# SANS Stormcast Tuesday, April 21st, 2026: CVE and EPSS; Windows Server 2025 OOB; QEMU Abuse; (#) Page: https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820/sans-stormcast-tuesday-april-21st-2026-cve-and-epss-windows-server-2025-oob-qemu-abuse Text version: https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820/sans-stormcast-tuesday-april-21st-2026-cve-and-epss-windows-server-2025-oob-qemu-abuse.md Podcast: [SANS Internet Storm Center's Daily Network Security News Podcast](https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820) Published: 2026-04-20T20:18:33+00:00 Episode link: https://mp3.sans.edu/sans-stormcast-tuesday-april-21st-2026-cve-and-epss-windows-server-2025-oob-qemu-abuse Audio file: https://traffic.libsyn.com/secure/securitypodcast/9900.mp3?dest-id=448030 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820/episodes/sans-stormcast-tuesday-april-21st-2026-cve-and-epss-windows-server-2025-oob-qemu-abuse Duration seconds: 334 ## Resource SANS Stormcast Tuesday, April 21st, 2026: CVE and EPSS; Windows Server 2025 OOB; QEMU Abuse; Handling the CVE Flood With EPSS https://isc.sans.edu/diary/Handling%20the%20CVE%20Flood%20With%20EPSS/32914 Windows Server 2025 Out of Band Patch https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#4835 QEMU abused to evade detection and enable ransomware delivery https://www.sophos.com/en-us/blog/qemu-abused-to-evade-detection-and-enable-ransomware-delivery keywords: qemu; windows; server; 2025; oob; patch; cve; epss ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820/episodes/sans-stormcast-tuesday-april-21st-2026-cve-and-epss-windows-server-2025-oob-qemu-abuse/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820/sans-stormcast-tuesday-april-21st-2026-cve-and-epss-windows-server-2025-oob-qemu-abuse.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.