- 6 minutes 43 secondsSANS Stormcast Wednesday, October 7th, 2026: RMM Tools; libHEIF RCE; Sonicwall SMA1000, OpenSSH updates, DNSSEC KSK Rollover
More RMM Tools In the Wild
https://isc.sans.edu/diary/More%20RMM%20Tools%20In%20the%20Wild/33400
WORDPRESS LIBHEIF RCE
https://fortbridge.co.uk/research/wordpress-libheif-rce/
SONICWALL SMA1000 SERIES APPLIANCES Vulnerabilities CVE-2026-102255, CVE-2026-102256, CVE-2026-102257, CVE-2026-102258
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017
OpenSSH 10.6 Released
https://seclists.org/oss-sec/2026/q4/58
DNSSEC Root Key Signing Key Rollover
https://blog.cloudflare.com/root-ksk-2024-rollover/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich7 October 2026, 2:00 am - 6 minutes 8 secondsSANS Stormcast Tuesday, October 6th, 2026: cowrie tty Logs; Another Netscaler 0-Day; Exchange Patch
TTY Logs and the Data it Captures
https://isc.sans.edu/diary/TTY%20Logs%20and%20the%20Data%20it%20Captures/33396
Citrix Netscaler SAML Vulnerability (0-Day) CVE-2026-88779
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174
https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/
Microsoft Exchange September 2026 V2 Update CVE-2026-96940
https://techcommunity.microsoft.com/blog/exchange/released-september-2026-v2-exchange-server-security-updates/4561718
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich6 October 2026, 11:45 am - 7 minutes 24 secondsSANS Stormcast Monday, October 5th, 2026: Funny User-Agents; FortMail 0-Day; GitLab Patch; macOS Full Disk Access
User Agent Strings Curiosities
https://isc.sans.edu/diary/User%20Agent%20Strings%20Curiosities/33394
FortiMail Improper limitation of a pathname to a restricted directory CVE-2026-104286
https://fortiguard.fortinet.com/psirt/FG-IR-26-175
Critical GitLab Vulnerability CVE-2026-90970
https://docs.gitlab.com/releases/patches/other-patches/patch-release-gitlab-ai-gateway-19-4-1-released/
Updates to Full Disk Access in macOS
https://developer.apple.com/news/?id=p6zjojqw
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich5 October 2026, 2:00 am - 6 minutes 36 secondsSANS Stormcast Friday, October 2nd, 2026: ScreenConnect Abuse; ChatGPT Abuse; Spoofing iCloud; Proton Mail display name
ScreenConnect Client (Ab)used by Attackers
https://isc.sans.edu/diary/ScreenConnect+Client+Abused+by+Attackers/33388/#comments
Attackers abuse ChatGPT to deliver RAT via ClickFix
https://www.huntress.com/blog/chatgpt-custom-gpts-clickfix-rat?_sp=51406044-aa1d-4278-a4e7-adb5b8ef84b2.1790890760100
Spoofing iCloud From Address
https://sec-consult.com/blog/detail/from-anyoneicloudcom-spoofing-arbitrary-apple-icloud-identities/
Sender spoofing in Proton Mail via display-name homograph
https://alonsovidales.github.io/protonmail-sender-spoofing/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich2 October 2026, 2:00 am - 5 minutes 7 secondsSANS Stormcast Thursday, October 1st, 2026: Cisco Catalyst SD-WAN Manager 0-day; Watchguard AP RCE; OpenBao/Vault RCE; Post Quantum Certs
Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability CVE-2026-76504
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU
WatchGuard AP Command Injection in Internal Management API Allows Command Execution
https://psirt.watchguard.com/CVE-2026-86102/
A Realistic Code Execution Exploit Chain in OpenBao and Vault
https://control-plane.io/posts/unauthed-to-rce-in-vault-and-openbao/
Building a post-quantum certificate authority with Merkle Tree Certificates
https://blog.cloudflare.com/pq-ca-with-mtcs/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich1 October 2026, 2:00 am - 5 minutes 55 secondsSANS Stormcast Wednesday, September 30th, 2026: Wordfence Scans; MikroTik Vulnerability; Poper Blocker Spyware
Scans for Wordfence Protected Websites
https://isc.sans.edu/diary/Scans%20for%20Wordfence%20Protected%20Websites/33382
MikroTik RouterOS Vulnerability (CVE-2026-84411)
https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06
Poper Blocker: The Adblocker That Spies on You
https://amibeingpwned.com/blog/poper-blocker-the-adblocker-that-spies-on-you
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich30 September 2026, 2:00 am - 6 minutes 33 secondsSANS Stormcast Tuesday, September 29th, 2026: MacOS/iOS 0-Day Patch; macOS priv. escalation 0-day; File Notification Attacks
Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950)
https://isc.sans.edu/diary/Apple%20Emergency%20Patch%20for%20iOS%2026%2C%20macOS26%2C%20macOS15%20%28CVE-2026-86950%29/33376
https://support.apple.com/en-us/100100
Proof of concept for macOS CoreServices Priv. Escalation (CVE-2026-43786)
https://github.com/Malwation/CVE-2026-43786
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
https://www.microsoft.com/en-us/security/blog/2026/09/28/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations/
File Notification Attacks https://inoti.fyi/pubs/file-notification-attacks.pdf
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich29 September 2026, 2:00 am - 6 minutes 40 secondsSANS Stormcast Monday, September 28th, 2026: Macfinger Details; NetScaler 0-Day; KiteWorks 0-Day; ShinyHunters and PeopleSoft
A Closer Look at Malware From the Macfinger ClickFix Campaign
https://isc.sans.edu/diary/A%20Closer%20Look%20at%20Malware%20From%20the%20Macfinger%20ClickFix%20Campaign/33368
Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778
https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/
KiteWorks Urges Customers to Shut Down Servers
https://www.heise.de/en/news/Imminent-Zero-Day-Attack-KiteWorks-Urges-Customers-to-Shut-Down-Servers-11466375.html
ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft
https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich28 September 2026, 2:00 am - 7 minutes 10 secondsSANS Stormcast Friday, September 25th, 2026: Tricky Phishing URL; MacSync Malware Update; SolarWinds Observable Patch
One URL, Three Different Tricks
https://isc.sans.edu/diary/33366
Send GitLab an email, push to main
https://www.aikido.dev/blog/gitlab-email-push-to-main
macOS MacSync Malware Update
https://securelist.com/macsync-new-version/121383/
SolarWinds Observability Self-Hosted 2026.2.3
https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/hco_2026-2-3_release_notes.htm
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich25 September 2026, 3:45 am - 5 minutes 56 secondsSANS Stormcast Thursday, September 24th, 2026: Macfinger ClickFix; Malicious Terraform; MikroTik and F5 Big IP Vulnerability Details
Macfinger ClickFix Campaign
https://isc.sans.edu/diary/Macfinger%20ClickFix%20campaign/33360
Graphalgo campaign spreads to Terraform providers and Go Modules
https://www.aikido.dev/blog/graphalgo-terraform-go-modules
MikroTik vulnerabilities technical analysis,
https://cert.pl/en/posts/2026/09/mikrotrick-technical-analysis/
F5 Big-IP Vulnerability Details CVE-2026-94127
https://labs.watchtowr.com/is-this-a-joke-in-the-auth-header-f5-big-ip-unauth-heap-overflow-to-rce-cve-2026-94127/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich24 September 2026, 3:50 am - 4 minutes 52 secondsSANS Stormcast Wednesday, September 23rd, 2026: GET with Body; Checkpoint, VeloCloud, BigIP and Microsoft Defender 0-days
The Truth about GET and HTTP Standards
https://isc.sans.edu/diary/The%20Truth%20about%20GET%20and%20HTTP%20Standards/33358
CVE-2026-93616: 0-Day Remote Code Execution Vulnerability patch in Checkpoint Management Server
https://support.checkpoint.com/results/sk/sk1000171/
VeloCloud Orchestrator (VCO) Patch for Exploited Vulnerability CVE-2026-93952
https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183
F5 BigIP APM Exploited Vulnerability Patched CVE-2026-94127
https://my.f5.com/manage/s/article/K000162605
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich23 September 2026, 2:40 am - More Episodes? Get the App