A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

SANS Stormcast Monday, September 14th, 2026: Self-Expanding Stolen LLM Gateways; PAN-OS Vuln; OpenAI Hacked Ruby; Passkey Themed Social Engineering

September 13, 2026 6:52 1.13 MB ( 4.63 MB less) Downloads: 0

The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access
https://isc.sans.edu/diary/The%20Self-Expanding%20Stolen%20Inference%20Supply%20Chain%3A%20An%20AI%20Agent%20Harvesting%20and%20Re-Serving%20LLM%20Access/33332
CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing
https://security.paloaltonetworks.com/CVE-2026-0310
OpenAI agents carried out an undisclosed cyber-attack on RubyGems
https://www.rubyhack.ai
Passkey-themed social engineering leads to identity and cloud compromise
https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich