Handler on Duty: Guy Bruneau
Threat Level: green
Podcast Detail
SANS Stormcast Friday, July 31st, 2026: Pre Botnet Recon; Cisco Backdoor Exploited; Inconsistent Group Chats
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10032.mp3
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner
https://isc.sans.edu/diary/Reconnaissance%20First%3A%20An%20SSH%20Bot%20That%20Sizes%20Up%20Your%20Hardware%20Before%20Deploying%20a%20Miner%20%5BGuest%20Diary%5D/33198
Cisco Secure Firewall Management Center Software Static Credential Vulnerability Exploited CVE-2026-20316
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
Inconsistent Group Chats
https://www.usenix.org/conference/usenixsecurity26/presentation/gegenhuber
https://www.heise.de/en/news/Encrypted-but-wrong-Group-chats-vulnerable-to-manipulated-content-11384112.html
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Application Security: Securing Web Apps, APIs, and Microservices | Las Vegas | Sep 21st - Sep 25th 2026 |
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Apps, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Apps, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 20th 2027 |
Podcast Transcript
Hello and welcome to the Friday, July 31st, 2026 edition of the SANS and at Storm Center's Stormcast. My name is Johannes Ullrich, recording today from Jacksonville, Florida. And this episode is brought to you by the SANS.edu Master's Degree Program in Information Security Engineering. Today we have yet another diary from one of our undergraduate interns. These bachelor's degree students are working with our honeypots to look for new, exciting, interesting events. And well, in this case, Adam Kahn has found kind of an interesting event and that's a little bit more advanced hardware fingerprinting of the honeypot after it was compromised using a weak SSH password. Now typically these honeypots, if the attacker finds them valuable, are often used for crypto coin mining. And that may be the intent of this particular attack as well. A couple of interesting things here. It's looking very carefully at different hardware properties. So, for example, it's looking for an Nvidia video card. Maybe we'll soon see some of these attacks trying to use honeypots for AI training instead of crypto coin mining. It's also looking whether it has more than one gigabyte of RAM and whether the user it's connecting as can actually escalate privileges to root via sudo. So, this is a little bit more detailed fingerprinting than we saw in the past. We have seen sometimes crypto coin miners being deployed on very inadequate systems that didn't really mine any crypto coins. And maybe attackers are getting a little bit more discriminating here just to also attract less attention by hacking multiple devices and building these large botnet fleets that really don't provide any value. Now, these honeypot attacks, they often take advantage of well-known default passwords that are commonly associated with more low-end devices like DVRs and the like. And that's why they are a little bit more discriminating here, trying to find better hardware. Well, maybe they should be going after Cisco equipment. Cisco did patch Warner building their firewall management center. They call it a static user credential that they patched. Others call it a back door. Luckily, it only provides access to a low -privileged user account. But still, it's your firewall management center. So, basically, the software that you are trusting to manage all your firewalls. I'm sure the account is low-level enough where there's absolutely no possibility that any of the about dozen or so Unix and Linux approach escalation flaws apply to the particular operating system here. Cisco has released a patch for this vulnerability, but the vulnerability is also already being exploited in the wild. So, as usual, assume compromise. In particular, if access to the firewall management center is connected to the internet. And a paper going to be presented by several Austrian researchers at an upcoming USENIX security symposium is going to reveal some interesting vulnerabilities in end-to-end encrypted chat systems when it comes to group messages. Now, this is for a change, not a paper that talks about decrypting the messages or anything like that, but instead about how different participants in a group chat may intentionally be served different content. So, the threat is here that a malicious participant in the group chat is, for example, putting up some item for vote and is sending sort of different proposals to different participants in the group chat. And then, of course, everybody agrees to the proposal, but they don't realize that they agreed to very different things. So, the way this works is that there are two ways how group chats work. One is where the message is being sent to a server and then the server distributes these messages to individuals within the group chat. The problem with this, of course, is with end-to-end encryption that sort of puts the server here in a machine in the middle position. So, instead, some chat systems offer the option to send messages to each user individually from the sender. And then, of course, the sender has the option to send different messages to different recipients. As long as the message ID, so the message sequence essentially, is the same, this usually goes undetected according to the paper. Now, the full paper is not public yet. I'll link to the Usenix abstract and also to an article by Heise that does discuss this paper in more detail. Well, and that's it for today. Just the two small items here. There are updates for IBM WebSphere that you probably should take a look at. And then yet another flaw in NGINX, this time in HTTP 3. So, keep an eye for patches for either of these two products. And that's it for today. Thanks for listening. Thanks for subscribing. Thanks for liking this podcast and doing whatever you do in order to get us a couple more listeners. And talk to you again on Monday. Bye. Bye. Bye. Bye. Bye. Thank you.





