SANS Internet Storm Center's Daily Network Security News Podcast
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Storm Center. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
SANS Stormcast Friday, October 9th, 2026: AI Agent Forensics; AI-Assisted Attack on South Korean Banks; IDN Typosquatting; Cisco Finesse SSRF (CVE-2026-20362) (#)
SANS Stormcast Friday, October 9th, 2026: AI Agent Forensics; AI-Assisted Attack on South Korean Banks; IDN Typosquatting; Cisco Finesse SSRF (CVE-2026-20362) In today's episode: new scripts for reconstructing AI agent activity during forensic investigations, an attacker's Claude chat history recovered after breaches at South Korean financial institutions, internationalized domain name (IDN) lookalikes that still get past Chrome, and an unpatched Cisco Finesse server-side request forgery (SSRF) vulnerability. Reconstructing AI Agent Activity: Two New Scripts for Forensic Review Jim Clausing released two scripts that turn the logs left behind by the OpenCode and Hermes AI agents into searchable JSON, so incident...
SANS Stormcast Thursday, October 8th, 2026: Atlassian Vulnerabilities; ccTLD Compormise; Outlook blocking .msix (#)
SANS Stormcast Thursday, October 8th, 2026: Atlassian Vulnerabilities; ccTLD Compormise; Outlook blocking .msix Scans for Atlassian vulnerablity (CVE-2026-21589) https://isc.sans.edu/diary/Scans%20for%20Atlassian%20vulnerablity%20%28CVE-2026-21589%29/33406 
.gh, .sl and .as ccTLD Compromise https://blog.google/security/chromes-response-to-recent-cctld-registry-hijacks/ Cisco Nexus 3000 and 9000 Series Switches Remote Code Execution Vulnerabilities https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ngoam-rce-LWKQ4BU Outlook Blocking MSIX Files https://www.bleepingcomputer.com/news/microsoft/microsoft-outlook-to-block-msix-attachments-used-in-attacks/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: msix; outlook; microsoft; cisco; nexus; nx-os; patches; atlassian; vulnerability; exploits
SANS Stormcast Wednesday, October 7th, 2026: RMM Tools; libHEIF RCE; Sonicwall SMA1000, OpenSSH updates, DNSSEC KSK Rollover (#)
SANS Stormcast Wednesday, October 7th, 2026: RMM Tools; libHEIF RCE; Sonicwall SMA1000, OpenSSH updates, DNSSEC KSK Rollover More RMM Tools In the Wild https://isc.sans.edu/diary/More%20RMM%20Tools%20In%20the%20Wild/33400 WORDPRESS LIBHEIF RCE https://fortbridge.co.uk/research/wordpress-libheif-rce/ SONICWALL SMA1000 SERIES APPLIANCES Vulnerabilities CVE-2026-102255, CVE-2026-102256, CVE-2026-102257, CVE-2026-102258 https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017 OpenSSH 10.6 Released https://seclists.org/oss-sec/2026/q4/58 DNSSEC Root Key Signing Key Rollover https://blog.cloudflare.com/root-ksk-2024-rollover/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: DNSSEC; ksk; openssh; sonicwall; wordpress; libheif; heif; rmm;
SANS Stormcast Tuesday, October 6th, 2026: cowrie tty Logs; Another Netscaler 0-Day; Exchange Patch (#)
SANS Stormcast Tuesday, October 6th, 2026: cowrie tty Logs; Another Netscaler 0-Day; Exchange Patch TTY Logs and the Data it Captures https://isc.sans.edu/diary/TTY%20Logs%20and%20the%20Data%20it%20Captures/33396 Citrix Netscaler SAML Vulnerability (0-Day) CVE-2026-88779 https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174 https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/ Microsoft Exchange September 2026 V2 Update CVE-2026-96940 https://techcommunity.microsoft.com/blog/exchange/released-september-2026-v2-exchange-server-security-updates/4561718 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: exchange update; ctirix; netscaler
SANS Stormcast Monday, October 5th, 2026: Funny User-Agents; FortMail 0-Day; GitLab Patch; macOS Full Disk Access (#)
SANS Stormcast Monday, October 5th, 2026: Funny User-Agents; FortMail 0-Day; GitLab Patch; macOS Full Disk Access User Agent Strings Curiosities https://isc.sans.edu/diary/User%20Agent%20Strings%20Curiosities/33394 FortiMail Improper limitation of a pathname to a restricted directory CVE-2026-104286 https://fortiguard.fortinet.com/psirt/FG-IR-26-175 Critical GitLab Vulnerability CVE-2026-90970 https://docs.gitlab.com/releases/patches/other-patches/patch-release-gitlab-ai-gateway-19-4-1-released/ Updates to Full Disk Access in macOS https://developer.apple.com/news/?id=p6zjojqw My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: macos; disc access; gitlab; ai gateway; fortimail; fortinet; 0-day; user-agents
SANS Stormcast Friday, October 2nd, 2026: ScreenConnect Abuse; ChatGPT Abuse; Spoofing iCloud; Proton Mail display name (#)
SANS Stormcast Friday, October 2nd, 2026: ScreenConnect Abuse; ChatGPT Abuse; Spoofing iCloud; Proton Mail display name ScreenConnect Client (Ab)used by Attackers https://isc.sans.edu/diary/ScreenConnect+Client+Abused+by+Attackers/33388/#comments Attackers abuse ChatGPT to deliver RAT via ClickFix https://www.huntress.com/blog/chatgpt-custom-gpts-clickfix-rat?_sp=51406044-aa1d-4278-a4e7-adb5b8ef84b2.1790890760100 Spoofing iCloud From Address https://sec-consult.com/blog/detail/from-anyoneicloudcom-spoofing-arbitrary-apple-icloud-identities/ Sender spoofing in Proton Mail via display-name homograph https://alonsovidales.github.io/protonmail-sender-spoofing/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: icloud; proton; mail; email; from; chatgpt; clickfix; screenconnect
SANS Stormcast Thursday, October 1st, 2026: Cisco Catalyst SD-WAN Manager 0-day; Watchguard AP RCE; OpenBao/Vault RCE; Post Quantum Certs (#)
SANS Stormcast Thursday, October 1st, 2026: Cisco Catalyst SD-WAN Manager 0-day; Watchguard AP RCE; OpenBao/Vault RCE; Post Quantum Certs Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability CVE-2026-76504 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU WatchGuard AP Command Injection in Internal Management API Allows Command Execution https://psirt.watchguard.com/CVE-2026-86102/ A Realistic Code Execution Exploit Chain in OpenBao and Vault https://control-plane.io/posts/unauthed-to-rce-in-vault-and-openbao/ Building a post-quantum certificate authority with Merkle Tree Certificates https://blog.cloudflare.com/pq-ca-with-mtcs/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: merkle tree; certificate; post-quantum...
SANS Stormcast Wednesday, September 30th, 2026: Wordfence Scans; MikroTik Vulnerability; Poper Blocker Spyware (#)
SANS Stormcast Wednesday, September 30th, 2026: Wordfence Scans; MikroTik Vulnerability; Poper Blocker Spyware Scans for Wordfence Protected Websites https://isc.sans.edu/diary/Scans%20for%20Wordfence%20Protected%20Websites/33382 MikroTik RouterOS Vulnerability (CVE-2026-84411) https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06 Poper Blocker: The Adblocker That Spies on You https://amibeingpwned.com/blog/poper-blocker-the-adblocker-that-spies-on-you My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: mikrotik; poper blocker; adblocker; spyware; wordfence;
SANS Stormcast Tuesday, September 29th, 2026: MacOS/iOS 0-Day Patch; macOS priv. escalation 0-day; File Notification Attacks (#)
SANS Stormcast Tuesday, September 29th, 2026: MacOS/iOS 0-Day Patch; macOS priv. escalation 0-day; File Notification Attacks Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950) https://isc.sans.edu/diary/Apple%20Emergency%20Patch%20for%20iOS%2026%2C%20macOS26%2C%20macOS15%20%28CVE-2026-86950%29/33376 https://support.apple.com/en-us/100100 Proof of concept for macOS CoreServices Priv. Escalation (CVE-2026-43786) https://github.com/Malwation/CVE-2026-43786 NeedyMantis: Unpacking a post-compromise malware family used in targeted operations https://www.microsoft.com/en-us/security/blog/2026/09/28/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations/ File Notification Attacks
https://inoti.fyi/pubs/file-notification-attacks.pdf My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: file no...
SANS Stormcast Monday, September 28th, 2026: Macfinger Details; NetScaler 0-Day; KiteWorks 0-Day; ShinyHunters and PeopleSoft (#)
SANS Stormcast Monday, September 28th, 2026: Macfinger Details; NetScaler 0-Day; KiteWorks 0-Day; ShinyHunters and PeopleSoft A Closer Look at Malware From the Macfinger ClickFix Campaign https://isc.sans.edu/diary/A%20Closer%20Look%20at%20Malware%20From%20the%20Macfinger%20ClickFix%20Campaign/33368 Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778 https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/ KiteWorks Urges Customers to Shut Down Servers https://www.heise.de/en/news/Imminent-Zero-Day-Attack-KiteWorks-Urges-Customers-to-Shut-Down-Servers-11466375.html ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft My Upcoming Classes https://www...
SANS Stormcast Friday, September 25th, 2026: Tricky Phishing URL; MacSync Malware Update; SolarWinds Observable Patch (#)
SANS Stormcast Friday, September 25th, 2026: Tricky Phishing URL; MacSync Malware Update; SolarWinds Observable Patch One URL, Three Different Tricks https://isc.sans.edu/diary/33366 Send GitLab an email, push to main https://www.aikido.dev/blog/gitlab-email-push-to-main macOS MacSync Malware Update https://securelist.com/macsync-new-version/121383/ SolarWinds Observability Self-Hosted 2026.2.3 https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/hco_2026-2-3_release_notes.htm My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: solarwinds; macos; macsync; malware; patch; gitlab; phishing
SANS Stormcast Thursday, September 24th, 2026: Macfinger ClickFix; Malicious Terraform; MikroTik and F5 Big IP Vulnerability Details (#)
SANS Stormcast Thursday, September 24th, 2026: Macfinger ClickFix; Malicious Terraform; MikroTik and F5 Big IP Vulnerability Details Macfinger ClickFix Campaign https://isc.sans.edu/diary/Macfinger%20ClickFix%20campaign/33360 Graphalgo campaign spreads to Terraform providers and Go Modules https://www.aikido.dev/blog/graphalgo-terraform-go-modules MikroTik vulnerabilities technical analysis, https://cert.pl/en/posts/2026/09/mikrotrick-technical-analysis/ F5 Big-IP Vulnerability Details CVE-2026-94127 https://labs.watchtowr.com/is-this-a-joke-in-the-auth-header-f5-big-ip-unauth-heap-overflow-to-rce-cve-2026-94127/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: f5; big-ip; mitrotik; graphalgo; terraform; clickfix; macfinger;
SANS Stormcast Wednesday, September 23rd, 2026: GET with Body; Checkpoint, VeloCloud, BigIP and Microsoft Defender 0-days (#)
SANS Stormcast Wednesday, September 23rd, 2026: GET with Body; Checkpoint, VeloCloud, BigIP and Microsoft Defender 0-days The Truth about GET and HTTP Standards https://isc.sans.edu/diary/The%20Truth%20about%20GET%20and%20HTTP%20Standards/33358 CVE-2026-93616: 0-Day Remote Code Execution Vulnerability patch in Checkpoint Management Server https://support.checkpoint.com/results/sk/sk1000171/ VeloCloud Orchestrator (VCO) Patch for Exploited Vulnerability CVE-2026-93952 https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183 F5 BigIP APM Exploited Vulnerability Patched CVE-2026-94127 https://my.f5.com/manage/s/article/K000162605 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: f5; bigip; velocloud...
SANS Stormcast Tuesday, September 22nd, 2026: PNG Stego Analysis; NPM BTree Malware; Pi-Hole Advisory (#)
SANS Stormcast Tuesday, September 22nd, 2026: PNG Stego Analysis; NPM BTree Malware; Pi-Hole Advisory TerminalFix PNG Steganography https://isc.sans.edu/diary/TerminalFix%3A%20PNG%20Steganography/33318 NPM Btree Malware Campaign Without Install Script https://checkmarx.com/zero-post/npm-btree-malware-campaign-affects-millions-of-downloads-no-need-for-install-script/ Pi-Hole Update and Advisory https://github.com/pi-hole/FTL/security/advisories/GHSA-2794-hrj8-5jg9 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: pihole; npm; btree; termianlfix; png; steganography
SANS Stormcast Monday, September 21st, 2026: HTTP Query; Docker Escape; Brevo ClickFix Attack; LastPass Fake GitHub Repo (#)
SANS Stormcast Monday, September 21st, 2026: HTTP Query; Docker Escape; Brevo ClickFix Attack; LastPass Fake GitHub Repo HTTP QUERY Method: The Grey Zone Between GET and POST https://isc.sans.edu/diary/HTTP%20QUERY%20Method%3A%20The%20Grey%20Zone%20Between%20GET%20And%20POST./33352 Simple MacOS Docker Escape https://www.accomplish.ai/blog/escaping-dockers-hypervisor/ CVE-2026-77179 Brevo ClickFix Compromise https://status.brevo.com/incidents/01M2QBC4EZ24ZACW6SWQYVW8N3/write-up LastPass (and other) lookalike GitHub Repo and Kernel Module Infostealer https://blog.lastpass.com/posts/lastpass-delphos-report-rapuncel-infostealer My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: lastpass; github; rapuncel; delphos; brevo...
