meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Tuesday, April 21st, 2026: CVE and EPSS; Windows Server 2025 OOB; QEMU Abuse;

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 21 April 2026

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Tuesday, April 21st, 2026: CVE and EPSS; Windows Server 2025 OOB; QEMU Abuse;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, April 21st, 2006 edition of the Sands Internet Storm Centers.

0:12.6

Stormcast, my name is Johannes Ulrich, recording day from Amsterdam, Netherlands.

0:18.8

And this episode is brought you by the sands.edu credit certificate program

0:23.7

in cybersecurity leadership. Well, I already mentioned that we do have this flood of new

0:32.0

vulnerabilities that's currently sort of hitting the CVE database that has caused the issues like, for example,

0:39.7

NVD no longer being able to really provide enrichment for many of the new discovered

0:45.7

vulnerabilities. So what are some of the alternatives? And we do have an option here by

0:51.3

Xavier, the EPSS.

0:54.8

EPSS stands for the exploit probability scoring system, and what it attempts to accomplish is

1:03.2

to essentially assign a probability to a vulnerability to figure out how likely it is to

1:10.4

actually be exploited, which of course then

1:13.4

assists you in properly prioritizing this vulnerability. What also makes this interesting is that

1:21.3

this is a newer system was just introduced a few years ago and updated then again three years ago.

1:29.9

Well, this system developed by first is based on an automatic generation of these EPSS scores.

1:38.7

So that makes it sort of more inherently scalable than some of the work that NIST has been doing. So pretty interesting number

1:46.8

that you can add to your vulnerability management process. And to help you out with this,

1:52.9

Xavier also demonstrated how to automatically use it to enrich your data. And as an example,

2:00.4

Xavier implemented this enrichment in Wazoo.

2:04.2

So take a look at the diary and see if this is something that may be useful for your

2:09.3

vulnerability management program. And talking about all the things that can go wrong when

2:14.4

you are rolling out patches. Well, Microsoft this weekend did release an out-of-band patch for Server 2025 to address

2:24.5

issues that were introduced with the security updates released last Tuesday.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.