# SANS Stormcast Wednesday, June 24th, 2026: Patching vs. Configurations Updates; libssh2 and ffmpeg vuln; (#) Page: https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820/sans-stormcast-wednesday-june-24th-2026-patching-vs-configurations-updates-libssh2-and-ffmpeg-vuln Text version: https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820/sans-stormcast-wednesday-june-24th-2026-patching-vs-configurations-updates-libssh2-and-ffmpeg-vuln.md Podcast: [SANS Internet Storm Center's Daily Network Security News Podcast](https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820) Published: 2026-06-24T00:14:21+00:00 Episode link: https://mp3.sans.edu/sans-stormcast-wednesday-june-24th-2026-patching-vs-configurations-updates-libssh2-and-ffmpeg-vuln Audio file: https://traffic.libsyn.com/secure/securitypodcast/9984.mp3?dest-id=448030 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820/episodes/sans-stormcast-wednesday-june-24th-2026-patching-vs-configurations-updates-libssh2-and-ffmpeg-vuln Duration seconds: 408 ## Resource SANS Stormcast Wednesday, June 24th, 2026: Patching vs. Configurations Updates; libssh2 and ffmpeg vuln; CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration. https://isc.sans.edu/diary/CVE-2024-40766%3A%20The%20Patch%20Fixed%20the%20Bug.%20Nobody%20Fixed%20the%20Configuration./33094 libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c https://www.vulncheck.com/advisories/libssh2-out-of-bounds-write-via-unchecked-packet-length-in-transport-c PixelSmash – Critical FFmpeg Vulnerability Turns Media Files into Weapons https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: sonicwall; patching; configurations; libssh2; ssh; pixelsmash; ffmpeg ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820/episodes/sans-stormcast-wednesday-june-24th-2026-patching-vs-configurations-updates-libssh2-and-ffmpeg-vuln/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820/sans-stormcast-wednesday-june-24th-2026-patching-vs-configurations-updates-libssh2-and-ffmpeg-vuln.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.