Skip to content

Podcasts

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

Hosted by Johannes B. Ullrich

Five to eight minutes every weekday morning on what the SANS honeypots and handlers saw overnight.

Solo Daily Under 30 min· Started 2009
Level
Practitioner, assumes you work in or study security
Status
Active, last episode
Who's behind it
Vendor-run, SANS Institute sourceProduced by the SANS Internet Storm Center; released under a Creative Commons licence.
Last verified
Transcripts for some episodes

Listed underThreat intel and newsSOC and blue team

Editorial take

The most useful five minutes in security audio for anyone who defends a network. Johannes Ullrich, dean of research at the SANS Technology Institute, reads through the Internet Storm Center's handler diaries and the day's patches, exploited zero-days, and scan trends, with almost no filler. What sets it apart from other daily briefs is the data: stories often start from what the ISC sensors and honeypots actually logged, not from a press release. Friday episodes regularly add a short interview with a SANS.edu graduate student about their research paper. The limitation is depth: five minutes can name a CVE and say patch it, not teach you why it works. Treat it as a morning checklist, then go read the linked diary.

Last hand-checked 2026-09-30.

Listen if you …

  • work in a SOC or run infrastructure and need to know what to patch today
  • want sensor and honeypot data rather than vendor marketing in your news
  • have five minutes, not fifty, and want them used well

Skip if you …

  • you are new to security, it assumes you know what a CVE, a honeypot, or an SD-WAN manager is
  • you want analysis or opinion, this is a fast technical brief

Start with these 3 episodes

  1. 01

    SANS Stormcast Friday, September 25th, 2026: Tricky Phishing URL; MacSync Malware Update; SolarWinds Observable Patch

    · 7 min · Practitioner

    A typical recent episode: a phishing trick, a malware update, and a patch, all in seven minutes.

  2. 02

    SANS ISC Stormcast, Jan 17, 2025: Analyzing Complex Datasets, Citrix Update Issues, Ivanti's Security Advisory, and the Future of Passkeys (@sans_edu)

    · 13 min · Practitioner

    Shows the Friday research segment, here on where passkeys are heading, alongside the usual patch notes.

  3. 03

    SANS Stormcast Friday Feb 28th: Njrat devtunnels.ms; Apple FindMe Abuse; XSS Exploited; @sans_edu Ben Powell EDR vs. Ransomware

    · 14 min · Practitioner

    The SANS.edu interview tests EDR against real ransomware, the kind of evidence most daily shows never get to.

About the show

Stormcast is the daily podcast of the SANS Internet Storm Center, a volunteer handler team run by the SANS Institute that has tracked internet attack activity since 2001. Johannes B. Ullrich, who founded DShield and leads research at the SANS Technology Institute, hosts every episode.

Episodes publish each weekday and run five to eight minutes. Each one covers three or four items: ISC handler diaries, exploited vulnerabilities, and vendor patches, with links on the episode page. Friday editions often include a short interview with a SANS.edu student on their research.

If SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) works for you, these likely will too.