
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
A brief daily summary of what is important in cyber security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually about 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter.
Episodes

SANS Stormcast Friday, September 18th, 2026: LousivLaoder Analysis; Issabel Framework 0-Day; Cyber Decoys; CISA Vuln Bulletin; Unbound Vulnerability
LausivLoader analysis, or how to pass data between malware stages
https://isc.sans.edu/diary/LausivLoader%20analysis%2C%20or%20how%20to%20pass%20data%20between%20malware%20stages/33348
Issabel Framework Hard-coded JWT Key RCE CVE-2026-89026
https://www.vulncheck.com/advisories/issabel-pbx-hard-coded-jwt-key-rce-via-pbxapi-manager-originate
Using Cyber Decoys to Strengthen Detection and Response
h

SANS Stormcast Thursday, September 17th, 2026: Hospitality Scans; Cisco, Acronis, and Pixel 0-Day; Dynamic Incident Response
Scans Targeting Hospitality Applications
https://isc.sans.edu/diary/Scans%20Targeting%20Hospitality%20Applications/33344
Cisco Identity Services Engine Authentication Bypass Vulnerability CVE-2026-76460
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5
Acronis Local privilege escalation due to insecure file permissions CVE-2026-87886
https://s

SANS Stormcast Wednesday, September 16th, 2026: MacOS 27 Traffic; Cisco 0-Day; Protecting Active Directory and API Tokens
MacOS 27 - First Boot
https://isc.sans.edu/diary/MacOS%2027%20-%20First%20Boot/33340
Cisco Secure Email Gateway SQL Injection Vulnerability CVE-2026-76461
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
Detecting and Mitigating Active Directory Compromises
https://www.cisa.gov/resources-tools/resources/detecting-and-mitigating-active-directo

SANS Stormcast Tuesday, September 15th, 2026: Apple Updates; Homebrew Update; MSFT OOB Patch; Telegram Vuln
Apple Updates Everything
https://isc.sans.edu/diary/Apple%20Updates%20Everything/33336
Homebrew 7 Released
https://brew.sh/2026/09/13/homebrew-7.0.0/
Microsoft Out-of-Band Patch
https://support.microsoft.com/en-us/servicing/os/windows-11/2026/09/kb5129195-windows-11-24h2-25h2-security-update
Telegram XSS Vulnerability
https://expatch.com/writeups/telegram-html-export-xss.html
My Upcoming Classes

SANS Stormcast Monday, September 14th, 2026: Self-Expanding Stolen LLM Gateways; PAN-OS Vuln; OpenAI Hacked Ruby; Passkey Themed Social Engineering
The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access
https://isc.sans.edu/diary/The%20Self-Expanding%20Stolen%20Inference%20Supply%20Chain%3A%20An%20AI%20Agent%20Harvesting%20and%20Re-Serving%20LLM%20Access/33332
CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing
https://security.paloaltonetworks.com/CVE-2026-0310
OpenAI agents car

SANS Stormcast Friday, September 11th, 2026: Redtail Analsys (@sans_edu); Checkpoint VPN Patch; Netscaler and Sonicwall Attacks
Redtail Payload Analysis
https://isc.sans.edu/diary/Redtail%20Payload%20Analysis%20%5BGuest%20Diary%5D/33326
Checkpoint Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510
https://community.checkpoint.com/t5/General-Topics/Action-Required-Critical-Security-Advisory-VPN-Vulnerabilities/td-p/281995
Cisco Secure Firewall Management Center Software Authentication Bypass V

SANS Stormcast Thursday, September 10th, 2026: Proxmox Scans; MSFT Defender, Gogole Chorme, and FortiPAM Vulns.
Scans for Proxmox Servers
https://isc.sans.edu/diary/Scans%20for%20Proxmox%20Servers/33324
Next Nightmare Eclipse Vulnerability
https://github.com/MSNightmare/ShieldCrash/blob/main/README.md
Google Chrome Updates
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html
FortiPAM Vulnerability
https://amibeingpwned.com/blog/fortinet-pam-vuln
My Upcoming Cl

SANS Stormcast Wednesday, September 9th, 2026: Microsoft, Adobe, Ivanti, Fortinet Patch Tuesday
September 2026 Microsoft Patch Tuesday
https://isc.sans.edu/diary/September%202026%20Microsoft%20Patch%20Tuesday/33320
Adobe Security Bulletins
https://helpx.adobe.com/security/security-bulletin.html
Security Advisory Ivanti Neurons for ITSM
https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US
Fortinet Advisory
https://www.fortiguard.com/psirt/FG

SANS Stormcast Tuesday, September 8th, 2026: numbat; MicroTik and Magento (Adobe Commerce) 0-Day
numbat - AI agent observability
https://isc.sans.edu/diary/numbat%20-%20AI%20agent%20observability/33312
MicroTik SSH 0-Day Exploited
https://mikrotik.com/supportsec/september-2026-vulnerability/
https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/
Adobe Commerce - Magento - 0-Day Exploited
https://sansec.io/research/stylesmuggler-0day
N-Able 4th Hotpatch
http

SANS Stormcast Friday, September 4th, 2026: AV Exploits; Plex Update; Cisco Patches; Sangoma Switchvox Exploited
Nightmare Eclipse Discloses Several Anti-Malware Privilege Escalation Exploits
https://github.com/MSNightmare
Plex Update
https://forums.plex.tv/t/important-security-update-for-plex-media-server-v1-43-2-and-earlier/942319
Cisco Update
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM
https://sec.cloudapps.cisco.com/security/center/conte

SANS Stormcast Thursday, September 3rd, 2026: SMA1000 0-Day Patch; SSRF Validation Issues; Faronics Abuse
Sonicwall SMA1000 Exploited Vulnerability Patched
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016
SSRF: The Validator Can Lie
https://xclow3n.com/post/the-validator-can-lie/
Git Hijack for AI Agents
https://www.manifold.security/blog/ai-coding-agents-git-hijack
Fronics Deploy Abuse
https://www.huntress.com/blog/faronics-deploy-abuse
My Upcoming Classes
https://www.sans.org

SANS Stormcast Wednesday, September 2nd, 2026: Guildma Update; Proxmox 7 Auth Bypass; Windows Hotpatch; Virtualizor BGP Hack
Guildma (Astaroth) malware infection from Brazilian Portuguese email
https://isc.sans.edu/diary/Guildma%20%28Astaroth%29%20malware%20infection%20from%20Brazilian%20Portuguese%20email/33300
Authentication bypass in EOL Proxmox VE 7 release
https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/page-4#post-867929
https://gist.github.com/nebusecurity/65fe90dd673d39

SANS Stormcast Tuesday, September 1st, 2026: LLM Honeypot; PaperCut Update; TerminalFix Malware;
The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary
https://isc.sans.edu/diary/The%20Coding-Agent%20Trap%3A%20When%20a%20%22Free%22%20LLM%20Endpoint%20Is%20the%20Adversary/33298
PaperCut Public Exploit Available
https://github.com/rapid7/metasploit-framework/pull/21842
TerminalFix Campaign;
https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-revers

SANS Stormcast Monday, August 31st, 2026: Malware Statistics; PaperCut Update; Watchguard and DLink Patches;
Some Malicious PE Stats
https://isc.sans.edu/diary/Some%20Malicious%20PE%20Stats/33292
PaperCut Releases Two Preliminary Patches for Exploited Vulnerability
https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/
DLink Vulnerabliities
https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10513
Watchguard Patches
https://psirt.watchguard.com
My

SANS Stormcast Friday, August 28th, 2026: Broken Polymorphic Phishing; Router Implants; llms.txt exploits; Papercut 0-Day
A polymorphic phishing page (that occasionally breaks itself)
https://isc.sans.edu/diary/A%20polymorphic%20phishing%20page%20%28that%20occasionally%20breaks%20itself%29/33290
Chinese Implants in the Supply Chain
https://www.vulncheck.com/blog/zbt-darklantern-speakingstone?_sp=1068fa46-3d91-427e-8120-aa6d8bda2912.1787865822277
Data Became Code: We Ran Code Inside Fortune 500s Using Files They Publ

SANS Stormcast Thursday, August 27th, 2026: Entra ID Admins; Unifi Patches; log4j Vuln; Sleepwalker Malware
Who Has Admin Rights in your Entra ID Directory?
https://isc.sans.edu/diary/Who%20Has%20Admin%20Rights%20in%20your%20Entra%20ID%20Directory%3F/33284
Ubiquity Unifi Patches
https://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9
Log4J FilteredObjectInputStream Vulnerability
https://github.com/joanbono/log4j2-4255-exploit
https://jeffmcjunkin.com/posts/

SANS Stormcast Wednesday, August 26th, 2026: Obfuscating SSRF; Paint and Photos AI Watermarks; FTP Banner C2;
Obfuscating IP Addresses as Hostnames
https://isc.sans.edu/diary/Obfuscating%20IP%20Addresses%20as%20Hostnames/33280
Microsoft Paint and Photos Embed Server-Issued GUIDs as Invisible Watermarks in Locally-Generated Images
https://xusheng.dev/posts/reversing/mspaint_invisible_watermark/main/
FTP Banners The New Dead Drop Resolver Delivering Novel RATs
https://socradar.io/blog/ftp-banners-new-dead-

SANS Stormcast Tuesday, August 25th, 2026: DOUBLECUP PNG; WebAudio Fingerprinting; Expired Domains; Android; Car
DOUBLECUP's PNG Payload
https://isc.sans.edu/diary/DOUBLECUP%27s%20PNG%20Payload/33274
AliExpress WebAudio fingerprinting
https://blog.laserphile.com/2026/08/aliexpress-webpage-keeping-multipoint.html
Expired DMARC Reporting Domain Exposed 86 Domains
https://www.sh.consulting/blog/abandoned-dmarc-reporting-domain
Android Car Malware
https://securelist.com/android-head-unit-malware/121106/
My

SANS Stormcast Monday, August 24th, 2026: More Entra Powershell; Entra Vulnerability; GitLab Vuln (and PoC); GTA 6 Leak Malware
Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!
https://isc.sans.edu/diary/Who%20Got%20Missed%20in%20the%20MFA%20Rollout%3F%20More%20Powershell%20%2B%20Graph%20%2B%20Entra%20scripting!/33272
Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays
https://isc.sans.edu/diary/Even%20MOAR%20Powershell%2C%20looking%20at%20Entra%20logins%2

SANS Stormcast Friday, August 21st, 2026: Microsoft Graph and Powershell; Keycloak Vuln; Cryptographic Context Injection; N-Able Password Leak
Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses
https://isc.sans.edu/diary/Using%20Microsoft%20Graph%20and%20Powershell%20to%20Mine%20for%20Information%20-%20Stale%20Accounts%20and%20Licenses/33264
Using Microsoft Graph and Powershell - Risk Detection Commands
https://isc.sans.edu/diary/Using%20Microsoft%20Graph%20and%20Powershell%20-%20Risk%20Detection%

