SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
by Johannes B. Ullrich
(c) SANS Institute 2026 This work is licensed under a Creative Commons License - Attribution-NonCommercial-ShareAlike - https://creativecommons.org/licenses/by-nc-sa/4.0/
Oct 8, 2026Episodes (2535)

SANS Stormcast Thursday, October 8th, 2026: Atlassian Vulnerabilities; ccTLD Compormise; Outlook blocking .msix
Oct 8, 20266m#10128
Scans for Atlassian vulnerablity (CVE-2026-21589) https://isc.sans.edu/diary/Scans%20for%20Atlassian%20vulnerablity%20%28CVE-2026-21589%29/33406 .gh, .sl and .as ccTLD Compromise https://blog.google/security/chromes-resp

SANS Stormcast Wednesday, October 7th, 2026: RMM Tools; libHEIF RCE; Sonicwall SMA1000, OpenSSH updates, DNSSEC KSK Rollover
Oct 7, 20266m#10126
More RMM Tools In the Wild https://isc.sans.edu/diary/More%20RMM%20Tools%20In%20the%20Wild/33400 WORDPRESS LIBHEIF RCE https://fortbridge.co.uk/research/wordpress-libheif-rce/ SONICWALL SMA1000 SERIES APPLIANCES Vulnerab

SANS Stormcast Tuesday, October 6th, 2026: cowrie tty Logs; Another Netscaler 0-Day; Exchange Patch
Oct 6, 20266m#10124
TTY Logs and the Data it Captures https://isc.sans.edu/diary/TTY%20Logs%20and%20the%20Data%20it%20Captures/33396 Citrix Netscaler SAML Vulnerability (0-Day) CVE-2026-88779 https://support.citrix.com/support-home/kbsearch

SANS Stormcast Monday, October 5th, 2026: Funny User-Agents; FortMail 0-Day; GitLab Patch; macOS Full Disk Access
Oct 5, 20267m#10122
User Agent Strings Curiosities https://isc.sans.edu/diary/User%20Agent%20Strings%20Curiosities/33394 FortiMail Improper limitation of a pathname to a restricted directory CVE-2026-104286 https://fortiguard.fortinet.com/p

SANS Stormcast Friday, October 2nd, 2026: ScreenConnect Abuse; ChatGPT Abuse; Spoofing iCloud; Proton Mail display name
Oct 2, 20266m#10120
ScreenConnect Client (Ab)used by Attackers https://isc.sans.edu/diary/ScreenConnect+Client+Abused+by+Attackers/33388/#comments Attackers abuse ChatGPT to deliver RAT via ClickFix https://www.huntress.com/blog/chatgpt-cus

SANS Stormcast Thursday, October 1st, 2026: Cisco Catalyst SD-WAN Manager 0-day; Watchguard AP RCE; OpenBao/Vault RCE; Post Quantum Certs
Oct 1, 20265m#10118
Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability CVE-2026-76504 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU WatchGuard AP Command Inj

SANS Stormcast Wednesday, September 30th, 2026: Wordfence Scans; MikroTik Vulnerability; Poper Blocker Spyware
Sep 30, 20265m#10116
Scans for Wordfence Protected Websites https://isc.sans.edu/diary/Scans%20for%20Wordfence%20Protected%20Websites/33382 MikroTik RouterOS Vulnerability (CVE-2026-84411) https://www.cisa.gov/news-events/ics-advisories/icsa

SANS Stormcast Tuesday, September 29th, 2026: MacOS/iOS 0-Day Patch; macOS priv. escalation 0-day; File Notification Attacks
Sep 29, 20266m#10114
Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950) https://isc.sans.edu/diary/Apple%20Emergency%20Patch%20for%20iOS%2026%2C%20macOS26%2C%20macOS15%20%28CVE-2026-86950%29/33376 https://support.apple.com/e

SANS Stormcast Monday, September 28th, 2026: Macfinger Details; NetScaler 0-Day; KiteWorks 0-Day; ShinyHunters and PeopleSoft
Sep 28, 20266m#10112
A Closer Look at Malware From the Macfinger ClickFix Campaign https://isc.sans.edu/diary/A%20Closer%20Look%20at%20Malware%20From%20the%20Macfinger%20ClickFix%20Campaign/33368 Citrix NetScaler ADC and Citrix NetScaler Gat

SANS Stormcast Friday, September 25th, 2026: Tricky Phishing URL; MacSync Malware Update; SolarWinds Observable Patch
Sep 25, 20267m#10110
One URL, Three Different Tricks https://isc.sans.edu/diary/33366 Send GitLab an email, push to main https://www.aikido.dev/blog/gitlab-email-push-to-main macOS MacSync Malware Update https://securelist.com/macsync-new-ve

SANS Stormcast Thursday, September 24th, 2026: Macfinger ClickFix; Malicious Terraform; MikroTik and F5 Big IP Vulnerability Details
Sep 24, 20265m#10108
Macfinger ClickFix Campaign https://isc.sans.edu/diary/Macfinger%20ClickFix%20campaign/33360 Graphalgo campaign spreads to Terraform providers and Go Modules https://www.aikido.dev/blog/graphalgo-terraform-go-modules Mik

SANS Stormcast Wednesday, September 23rd, 2026: GET with Body; Checkpoint, VeloCloud, BigIP and Microsoft Defender 0-days
Sep 23, 20264m#10106
The Truth about GET and HTTP Standards https://isc.sans.edu/diary/The%20Truth%20about%20GET%20and%20HTTP%20Standards/33358 CVE-2026-93616: 0-Day Remote Code Execution Vulnerability patch in Checkpoint Management Server h

SANS Stormcast Tuesday, September 22nd, 2026: PNG Stego Analysis; NPM BTree Malware; Pi-Hole Advisory
Sep 22, 20265m#10104
TerminalFix PNG Steganography https://isc.sans.edu/diary/TerminalFix%3A%20PNG%20Steganography/33318 NPM Btree Malware Campaign Without Install Script https://checkmarx.com/zero-post/npm-btree-malware-campaign-affects-mil

SANS Stormcast Monday, September 21st, 2026: HTTP Query; Docker Escape; Brevo ClickFix Attack; LastPass Fake GitHub Repo
Sep 21, 20267m#10102
HTTP QUERY Method: The Grey Zone Between GET and POST https://isc.sans.edu/diary/HTTP%20QUERY%20Method%3A%20The%20Grey%20Zone%20Between%20GET%20And%20POST./33352 Simple MacOS Docker Escape https://www.accomplish.ai/blog/

SANS Stormcast Friday, September 18th, 2026: LousivLaoder Analysis; Issabel Framework 0-Day; Cyber Decoys; CISA Vuln Bulletin; Unbound Vulnerability
Sep 18, 20267m#10100
LausivLoader analysis, or how to pass data between malware stages https://isc.sans.edu/diary/LausivLoader%20analysis%2C%20or%20how%20to%20pass%20data%20between%20malware%20stages/33348 Issabel Framework Hard-coded JWT Ke

SANS Stormcast Thursday, September 17th, 2026: Hospitality Scans; Cisco, Acronis, and Pixel 0-Day; Dynamic Incident Response
Sep 17, 20266m#10098
Scans Targeting Hospitality Applications https://isc.sans.edu/diary/Scans%20Targeting%20Hospitality%20Applications/33344 Cisco Identity Services Engine Authentication Bypass Vulnerability CVE-2026-76460 https://sec.cloud

SANS Stormcast Wednesday, September 16th, 2026: MacOS 27 Traffic; Cisco 0-Day; Protecting Active Directory and API Tokens
Sep 16, 20267m#10096
MacOS 27 - First Boot https://isc.sans.edu/diary/MacOS%2027%20-%20First%20Boot/33340 Cisco Secure Email Gateway SQL Injection Vulnerability CVE-2026-76461 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecu

SANS Stormcast Tuesday, September 15th, 2026: Apple Updates; Homebrew Update; MSFT OOB Patch; Telegram Vuln
Sep 15, 20267m#10094
Apple Updates Everything https://isc.sans.edu/diary/Apple%20Updates%20Everything/33336 Homebrew 7 Released https://brew.sh/2026/09/13/homebrew-7.0.0/ Microsoft Out-of-Band Patch https://support.microsoft.com/en-us/servic

SANS Stormcast Monday, September 14th, 2026: Self-Expanding Stolen LLM Gateways; PAN-OS Vuln; OpenAI Hacked Ruby; Passkey Themed Social Engineering
Sep 14, 20266m#10092
The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access https://isc.sans.edu/diary/The%20Self-Expanding%20Stolen%20Inference%20Supply%20Chain%3A%20An%20AI%20Agent%20Harvesting%2

SANS Stormcast Friday, September 11th, 2026: Redtail Analsys (@sans_edu); Checkpoint VPN Patch; Netscaler and Sonicwall Attacks
Sep 11, 20265m#10090
Redtail Payload Analysis https://isc.sans.edu/diary/Redtail%20Payload%20Analysis%20%5BGuest%20Diary%5D/33326 Checkpoint Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510 https://community.c

SANS Stormcast Thursday, September 10th, 2026: Proxmox Scans; MSFT Defender, Gogole Chorme, and FortiPAM Vulns.
Sep 10, 20265m#10088
Scans for Proxmox Servers https://isc.sans.edu/diary/Scans%20for%20Proxmox%20Servers/33324 Next Nightmare Eclipse Vulnerability https://github.com/MSNightmare/ShieldCrash/blob/main/README.md Google Chrome Updates https:/

SANS Stormcast Wednesday, September 9th, 2026: Microsoft, Adobe, Ivanti, Fortinet Patch Tuesday
Sep 9, 20266m#10086
September 2026 Microsoft Patch Tuesday https://isc.sans.edu/diary/September%202026%20Microsoft%20Patch%20Tuesday/33320 Adobe Security Bulletins https://helpx.adobe.com/security/security-bulletin.html Security Advisory Iv

SANS Stormcast Tuesday, September 8th, 2026: numbat; MicroTik and Magento (Adobe Commerce) 0-Day
Sep 8, 20265m#10084
numbat - AI agent observability https://isc.sans.edu/diary/numbat%20-%20AI%20agent%20observability/33312 MicroTik SSH 0-Day Exploited https://mikrotik.com/supportsec/september-2026-vulnerability/ https://cert.pl/en/posts

SANS Stormcast Friday, September 4th, 2026: AV Exploits; Plex Update; Cisco Patches; Sangoma Switchvox Exploited
Sep 4, 20265m#10082
Nightmare Eclipse Discloses Several Anti-Malware Privilege Escalation Exploits https://github.com/MSNightmare Plex Update https://forums.plex.tv/t/important-security-update-for-plex-media-server-v1-43-2-and-earlier/94231

SANS Stormcast Thursday, September 3rd, 2026: SMA1000 0-Day Patch; SSRF Validation Issues; Faronics Abuse
Sep 3, 20265m#10080
Sonicwall SMA1000 Exploited Vulnerability Patched https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 SSRF: The Validator Can Lie https://xclow3n.com/post/the-validator-can-lie/ Git Hijack for AI Agents https