SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
by Johannes B. Ullrich
(c) SANS Institute 2026 This work is licensed under a Creative Commons License - Attribution-NonCommercial-ShareAlike - https://creativecommons.org/licenses/by-nc-sa/4.0/
Sep 21, 2026Episodes (2522)

SANS Stormcast Monday, September 21st, 2026: HTTP Query; Docker Escape; Brevo ClickFix Attack; LastPass Fake GitHub Repo
Sep 21, 20267m#10102
HTTP QUERY Method: The Grey Zone Between GET and POST https://isc.sans.edu/diary/HTTP%20QUERY%20Method%3A%20The%20Grey%20Zone%20Between%20GET%20And%20POST./33352 Simple MacOS Docker Escape https://www.accomplish.ai/blog/

SANS Stormcast Friday, September 18th, 2026: LousivLaoder Analysis; Issabel Framework 0-Day; Cyber Decoys; CISA Vuln Bulletin; Unbound Vulnerability
Sep 18, 20267m#10100
LausivLoader analysis, or how to pass data between malware stages https://isc.sans.edu/diary/LausivLoader%20analysis%2C%20or%20how%20to%20pass%20data%20between%20malware%20stages/33348 Issabel Framework Hard-coded JWT Ke

SANS Stormcast Thursday, September 17th, 2026: Hospitality Scans; Cisco, Acronis, and Pixel 0-Day; Dynamic Incident Response
Sep 17, 20266m#10098
Scans Targeting Hospitality Applications https://isc.sans.edu/diary/Scans%20Targeting%20Hospitality%20Applications/33344 Cisco Identity Services Engine Authentication Bypass Vulnerability CVE-2026-76460 https://sec.cloud

SANS Stormcast Wednesday, September 16th, 2026: MacOS 27 Traffic; Cisco 0-Day; Protecting Active Directory and API Tokens
Sep 16, 20267m#10096
MacOS 27 - First Boot https://isc.sans.edu/diary/MacOS%2027%20-%20First%20Boot/33340 Cisco Secure Email Gateway SQL Injection Vulnerability CVE-2026-76461 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecu

SANS Stormcast Tuesday, September 15th, 2026: Apple Updates; Homebrew Update; MSFT OOB Patch; Telegram Vuln
Sep 15, 20267m#10094
Apple Updates Everything https://isc.sans.edu/diary/Apple%20Updates%20Everything/33336 Homebrew 7 Released https://brew.sh/2026/09/13/homebrew-7.0.0/ Microsoft Out-of-Band Patch https://support.microsoft.com/en-us/servic

SANS Stormcast Monday, September 14th, 2026: Self-Expanding Stolen LLM Gateways; PAN-OS Vuln; OpenAI Hacked Ruby; Passkey Themed Social Engineering
Sep 14, 20266m#10092
The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access https://isc.sans.edu/diary/The%20Self-Expanding%20Stolen%20Inference%20Supply%20Chain%3A%20An%20AI%20Agent%20Harvesting%2

SANS Stormcast Friday, September 11th, 2026: Redtail Analsys (@sans_edu); Checkpoint VPN Patch; Netscaler and Sonicwall Attacks
Sep 11, 20265m#10090
Redtail Payload Analysis https://isc.sans.edu/diary/Redtail%20Payload%20Analysis%20%5BGuest%20Diary%5D/33326 Checkpoint Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510 https://community.c

SANS Stormcast Thursday, September 10th, 2026: Proxmox Scans; MSFT Defender, Gogole Chorme, and FortiPAM Vulns.
Sep 10, 20265m#10088
Scans for Proxmox Servers https://isc.sans.edu/diary/Scans%20for%20Proxmox%20Servers/33324 Next Nightmare Eclipse Vulnerability https://github.com/MSNightmare/ShieldCrash/blob/main/README.md Google Chrome Updates https:/

SANS Stormcast Wednesday, September 9th, 2026: Microsoft, Adobe, Ivanti, Fortinet Patch Tuesday
Sep 9, 20266m#10086
September 2026 Microsoft Patch Tuesday https://isc.sans.edu/diary/September%202026%20Microsoft%20Patch%20Tuesday/33320 Adobe Security Bulletins https://helpx.adobe.com/security/security-bulletin.html Security Advisory Iv

SANS Stormcast Tuesday, September 8th, 2026: numbat; MicroTik and Magento (Adobe Commerce) 0-Day
Sep 8, 20265m#10084
numbat - AI agent observability https://isc.sans.edu/diary/numbat%20-%20AI%20agent%20observability/33312 MicroTik SSH 0-Day Exploited https://mikrotik.com/supportsec/september-2026-vulnerability/ https://cert.pl/en/posts

SANS Stormcast Friday, September 4th, 2026: AV Exploits; Plex Update; Cisco Patches; Sangoma Switchvox Exploited
Sep 4, 20265m#10082
Nightmare Eclipse Discloses Several Anti-Malware Privilege Escalation Exploits https://github.com/MSNightmare Plex Update https://forums.plex.tv/t/important-security-update-for-plex-media-server-v1-43-2-and-earlier/94231

SANS Stormcast Thursday, September 3rd, 2026: SMA1000 0-Day Patch; SSRF Validation Issues; Faronics Abuse
Sep 3, 20265m#10080
Sonicwall SMA1000 Exploited Vulnerability Patched https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 SSRF: The Validator Can Lie https://xclow3n.com/post/the-validator-can-lie/ Git Hijack for AI Agents https

SANS Stormcast Wednesday, September 2nd, 2026: Guildma Update; Proxmox 7 Auth Bypass; Windows Hotpatch; Virtualizor BGP Hack
Sep 2, 20266m#10078
Guildma (Astaroth) malware infection from Brazilian Portuguese email https://isc.sans.edu/diary/Guildma%20%28Astaroth%29%20malware%20infection%20from%20Brazilian%20Portuguese%20email/33300 Authentication bypass in EOL Pr

SANS Stormcast Tuesday, September 1st, 2026: LLM Honeypot; PaperCut Update; TerminalFix Malware;
Sep 1, 20266m#10076
The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary https://isc.sans.edu/diary/The%20Coding-Agent%20Trap%3A%20When%20a%20%22Free%22%20LLM%20Endpoint%20Is%20the%20Adversary/33298 PaperCut Public Exploit Ava

SANS Stormcast Monday, August 31st, 2026: Malware Statistics; PaperCut Update; Watchguard and DLink Patches;
Aug 31, 20265m#10074
Some Malicious PE Stats https://isc.sans.edu/diary/Some%20Malicious%20PE%20Stats/33292 PaperCut Releases Two Preliminary Patches for Exploited Vulnerability https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-

SANS Stormcast Friday, August 28th, 2026: Broken Polymorphic Phishing; Router Implants; llms.txt exploits; Papercut 0-Day
Aug 28, 20267m#10072
A polymorphic phishing page (that occasionally breaks itself) https://isc.sans.edu/diary/A%20polymorphic%20phishing%20page%20%28that%20occasionally%20breaks%20itself%29/33290 Chinese Implants in the Supply Chain https://

SANS Stormcast Thursday, August 27th, 2026: Entra ID Admins; Unifi Patches; log4j Vuln; Sleepwalker Malware
Aug 27, 20267m#10070
Who Has Admin Rights in your Entra ID Directory? https://isc.sans.edu/diary/Who%20Has%20Admin%20Rights%20in%20your%20Entra%20ID%20Directory%3F/33284 Ubiquity Unifi Patches https://community.ui.com/releases/Security-Advis

SANS Stormcast Wednesday, August 26th, 2026: Obfuscating SSRF; Paint and Photos AI Watermarks; FTP Banner C2;
Aug 26, 20265m#10068
Obfuscating IP Addresses as Hostnames https://isc.sans.edu/diary/Obfuscating%20IP%20Addresses%20as%20Hostnames/33280 Microsoft Paint and Photos Embed Server-Issued GUIDs as Invisible Watermarks in Locally-Generated Image

SANS Stormcast Tuesday, August 25th, 2026: DOUBLECUP PNG; WebAudio Fingerprinting; Expired Domains; Android; Car
Aug 25, 20267m#10066
DOUBLECUP's PNG Payload https://isc.sans.edu/diary/DOUBLECUP%27s%20PNG%20Payload/33274 AliExpress WebAudio fingerprinting https://blog.laserphile.com/2026/08/aliexpress-webpage-keeping-multipoint.html Expired DMARC Repor

SANS Stormcast Monday, August 24th, 2026: More Entra Powershell; Entra Vulnerability; GitLab Vuln (and PoC); GTA 6 Leak Malware
Aug 24, 20265m#10064
Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting! https://isc.sans.edu/diary/Who%20Got%20Missed%20in%20the%20MFA%20Rollout%3F%20More%20Powershell%20%2B%20Graph%20%2B%20Entra%20scripting!/33272

SANS Stormcast Friday, August 21st, 2026: Microsoft Graph and Powershell; Keycloak Vuln; Cryptographic Context Injection; N-Able Password Leak
Aug 21, 20267m#10062
Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses https://isc.sans.edu/diary/Using%20Microsoft%20Graph%20and%20Powershell%20to%20Mine%20for%20Information%20-%20Stale%20Accounts%20

SANS Stormcast Thursday, August 20th, 2026: Cloud Metadata Scans; Oracle and Netscaler Patches; Fake Ransomware Rescuers
Aug 20, 20266m#10060
Simple Scans for Cloud Metadata Service https://isc.sans.edu/diary/Simple%20Scans%20for%20Cloud%20Metadata%20Service/33260 Oracle Critical Security Patch Update Advisory - August 2026 https://www.oracle.com/security-aler

SANS Stormcast Wednesday, August 19th, 2026: Copilot as Whitstleblower; GEEKOM Bad Driver; Medusa Update; Encrypted AI
Aug 19, 20268m#10058
CoSnitch: When Your AI Assistant Becomes Its Own Whistleblower https://www.varonis.com/blog/cosnitch GEEKOM confirms malware was hosted on its website https://videocardz.com/newz/geekom-apologizes-for-hosting-malware-in-

SANS Stormcast Tuesday, August 18th, 2026: Apple Patches; Screen Sharing Security; Download More RAM
Aug 18, 20269m#10056
Apple Patches or iOS and macOS https://isc.sans.edu/diary/Apple%20Patches%20iOS%20and%20macOS/33254 Screen Sharing Security https://isc.sans.edu/diary/Apple%20Screen%20Sharing%20Security/33252 Download More RAM: Dismantl

SANS Stormcast Monday, August 17th, 2026: MacOS Screen Sharing; GeoServer Patch; SAP Exploited;
Aug 17, 20265m#10054
macOS Screen Sharing Vulnerability Exploited https://advisories.ncsc.nl/2026/ncsc-2026-0280.html GeoServer Patch https://geoserver.org/announcements/vulnerability/2026/08/14/geoserver-3-0-1-released.html Recent SAP Comme