meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Thursday, June 4th, 2026: swagger.json Scans; Android Fake Call Detection; Anthropic Dashboard

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 4 June 2026

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Thursday, June 4th, 2026: swagger.json Scans; Android Fake Call Detection; Anthropic Dashboard

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, June 4th, 2006 edition of the Sands Internet Storm Center's Stormcast.

0:12.2

My name is Johannes Ulrich, recording today from Jacksonville, Florida.

0:17.1

And this episode is brought you by the Sands.edu undergraduate certificate program in Cybersecurity Fundamentals.

0:25.8

Today's diary is nothing earth-shattering new, but I noticed that we still get a ton of requests and with a somewhat sort of increasing tendency for swagger.jason.

0:37.0

Swagger.jason is aagger.J.son is a file that defines Rest Web Services using the Swagger

0:42.8

Open API standard. This is usually sort of reconnaissance. They either look for what particular

0:50.5

API functionality is supported, but also often what type of API it is,

0:56.5

if it's some kind of standard package or so,

0:59.5

that can be identified via the Spaggar.jason metadata,

1:03.6

which often includes something like name of the particular API.

1:09.0

So that can then be used to, for example, look for vulnerable APIs.

1:15.1

Spaggart.jason is certainly something that you should keep installed

1:20.0

if the API is intended to be sort of for public consumption.

1:24.4

On the other hand, well, it's I think something where you should really stay ahead

1:28.0

of the attackers here and should proactively scan sort of your internal API attack surface

1:34.5

to figure out if there's anything that's outdated that's not supposed to be there or just not

1:40.5

supposed to be public. And Google published an interesting blog post how they're going to roll out a new type of caller

1:49.7

ID verification.

1:51.7

Now, spoof caller ID is nothing new.

1:53.6

Has been done for decades probably now.

1:56.5

But it has become more and more of a problem because, of course, AI is now being used to accurately impersonate the voice.

2:04.8

And in some cases, even sort of the face and video calls.

...

Transcript will be available on the free plan in 25 days. Upgrade to see the full transcript now.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.