SANS Stormcast Friday, October 9th, 2026: AI Agent Forensics; AI-Assisted Attack on South Korean Banks; IDN Typosquatting; Cisco Finesse SSRF (CVE-2026-20362)
Show notes
In today's episode: new scripts for reconstructing AI agent activity during forensic investigations, an attacker's Claude chat history recovered after breaches at South Korean financial institutions, internationalized domain name (IDN) lookalikes that still get past Chrome, and an unpatched Cisco Finesse server-side request forgery (SSRF) vulnerability.
Reconstructing AI Agent Activity: Two New Scripts for Forensic Review
Jim Clausing released two scripts that turn the logs left behind by the OpenCode and Hermes AI agents into searchable JSON, so incident responders can see what an AI agent did on an attacker's or a victim's system.
https://isc.sans.edu/diary/Reconstructing%20AI%20Agent%20Activity%3A%20Two%20New%20Scripts%20for%20Forensic%20Review/33410
Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance
While investigating breaches at South Korean financial institutions, CrowdStrike recovered the attacker's CLAUDE.md file and Claude chat history, a rare look at how a low-skill "prompt kiddie" uses AI to run an attack.
https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/
Turning IDN Edge Cases into Typosquats
Attackers can still register convincing lookalike domains using Unicode characters that resemble Latin letters but are not on Chrome's list of known confusables. One test domain impersonating Apple displayed in Chrome but not in Safari.
https://haveibeensquatted.com/blog/turning-idn-edge-cases-into-typosquats
Cisco Finesse SSRF Vulnerability (CVE-2026-20362)
Cisco disclosed an unauthenticated server-side request forgery vulnerability in the Cisco Finesse web-based management interface, rated High (CVSS 7.2). Details are already public, there is no workaround, and fixed releases are not expected until January or February 2027.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-finesse-ssrf-mmSuyugS
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich