SANS Stormcast Monday, September 21st, 2026: HTTP Query; Docker Escape; Brevo ClickFix Attack; LastPass Fake GitHub Repo
Show notes
HTTP QUERY Method: The Grey Zone Between GET and POST
https://isc.sans.edu/diary/HTTP%20QUERY%20Method%3A%20The%20Grey%20Zone%20Between%20GET%20And%20POST./33352
Simple MacOS Docker Escape
https://www.accomplish.ai/blog/escaping-dockers-hypervisor/ CVE-2026-77179
Brevo ClickFix Compromise
https://status.brevo.com/incidents/01M2QBC4EZ24ZACW6SWQYVW8N3/write-up
LastPass (and other) lookalike GitHub Repo and Kernel Module Infostealer
https://blog.lastpass.com/posts/lastpass-delphos-report-rapuncel-infostealer
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich