meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Friday, April 17th, 2026: DVRs Again; Cisco Again; Windows Defender Again; Sonatype

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 17 April 2026

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Friday, April 17th, 2026: DVRs Again; Cisco Again; Windows Defender Again; Sonatype

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Friday, April 17th,

0:07.4

2026 edition of the Sands Internet Storm centers.

0:12.2

Stormcast, my name is Johannes Ulrich,

0:15.0

recording today from Stockholm, Germany.

0:18.5

And this episode is brought you by the sands.edu credit certificate program

0:22.9

in Purple Team Operations. Before starting this podcast, I did a quick look to see when we first

0:30.2

talked about DVRs, digital video recorders getting compromised at scale. And this was about

0:37.4

12 years ago in 2014. One of the sad things

0:42.8

about, well, doing this kind of work for so long is that often the problem isn't off

0:47.1

the flashy new stuff, but what I often call the mosquitoes of the internet, they're around

0:52.8

everywhere. They're really annoying,

0:54.7

but sometimes deadly. And that's these IoT devices and these video devices that are still

1:01.9

being attacked. We do have a diary by one of our interns, Alighiafi, just dissecting one

1:09.5

of these attacks yet again. And yes, there are still thousands of

1:14.2

these devices exposed and the same number pretty much being attached to Alex Botnet here that

1:21.6

he found. Well, take a look at his work. It is evolving. There are ever so often some little tweaks they're making

1:31.2

to their software, but ultimately the old thing still applies if you're connecting a system to the

1:37.7

internet with a well-known password. Well, it's going to get compromised within probably less than a minute.

1:45.4

So let's talk about something new and exciting. Well, imagine that. We do have still Cisco

1:51.2

vulnerabilities. First one, WebEx. WebEx apparently doesn't care. What certificate was

1:57.5

used to sign your single sign-on assertion, so anybody is let in and you're

2:02.9

easily able to impersonate arbitrary users. But it's not just WebEx, wherever you have problems,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.