• SANS Stormcast Friday, September 25th, 2026: Tricky Phishing URL; MacSync Malware Update; SolarWinds Observable Patch
    2026/09/25

    One URL, Three Different Tricks
    https://isc.sans.edu/diary/33366
    Send GitLab an email, push to main
    https://www.aikido.dev/blog/gitlab-email-push-to-main
    macOS MacSync Malware Update
    https://securelist.com/macsync-new-version/121383/
    SolarWinds Observability Self-Hosted 2026.2.3
    https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/hco_2026-2-3_release_notes.htm
    My Upcoming Classes
    https://www.sans.org/profiles/dr-johannes-ullrich
    続きを読む 一部表示
    7 分
  • SANS Stormcast Thursday, September 24th, 2026: Macfinger ClickFix; Malicious Terraform; MikroTik and F5 Big IP Vulnerability Details
    2026/09/24

    Macfinger ClickFix Campaign
    https://isc.sans.edu/diary/Macfinger%20ClickFix%20campaign/33360
    Graphalgo campaign spreads to Terraform providers and Go Modules
    https://www.aikido.dev/blog/graphalgo-terraform-go-modules
    MikroTik vulnerabilities technical analysis,
    https://cert.pl/en/posts/2026/09/mikrotrick-technical-analysis/
    F5 Big-IP Vulnerability Details CVE-2026-94127
    https://labs.watchtowr.com/is-this-a-joke-in-the-auth-header-f5-big-ip-unauth-heap-overflow-to-rce-cve-2026-94127/
    My Upcoming Classes
    https://www.sans.org/profiles/dr-johannes-ullrich
    podscan_ceKfRJw0F1fvyCUUhxsyFRhNvabT1TnF
    続きを読む 一部表示
    6 分
  • SANS Stormcast Wednesday, September 23rd, 2026: GET with Body; Checkpoint, VeloCloud, BigIP and Microsoft Defender 0-days
    2026/09/23

    The Truth about GET and HTTP Standards
    https://isc.sans.edu/diary/The%20Truth%20about%20GET%20and%20HTTP%20Standards/33358
    CVE-2026-93616: 0-Day Remote Code Execution Vulnerability patch in Checkpoint Management Server
    https://support.checkpoint.com/results/sk/sk1000171/
    VeloCloud Orchestrator (VCO) Patch for Exploited Vulnerability CVE-2026-93952
    https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183
    F5 BigIP APM Exploited Vulnerability Patched CVE-2026-94127
    https://my.f5.com/manage/s/article/K000162605
    My Upcoming Classes
    https://www.sans.org/profiles/dr-johannes-ullrich
    続きを読む 一部表示
    5 分
  • SANS Stormcast Tuesday, September 22nd, 2026: PNG Stego Analysis; NPM BTree Malware; Pi-Hole Advisory
    2026/09/22

    TerminalFix PNG Steganography
    https://isc.sans.edu/diary/TerminalFix%3A%20PNG%20Steganography/33318
    NPM Btree Malware Campaign Without Install Script
    https://checkmarx.com/zero-post/npm-btree-malware-campaign-affects-millions-of-downloads-no-need-for-install-script/
    Pi-Hole Update and Advisory
    https://github.com/pi-hole/FTL/security/advisories/GHSA-2794-hrj8-5jg9
    My Upcoming Classes
    https://www.sans.org/profiles/dr-johannes-ullrich
    続きを読む 一部表示
    6 分
  • SANS Stormcast Monday, September 21st, 2026: HTTP Query; Docker Escape; Brevo ClickFix Attack; LastPass Fake GitHub Repo
    2026/09/21

    HTTP QUERY Method: The Grey Zone Between GET and POST
    https://isc.sans.edu/diary/HTTP%20QUERY%20Method%3A%20The%20Grey%20Zone%20Between%20GET%20And%20POST./33352
    Simple MacOS Docker Escape
    https://www.accomplish.ai/blog/escaping-dockers-hypervisor/ CVE-2026-77179
    Brevo ClickFix Compromise
    https://status.brevo.com/incidents/01M2QBC4EZ24ZACW6SWQYVW8N3/write-up
    LastPass (and other) lookalike GitHub Repo and Kernel Module Infostealer
    https://blog.lastpass.com/posts/lastpass-delphos-report-rapuncel-infostealer
    My Upcoming Classes
    https://www.sans.org/profiles/dr-johannes-ullrich
    続きを読む 一部表示
    7 分
  • SANS Stormcast Friday, September 18th, 2026: LousivLaoder Analysis; Issabel Framework 0-Day; Cyber Decoys; CISA Vuln Bulletin; Unbound Vulnerability
    2026/09/18

    LausivLoader analysis, or how to pass data between malware stages
    https://isc.sans.edu/diary/LausivLoader%20analysis%2C%20or%20how%20to%20pass%20data%20between%20malware%20stages/33348
    Issabel Framework Hard-coded JWT Key RCE CVE-2026-89026
    https://www.vulncheck.com/advisories/issabel-pbx-hard-coded-jwt-key-rce-via-pbxapi-manager-originate
    Using Cyber Decoys to Strengthen Detection and Response
    https://www.cisa.gov/sites/default/files/2026-09/using-cyber-decoys-to-strengthen-detection-and-response_508c.pdf
    CISA to Sunset Weekly Vulnerability Bulletin on September 28, 2026
    https://content.govdelivery.com/accounts/USDHSCISA/bulletins/42b055b
    Unbound Vulnerability
    https://nlnetlabs.nl/projects/unbound/security-advisories/
    My Upcoming Classes
    https://www.sans.org/profiles/dr-johannes-ullrich
    続きを読む 一部表示
    7 分
  • SANS Stormcast Thursday, September 17th, 2026: Hospitality Scans; Cisco, Acronis, and Pixel 0-Day; Dynamic Incident Response
    2026/09/17

    Scans Targeting Hospitality Applications
    https://isc.sans.edu/diary/Scans%20Targeting%20Hospitality%20Applications/33344
    Cisco Identity Services Engine Authentication Bypass Vulnerability CVE-2026-76460
    https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5
    Acronis Local privilege escalation due to insecure file permissions CVE-2026-87886
    https://security-advisory.acronis.com/advisories/SEC-10986
    Pixel Update Bulletin September 2026
    https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01
    Dynamic Incident Response (Free E-Book)
    https://dynamicincidentresponse.com
    My Upcoming Classes
    https://www.sans.org/profiles/dr-johannes-ullrich
    続きを読む 一部表示
    6 分
  • SANS Stormcast Wednesday, September 16th, 2026: MacOS 27 Traffic; Cisco 0-Day; Protecting Active Directory and API Tokens
    2026/09/16

    MacOS 27 - First Boot
    https://isc.sans.edu/diary/MacOS%2027%20-%20First%20Boot/33340
    Cisco Secure Email Gateway SQL Injection Vulnerability CVE-2026-76461
    https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
    Detecting and Mitigating Active Directory Compromises
    https://www.cisa.gov/resources-tools/resources/detecting-and-mitigating-active-directory-compromises
    Protecting Tokens and Assertions from Forgery, Theft, and Misuse
    https://nvlpubs.nist.gov/nistpubs/ir/2026/NIST.IR.8587.pdf
    My Upcoming Classes
    https://www.sans.org/profiles/dr-johannes-ullrich
    続きを読む 一部表示
    7 分