SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
A brief daily summary of what is important in cyber security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually about 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
SANS Stormcast Friday, September 11th, 2026: Redtail Analsys (@sans_edu); Checkpoint VPN Patch; Netscaler and Sonicwall Attacks
Redtail Payload Analysis
https://isc.sans.edu/diary/Redtail%20Payload%20Analysis%20%5BGuest%20Diary%5D/33326
Checkpoint Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510
https://community.checkpoint.com/t5/General-Topics/Action-Required-Critical-Security-Advisory-VPN-Vulnerabilities/td-p/281995
Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
Netscaler ADC Exploit
https://x.com/ethicalhack3r/status/2095480651478663393
Sonicwall SMA1000 Attack
https://hunt.io/blog/sonicwall-sma1000-uk-council-attack
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Thursday, September 10th, 2026: Proxmox Scans; MSFT Defender, Gogole Chorme, and FortiPAM Vulns.
Scans for Proxmox Servers
https://isc.sans.edu/diary/Scans%20for%20Proxmox%20Servers/33324
Next Nightmare Eclipse Vulnerability
https://github.com/MSNightmare/ShieldCrash/blob/main/README.md
Google Chrome Updates
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html
FortiPAM Vulnerability
https://amibeingpwned.com/blog/fortinet-pam-vuln
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Wednesday, September 9th, 2026: Microsoft, Adobe, Ivanti, Fortinet Patch Tuesday
September 2026 Microsoft Patch Tuesday
https://isc.sans.edu/diary/September%202026%20Microsoft%20Patch%20Tuesday/33320
Adobe Security Bulletins
https://helpx.adobe.com/security/security-bulletin.html
Security Advisory Ivanti Neurons for ITSM
https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US
Fortinet Advisory
https://www.fortiguard.com/psirt/FG-IR-26-174
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Tuesday, September 8th, 2026: numbat; MicroTik and Magento (Adobe Commerce) 0-Day
numbat - AI agent observability
https://isc.sans.edu/diary/numbat%20-%20AI%20agent%20observability/33312
MicroTik SSH 0-Day Exploited
https://mikrotik.com/supportsec/september-2026-vulnerability/
https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/
Adobe Commerce - Magento - 0-Day Exploited
https://sansec.io/research/stylesmuggler-0day
N-Able 4th Hotpatch
https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF4_Release_Notes.htm
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Friday, September 4th, 2026: AV Exploits; Plex Update; Cisco Patches; Sangoma Switchvox Exploited
Nightmare Eclipse Discloses Several Anti-Malware Privilege Escalation Exploits
https://github.com/MSNightmare
Plex Update
https://forums.plex.tv/t/important-security-update-for-plex-media-server-v1-43-2-and-earlier/942319
Cisco Update
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-smime-disc-dzw4rEdY
Sangoma Switchvox Exploit
https://horizon3.ai/attack-research/disclosures/cve-2026-9586-sangoma-switchvox-rce/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Thursday, September 3rd, 2026: SMA1000 0-Day Patch; SSRF Validation Issues; Faronics Abuse
Sonicwall SMA1000 Exploited Vulnerability Patched
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016
SSRF: The Validator Can Lie
https://xclow3n.com/post/the-validator-can-lie/
Git Hijack for AI Agents
https://www.manifold.security/blog/ai-coding-agents-git-hijack
Fronics Deploy Abuse
https://www.huntress.com/blog/faronics-deploy-abuse
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Wednesday, September 2nd, 2026: Guildma Update; Proxmox 7 Auth Bypass; Windows Hotpatch; Virtualizor BGP Hack
Guildma (Astaroth) malware infection from Brazilian Portuguese email
https://isc.sans.edu/diary/Guildma%20%28Astaroth%29%20malware%20infection%20from%20Brazilian%20Portuguese%20email/33300
Authentication bypass in EOL Proxmox VE 7 release
https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/page-4#post-867929
https://gist.github.com/nebusecurity/65fe90dd673d395b7926278d7eaf5849
Updated Windows Server hotpatch calendar
https://learn.microsoft.com/en-us/windows/release-health/windows-server-release-info#windows-server-hotpatch-calendar
Virtualizor BGP Hijacking