SANS Stormcast Thursday, August 20th, 2026: Cloud Metadata Scans; Oracle and Netscaler Patches; Fake Ransomware Rescuers
Simple Scans for Cloud Metadata Service
https://isc.sans.edu/diary/Simple%20Scans%20for%20Cloud%20Metadata%20Service/33260
Oracle Critical Security Patch Update Advisory - August 2026
https://www.oracle.com/security-alerts/cspuaug2026.html
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490
https://support.citrix.com/support-home/kbsearch/article?articleNum

SANS Stormcast Wednesday, August 19th, 2026: Copilot as Whitstleblower; GEEKOM Bad Driver; Medusa Update; Encrypted AI
CoSnitch: When Your AI Assistant Becomes Its Own Whistleblower
https://www.varonis.com/blog/cosnitch
GEEKOM confirms malware was hosted on its website
https://videocardz.com/newz/geekom-apologizes-for-hosting-malware-in-driver-package-for-its-mini-pcs
Medusa Ransomware Update
https://www.cisa.gov/sites/default/files/2026-08/aa25-071a-stopransomware-medusa-ransomware-508c.pdf
How Google is Making

SANS Stormcast Tuesday, August 18th, 2026: Apple Patches; Screen Sharing Security; Download More RAM
Apple Patches or iOS and macOS
https://isc.sans.edu/diary/Apple%20Patches%20iOS%20and%20macOS/33254
Screen Sharing Security
https://isc.sans.edu/diary/Apple%20Screen%20Sharing%20Security/33252
Download More RAM: Dismantling Windows Operating System Defenses with Mischievous Memory
https://www.usenix.org/system/files/usenixsecurity26-collins.pdf
My Upcoming Classes
https://www.sans.org/profiles/dr

SANS Stormcast Monday, August 17th, 2026: MacOS Screen Sharing; GeoServer Patch; SAP Exploited;
macOS Screen Sharing Vulnerability Exploited
https://advisories.ncsc.nl/2026/ncsc-2026-0280.html
GeoServer Patch
https://geoserver.org/announcements/vulnerability/2026/08/14/geoserver-3-0-1-released.html
Recent SAP Commerce Cloud Vuln Exploited
https://x.com/DefusedCyber/status/2088240809355153647
ChainDrop npm Worm
https://medium.com/governed-at-the-source/the-chaindrop-npm-worm-august-2026-how-

SANS Stormcast Friday, August 14th, 2026: AI vs. Honeypot Data; CPU Bugs; GeoServer 0-Day; Windows USB Driver Confusion
Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI
https://isc.sans.edu/diary/Using%20Gemma4%20with%20Ollama%20-%20Testing%20File%20Hash%20Analysis%20and%20Recommendations%20with%20AI/33242
CPU Privilege Escalation
https://github.com/xoreaxeaxeax/smiiiiiiiiiiiiiiii
https://github.com/xoreaxeaxeax/skitter-creek-bath-salts
GeoServer Vulnerability
https://x.com/q1uf3ng

SANS Stormcast Thursday, August 13th, 2026: Process Accounting; ShieldBreak; SharePoint JWT Vuln PoC; AI regulation
Linux Kernel Process Accounting
https://isc.sans.edu/diary/Linux%20Kernel%20Process%20Accounting/33240
ShieldBreak - Windows Defender 0day vulnerability
https://git.projectnightcrawler.dev/NightmareEclipse/ShieldBreak/src/branch/main
Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-20

SANS Stormcast Wednesday, August 12th, 2026: Microsoft Patch Tuesday; Zoom Vulnerabilities; Mozilla Revokes Key; Rogue Inflight Wifi
Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20August%202026/33236
Zoom Vulnerablities CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415
https://a.security/blog/asecurity-zoomsday
Mozilla Revokes GPG Key
https://blog.mozilla.org/security/2026/08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/
Rogue Inflight Wifi
https://www.bleepingcomputer.com/

SANS Stormcast Tuesday, August 11th, 2026: Solana Attacks; AI Generated Patches; Gunra Ransomware; Neo4J/GraphQL Patch
Scans for Solana (Surfpool?) Endpoints
https://isc.sans.edu/diary/Scans%20for%20Solana%20%28Surfpool%3F%29%20Endpoints/33230
Why AI-generated vulnerability patches still require expert human review
https://1password.com/blog/why-ai-generated-patches-still-require-human-review?_sp=15ec2845-9e6c-4d15-8ac5-fe9bc1fe4c08.1786396502013
Gunra Ransomware
https://www.cisa.gov/sites/default/files/2026-08/a

SANS Stormcast Monday, August 10th, 2026: Linux Shell Forensics; Criticial MacOS Patch; More N-Central Hotfixes; Exploited Metabase Vuln;
Linux Shell Forensic: Let s Dive Into Atuin!
https://isc.sans.edu/diary/Linux+Shell+Forensic+Lets+Dive+Into+Atuin/33226
Apple Patches macOS Screen Sharing Vulnerability
https://support.apple.com/en-us/148170
More N-Able N-Central Issues
https://www.n-able.com/blog/n-central-security-update-august-6-2026
Metabase Unauthenticated SQL injection
https://github.com/metabase/metabase/security/advisorie

SANS Stormcast Friday, August 7th, 2026: Fast SSH Attacks; Dell BIOS Passwd Weakness; Crypto Wallet Vuln; Benchmarking LLMs for Threat Intel (@sans_edu)
22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary]
https://isc.sans.edu/diary/22+Seconds+to+Compromise+How+Automated+SSH+Actors+Move+From+Login+to+Persistence+Before+You+Can+Blink+Guest+Diary/33220
Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)
https://blog.amberwolf.com/blog/2026/july/dell

SANS Stormcast Thursday, August 6th, 2026: keyv/cachable Worm IR; Apple Private Relay Leak; COLDCARD Phish
Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm
https://isc.sans.edu/diary/Don%27t%20Revoke%20That%20Token%20Yet%3A%20Inside%20the%20keyv%20cacheable%20npm%20Worm/33218
IP and DNS Leaks in WebKit Affecting Proxy Browsers and Apple iCloud Private Relay
https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/?ref=404media.co
COLDCARD Issues
https://x.com/threatinsight

SANS Stormcast Wednesday, August 5th, 2026: Diagnostic Tool Hunt; Device Code Phishing; XCSSET; NuGet API Keys
Botnet Hunting for Vulnerabilities in Diagnostic Tools
https://isc.sans.edu/diary/Botnet%20Hunting%20for%20Vulnerabilities%20in%20Diagnostic%20Tools/33214
Inside Greatness: Telegram-Distributed M365 AiTM PhaaS
https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing
A Deep Dive Into the Latest XCSSET Version
https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/
Strengthen

SANS Stormcast Tuesday, August 4th, 2026: More Arch Linux AUR trouble; iCloud Sharing; Pass the Passkey
AUR packages adoption disabled
https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/DRDEU3JUSC72CB265XHXPFA3DFSLXPBP/
Apple's iCloud File Sharing Left Ex-Employees With Access to Secret Documents
https://www.macrumors.com/2026/08/03/apple-icloud-sharing-ex-employees/
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
https://unit42.paloaltonetworks

SANS Stormcast Monday, August 3rd, 2026: zipdump.py update; Atomic MacOS Analysis; OpenAI Phishing; COLDCARD Vulnerability
zipdump.py Metadata Encoding
https://isc.sans.edu/diary/zipdumppy+Metadata+Encoding/33202/
Atomic MacOS (AMOS) stealer infection
https://isc.sans.edu/diary/Atomic%20MacOS%20%28AMOS%29%20stealer%20infection/33208
Phishing Campaigns Targeting AI Solutions Providers
https://isc.sans.edu/diary/Phishing+Campaigns+Targeting+AI+Solutions+Providers/33206/
Predictable RNG Fallback and 32-Bit Reseed in COL

SANS Stormcast Friday, July 31st, 2026: Pre Botnet Recon; Cisco Backdoor Exploited; Inconsistent Group Chats
Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner
https://isc.sans.edu/diary/Reconnaissance%20First%3A%20An%20SSH%20Bot%20That%20Sizes%20Up%20Your%20Hardware%20Before%20Deploying%20a%20Miner%20%5BGuest%20Diary%5D/33198
Cisco Secure Firewall Management Center Software Static Credential Vulnerability Exploited CVE-2026-20316
https://sec.cloudapps.cisco.com/securi

SANS Stormcast Thursday, July 30th, 2026: Apple Patches; IPMI Admin PW Hash Leak; VMWare Patches; OpenWRT Patch
Apple Patch Summary / Postscript
https://isc.sans.edu/diary/Apple%20Patches%20Everything%20%28July%202026%29/33196
IPMI Admin Password Hash Leak
https://lavahq.io/research/bmc-exposure-alert
Patches for VMWare
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
OpenWRT Patch, odhcpd vulnerability CVE-2026-53921
https://github.com/openwrt

SANS Stormcast Wednesday, July 29th, 2026: AutoIT Payload Injector; Appele Patches; SourTrade Malware; NGINX Exploit
AutoIT Payload Injector
https://isc.sans.edu/diary/AutoIT%20Payload%20Injector%20/33192
Apple Security Update
https://support.apple.com/en-us/100100
SourTrade: Browser-Assembled Malware Delivered Through Malvertising
https://blog.confiant.com/p/sourtrade-browser-assembled-malware
NGINX Exploit CVE-2026-42530, CVE-2026-42533
https://github.com/DepthFirstDisclosures/Nginx-Rift/tree/main
My Upcoming

SANS Stormcast Tuesday, July 28th, 2026: Spring Boot Scans; VBulletin Vulnerability; MSFT Defender for Linux; MongoDB Update
Java Spring Boot "heapdump" scans
https://isc.sans.edu/diary/Java%20Spring%20Boot%20%22heapdump%22%20scans/33188
VBULLETIN RUNTIME TEMPLATE RUNMATHS PREAUTH RCE
https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/
Microsoft Defender for Linux Update may disable restart
https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint-releases#issues-have-been-

SANS Stormcast Monday, July 27th, 2026: ESAFENET CDG Scans; DNS Poisoning; macOS Gatekeeper bypass; GitHub and PyPi updates
Scans for ESAFENET CDG 3 Document Management System Weak Logins
https://isc.sans.edu/diary/Scans%20for%20ESAFENET%20CDG%203%20Document%20Management%20System%20Weak%20Logins/33184
DNS Poisoning Tactics Expand to Hospitality Wi-Fi
https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/
Silent Replacement of Trusted macOS App Executables
https://mysk.blog/2026/07/23

SANS Stormcast Friday, July 24th, 2026: OpenAI vs. Huggingface; Zimbra Exploited; Notepad++ Abuse; Browser as C2
When the "Autonomous Attacker" Is Your Own AI Model
https://isc.sans.edu/diary/When%20the%20%22Autonomous%20Attacker%22%20Is%20Your%20Own%20AI%20Model/33180
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra
https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a
https://cert.gov.ua/article/6318634
https://cybersecuritynews.com/hackers-abuse-notep

