SANS Stormcast Wednesday, December 3rd, 2025: SmartTube Compromise; NPM Malware Prompt Injection Attempt; Angular XSS Vulnerability (#)

SANS Stormcast Wednesday, December 3rd, 2025: SmartTube Compromise; NPM Malware Prompt Injection Attempt; Angular XSS Vulnerability (#)

Author: Johannes B. Ullrich December 3, 2025 Duration: 6:06
SANS Stormcast Wednesday, December 3rd, 2025: SmartTube Compromise; NPM Malware Prompt Injection Attempt; Angular XSS Vulnerability SmartTube Android App Compromise The key a developer used to sign the Android YouTube player SmartTube was compromised and used to publish a malicious version. https://github.com/yuliskov/SmartTube/issues/5131#issue-3670629826 https://github.com/yuliskov/SmartTube/releases/tag/notification Two Years, 17K Downloads: The NPM Malware That Tried to Gaslight Security Scanners Over the course of two years, a malicious NPM package was updated to evade detection and has now been identified, in part, due to its attempt to bypass AI scanners through prompt injection. https://www.koi.ai/blog/two-years-17k-downloads-the-npm-malware-that-tried-to-gaslight-security-scanners Stored XSS Vulnerability via SVG Animation, SVG URL, and MathML Attributes Angular fixed a store XSS vulnerability. https://github.com/angular/angular/security/advisories/GHSA-v4hv-rgfq-gp49 keywords: angular; xss; svg; mathml; npm; smarttube;

Each weekday morning, Johannes B. Ullrich provides a concise, actionable briefing on the shifting landscape of digital threats and defenses with SANS Internet Storm Center's Daily Network Security News Podcast. Think of it as your first cup of coffee for cybersecurity awareness-a focused, five-minute update that cuts through the noise. The content is shaped by real-time data and analysis from the SANS Internet Storm Center, enriched by questions and experiences shared directly from the community of professionals in the field. You’ll hear about emerging vulnerabilities, active exploits, and practical insights that are both late-breaking and genuinely educational, all delivered in a straightforward, no-frills manner. This podcast serves as a reliable filter, turning the overwhelming flow of security news into a clear, digestible summary that helps you understand current risks and start your day informed. It’s built on a foundation of shared knowledge, where listener contributions actively guide the discussion, making each episode a collaborative reflection of what matters right now in network security.
Author: Language: English Episodes: 100

SANS Internet Storm Center's Daily Network Security News Podcast
Podcast Episodes