https://www.virtualizor.com/blog/security-incident-bgp-hijacking/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Tuesday, September 1st, 2026: LLM Honeypot; PaperCut Update; TerminalFix Malware;
The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary
https://isc.sans.edu/diary/The%20Coding-Agent%20Trap%3A%20When%20a%20%22Free%22%20LLM%20Endpoint%20Is%20the%20Adversary/33298
PaperCut Public Exploit Available
https://github.com/rapid7/metasploit-framework/pull/21842
TerminalFix Campaign;
https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Monday, August 31st, 2026: Malware Statistics; PaperCut Update; Watchguard and DLink Patches;
Some Malicious PE Stats
https://isc.sans.edu/diary/Some%20Malicious%20PE%20Stats/33292
PaperCut Releases Two Preliminary Patches for Exploited Vulnerability
https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/
DLink Vulnerabliities
https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10513
Watchguard Patches
https://psirt.watchguard.com
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Friday, August 28th, 2026: Broken Polymorphic Phishing; Router Implants; llms.txt exploits; Papercut 0-Day
A polymorphic phishing page (that occasionally breaks itself)
https://isc.sans.edu/diary/A%20polymorphic%20phishing%20page%20%28that%20occasionally%20breaks%20itself%29/33290
Chinese Implants in the Supply Chain
https://www.vulncheck.com/blog/zbt-darklantern-speakingstone?_sp=1068fa46-3d91-427e-8120-aa6d8bda2912.1787865822277
Data Became Code: We Ran Code Inside Fortune 500s Using Files They Published for AI Agents
https://medium.com/@alonhertz1/data-became-code-we-ran-code-inside-fortune-500s-using-files-they-published-for-ai-agents-0cd67ffbbffc
Papercut Security Advisory
https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Thursday, August 27th, 2026: Entra ID Admins; Unifi Patches; log4j Vuln; Sleepwalker Malware
Who Has Admin Rights in your Entra ID Directory?
https://isc.sans.edu/diary/Who%20Has%20Admin%20Rights%20in%20your%20Entra%20ID%20Directory%3F/33284
Ubiquity Unifi Patches
https://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9
Log4J FilteredObjectInputStream Vulnerability
https://github.com/joanbono/log4j2-4255-exploit
https://jeffmcjunkin.com/posts/log4j2-fois-marshalledobject/
Sleepwalker Malware
https://r136a1.dev/2026/08/24/sleepwalker-a-passive-backdoor-with-its-own-command-language/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Wednesday, August 26th, 2026: Obfuscating SSRF; Paint and Photos AI Watermarks; FTP Banner C2;
Obfuscating IP Addresses as Hostnames
https://isc.sans.edu/diary/Obfuscating%20IP%20Addresses%20as%20Hostnames/33280
Microsoft Paint and Photos Embed Server-Issued GUIDs as Invisible Watermarks in Locally-Generated Images
https://xusheng.dev/posts/reversing/mspaint_invisible_watermark/main/
FTP Banners The New Dead Drop Resolver Delivering Novel RATs
https://socradar.io/blog/ftp-banners-new-dead-drop-resolver-rats/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Tuesday, August 25th, 2026: DOUBLECUP PNG; WebAudio Fingerprinting; Expired Domains; Android; Car
DOUBLECUP's PNG Payload
https://isc.sans.edu/diary/DOUBLECUP%27s%20PNG%20Payload/33274
AliExpress WebAudio fingerprinting
https://blog.laserphile.com/2026/08/aliexpress-webpage-keeping-multipoint.html
Expired DMARC Reporting Domain Exposed 86 Domains
https://www.sh.consulting/blog/abandoned-dmarc-reporting-domain
Android Car Malware
https://securelist.com/android-head-unit-malware/121106/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Monday, August 24th, 2026: More Entra Powershell; Entra Vulnerability; GitLab Vuln (and PoC); GTA 6 Leak Malware
Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!
https://isc.sans.edu/diary/Who%20Got%20Missed%20in%20the%20MFA%20Rollout%3F%20More%20Powershell%20%2B%20Graph%20%2B%20Entra%20scripting!/33272
Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays
https://isc.sans.edu/diary/Even%20MOAR%20Powershell%2C%20looking%20at%20Entra%20logins%20-%20the%20good%2C%20the%20bad%20and%20the%20password%20sprays/33268
Microsoft Entra ID Remote Code Execution Vulnerability CVE-2026-69836
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836
GitLab Critical Patch Release CVE-2026...
SANS Stormcast Friday, August 21st, 2026: Microsoft Graph and Powershell; Keycloak Vuln; Cryptographic Context Injection; N-Able Password Leak
Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses
https://isc.sans.edu/diary/Using%20Microsoft%20Graph%20and%20Powershell%20to%20Mine%20for%20Information%20-%20Stale%20Accounts%20and%20Licenses/33264
Using Microsoft Graph and Powershell - Risk Detection Commands
https://isc.sans.edu/diary/Using%20Microsoft%20Graph%20and%20Powershell%20-%20Risk%20Detection%20Commands/33266
Keycloak Vulnerability
https://github.com/keycloak/keycloak/issues/51833 https://www.keycloak.org/2026/08/keycloak-2672-released
CRYPTOGRAPHIC CONTEXT INJECTION ATTACK
https://adversa.ai/blog/cryptographic-context-injection-grok-data-theft/
N-able password manager
https://amibeingpwned.com/blog/solar-winds-part-2-avoided?_sp=75fd154...
SANS Stormcast Thursday, August 20th, 2026: Cloud Metadata Scans; Oracle and Netscaler Patches; Fake Ransomware Rescuers
Simple Scans for Cloud Metadata Service
https://isc.sans.edu/diary/Simple%20Scans%20for%20Cloud%20Metadata%20Service/33260
Oracle Critical Security Patch Update Advisory - August 2026
https://www.oracle.com/security-alerts/cspuaug2026.html
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939
Beware of Ransomware Rescuers
https://www.guidepointsecurity.com/blog/beware-ransom-busters/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Wednesday, August 19th, 2026: Copilot as Whitstleblower; GEEKOM Bad Driver; Medusa Update; Encrypted AI
CoSnitch: When Your AI Assistant Becomes Its Own Whistleblower
https://www.varonis.com/blog/cosnitch
GEEKOM confirms malware was hosted on its website
https://videocardz.com/newz/geekom-apologizes-for-hosting-malware-in-driver-package-for-its-mini-pcs
Medusa Ransomware Update
https://www.cisa.gov/sites/default/files/2026-08/aa25-071a-stopransomware-medusa-ransomware-508c.pdf
How Google is Making Private AI Practical with Homomorphic Encryption
https://blog.google/security/how-google-is-making-private-ai-practical-with-homomorphic-encryption/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Tuesday, August 18th, 2026: Apple Patches; Screen Sharing Security; Download More RAM
Apple Patches or iOS and macOS
https://isc.sans.edu/diary/Apple%20Patches%20iOS%20and%20macOS/33254
Screen Sharing Security
https://isc.sans.edu/diary/Apple%20Screen%20Sharing%20Security/33252
Download More RAM: Dismantling Windows Operating System Defenses with Mischievous Memory
https://www.usenix.org/system/files/usenixsecurity26-collins.pdf
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Monday, August 17th, 2026: MacOS Screen Sharing; GeoServer Patch; SAP Exploited;
macOS Screen Sharing Vulnerability Exploited
https://advisories.ncsc.nl/2026/ncsc-2026-0280.html
GeoServer Patch
https://geoserver.org/announcements/vulnerability/2026/08/14/geoserver-3-0-1-released.html
Recent SAP Commerce Cloud Vuln Exploited
https://x.com/DefusedCyber/status/2088240809355153647
ChainDrop npm Worm
https://medium.com/governed-at-the-source/the-chaindrop-npm-worm-august-2026-how-444-packages-were-compromised-without-a-single-npm-b0c9e5a4c387
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Friday, August 14th, 2026: AI vs. Honeypot Data; CPU Bugs; GeoServer 0-Day; Windows USB Driver Confusion
Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI
https://isc.sans.edu/diary/Using%20Gemma4%20with%20Ollama%20-%20Testing%20File%20Hash%20Analysis%20and%20Recommendations%20with%20AI/33242
CPU Privilege Escalation
https://github.com/xoreaxeaxeax/smiiiiiiiiiiiiiiii
https://github.com/xoreaxeaxeax/skitter-creek-bath-salts
GeoServer Vulnerability
https://x.com/q1uf3ng/status/2087490992723407096
Windows USB Driver Vulnerability
https://x.com/0xedh/status/2085842285481062887
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Thursday, August 13th, 2026: Process Accounting; ShieldBreak; SharePoint JWT Vuln PoC; AI regulation
Linux Kernel Process Accounting
https://isc.sans.edu/diary/Linux%20Kernel%20Process%20Accounting/33240
ShieldBreak - Windows Defender 0day vulnerability
https://git.projectnightcrawler.dev/NightmareEclipse/ShieldBreak/src/branch/main
Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/
California law puts digital fingerprints on AI fakes
https://digital-strategy.ec.europa.eu/en/policies/eu-icons-labelling-ai-generated-content
https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Wednesday, August 12th, 2026: Microsoft Patch Tuesday; Zoom Vulnerabilities; Mozilla Revokes Key; Rogue Inflight Wifi
Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20August%202026/33236
Zoom Vulnerablities CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415
https://a.security/blog/asecurity-zoomsday
Mozilla Revokes GPG Key
https://blog.mozilla.org/security/2026/08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/
Rogue Inflight Wifi
https://www.bleepingcomputer.com/news/security/delta-probes-wi-fi-deauth-attack-on-flight-carrying-def-con-attendees/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Tuesday, August 11th, 2026: Solana Attacks; AI Generated Patches; Gunra Ransomware; Neo4J/GraphQL Patch
Scans for Solana (Surfpool?) Endpoints
https://isc.sans.edu/diary/Scans%20for%20Solana%20%28Surfpool%3F%29%20Endpoints/33230
Why AI-generated vulnerability patches still require expert human review
https://1password.com/blog/why-ai-generated-patches-still-require-human-review?_sp=15ec2845-9e6c-4d15-8ac5-fe9bc1fe4c08.1786396502013
Gunra Ransomware
https://www.cisa.gov/sites/default/files/2026-08/aa26-222a-stopransomware-gunra-ransomware_508c.pdf
Neo4J/GraphQL Vulnerability CVE-2026-5423
https://github.com/neo4j/graphql/security/advisories/GHSA-fcpg-3fw5-vc65
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Monday, August 10th, 2026: Linux Shell Forensics; Criticial MacOS Patch; More N-Central Hotfixes; Exploited Metabase Vuln;
Linux Shell Forensic: Let s Dive Into Atuin!
https://isc.sans.edu/diary/Linux+Shell+Forensic+Lets+Dive+Into+Atuin/33226
Apple Patches macOS Screen Sharing Vulnerability
https://support.apple.com/en-us/148170
More N-Able N-Central Issues
https://www.n-able.com/blog/n-central-security-update-august-6-2026
Metabase Unauthenticated SQL injection
https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Friday, August 7th, 2026: Fast SSH Attacks; Dell BIOS Passwd Weakness; Crypto Wallet Vuln; Benchmarking LLMs for Threat Intel (@sans_edu)
22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary]
https://isc.sans.edu/diary/22+Seconds+to+Compromise+How+Automated+SSH+Actors+Move+From+Login+to+Persistence+Before+You+Can+Blink+Guest+Diary/33220
Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)
https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/
Ill Bloom: Crypto Wallet Vulnerability
https://illbloom.org
Benchmarking Free-Tier Large Language Models as Cognitive Aids for Operationalizing Unstructured Cyber Threat Intelligence
https://www.sans.edu/cyber-research/benchmarking-free-tier-large-language-models-cognitive-aids-operationalizing-unstructured-cyber-threat-intelligence
My...
SANS Stormcast Thursday, August 6th, 2026: keyv/cachable Worm IR; Apple Private Relay Leak; COLDCARD Phish
Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm
https://isc.sans.edu/diary/Don%27t%20Revoke%20That%20Token%20Yet%3A%20Inside%20the%20keyv%20cacheable%20npm%20Worm/33218
IP and DNS Leaks in WebKit Affecting Proxy Browsers and Apple iCloud Private Relay
https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/?ref=404media.co
COLDCARD Issues
https://x.com/threatinsight/status/2084328552481112429
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Wednesday, August 5th, 2026: Diagnostic Tool Hunt; Device Code Phishing; XCSSET; NuGet API Keys
Botnet Hunting for Vulnerabilities in Diagnostic Tools
https://isc.sans.edu/diary/Botnet%20Hunting%20for%20Vulnerabilities%20in%20Diagnostic%20Tools/33214
Inside Greatness: Telegram-Distributed M365 AiTM PhaaS
https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing
A Deep Dive Into the Latest XCSSET Version
https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/
Strengthening NuGet Supply Chain Security: Reducing API Key Lifetime
https://devblogs.microsoft.com/dotnet/strengthening-nuget-supply-chain-security-reducing-api-key-lifetime/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Tuesday, August 4th, 2026: More Arch Linux AUR trouble; iCloud Sharing; Pass the Passkey
AUR packages adoption disabled
https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/DRDEU3JUSC72CB265XHXPFA3DFSLXPBP/
Apple's iCloud File Sharing Left Ex-Employees With Access to Secret Documents
https://www.macrumors.com/2026/08/03/apple-icloud-sharing-ex-employees/
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Monday, August 3rd, 2026: zipdump.py update; Atomic MacOS Analysis; OpenAI Phishing; COLDCARD Vulnerability
zipdump.py Metadata Encoding
https://isc.sans.edu/diary/zipdumppy+Metadata+Encoding/33202/
Atomic MacOS (AMOS) stealer infection
https://isc.sans.edu/diary/Atomic%20MacOS%20%28AMOS%29%20stealer%20infection/33208
Phishing Campaigns Targeting AI Solutions Providers
https://isc.sans.edu/diary/Phishing+Campaigns+Targeting+AI+Solutions+Providers/33206/
Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware
https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Friday, July 31st, 2026: Pre Botnet Recon; Cisco Backdoor Exploited; Inconsistent Group Chats
Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner
https://isc.sans.edu/diary/Reconnaissance%20First%3A%20An%20SSH%20Bot%20That%20Sizes%20Up%20Your%20Hardware%20Before%20Deploying%20a%20Miner%20%5BGuest%20Diary%5D/33198
Cisco Secure Firewall Management Center Software Static Credential Vulnerability Exploited CVE-2026-20316
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
Inconsistent Group Chats
https://www.usenix.org/conference/usenixsecurity26/presentation/gegenhuber
https://www.heise.de/en/news/Encrypted-but-wrong-Group-chats-vulnerable-to-manipulated-content-11384112.html
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Thursday, July 30th, 2026: Apple Patches; IPMI Admin PW Hash Leak; VMWare Patches; OpenWRT Patch
Apple Patch Summary / Postscript
https://isc.sans.edu/diary/Apple%20Patches%20Everything%20%28July%202026%29/33196
IPMI Admin Password Hash Leak
https://lavahq.io/research/bmc-exposure-alert
Patches for VMWare
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
OpenWRT Patch, odhcpd vulnerability CVE-2026-53921
https://github.com/openwrt/odhcpd/security/advisories/GHSA-7fwx-hhrg-3496
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Wednesday, July 29th, 2026: AutoIT Payload Injector; Appele Patches; SourTrade Malware; NGINX Exploit
AutoIT Payload Injector
https://isc.sans.edu/diary/AutoIT%20Payload%20Injector%20/33192
Apple Security Update
https://support.apple.com/en-us/100100
SourTrade: Browser-Assembled Malware Delivered Through Malvertising
https://blog.confiant.com/p/sourtrade-browser-assembled-malware
NGINX Exploit CVE-2026-42530, CVE-2026-42533
https://github.com/DepthFirstDisclosures/Nginx-Rift/tree/main
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Tuesday, July 28th, 2026: Spring Boot Scans; VBulletin Vulnerability; MSFT Defender for Linux; MongoDB Update
Java Spring Boot "heapdump" scans
https://isc.sans.edu/diary/Java%20Spring%20Boot%20%22heapdump%22%20scans/33188
VBULLETIN RUNTIME TEMPLATE RUNMATHS PREAUTH RCE
https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/