SANS Stormcast Thursday, July 23rd, 2026: Rondo and Geoserver; Oracle Patches; Checkpoint 0-day; OpenAI vs Huggingface
Rondo Meets Geoserver
https://isc.sans.edu/diary/Rondo%20Meets%20Geoserver/33176
Oracle July Patch Update
https://www.oracle.com/security-alerts/cpujul2026.html
OpenAI and Hugging Face partner to address security incident during model evaluation
https://openai.com/index/hugging-face-model-evaluation-security-incident/
Checkpoint July 2026 Security Advisory (CVE-2026-16232)
https://blog.checkpoint

SANS Stormcast Wednesday, July 22nd, 2026: Captive Portals; Critical Serv-U and Zimbra Update; Apple Hide-My-Email fix
Captive Portal Detection
https://isc.sans.edu/diary/Captive%20Portal%20Detection/33172
Critical SolarWinds Serv-U Update
https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm
Zimbra Update with Critical Security Fixes
https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/
Apple Fixed Hide My E-Mail Leak
https://www.404media

SANS Stormcast Tuesday, July 21st, 2026: More Wordpress Details; HOLLOWGRAPH MSFT Calendar Abuse; Gitea Vulnerability
WordPress Exploitation Underway (CVE-2026-63030)
https://isc.sans.edu/diary/WordPress%20Exploitation%20Underway%20%28CVE-2026-63030%29/33168
HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels
https://www.group-ib.com/blog/hollowgraph-microsoft-365/
Gitea Vulnerablity CVE-2026-58443
https://github.com/go-gitea/gitea/security/advisories/GHSA-xxjv-752h-3vp2
My

SANS Stormcast Monday, July 20th, 2026: Hikvision Scans; LG Spyware; Huggingface Hack; Wordpress Core RCE
Scans for Hikvision Intelligent Security API
https://isc.sans.edu/diary/Scans%20for%20Hikvision%20Intelligent%20Security%20API/33164
LG Monitor Spyware
https://www.techradar.com/televisions/lgs-gaming-monitors-and-tvs-are-facing-a-user-revolt https://www.youtube.com/watch?v=Q9uefFYe6bM
Huggingface Hack
https://huggingface.co/blog/security-incident-july-2026
Wordpress Core RCE
https://wp2shell.com

SANS Stormcast Friday, July 17th, 2026: Windows Hello for Business; NGINX Vuln; 7-zip vuln
German Federal Information Security Office Analyzes Windows Hello for Business
https://www.heise.de/en/news/BSI-dissects-Windows-Hello-Where-Microsoft-s-login-reaches-its-limits-11366125.html
https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/Studies/Windows_dissected/AP1_Windows-Hello-for-Business.pdf?__blob=publicationFile&v=7
NGINX Vulnerability
https://my.f5.com/manage/s/art

SANS Stormcast Thursday, July 16th, 2026: DShield SIEM Update; MSFT Patches vs. Intel IPF; Zoom Patch; Forgotten UEFI Shims
DShield SIEM Update
https://isc.sans.edu/diary/Recent%20DShield%20SIEM%20Update/33156
Microsoft Patch Tuesday vs. Dell Intel Innovation Platform Framework (IPF) drivers
https://support.microsoft.com/en-us/servicing/os/windows-11/2026/07/july-14-2026-kb5101650-os-builds-26200-8875-and-26100-8875
Zoom Account Takeover Patch
https://www.zoom.com/en/trust/security-bulletin/zsb-26014/
Forgotten UEFI s

SANS Stormcast Wednesday, July 15th, 2026: Microsoft Patches; New MSFT Priv Escalation; Progress ShareFile 0-Day; Grok Exfiltration
Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20July%202026%20-%20The%20AI%20Acopolypse%20is%20Here%20/33154
LegacyHive : Windows user profile service arbitrary hive load elevation of privileges vulnerability
https://git.projectnightcrawler.dev/NightmareEclipse/LegacyHive
Progress confirms ShareFile zero-day flaw behind Storag

SANS Stormcast Tuesday, July 14th, 2026: MCP/AI Related Scans; Improve Router Hygiene; OAuth Client ID Spoofing; Veeam Vuln;
Someone Is Scanning for Your MCP Servers and AI Assistant Credentials
https://isc.sans.edu/diary/Someone%20Is%20Scanning%20for%20Your%20MCP%20Servers%20and%20AI%20Assistant%20Credentials/33150
Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting
https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a
OAuth Client ID Spoofing
https://www.proofpoint.com/us/blog/th

SANS Stormcast Monday, July 13th, 2026: Progress Sharefile Shutdown; U-Boot Vuln; More Nightmare Eclipse; Cisco AI Response
Progress Sharefile Emergency Shutdown Notice
https://status.sharefile.com
https://www.reddit.com/r/sysadmin/comments/1usohco/psa_shutdown_your_sharefile_storage_zone/
https://www.bleepingcomputer.com/news/security/progress-urges-sharefile-customers-to-shut-down-servers-over-credible-threat/
U-Boot Vulnerabilities
https://www.binarly.io/blog/unfit-to-boot-breaking-u-boots-fit-signature-verificatio

SANS Stormcast Friday, July 10th, 2026: Belarus Graffiti Bot @sans_edu; Discontinuing Mac OS Ext. FS; Chrome Update; Rogue Planet Patch
_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary]
https://isc.sans.edu/diary/_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_%20%5BGuest%20Diary%5D/33130
Apple Discontinuing Support for Encrypted Mac OS Extended disks in macOS 28
https://support.apple.com/en-us/125615
Google Chrome Update
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html
Microsoft Patches Rogue

