meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Monday, January 5th, 2026: MongoBleed/React2Shell Recap; Crypto Scams; DNS Stats; Old Fortinet Vulns

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 5 January 2026

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Monday, January 5th, 2026: MongoBleed/React2Shell Recap; Crypto Scams; DNS Stats; Old Fortinet Vulns

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, January 5th, 2026th edition of the Sands

0:09.9

and net Storm Center's Stormcast. My name is Johannes Ulrich, recording today from Jacksonville, Florida.

0:17.0

And this episode is brought you by the Sands.edu credit certificate program in cyber defense operations.

0:24.6

Well, first podcast of the new year, so I want to do a quick recap here.

0:29.9

First of all, React to Shell, still hitting the news ever so often year and there.

0:35.1

Mostly various botnets and such,

0:38.9

adding it to their arsenal.

0:41.2

So nothing really too terribly exciting.

0:43.6

Secondly, Mongo Pleat.

0:46.7

I did a special podcast last week,

0:50.1

just to sort of keep everyone in a loop on this one.

0:53.7

Haven't seen a ton of news about this,

0:59.4

but definitely, you know, number one, if you're running MongoDB, make sure that you're patched.

1:05.1

Secondly, you probably want to make sure that MongoDB is not directly exposed to the internet.

1:14.6

And well, in Diaries, we had one this weekend from Brad who wrote about a recent cryptocurrency scam that Brad observed.

1:18.6

This one is your classic advance fee type scam.

1:28.5

The attacker is sending spam messages, claiming that the recipient has some pending cryptocurrency deposit waiting for them.

1:31.0

The way this is sort of made plausible is that they say that the victim signed up

1:33.7

for some kind of cryptocurrency mining

1:36.2

and while their cryptocurrency that they mined

1:39.5

is now basically ready to be withdrawn.

1:43.4

They're promising quite a substantial amount, sort of in the

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.