Microsoft Defender for Linux Update may disable restart
https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint-releases#issues-have-been-found-with-versions-101260420000101260420009
MongoDB Updates CVE-2026-13072
https://github.com/advisories/GHSA-wvx7-gr2m-7rf5
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Monday, July 27th, 2026: ESAFENET CDG Scans; DNS Poisoning; macOS Gatekeeper bypass; GitHub and PyPi updates
Scans for ESAFENET CDG 3 Document Management System Weak Logins
https://isc.sans.edu/diary/Scans%20for%20ESAFENET%20CDG%203%20Document%20Management%20System%20Weak%20Logins/33184
DNS Poisoning Tactics Expand to Hospitality Wi-Fi
https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/
Silent Replacement of Trusted macOS App Executables
https://mysk.blog/2026/07/23/macos-overwrite-app-executables/
GitHub and PyPi Defense updates
https://github.blog/security/supply-chain-security/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates/
https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days/
https://www.bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Friday, July 24th, 2026: OpenAI vs. Huggingface; Zimbra Exploited; Notepad++ Abuse; Browser as C2
When the "Autonomous Attacker" Is Your Own AI Model
https://isc.sans.edu/diary/When%20the%20%22Autonomous%20Attacker%22%20Is%20Your%20Own%20AI%20Model/33180
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra
https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a
https://cert.gov.ua/article/6318634
https://cybersecuritynews.com/hackers-abuse-notepad-plugins/
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Thursday, July 23rd, 2026: Rondo and Geoserver; Oracle Patches; Checkpoint 0-day; OpenAI vs Huggingface
Rondo Meets Geoserver
https://isc.sans.edu/diary/Rondo%20Meets%20Geoserver/33176
Oracle July Patch Update
https://www.oracle.com/security-alerts/cpujul2026.html
OpenAI and Hugging Face partner to address security incident during model evaluation
https://openai.com/index/hugging-face-model-evaluation-security-incident/
Checkpoint July 2026 Security Advisory (CVE-2026-16232)
https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Wednesday, July 22nd, 2026: Captive Portals; Critical Serv-U and Zimbra Update; Apple Hide-My-Email fix
Captive Portal Detection
https://isc.sans.edu/diary/Captive%20Portal%20Detection/33172
Critical SolarWinds Serv-U Update
https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm
Zimbra Update with Critical Security Fixes
https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/
Apple Fixed Hide My E-Mail Leak
https://www.404media.co/apple-fixes-hide-my-email-vulnerability-after-404-media-coverage/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Tuesday, July 21st, 2026: More Wordpress Details; HOLLOWGRAPH MSFT Calendar Abuse; Gitea Vulnerability
WordPress Exploitation Underway (CVE-2026-63030)
https://isc.sans.edu/diary/WordPress%20Exploitation%20Underway%20%28CVE-2026-63030%29/33168
HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels
https://www.group-ib.com/blog/hollowgraph-microsoft-365/
Gitea Vulnerablity CVE-2026-58443
https://github.com/go-gitea/gitea/security/advisories/GHSA-xxjv-752h-3vp2
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
SANS Stormcast Friday, July 17th, 2026: Hikvision Scans; LG Spyware; Huggingface Hack; Wordpress Core RCE
Scans for Hikvision Intelligent Security API
https://isc.sans.edu/diary/Scans%20for%20Hikvision%20Intelligent%20Security%20API/33164
LG Monitor Spyware
https://www.techradar.com/televisions/lgs-gaming-monitors-and-tvs-are-facing-a-user-revolt https://www.youtube.com/watch?v=Q9uefFYe6bM
Huggingface Hack
https://huggingface.co/blog/security-incident-july-2026
Wordpress Core RCE
https://wp2shell.com
SANS Stormcast Friday, July 17th, 2026: Windows Hello for Business; NGINX Vuln; 7-zip vuln
German Federal Information Security Office Analyzes Windows Hello for Business
https://www.heise.de/en/news/BSI-dissects-Windows-Hello-Where-Microsoft-s-login-reaches-its-limits-11366125.html
https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/Studies/Windows_dissected/AP1_Windows-Hello-for-Business.pdf?__blob=publicationFile&v=7
NGINX Vulnerability
https://my.f5.com/manage/s/article/K000162097
7-Zip XZ Decompression CVE-2026-14266
https://www.zerodayinitiative.com/advisories/ZDI-26-444/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich