A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

Similar Podcasts

Thinking Elixir Podcast

Thinking Elixir Podcast
The Thinking Elixir podcast is a weekly show where we talk about the Elixir programming language and the community around it. We cover news and interview guests to learn more about projects and developments in the community.

Elixir Outlaws

Elixir Outlaws
Elixir Outlaws is an informal discussion about interesting things happening in Elixir. Our goal is to capture the spirit of a conference hallway discussion in a podcast.

Linux For Everyone

Linux For Everyone
A show about the thrilling world of desktop Linux, open-source software, and the community creating it. For beginners and veterans alike! Hosted by Jason Evangelho, Jerry Morrison and Schykle.

SANS Stormcast Friday, October 9th, 2026: AI Agent Forensics; AI-Assisted Attack on South Korean Banks; IDN Typosquatting; Cisco Finesse SSRF (CVE-2026-20362)

October 09, 2026 6:14 1.03 MB ( 4.21 MB less) Downloads: 0

In today's episode: new scripts for reconstructing AI agent activity during forensic investigations, an attacker's Claude chat history recovered after breaches at South Korean financial institutions, internationalized domain name (IDN) lookalikes that still get past Chrome, and an unpatched Cisco Finesse server-side request forgery (SSRF) vulnerability. Reconstructing AI Agent Activity: Two New Scripts for Forensic Review Jim Clausing released two scripts that turn the logs left behind by the OpenCode and Hermes AI agents into searchable JSON, so incident responders can see what an AI agent did on an attacker's or a victim's system. https://isc.sans.edu/diary/Reconstructing%20AI%20Agent%20Activity%3A%20Two%20New%20Scripts%20for%20Forensic%20Review/33410 Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance While investigating breaches at South Korean financial institutions, CrowdStrike recovered the attacker's CLAUDE.md file and Claude chat history, a rare look at how a low-skill "prompt kiddie" uses AI to run an attack. https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/ Turning IDN Edge Cases into Typosquats Attackers can still register convincing lookalike domains using Unicode characters that resemble Latin letters but are not on Chrome's list of known confusables. One test domain impersonating Apple displayed in Chrome but not in Safari. https://haveibeensquatted.com/blog/turning-idn-edge-cases-into-typosquats Cisco Finesse SSRF Vulnerability (CVE-2026-20362) Cisco disclosed an unauthenticated server-side request forgery vulnerability in the Cisco Finesse web-based management interface, rated High (CVSS 7.2). Details are already public, there is no workaround, and fixed releases are not expected until January or February 2027. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-finesse-ssrf-mmSuyugS My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SANS Stormcast Thursday, October 8th, 2026: Atlassian Vulnerabilities; ccTLD Compormise; Outlook blocking .msix

October 07, 2026 6:58 1.15 MB ( 4.7 MB less) Downloads: 0

Scans for Atlassian vulnerablity (CVE-2026-21589) https://isc.sans.edu/diary/Scans%20for%20Atlassian%20vulnerablity%20%28CVE-2026-21589%29/33406 .gh, .sl and .as ccTLD Compromise https://blog.google/security/chromes-response-to-recent-cctld-registry-hijacks/ Cisco Nexus 3000 and 9000 Series Switches Remote Code Execution Vulnerabilities https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ngoam-rce-LWKQ4BU Outlook Blocking MSIX Files https://www.bleepingcomputer.com/news/microsoft/microsoft-outlook-to-block-msix-attachments-used-in-attacks/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SANS Stormcast Wednesday, October 7th, 2026: RMM Tools; libHEIF RCE; Sonicwall SMA1000, OpenSSH updates, DNSSEC KSK Rollover

October 06, 2026 6:43 1.11 MB ( 4.52 MB less) Downloads: 0

More RMM Tools In the Wild https://isc.sans.edu/diary/More%20RMM%20Tools%20In%20the%20Wild/33400 WORDPRESS LIBHEIF RCE https://fortbridge.co.uk/research/wordpress-libheif-rce/ SONICWALL SMA1000 SERIES APPLIANCES Vulnerabilities CVE-2026-102255, CVE-2026-102256, CVE-2026-102257, CVE-2026-102258 https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017 OpenSSH 10.6 Released https://seclists.org/oss-sec/2026/q4/58 DNSSEC Root Key Signing Key Rollover https://blog.cloudflare.com/root-ksk-2024-rollover/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SANS Stormcast Tuesday, October 6th, 2026: cowrie tty Logs; Another Netscaler 0-Day; Exchange Patch