SANS Stormcast Friday, September 18th, 2026: LousivLaoder Analysis; Issabel Framework 0-Day; Cyber Decoys; CISA Vuln Bulletin; Unbound Vulnerability (#)
SANS Stormcast Friday, September 18th, 2026: LousivLaoder Analysis; Issabel Framework 0-Day; Cyber Decoys; CISA Vuln Bulletin; Unbound Vulnerability LausivLoader analysis, or how to pass data between malware stages https://isc.sans.edu/diary/LausivLoader%20analysis%2C%20or%20how%20to%20pass%20data%20between%20malware%20stages/33348 Issabel Framework Hard-coded JWT Key RCE CVE-2026-89026 https://www.vulncheck.com/advisories/issabel-pbx-hard-coded-jwt-key-rce-via-pbxapi-manager-originate Using Cyber Decoys to Strengthen Detection and Response https://www.cisa.gov/sites/default/files/2026-09/using-cyber-decoys-to-strengthen-detection-and-response_508c.pdf CISA to Sunset Weekly Vulnerability Bulletin on September 28, 2026 https://content.govdelivery.com/accounts/USDHSCISA/bulletins/42b055b Unbound Vulnerability https://nlnetlabs.nl/projects/unbound...
SANS Stormcast Thursday, September 17th, 2026: Hospitality Scans; Cisco, Acronis, and Pixel 0-Day; Dynamic Incident Response (#)
SANS Stormcast Thursday, September 17th, 2026: Hospitality Scans; Cisco, Acronis, and Pixel 0-Day; Dynamic Incident Response Scans Targeting Hospitality Applications https://isc.sans.edu/diary/Scans%20Targeting%20Hospitality%20Applications/33344 Cisco Identity Services Engine Authentication Bypass Vulnerability CVE-2026-76460 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5 Acronis Local privilege escalation due to insecure file permissions CVE-2026-87886 https://security-advisory.acronis.com/advisories/SEC-10986 Pixel Update Bulletin—September 2026 https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 Dynamic Incident Response (Free E-Book) https://dynamicincidentresponse.com My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: dynamic; incided; response; ir...
SANS Stormcast Wednesday, September 16th, 2026: MacOS 27 Traffic; Cisco 0-Day; Protecting Active Directory and API Tokens (#)
SANS Stormcast Wednesday, September 16th, 2026: MacOS 27 Traffic; Cisco 0-Day; Protecting Active Directory and API Tokens MacOS 27 - First Boot https://isc.sans.edu/diary/MacOS%2027%20-%20First%20Boot/33340 Cisco Secure Email Gateway SQL Injection Vulnerability CVE-2026-76461 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX Detecting and Mitigating Active Directory Compromises https://www.cisa.gov/resources-tools/resources/detecting-and-mitigating-active-directory-compromises Protecting Tokens and Assertions from Forgery, Theft, and Misuse https://nvlpubs.nist.gov/nistpubs/ir/2026/NIST.IR.8587.pdf My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: tokens; api; active directory; cisco; macos;
SANS Stormcast Tuesday, September 15th, 2026: Apple Updates; Homebrew Update; MSFT OOB Patch; Telegram Vuln (#)
SANS Stormcast Tuesday, September 15th, 2026: Apple Updates; Homebrew Update; MSFT OOB Patch; Telegram Vuln Apple Updates Everything https://isc.sans.edu/diary/Apple%20Updates%20Everything/33336 Homebrew 7 Released https://brew.sh/2026/09/13/homebrew-7.0.0/ Microsoft Out-of-Band Patch https://support.microsoft.com/en-us/servicing/os/windows-11/2026/09/kb5129195-windows-11-24h2-25h2-security-update Telegram XSS Vulnerability https://expatch.com/writeups/telegram-html-export-xss.html My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: telegram; microsoft; rds; homebrew; apple; macos; ios; ipadod; watchos; tvos
SANS Stormcast Monday, September 14th, 2026: Self-Expanding Stolen LLM Gateways; PAN-OS Vuln; OpenAI Hacked Ruby; Passkey Themed Social Engineering (#)
SANS Stormcast Monday, September 14th, 2026: Self-Expanding Stolen LLM Gateways; PAN-OS Vuln; OpenAI Hacked Ruby; Passkey Themed Social Engineering The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access https://isc.sans.edu/diary/The%20Self-Expanding%20Stolen%20Inference%20Supply%20Chain%3A%20An%20AI%20Agent%20Harvesting%20and%20Re-Serving%20LLM%20Access/33332 CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing https://security.paloaltonetworks.com/CVE-2026-0310 OpenAI agents carried out an undisclosed cyber-attack on RubyGems https://www.rubyhack.ai Passkey-themed social engineering leads to identity and cloud compromise https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/ My Upcoming Classes...
SANS Stormcast Friday, September 11th, 2026: Redtail Analsys (@sans_edu); Checkpoint VPN Patch; Netscaler and Sonicwall Attacks (#)
SANS Stormcast Friday, September 11th, 2026: Redtail Analsys (@sans_edu); Checkpoint VPN Patch; Netscaler and Sonicwall Attacks Redtail Payload Analysis https://isc.sans.edu/diary/Redtail%20Payload%20Analysis%20%5BGuest%20Diary%5D/33326 Checkpoint Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510 https://community.checkpoint.com/t5/General-Topics/Action-Required-Critical-Security-Advisory-VPN-Vulnerabilities/td-p/281995 Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2 Netscaler ADC Exploit https://x.com/ethicalhack3r/status/2095480651478663393 Sonicwall SMA1000 Attack https://hunt.io/blog/sonicwall-sma1000-uk-council-attack My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: sonicwall; netscaler...
SANS Stormcast Thursday, September 10th, 2026: Proxmox Scans; MSFT Defender, Gogole Chorme, and FortiPAM Vulns. (#)
SANS Stormcast Thursday, September 10th, 2026: Proxmox Scans; MSFT Defender, Gogole Chorme, and FortiPAM Vulns. Scans for Proxmox Servers https://isc.sans.edu/diary/Scans%20for%20Proxmox%20Servers/33324 Next Nightmare Eclipse Vulnerability https://github.com/MSNightmare/ShieldCrash/blob/main/README.md Google Chrome Updates https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html FortiPAM Vulnerability https://amibeingpwned.com/blog/fortinet-pam-vuln My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: fortipam; google; chrome; proxmox
SANS Stormcast Wednesday, September 9th, 2026: Microsoft, Adobe, Ivanti, Fortinet Patch Tuesday (#)
SANS Stormcast Wednesday, September 9th, 2026: Microsoft, Adobe, Ivanti, Fortinet Patch Tuesday September 2026 Microsoft Patch Tuesday https://isc.sans.edu/diary/September%202026%20Microsoft%20Patch%20Tuesday/33320 Adobe Security Bulletins https://helpx.adobe.com/security/security-bulletin.html Security Advisory Ivanti Neurons for ITSM https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US Fortinet Advisory https://www.fortiguard.com/psirt/FG-IR-26-174 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: fortinet; ivanti; neurons; itsm; adobe; microsoft
SANS Stormcast Tuesday, September 8th, 2026: numbat; MicroTik and Magento (Adobe Commerce) 0-Day (#)
SANS Stormcast Tuesday, September 8th, 2026: numbat; MicroTik and Magento (Adobe Commerce) 0-Day numbat - AI agent observability https://isc.sans.edu/diary/numbat%20-%20AI%20agent%20observability/33312 MicroTik SSH 0-Day Exploited https://mikrotik.com/supportsec/september-2026-vulnerability/ https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/ Adobe Commerce - Magento - 0-Day Exploited https://sansec.io/research/stylesmuggler-0day N-Able 4th Hotpatch https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF4_Release_Notes.htm My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: n-able; hotpatch; adobe; commerce; magento; microtik; numbat
SANS Stormcast Friday, September 4th, 2026: AV Exploits; Plex Update; Cisco Patches; Sangoma Switchvox Exploited (#)
SANS Stormcast Friday, September 4th, 2026: AV Exploits; Plex Update; Cisco Patches; Sangoma Switchvox Exploited Nightmare Eclipse Discloses Several Anti-Malware Privilege Escalation Exploits https://github.com/MSNightmare Plex Update https://forums.plex.tv/t/important-security-update-for-plex-media-server-v1-43-2-and-earlier/942319 Cisco Update https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-smime-disc-dzw4rEdY Sangoma Switchvox Exploit https://horizon3.ai/attack-research/disclosures/cve-2026-9586-sangoma-switchvox-rce/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: sangoma; switchvox; csicso; plex; nightmare; eclips; kaspersky; avast; crowdstrike; falcon
SANS Stormcast Thursday, September 3rd, 2026: SMA1000 0-Day Patch; SSRF Validation Issues; Faronics Abuse (#)
