meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Thursday, June 11th, 2026: Framing Protections; npm improvements; Adobe Patches; New Defender 0-day

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9755 Ratings

🗓️ 11 June 2026

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Thursday, June 11th, 2026: Framing Protections; npm improvements; Adobe Patches; New Defender 0-day

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, June 11th,

0:07.5

2006 edition of the Sands and then at Storm Center's Stormcast.

0:12.3

My name is Johannes Ulrich, recording today from Jacksonville, Florida.

0:17.3

And this episode is brought you by the sands.edu credit certificate program in industrial control system security.

0:25.6

Jan today published a diary on Consecure Policy and how the X-frame options header is sort of starting to get replaced, supplemented with the frame ancestor property in CSP.

0:39.9

This is something that Jan looked first at three years ago,

0:43.7

so what he published today was an update, essentially,

0:47.6

to what was going on more recently.

0:50.6

Now, the X-frame Options header still works.

0:53.8

So in so far, there's nothing really wrong with it.

0:56.0

However, officially it got now replaced with con security policy.

1:00.6

And what Jan found is actually over the last years, over the last three years,

1:05.3

there was a significant increase in the uptake of con and secure policy

1:10.0

and the frame ancestor directive when it comes

1:14.1

to con and security policy. So it's overall a good thing that this has been improving. I would still

1:22.9

kind of leave the X-frame options header in place personally. Yes, you know, sort of does the same

1:29.3

thing as frame ancestors. I find that with concert policy, it's easier to sort of get lost to

1:34.8

complexity and maybe have a syntax error or something like this. So the frame ancestor directive

1:40.4

may not work as expected. And as far as I know all existing browsers still support

1:46.1

X-frame options, so kind of a nice backup, I guess, in this case.

1:52.0

And in a blog post, NPM did announce some changes in the upcoming NPM 12 release, which is expected in July.

2:02.5

These changes are changes to default behaviors that are not really new features

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.