October 06, 2026 6:08 1.01 MB ( 4.13 MB less) Downloads: 0

TTY Logs and the Data it Captures https://isc.sans.edu/diary/TTY%20Logs%20and%20the%20Data%20it%20Captures/33396 Citrix Netscaler SAML Vulnerability (0-Day) CVE-2026-88779 https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174 https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/ Microsoft Exchange September 2026 V2 Update CVE-2026-96940 https://techcommunity.microsoft.com/blog/exchange/released-september-2026-v2-exchange-server-security-updates/4561718 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SANS Stormcast Monday, October 5th, 2026: Funny User-Agents; FortMail 0-Day; GitLab Patch; macOS Full Disk Access

October 04, 2026 7:24 1.23 MB ( 4.98 MB less) Downloads: 0

User Agent Strings Curiosities https://isc.sans.edu/diary/User%20Agent%20Strings%20Curiosities/33394 FortiMail Improper limitation of a pathname to a restricted directory CVE-2026-104286 https://fortiguard.fortinet.com/psirt/FG-IR-26-175 Critical GitLab Vulnerability CVE-2026-90970 https://docs.gitlab.com/releases/patches/other-patches/patch-release-gitlab-ai-gateway-19-4-1-released/ Updates to Full Disk Access in macOS https://developer.apple.com/news/?id=p6zjojqw My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SANS Stormcast Friday, October 2nd, 2026: ScreenConnect Abuse; ChatGPT Abuse; Spoofing iCloud; Proton Mail display name

October 01, 2026 6:36 1.09 MB ( 4.45 MB less) Downloads: 0

ScreenConnect Client (Ab)used by Attackers https://isc.sans.edu/diary/ScreenConnect+Client+Abused+by+Attackers/33388/#comments Attackers abuse ChatGPT to deliver RAT via ClickFix https://www.huntress.com/blog/chatgpt-custom-gpts-clickfix-rat?_sp=51406044-aa1d-4278-a4e7-adb5b8ef84b2.1790890760100 Spoofing iCloud From Address https://sec-consult.com/blog/detail/from-anyoneicloudcom-spoofing-arbitrary-apple-icloud-identities/ Sender spoofing in Proton Mail via display-name homograph https://alonsovidales.github.io/protonmail-sender-spoofing/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SANS Stormcast Thursday, October 1st, 2026: Cisco Catalyst SD-WAN Manager 0-day; Watchguard AP RCE; OpenBao/Vault RCE; Post Quantum Certs

September 30, 2026 5:07 0.84 MB ( 3.45 MB less) Downloads: 0

Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability CVE-2026-76504 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU WatchGuard AP Command Injection in Internal Management API Allows Command Execution https://psirt.watchguard.com/CVE-2026-86102/ A Realistic Code Execution Exploit Chain in OpenBao and Vault https://control-plane.io/posts/unauthed-to-rce-in-vault-and-openbao/ Building a post-quantum certificate authority with Merkle Tree Certificates https://blog.cloudflare.com/pq-ca-with-mtcs/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SANS Stormcast Wednesday, September 30th, 2026: Wordfence Scans; MikroTik Vulnerability; Poper Blocker Spyware

September 29, 2026 5:55 0.97 MB ( 4.0 MB less) Downloads: 0

Scans for Wordfence Protected Websites https://isc.sans.edu/diary/Scans%20for%20Wordfence%20Protected%20Websites/33382 MikroTik RouterOS Vulnerability (CVE-2026-84411) https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06 Poper Blocker: The Adblocker That Spies on You https://amibeingpwned.com/blog/poper-blocker-the-adblocker-that-spies-on-you My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SANS Stormcast Tuesday, September 29th, 2026: MacOS/iOS 0-Day Patch; macOS priv. escalation 0-day; File Notification Attacks

September 28, 2026 6:33 1.08 MB ( 4.42 MB less) Downloads: 0

Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950) https://isc.sans.edu/diary/Apple%20Emergency%20Patch%20for%20iOS%2026%2C%20macOS26%2C%20macOS15%20%28CVE-2026-86950%29/33376 https://support.apple.com/en-us/100100 Proof of concept for macOS CoreServices Priv. Escalation (CVE-2026-43786) https://github.com/Malwation/CVE-2026-43786 NeedyMantis: Unpacking a post-compromise malware family used in targeted operations https://www.microsoft.com/en-us/security/blog/2026/09/28/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations/ File Notification Attacks https://inoti.fyi/pubs/file-notification-attacks.pdf My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SANS Stormcast Monday, September 28th, 2026: Macfinger Details; NetScaler 0-Day; KiteWorks 0-Day; ShinyHunters and PeopleSoft

September 27, 2026 6:40 1.1 MB ( 4.49 MB less) Downloads: 0

A Closer Look at Malware From the Macfinger ClickFix Campaign https://isc.sans.edu/diary/A%20Closer%20Look%20at%20Malware%20From%20the%20Macfinger%20ClickFix%20Campaign/33368 Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778 https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/ KiteWorks Urges Customers to Shut Down Servers https://www.heise.de/en/news/Imminent-Zero-Day-Attack-KiteWorks-Urges-Customers-to-Shut-Down-Servers-11466375.html ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SANS Stormcast Friday, September 25th, 2026: Tricky Phishing URL; MacSync Malware Update; SolarWinds Observable Patch

September 24, 2026 7:10 6.02 MB Downloads: 0

One URL, Three Different Tricks https://isc.sans.edu/diary/33366 Send GitLab an email, push to main https://www.aikido.dev/blog/gitlab-email-push-to-main macOS MacSync Malware Update https://securelist.com/macsync-new-version/121383/ SolarWinds Observability Self-Hosted 2026.2.3 https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/hco_2026-2-3_release_notes.htm My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SANS Stormcast Thursday, September 24th, 2026: Macfinger ClickFix; Malicious Terraform; MikroTik and F5 Big IP Vulnerability Details

September 23, 2026 5:56 4.99 MB Downloads: 0

Macfinger ClickFix Campaign https://isc.sans.edu/diary/Macfinger%20ClickFix%20campaign/33360 Graphalgo campaign spreads to Terraform providers and Go Modules https://www.aikido.dev/blog/graphalgo-terraform-go-modules MikroTik vulnerabilities technical analysis, https://cert.pl/en/posts/2026/09/mikrotrick-technical-analysis/ F5 Big-IP Vulnerability Details CVE-2026-94127 https://labs.watchtowr.com/is-this-a-joke-in-the-auth-header-f5-big-ip-unauth-heap-overflow-to-rce-cve-2026-94127/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich podscan_ceKfRJw0F1fvyCUUhxsyFRhNvabT1TnF

SANS Stormcast Wednesday, September 23rd, 2026: GET with Body; Checkpoint, VeloCloud, BigIP and Microsoft Defender 0-days

September 22, 2026 4:52 4.08 MB Downloads: 0

The Truth about GET and HTTP Standards https://isc.sans.edu/diary/The%20Truth%20about%20GET%20and%20HTTP%20Standards/33358 CVE-2026-93616: 0-Day Remote Code Execution Vulnerability patch in Checkpoint Management Server https://support.checkpoint.com/results/sk/sk1000171/ VeloCloud Orchestrator (VCO) Patch for Exploited Vulnerability CVE-2026-93952 https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183 F5 BigIP APM Exploited Vulnerability Patched CVE-2026-94127 https://my.f5.com/manage/s/article/K000162605 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SANS Stormcast Tuesday, September 22nd, 2026: PNG Stego Analysis; NPM BTree Malware; Pi-Hole Advisory

September 21, 2026 5:42 4.78 MB Downloads: 0

TerminalFix PNG Steganography https://isc.sans.edu/diary/TerminalFix%3A%20PNG%20Steganography/33318 NPM Btree Malware Campaign Without Install Script https://checkmarx.com/zero-post/npm-btree-malware-campaign-affects-millions-of-downloads-no-need-for-install-script/ Pi-Hole Update and Advisory https://github.com/pi-hole/FTL/security/advisories/GHSA-2794-hrj8-5jg9 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SANS Stormcast Monday, September 21st, 2026: HTTP Query; Docker Escape; Brevo ClickFix Attack; LastPass Fake GitHub Repo

September 21, 2026 7:24 6.21 MB Downloads: 0

HTTP QUERY Method: The Grey Zone Between GET and POST https://isc.sans.edu/diary/HTTP%20QUERY%20Method%3A%20The%20Grey%20Zone%20Between%20GET%20And%20POST./33352 Simple MacOS Docker Escape https://www.accomplish.ai/blog/escaping-dockers-hypervisor/ CVE-2026-77179 Brevo ClickFix Compromise https://status.brevo.com/incidents/01M2QBC4EZ24ZACW6SWQYVW8N3/write-up LastPass (and other) lookalike GitHub Repo and Kernel Module Infostealer https://blog.lastpass.com/posts/lastpass-delphos-report-rapuncel-infostealer My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich