Legal Cyber Academy
PodcastFreeCurrent

SANS Internet Storm Center Daily Stormcast

Access and status

Cost

Free

Free to read or download at source. No account, no purchase.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

A short daily audio briefing, typically five to ten minutes, summarising the Internet Storm Center diaries and the day's notable vulnerabilities and exploitation activity.

Who it is for, and when

The point is the length and the cadence: it is a daily situational-awareness habit rather than something you learn from. Useful in incident response for knowing which vulnerabilities were being actively exploited on a given date, which can matter when you are dating an intrusion. Published every weekday — episode 10090 dated 11 September 2026.

What it does not cover

It is vulnerability and threat news only — no forensic technique, no case discussion, and nothing on evidence handling or expert work.

Go to the source

Open at isc.sans.edu (opens in a new tab)

https://isc.sans.edu/podcast.html

Details

Type
Podcast
Written for
Working examinerWorking examiner
Topics
news, threat-hunting, network, incident-response
Checked at source
  • A daily handler diary — distinct from the SANS DFIR blog — in which a rotating roster of volunteer handlers writes up whatever they are currently seeing in honeypot data, malware samples, exploit traffic and log telemetry.

  • A gamified platform, run by Centri, of "security investigations and challenges covering; Incident Response, Digital Forensics, Security Operations, Reverse Engineering, and Threat Hunting". Challenges are downloadable artefacts — memory dumps, phishing emails, packet captures, logs — while investigations run in hosted lab instances.

  • CyberDefenders

    Partly free

    A blue-team lab platform hosting scenario-based investigations grouped as endpoint forensics, network forensics, malware analysis, cloud forensics, threat hunting, detection engineering and threat intelligence. Challenges are question-and-answer over supplied evidence, with a scoreboard.

  • Forensics placed inside the incident response lifecycle: building a response capability, response frameworks, evidence acquisition, volatile memory, disk and network evidence, threat intelligence, malware analysis, threat hunting, and reporting — with this edition reframed around ransomware.

  • The annual conference of FIRST, the global forum of incident response and security teams, which comprises over 800 member teams in more than 100 countries. The 2026 edition ran 14-19 June 2026 in Denver, Colorado.