Podcast Detail

SANS Stormcast Monday, August 24th, 2026: More Entra Powershell; Entra Vulnerability; GitLab Vuln (and PoC); GTA 6 Leak Malware

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10064.mp3

Podcast Logo
More Entra Powershell; Entra Vulnerability; GitLab Vuln (and PoC); GTA 6 Leak Malware
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

Podcast Transcript

 Hello and welcome to the Monday August 24th, 2026
 edition of the SANS Internet Storm Center's Stormcast. My
 name is Johannes Ullrich, recording today from
 Jacksonville, Florida. And this episode is brought to you
 by the SANS.edu Bachelor's degree program in Applied
 Cybersecurity. Well, on Friday, we got two more
 diaries from Rob showing how to interface PowerShell with
 EnteraID and how to better collect and summarize some of
 the events that you are getting out of EnteraID's
 logging. First one is about multi factor authentication.
 So the goal here is after you set up and configured multi
 factor authentication and rolled it out, well, to make
 sure that you really rolled it out completely and to look in
 any gaps, any accounts and such that are not yet using
 multi factor authentication. So really useful to identify
 these kind of lagging accounts and hopefully get them up to
 compliance fairly quickly. The second issue here is looking
 at the Entera logins. And this is like failed as well as
 valid logins, and then basically enrich that data
 with additional details. Like for example, IP addresses, the
 country the login came from, again, looking for some
 suspicious logins. On Thursday, Rob wrote a similar
 script where it was about the risk factor of particular
 logins. So this is sort of more universal and then you
 define kind of your own risks and your own cautions, which
 can work quite well if your organization, for example, is
 more geographically focused. If users usually log in from
 company systems via VPNs and such, then this will become
 quite useful. When talking about Microsoft's Entera ID
 product, on Thursday, Microsoft did publish a
 bulletin indicating that they did patch remote code
 execution vulnerability in Entera ID. This was a
 deserialization vulnerability. Now, what originally sort of
 caused some confusion was that Microsoft had marked this
 vulnerability as already being exploited. Later, they
 reversed this and they're announcing it has not yet been
 exploited. It's a deserialization vulnerability.
 So exploitation wouldn't necessarily be sort of out of
 the question for a vulnerability like this if an
 external entity discovered this vulnerability. But yes,
 right now, it doesn't look like it already was exploited.
 Now, there's nothing you need to do that affected
 Microsoft's own systems. They are and they have done this
 repeatedly in last year or so, been more transparent about
 vulnerabilities like this in their cloud software where
 they are publishing CVE numbers and bulletins just
 like for any sort of customer run software vulnerability.
 And this is just another case of this critical
 vulnerability. Microsoft patched it. So hopefully they
 caught this before it was actually exploited
 successfully. And then we do have an update for GitLab.
 This fixes two vulnerabilities. The first one
 is an interesting one. It's a code injection issue via
 GraphQL directive. This allows an unauthenticated attacker to
 delete or modify repositories. The modification part here is,
 of course, particularly tricky that could, I guess, lead them
 to sort of a full supply chain attack. The second one is a
 cross-site request forgery. Well, I talked a little bit
 about these type of attacks last week. And certainly don't
 underestimate them, but this one is less severe. Now, for
 the code injection issue, there is also proof of concept
 exploit code available. Definitely make sure if you're
 running GitLab on-prem that you're patching this. Well,
 and if you're at all involved in online gaming, you may have
 heard about the leak of Grand Theft Auto VI, the latest
 release of this game. And apparently there is currently
 an archive going around 113 gigabytes in size, which is a
 reasonable size for a game like this. But this archive
 does come with additional goodies in the form of
 malware. It's a very typical technique. And again, if you
 are involved in online gaming, you probably have seen this
 before, where either sort of jailbreaks or cheat codes or
 any kind of sort of gaming related software is often
 distributed with a malware attached to it. So be careful
 what you download and maybe wait for the official release
 of the game. Well, and that's it for today. So thanks for
 listening. Thanks for liking. Thanks for subscribing. And
 talk to you again tomorrow. Bye.
 Bye.