Handler on Duty: Didier Stevens
Threat Level: green
Podcast Detail
SANS Stormcast Monday, August 24th, 2026: More Entra Powershell; Entra Vulnerability; GitLab Vuln (and PoC); GTA 6 Leak Malware
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10064.mp3
More Entra Powershell; Entra Vulnerability; GitLab Vuln (and PoC); GTA 6 Leak Malware
00:00
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!
https://isc.sans.edu/diary/Who%20Got%20Missed%20in%20the%20MFA%20Rollout%3F%20More%20Powershell%20%2B%20Graph%20%2B%20Entra%20scripting!/33272
Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays
https://isc.sans.edu/diary/Even%20MOAR%20Powershell%2C%20looking%20at%20Entra%20logins%20-%20the%20good%2C%20the%20bad%20and%20the%20password%20sprays/33268
Microsoft Entra ID Remote Code Execution Vulnerability CVE-2026-69836
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836
GitLab Critical Patch Release CVE-2026-19478 CVE-2026-19650
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/
GTA 6 Leak File with Malware
https://x.com/Aidas29506493/status/2091194667073204624
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
Discussion
The Shibboleth vulnerability is quite interesting. In their example, the SAML signature covers the entire and they've made modifications to it (the changes to the uid) that should cause the signature to fail validation. This vulnerability speaks to larger architectural issues with Shibboleth. Obviously the signature validation is happening on a DIFFERENT document (the inline DTD defs are resolved and replaced) than the attribute extraction code works on (the inline DTD variables are not replaced). This is a HUGE no no and leads to the confused deputy issues that caused the vulnerability. I would bet other SP SAML parsing code is making similar mistakes.
Posted by Anonymous on Tue Jan 16 2018, 16:54
Login here to join the discussion.
| Application Security: Securing Web Applications, APIs, and Microservices | Las Vegas | Sep 21st - Sep 25th 2026 |
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 20th 2027 |