SANS Stormcast Thursday, September 3rd, 2026: SMA1000 0-Day Patch; SSRF Validation Issues; Faronics Abuse Sonicwall SMA1000 Exploited Vulnerability Patched https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 SSRF: The Validator Can Lie https://xclow3n.com/post/the-validator-can-lie/ Git Hijack for AI Agents https://www.manifold.security/blog/ai-coding-agents-git-hijack Fronics Deploy Abuse https://www.huntress.com/blog/faronics-deploy-abuse My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: faronics; deploy; git; hijack; ssrf; validator; sonicwall; sma1000
SANS Stormcast Wednesday, September 2nd, 2026: Guildma Update; Proxmox 7 Auth Bypass; Windows Hotpatch; Virtualizor BGP Hack (#)
SANS Stormcast Wednesday, September 2nd, 2026: Guildma Update; Proxmox 7 Auth Bypass; Windows Hotpatch; Virtualizor BGP Hack Guildma (Astaroth) malware infection from Brazilian Portuguese email https://isc.sans.edu/diary/Guildma%20%28Astaroth%29%20malware%20infection%20from%20Brazilian%20Portuguese%20email/33300 Authentication bypass in EOL Proxmox VE 7 release https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/page-4#post-867929 https://gist.github.com/nebusecurity/65fe90dd673d395b7926278d7eaf5849 Updated Windows Server hotpatch calendar https://learn.microsoft.com/en-us/windows/release-health/windows-server-release-info#windows-server-hotpatch-calendar Virtualizor BGP Hijacking https://www.virtualizor.com/blog/security-incident-bgp-hijacking/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: virtualizor; bgp; tls; windows; hotpatch...
SANS Stormcast Tuesday, September 1st, 2026: LLM Honeypot; PaperCut Update; TerminalFix Malware; (#)
SANS Stormcast Tuesday, September 1st, 2026: LLM Honeypot; PaperCut Update; TerminalFix Malware; The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary https://isc.sans.edu/diary/The%20Coding-Agent%20Trap%3A%20When%20a%20%22Free%22%20LLM%20Endpoint%20Is%20the%20Adversary/33298 PaperCut Public Exploit Available https://github.com/rapid7/metasploit-framework/pull/21842 TerminalFix Campaign; https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: terminalfix; papercut; clickfix; agent; llm; honeypot; free; stolen;
SANS Stormcast Monday, August 31st, 2026: Malware Statistics; PaperCut Update; Watchguard and DLink Patches; (#)
SANS Stormcast Monday, August 31st, 2026: Malware Statistics; PaperCut Update; Watchguard and DLink Patches; Some Malicious PE Stats https://isc.sans.edu/diary/Some%20Malicious%20PE%20Stats/33292 PaperCut Releases Two Preliminary Patches for Exploited Vulnerability https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ DLink Vulnerabliities https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10513 Watchguard Patches https://psirt.watchguard.com My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: watchguard; dlink; papercut; PE; stats; vulnerabilities
SANS Stormcast Friday, August 28th, 2026: Broken Polymorphic Phishing; Router Implants; llms.txt exploits; Papercut 0-Day (#)
SANS Stormcast Friday, August 28th, 2026: Broken Polymorphic Phishing; Router Implants; llms.txt exploits; Papercut 0-Day A polymorphic phishing page (that occasionally breaks itself) https://isc.sans.edu/diary/A%20polymorphic%20phishing%20page%20%28that%20occasionally%20breaks%20itself%29/33290 Chinese Implants in the Supply Chain https://www.vulncheck.com/blog/zbt-darklantern-speakingstone?_sp=1068fa46-3d91-427e-8120-aa6d8bda2912.1787865822277 Data Became Code: We Ran Code Inside Fortune 500s Using Files They Published for AI Agents https://medium.com/@alonhertz1/data-became-code-we-ran-code-inside-fortune-500s-using-files-they-published-for-ai-agents-0cd67ffbbffc Papercut Security Advisory https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ My Upcoming Classes https://www.sans.org...
SANS Stormcast Thursday, August 27th, 2026: Entra ID Admins; Unifi Patches; log4j Vuln; Sleepwalker Malware (#)
SANS Stormcast Thursday, August 27th, 2026: Entra ID Admins; Unifi Patches; log4j Vuln; Sleepwalker Malware Who Has Admin Rights in your Entra ID Directory? https://isc.sans.edu/diary/Who%20Has%20Admin%20Rights%20in%20your%20Entra%20ID%20Directory%3F/33284 Ubiquity Unifi Patches https://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9 Log4J FilteredObjectInputStream Vulnerability https://github.com/joanbono/log4j2-4255-exploit https://jeffmcjunkin.com/posts/log4j2-fois-marshalledobject/ Sleepwalker Malware https://r136a1.dev/2026/08/24/sleepwalker-a-passive-backdoor-with-its-own-command-language/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: log4j; unifi; ubiquity; patches; admin; entra...
SANS Stormcast Wednesday, August 26th, 2026: Obfuscating SSRF; Paint and Photos AI Watermarks; FTP Banner C2; (#)
SANS Stormcast Wednesday, August 26th, 2026: Obfuscating SSRF; Paint and Photos AI Watermarks; FTP Banner C2; Obfuscating IP Addresses as Hostnames https://isc.sans.edu/diary/Obfuscating%20IP%20Addresses%20as%20Hostnames/33280 Microsoft Paint and Photos Embed Server-Issued GUIDs as Invisible Watermarks in Locally-Generated Images https://xusheng.dev/posts/reversing/mspaint_invisible_watermark/main/ FTP Banners The New Dead Drop Resolver Delivering Novel RATs https://socradar.io/blog/ftp-banners-new-dead-drop-resolver-rats/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: ftp; microsoft; paint; watermark; ai; guid; ip; hostname;
SANS Stormcast Tuesday, August 25th, 2026: DOUBLECUP PNG; WebAudio Fingerprinting; Expired Domains; Android; Car (#)
SANS Stormcast Tuesday, August 25th, 2026: DOUBLECUP PNG; WebAudio Fingerprinting; Expired Domains; Android; Car DOUBLECUP's PNG Payload https://isc.sans.edu/diary/DOUBLECUP%27s%20PNG%20Payload/33274 AliExpress WebAudio fingerprinting https://blog.laserphile.com/2026/08/aliexpress-webpage-keeping-multipoint.html Expired DMARC Reporting Domain Exposed 86 Domains https://www.sh.consulting/blog/abandoned-dmarc-reporting-domain Android Car Malware https://securelist.com/android-head-unit-malware/121106/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: dmarc; aliexpress; webaudio; privacy; doublecup; png; android; car
SANS Stormcast Monday, August 24th, 2026: More Entra Powershell; Entra Vulnerability; GitLab Vuln (and PoC); GTA 6 Leak Malware (#)
SANS Stormcast Monday, August 24th, 2026: More Entra Powershell; Entra Vulnerability; GitLab Vuln (and PoC); GTA 6 Leak Malware Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting! https://isc.sans.edu/diary/Who%20Got%20Missed%20in%20the%20MFA%20Rollout%3F%20More%20Powershell%20%2B%20Graph%20%2B%20Entra%20scripting!/33272 Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays https://isc.sans.edu/diary/Even%20MOAR%20Powershell%2C%20looking%20at%20Entra%20logins%20-%20the%20good%2C%20the%20bad%20and%20the%20password%20sprays/33268 Microsoft Entra ID Remote Code Execution Vulnerability CVE-2026-69836 https://msrc.microsoft...
SANS Stormcast Friday, August 21st, 2026: Microsoft Graph and Powershell; Keycloak Vuln; Cryptographic Context Injection; N-Able Password Leak (#)
SANS Stormcast Friday, August 21st, 2026: Microsoft Graph and Powershell; Keycloak Vuln; Cryptographic Context Injection; N-Able Password Leak Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses https://isc.sans.edu/diary/Using%20Microsoft%20Graph%20and%20Powershell%20to%20Mine%20for%20Information%20-%20Stale%20Accounts%20and%20Licenses/33264 Using Microsoft Graph and Powershell - Risk Detection Commands https://isc.sans.edu/diary/Using%20Microsoft%20Graph%20and%20Powershell%20-%20Risk%20Detection%20Commands/33266 Keycloak Vulnerability https://github.com/keycloak/keycloak/issues/51833
https://www.keycloak.org/2026/08/keycloak-2672-released CRYPTOGRAPHIC CONTEXT INJECTION ATTACK https://adversa.ai/blog/cryptographic-context-injection-grok-data-theft/ N-able password manager https://am...
SANS Stormcast Thursday, August 20th, 2026: Cloud Metadata Scans; Oracle and Netscaler Patches; Fake Ransomware Rescuers (#)
SANS Stormcast Thursday, August 20th, 2026: Cloud Metadata Scans; Oracle and Netscaler Patches; Fake Ransomware Rescuers Simple Scans for Cloud Metadata Service https://isc.sans.edu/diary/Simple%20Scans%20for%20Cloud%20Metadata%20Service/33260 Oracle Critical Security Patch Update Advisory - August 2026 https://www.oracle.com/security-alerts/cspuaug2026.html NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490 https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939 Beware of Ransomware Rescuers https://www.guidepointsecurity.com/blog/beware-ransom-busters/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: ransomware; rescuers; busters; ransom; netscaler; citrix; adc; oracle; patches; metadata; imds;
SANS Stormcast Wednesday, August 19th, 2026: Copilot as Whitstleblower; GEEKOM Bad Driver; Medusa Update; Encrypted AI (#)
SANS Stormcast Wednesday, August 19th, 2026: Copilot as Whitstleblower; GEEKOM Bad Driver; Medusa Update; Encrypted AI CoSnitch: When Your AI Assistant Becomes Its Own Whistleblower https://www.varonis.com/blog/cosnitch GEEKOM confirms malware was hosted on its website https://videocardz.com/newz/geekom-apologizes-for-hosting-malware-in-driver-package-for-its-mini-pcs Medusa Ransomware Update https://www.cisa.gov/sites/default/files/2026-08/aa25-071a-stopransomware-medusa-ransomware-508c.pdf How Google is Making Private AI Practical with Homomorphic Encryption https://blog.google/security/how-google-is-making-private-ai-practical-with-homomorphic-encryption/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: AI; homomorphic; encryption; medusa; ransomware; geekom
SANS Stormcast Tuesday, August 18th, 2026: Apple Patches; Screen Sharing Security; Download More RAM (#)
SANS Stormcast Tuesday, August 18th, 2026: Apple Patches; Screen Sharing Security; Download More RAM Apple Patches or iOS and macOS https://isc.sans.edu/diary/Apple%20Patches%20iOS%20and%20macOS/33254 Screen Sharing Security https://isc.sans.edu/diary/Apple%20Screen%20Sharing%20Security/33252 Download More RAM: Dismantling Windows Operating System Defenses with Mischievous Memory https://www.usenix.org/system/files/usenixsecurity26-collins.pdf My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: macos; ios; apple; screen sharing; screensharing; vnc; ram; windows;
SANS Stormcast Monday, August 17th, 2026: MacOS Screen Sharing; GeoServer Patch; SAP Exploited; (#)
SANS Stormcast Monday, August 17th, 2026: MacOS Screen Sharing; GeoServer Patch; SAP Exploited; macOS Screen Sharing Vulnerability Exploited https://advisories.ncsc.nl/2026/ncsc-2026-0280.html GeoServer Patch https://geoserver.org/announcements/vulnerability/2026/08/14/geoserver-3-0-1-released.html Recent SAP Commerce Cloud Vuln Exploited https://x.com/DefusedCyber/status/2088240809355153647 ChainDrop npm Worm https://medium.com/governed-at-the-source/the-chaindrop-npm-worm-august-2026-how-444-packages-were-compromised-without-a-single-npm-b0c9e5a4c387 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: chaindrop; npm; worm; sap; commerce; cloud; geoserver; macos; screensharing
SANS Stormcast Friday, August 14th, 2026: AI vs. Honeypot Data; CPU Bugs; GeoServer 0-Day; Windows USB Driver Confusion (#)
SANS Stormcast Friday, August 14th, 2026: AI vs. Honeypot Data; CPU Bugs; GeoServer 0-Day; Windows USB Driver Confusion Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI https://isc.sans.edu/diary/Using%20Gemma4%20with%20Ollama%20-%20Testing%20File%20Hash%20Analysis%20and%20Recommendations%20with%20AI/33242 CPU Privilege Escalation https://github.com/xoreaxeaxeax/smiiiiiiiiiiiiiiii https://github.com/xoreaxeaxeax/skitter-creek-bath-salts GeoServer Vulnerability https://x.com/q1uf3ng/status/2087490992723407096 Windows USB Driver Vulnerability https://x.com/0xedh/status/2085842285481062887 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: windows; usb; geoserver; cpu; privilege escalation; ssm; gemma4; ai; honeypot; ollama...