SANS Stormcast Friday, December 19th, 2025: Less Vulnerabie Devices; Critical OneView Vulnerablity; Trufflehog finds JWTs
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 19 December 2025
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, December 19th, 2025 edition of the Sands Internet Storms Centers. |
| 0:11.6 | Stormcast, my name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:17.2 | And this episode is brought you by the Sands.edu graduate certificate program in cyber security engineering. |
| 0:24.8 | Stick big note about the next couple weeks because we do have holidays sort of midweek, both weeks. |
| 0:31.9 | I'm planning on having at least a podcast on the Monday of each week. |
| 0:37.4 | But aside of that, they'll lay a little bit by ear |
| 0:40.1 | and see if there's any significant news to make a podcast worthwhile. Other than that, |
| 0:45.1 | that'll probably just the one podcast, either Monday or Tuesday, of each week. |
| 0:51.3 | And talking about holidays, something to celebrate is certainly that we do appear to have |
| 0:56.1 | less exposed industrial control system devices and other simple, exploitable devices than we had |
| 1:04.7 | about a year ago. Jan took a look at some of the statistics in Shodan and he sort of has been tracking them continuously over a couple years now. |
| 1:15.7 | And when it comes to just industrial control system devices there, I don't think it's a done deal yet in the sense that they're going to soon be dying out here. |
| 1:26.1 | There seems to be some odd sort of peaks during the summer |
| 1:29.9 | month when we have more industrial control devices exposed than we had sort of during the winner. |
| 1:36.3 | But overall, there seems to be a downward tendency, even though we are at about the same level |
| 1:42.1 | as we had a year ago. |
| 1:44.5 | Where it looks much better is support for SSL version 3 and in particular SL version 2. |
| 1:52.6 | Both dropped approximately by half over the last year. |
| 1:57.5 | So that's pretty good. |
| 1:58.8 | Now, I was saying that it's unlikely that a server will be |
| 2:03.5 | exploited because it's running SL version 3 or SL version 2 for that matter, but it's often |
| 2:10.4 | an indicator that there's a lot of other things wrong with this particular server that, you know, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