SANS Stormcast Thursday, July 9th, 2026: Stack Simulator; RootAsRole; Hoymiles; Git Hash Malleability
My Stack Simulator https://isc.sans.edu/diary/My%20Stack%20Simulator/33138
RootAsRole
https://github.com/LeChatP/RootAsRole
Hoymiles Inverter Vulnerability
https://www.ccc.de/system/uploads/382/original/hoymiles_dtu_vuln.pdf
Git Hash Chain Malleability
https://arxiv.org/abs/2607.02820
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich

SANS Stormcast Wednesday, July 8th, 2026: Odd DNS; AnyDesk Phishing; Tenda Backdoor; GitLost
More Odd DNS Records: NIMLOC
https://isc.sans.edu/diary/More%20Odd%20DNS%20Records%3A%20NIMLOC/33128
From Invoice to AnyDesk: Uncovering a Phishing Campaign Targeting Russian Aerospace Organizations
https://www.seqrite.com/blog/from-invoice-to-anydesk-uncovering-a-phishing-campaign-targeting-russian-aerospace-organizations/
Tenda firmware (multiple versions) contains hidden authentication backd

SANS Stormcast Tuesday, July 7th, 2026: RCS and DNS; OpenSSH Update; Beyond Trust Advisory; PolinRider Update
RCS and DNS: The NAPTR Record
https://isc.sans.edu/diary/RCS%20and%20DNS%3A%20The%20NAPTR%20Record/33124
OpenSSH 10.4 released
https://seclists.org/oss-sec/2026/q3/62
Beyond Trust Advisory CVE-2026-40138 CVE-2026-40139
https://www.beyondtrust.com/trust-center/security-advisories/bt26-03
PolinRider: North Korea-Linked Supply Chain Campaign
https://socket.dev/blog/polinrider-north-korea-linked-supp

SANS Stormcast Monday, July 6th, 2026: Apple Patch Policy; FatFS Vulns; OpenWRT; Multi-Agent Offensive AI;
Apple Updated Patch Policy
https://www.reuters.com/business/apple-says-it-is-releasing-updates-early-response-ai-cybersecurity-concerns-2026-06-29/
T3MP3ST multi-agent offensive-security framework
https://github.com/elder-plinius/T3MP3ST
Seven FatFs bugs, one very large blast radius
https://www.runzero.com/blog/fatfs-bugs/
OpenWRT Releases v25.12.5
https://github.com/openwrt/openwrt/releases
My U

SANS Stormcast Thursday, July 2nd, 2026: MetaMask Phishing; Adobe Patches; Google Chrome Patches; Apple Hide-My-Email Vuln
Why Ask Credentials If There Are Secret Codes?
https://isc.sans.edu/diary/Why%20Ask%20Credentials%20If%20There%20Are%20Secret%20Codes%3F/33118
Adobe Patches and Updated Patch Release Policy
https://helpx.adobe.com/security/Home.html
https://blog.adobe.com/security/protecting-customers-faster-how-adobe-is-responding-to-ai-accelerated-vulnerability-discovery
Google Chrome Update (link had issues lo

SANS Stormcast Wednesday, July 1st, 2026: Apple Patches; SimpleHelp Exploit; Git DNS Tricks;
June 2026 Apple Updates
https://isc.sans.edu/diary/June%202026%20Apple%20Updates/33114
SimpleHelp Exploit used to reply TaskWeaver
https://blackpointcyber.com/blog/a-djinn-in-the-machine-taskweavers-node-js-intrusion-chain/
DNS Tricks to Load Malware into Cloned Repository
https://0din.ai/blog/clone-this-repo-and-i-own-your-machine
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ull

SANS Stormcast Tuesday, June 30th, 2026: Favicon Recon Automation; Targeting Messaging; Gemini CLI vuln; IPv6 Frag Escape
Adding some Automation to the favicon.ico method of Host Recon
https://isc.sans.edu/diary/Adding%20some%20Automation%20to%20the%20favicon.ico%20method%20of%20Host%20Recon/33110
Russian Intelligence Services Continue to Target Commercial Messaging Applications
https://www.ic3.gov/PSA/2026/PSA260626
Google Gemini CLI Vulnerability CVE-2026-12537
https://github.com/advisories/GHSA-jj69-4grx-fqj5
IPv

SANS Stormcast Monday, June 29th, 2026: Automated Cybercrime; Linux Process Names; Amazon Q VS Code
What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime
https://isc.sans.edu/diary/What%20do%20Ports%20Hear%20When%20Nobody%27s%20Listening%3F%20An%20Assessment%20of%20Automated%20Cybercrime%20%5BGuest%20Diary%5D/33104
Linux Process Name Masquerading
https://isc.sans.edu/diary/Linux+Process+Name+Masquerading/33102
Amazon Q VS Code Extension Vulnerability
https://www.wiz.

SANS Stormcast Wednesday, June 24th, 2026: Patching vs. Configurations Updates; libssh2 and ffmpeg vuln;
CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration.
https://isc.sans.edu/diary/CVE-2024-40766%3A%20The%20Patch%20Fixed%20the%20Bug.%20Nobody%20Fixed%20the%20Configuration./33094
libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
https://www.vulncheck.com/advisories/libssh2-out-of-bounds-write-via-unchecked-packet-length-in-transport-c
PixelSmash Critic

SANS Stormcast Tuesday, June 23rd, 2026: Webshells; GitHub Actions Update; Fortibleed Update; Private Access Control Tokens
Webshells Remain Popular
https://isc.sans.edu/diary/Webshells%20Remain%20Popular/33096
Safer pull_request_target defaults for GitHub Actions checkout
https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/
Private Access Control Tokens
https://cloudflare.net/news/news-details/2026/Cloudflare-Collaborates-With-Leading-Browsers-to-Develop-a-Privacy-F

