, April 1st, 2026: Application Control Bypass; Axios NPM Module Compromise; TeamPCP vs Cloud
Application Control Bypass for Data Exfiltration
https://isc.sans.edu/diary/Application%20Control%20Bypass%20for%20Data%20Exfiltration/32850
Axios NPM Module Supply Chain Compromise
https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan
https://www.linkedin.com/events/7444763050819092480/
TeamPCP vs. Cloud Resources
https://www.wiz.io/blog/tracking-

SANS Stormcast Tuesday, March 31st, 2026: Honeypot Session Lifetime; Let’s Encrypt Tests Mass Revocation; F5 RCE Exploited
Honeypot Session Lifetime
https://isc.sans.edu/diary/DShield%20%28Cowrie%29%20Honeypot%20Stats%20and%20When%20Sessions%20Disconnect/32840
Let s Encrypt Tests Mass Revocation
https://community.letsencrypt.org/t/lets-encrypt-2026-mass-revocation-simulation/245960
https://www.certkit.io/blog/ari-solves-mass-certificate-revocation
https://www.certkit.io/blog/lets-encrypt-mass-revocation-simulation
F5

SANS Stormcast Monday, March 30th, 2026: More TeamPCP: telnyx; Netscaler Exploit; macOS ClickFix Fix; Windows Smart Install
TeamPCP Update #2: Telnyx PyPi Compromise
https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Update%20002%20-%20Telnyx%20PyPI%20Compromise%2C%20Vect%20Ransomware%20Mass%20Affiliate%20Program%2C%20and%20First%20Named%20Victim%20Claim/32838
Citrix Netscaler Vulnerability Details
https://labs.watchtowr.com/the-sequels-are-never-as-good-but-were-still-in-pain-citrix-netscaler-cve-202

SANS Stormcast Friday, March 27th, 2026: TeamPCP Update; DarkSword vs Patches; LangFlow Exploited
TeamPCP Supply Chain Campaign: Update 001 - Checkmarx Scope Wider Than Reported, CISA KEV Entry, and Detection Tools Available
https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Update%20001%20-%20Checkmarx%20Scope%20Wider%20Than%20Reported%2C%20CISA%20KEV%20Entry%2C%20and%20Detection%20Tools%20Available/32834
DarkSword and This Weeks iOS Updates
https://cloud.google.com/blog/top

SANS Stormcast Thursday, March 26th, 2026: Apple Patches; SmatApeSG Update; Trivy/LiteLLM/TeamPCP Update; Google Accelerates Quantum Save Crypto Rollout
Apple Patches (almost) everything again. March 2026 edition.
https://isc.sans.edu/diary/Apple%20Patches%20%28almost%29%20everything%20again.%20March%202026%20edition./32830
SmartApeSG campaign pushes Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2)
https://isc.sans.edu/diary/SmartApeSG%20campaign%20pushes%20Remcos%20RAT%2C%20NetSupport%20RAT%2C%20StealC%2C%20and%20Sectop%20RAT%20

SANS Stormcast Wednesday, March 25th, 2026: IP KVM Usage; TeampPCP, Trivy, liteLLM and More
---
Special Webcast about Trivy Supply Chain Attacks
https://www.sans.org/webcasts/when-security-scanner-became-weapon
---
Detecting IP KVM Usage
https://isc.sans.edu/diary/Detecting%20IP%20KVMs/32824
TeamPCP, Trivy, liteLLM, Iran and more
https://www.aikido.dev/blog/teampcp-stage-payload-canisterworm-iran
https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know/
https://bl
Recommended

Ghost Stories For The End Of The World

Hoporenkv Native American Podcast

The Conspiracy Files

The Snow Plow Show Prank Call Podcast

World of Prank Calls

TechnoSnobCast

Snoop Dogg - Flash Biográfico

The Moral Support Podcast

Jubal Phone Pranks from The Jubal Show

پلی لیست | PlayList

Giants Talk: A San Francisco Giants Podcast

The Handlebar Podcast