Handler on Duty: Jesse La Grew
Threat Level: green
Podcast Detail
SANS Stormcast Friday April 24rd, 2026: Apple Update; Bitwarden Compromise; ASP.NET Core Patch
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/9906.mp3
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
Apple Patches Exploited Notification Flaw
https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Notification%20Flaw/32922
Bitwarden CLI Compromised
https://socket.dev/blog/bitwarden-cli-compromised
https://community.bitwarden.com/t/bitwarden-statement-on-checkmarx-supply-chain-incident/96127
Microsoft Security Advisory CVE-2026-40372 – ASP.NET Core Elevation of Privilege
https://github.com/dotnet/announcements/issues/395
| Application Security: Securing Web Apps, APIs, and Microservices | San Diego | May 11th - May 16th 2026 |
| Network Monitoring and Threat Detection In-Depth | Online | Arabian Standard Time | Jun 20th - Jun 25th 2026 |
| Network Monitoring and Threat Detection In-Depth | Riyadh | Jun 20th - Jun 25th 2026 |
| Application Security: Securing Web Apps, APIs, and Microservices | Washington | Jul 13th - Jul 18th 2026 |
| Application Security: Securing Web Apps, APIs, and Microservices | Online | British Summer Time | Jul 27th - Aug 1st 2026 |
| Application Security: Securing Web Apps, APIs, and Microservices | Las Vegas | Sep 21st - Sep 26th 2026 |