SANS Stormcast Monday, June 22nd, 2026: IPv4 Mapped Phish; nginx bug; squid bleeds; AMD encryption fix
eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address
https://isc.sans.edu/diary/eBanking%20Phishing%20Delivered%20Through%20IPv4-Mapped%20IPv6%20Address/33090
NGINX ngx_http_v3_module vulnerability CVE-2026-42530
https://my.f5.com/manage/s/article/K000161616
Squidbleed (CVE-2026-47729)
https://blog.calif.io/p/squidbleed-cve-2026-47729
AMD will reinstate memory encryption on Ryzen 9000 CPU

SANS Stormcast Thursday, June 18th, 2026: QUIC Challenge; Android 17; Oracle CSPU; JetBrains Plugins;
The browser blind spot: Why your security tool may not be blocking what you think it is [Guest Diary]
https://isc.sans.edu/diary/The%20browser%20blind%20spot%3A%20Why%20your%20security%20tool%20may%20not%20be%20blocking%20what%20you%20think%20it%20is%20%5BGuest%20Diary%5D/33084
Android 17 Security Patches
https://source.android.com/docs/security/bulletin/android-17
Oracle Critical Security Patch

SANS Stormcast Wednesday, June 17th, 2026: VHDX to Remocs RAT; Fake Job Offer; OpenBSD Vuln; Copilot M365 Leakage
From a VHDX File to a Remcos RAT
https://isc.sans.edu/diary/From%20a%20VHDX%20File%20to%20a%20Remcos%20RAT/33080
A backdoor in a LinkedIn job offer
https://roman.pt/posts/linkedin-backdoor/
A 27-Year-Old Authentication Bypass in OpenBSD's PPP Stack
https://blog.argus-systems.ai/blog/openbsd-pap-27-year-auth-bypass.html
Copilot M365 Data Leakage
https://www.varonis.com/blog/searchleak
My Upcoming

SANS Stormcast Tuesday, June 16th, 2026: BASE64 Statistics; Cisco SD-WAN Exploited; AMD TSME Disabled; Poisoning Deep Research Agents
Evil MSI Background: BASE64 Statistical Analysis
https://isc.sans.edu/diary/Evil%20MSI%20Background%3A%20BASE64%20Statistical%20Analysis/33072
Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ
TSME/SME not activating on Ryzen 7 9700X
https://github.com/AMDESE/AMDSEV/issues/292

SANS Stormcast Monday, June 15th, 2026: Arch Linux Malicious User Packages; Splunk Vuln and Exploit; Exploiting AI Coding Agents
Atomic Arch: Attackers Hijack Trusted AUR Packages to Deliver Rootkit-Like Malware
https://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency
Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE) https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/
A Fake B

SANS Stormcast Friday, June 12th, 2026: Bitlocker Trouble; Ivanti and Oracle Exploited; macOS Malicious Installers
More Bitlocker Issues: GreatXML
https://git.churchofmalware.org/Nightmare_Eclipse/GreatXML
Security Advisory Ivanti Sentry (CVE-2026-10520, CVE-2026-10523)
https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US
Oracle Security Alert Advisory - CVE-2026-35273
https://www.oracle.com/security-alerts/alert-cve-2026-35273.html
https://www.bleeping

SANS Stormcast Thursday, June 11th, 2026: Framing Protections; npm improvements; Adobe Patches; New Defender 0-day
How has use of framing protection security headers changed in the past 3 years?
https://isc.sans.edu/diary/How%20has%20use%20of%20framing%20protection%20security%20headers%20changed%20in%20the%20past%203%20years%3F/33068
Preparing for npm v12: install scripts and non-registry sources become opt-in
https://github.com/orgs/community/discussions/198547
Adobe Patches
https://helpx.adobe.com/security.

SANS Stormcast Wednesday, June 10th, 2026: Microsoft Patch Tuesday; Miasma Source Published; Fortinet Patches
Microsoft June 2026 Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20June%202026%20Patch%20Tuesday/33064
Miasma Software Supply Chain Attack Toolkit Source Published
https://safedep.io/inside-the-miasma-supply-chain-attack-toolkit/
Fortinet FortiSandbox Vulnerability
https://fortiguard.fortinet.com/psirt/FG-IR-26-141
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullric

SANS Stormcast Tuesday, June 9th, 2026: Azure Repos Infected; Checkpoint VPN 0-Day; Verizon VoLTE missing IPSec integrity prot.
Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack
https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents
Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751)
https://blog.checkpoint.com/security/check-point-releases-im

SANS Stormcast Monday, June 8th, 2026: Wetransfer Phish; Spying Smart TV; Dashlane Brute Force
The Evil MSI Background is Back!
https://isc.sans.edu/diary/The%20Evil%20MSI%20Background%20is%20Back!/33054
The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy
https://blog.includesecurity.com/2026/06/the-smart-tv-in-your-livingroom-is-a-node-in-the-aiscraping-economy/
UPDATE: For the story above, we received a notice from Bright Data's PR team. Please refer to the URL above for

SANS Stormcast Friday, June 5th, 2026: Coreutils for Windows; Cisco Unified Comm Manager Fix and Exploit; OAuth Orphans
Microsoft's Coreutils for Windows
https://isc.sans.edu/diary/Microsoft%27s%20Coreutils%20for%20Windows/33048
Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability CVE-2026-20230
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW
Firmware Update for Acer Connect W6x Router
https://community.acer.com/en/kb/articles/1967

SANS Stormcast Thursday, June 4th, 2026: swagger.json Scans; Android Fake Call Detection; Anthropic Dashboard
Continuing Scans for swagger.json
https://isc.sans.edu/diary/Continuing+Scans+for+swaggerjson/33044/#comments
Fake call detection on Android
https://blog.google/security/android-fake-call-detection/
Anthropic's coordinated vulnerability disclosure dashboard
https://red.anthropic.com/2026/cvd/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich

SANS Stormcast Wednesday, June 3rd, 2026: SVG Phishing; Android Patches; Poly Voice Vuln; Ivanti Neurons Priv Escelation
New Wave Of Phishing Emails with SVG Files
https://isc.sans.edu/diary/New%20Wave%20Of%20Phishing%20Emails%20with%20SVG%20Files/33040
Android 2026-06-01 security patch level vulnerability details
https://source.android.com/docs/security/bulletin/2026/2026-06-01
Poly Voice Possible Remote Control of Certain Poly Devices CVE-2026-0826
https://support.hp.com/us-en/document/ish_15052661-15052687-16/

SANS Stormcast Tuesday, June 2nd, 2026: Netlogon Exploit; Unidentified RAT; Windows Netlogon Exploited; RedHat npm Affected; Dashlane Bruteforce Attach
Unidentified RAT pushes NetSupport RAT
https://isc.sans.edu/diary/Unidentified%20RAT%20pushes%20NetSupport%20RAT/33034
CVE-2026-41089: Windows Netlogon Vulnerability Exploited
https://ccb.belgium.be/advisories/warning-microsoft-patch-tuesday-may-2026-patches-118-vulnerabilities-16-critical-102
RedHat npm Packages Affected
https://www.aikido.dev/blog/red-hat-npm-packages-compromised-credential-stea

SANS Stormcast Monday, June 1st, 2026: Bitskrieg; Gogs Unpatched Vuln; Oracle Critical Updates; PAN-OS Exploited;
Announcing Bitskrieg
https://deadeclipse666.blogspot.com/2026/05/announcing-bitskrieg.html
Vulnerability in Gogs
https://www.rapid7.com/blog/post/ve-authenticated-rce-via-argument-injection-gogs-unfixed/
Oracle Critical Security Patch Update Advisory - May 2026
https://www.oracle.com/security-alerts/cspumay2026.html
GlobalProtect Authentication Bypass Vulnerabilities CVE-2026-0257
https://securit

SANS Stormcast Friday, May 29th, 2026: @sans_edu research; Honeypot Log; VPN “Toad”; Silent Ransom Group
Research Review Journal
https://assets.contentstack.io/v3/assets/blt83c410d686aa5f84/blt3cff46f63887f83e/research-review-journal
https://www.sans.edu/cyber-research
Analysis of a Year of Files Uploaded to DShield Sensors
https://isc.sans.edu/diary/Analysis%20of%20a%20Year%20of%20Files%20Uploaded%20to%20DShield%20Sensors/33026
The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular

SANS Stormcast Thursday, May 28th, 2026: Akira Ransomware; Vaultjacking; Poisoned Chatbot and Search Results;
Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs
https://isc.sans.edu/diary/Reconstructing%20an%20Akira%20Ransomware%20Kill%20Chain%20from%20Perimeter%20and%20Endpoint%20Logs/33024
Vaultjacking: One Captured PIN, the Entire Google Password Manager Vault
https://phishu.net/blogs/blog-vaultjacking-phishing-the-google-password-manager-vault-in-the-phishu-framework.html

SANS Stormcast Wednesday, May 27th, 2026: Fake Claude Ads; SharePoint Vuln; Angular Vulnerabilities
Possible ACR Stealer From Page Impersonating Claude
https://isc.sans.edu/diary/Possible%20ACR%20Stealer%20From%20Page%20Impersonating%20Claude/33018
Microsoft SharePoint Remote Code Execution Vulnerability CVE-2026-45659
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659
Multiple Vulnerabilities in Angular Language Service VS Code Extension
https://github.com/angular/angular/sec

SANS Stormcast Tuesday, May 26th, 2026: VBA in MSFT Access; NPM Stealer; PHP Laravel Compromise; Google API Key Lag;
Microsoft Access VBA
https://isc.sans.edu/diary/Microsoft%20Access%20VBA/33012
An Example of Stack String in High Level Language
https://isc.sans.edu/diary/An%20Example%20of%20Stack%20String%20in%20High%20Level%20Language/33008
Cross-Platform NPM Stealer
https://isc.sans.edu/diary/Cross-Platform%20NPM%20Stealer/33006
Laravel Lang Compromised with RCE Backdoor Across
https://socket.dev/blog/larave

SANS Stormcast Friday, May 22nd, 2026: Selective HTTP Proxying; More GitHub Repo Trouble; MSFT Defender Patches;
Selective HTTP Proxying in Linux
https://isc.sans.edu/diary/Selective%20HTTP%20Proxying%20in%20Linux/33002
Megalodon: Mass GitHub Repo Backdooring via CI Workflows
https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows/
MSFT Patches Recent Windows Defender Flaws CVE-2026-41091, CVE-2026-45498, CVE-2026-45584
https://x.com/fabian_bader/status/2057198207243804881
Cisco Secure Worklo
Recommended

megahired.com

Hard Knocks Podcast

The Human-Animal Connection - Pet Life Radio Original

Medicine with Meaning

Infinite Health with Dr. Arasi Maran

Million Dollar Grit

Yours Truly Johnny Dollar Collection

Take Back Your Health®

CrossTalk

National Weather Service - FORT WALTON BEACH AND DESTIN FLORIDA FORECAST - by WARN

Back to the 80s Radio

Doctor Zhivago Slow Read