Handler on Duty: Didier Stevens
Threat Level: green
Podcast Detail
SANS Stormcast Monday, September 28th, 2026: Macfinger Details; NetScaler 0-Day; KiteWorks 0-Day; ShinyHunters and PeopleSoft
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10112.mp3
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
A Closer Look at Malware From the Macfinger ClickFix Campaign
https://isc.sans.edu/diary/A%20Closer%20Look%20at%20Malware%20From%20the%20Macfinger%20ClickFix%20Campaign/33368
Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778
https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/
KiteWorks Urges Customers to Shut Down Servers
https://www.heise.de/en/news/Imminent-Zero-Day-Attack-KiteWorks-Urges-Customers-to-Shut-Down-Servers-11466375.html
ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft
https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Eastern | Feb 8th - Feb 12th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 19th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Orlando | Apr 12th - Apr 16th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Mountain | Apr 21st - Apr 25th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Baltimore | May 17th - May 21st 2027 |
Podcast Transcript
Hello and welcome to the Monday, September 28th, 2026 edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich, recording today from Jacksonville, Florida. And this episode is brought to you by the SANS.edu Undergraduate Certificate Program in Cybersecurity Fundamentals. On Friday, Brad posted a diary that's a follow-up to a diary he actually posted a couple days earlier. That diary dealt with the MacFinger ClickFix campaign and back then Brad identified the eventual payload being installed as the Atomic macOS dealer or AMOS. Well, it turns out that this wasn't quite right or at least Brad isn't certain if it was this particular Steeler or maybe a new variant of it or maybe something somewhat different that sort of took some inspirations from AMOS Steeler. A couple differences here that Brad points out is that this Steeler, for example, does use WebSocket in order to exfiltrate data. Another sort of little odd thing about this Steeler is that it comes in two versions. It comes in the ARM and the x86-64 version. It does not come as a unified binary that you could use in macOS in order to essentially support both architectures. Well, the attacker then also exfiltrates data via post requests, but the bulk of the command control appears to be happening via the WebSocket connection, which may be done to evade some data leakage protection products. Well, if you need more details, indicators of compromise, specifically to the InfoSteeler that was detected here, please refer to Brad's diary. Well, the big story this weekend was certainly the exploitation of two unpatched vulnerabilities in Citrix Netscaler ADC and Citrix Netscaler Gateway. This originally sort of emerged as sort of a rumor on Friday. Apparently, an information security agency in the Netherlands did advise its constituency to turn off any Citrix Netscalers on Sunday. Citrix then released a patch fixing a total of eight vulnerabilities and stating that two of these vulnerabilities, both remote code execution vulnerabilities, are currently being exploited. The other six vulnerabilities aren't really all that harmless either. So if you have, for example, HTTP request smuggling, which then could be used to essentially attack systems behind Citrix Netscaler. Also, feature policy bypass due to improper HTTP URL-based expression usage. This is the lowest one according to CVSS score with 7.0. But we have a few 8.8 ones, including one that's sort of interesting here. Yeah, there is a TCP initial sequence number prediction of vulnerability. Now, in this case, you need to have the TCP configuration enabled in Netscaler ADC or Netscaler Gateway again. So get these patched, get these patched quickly. I don't want to recommend anybody just turn off Netscaler just because I know that these are usually systems that protect a number of different web applications and like. So disabling them is probably going to cause some significant disruption of your business. But on the other hand, ransomware is going to disrupt your business too. So carefully, way off the pros and cons here. And yes, definitely, this is a patch that you probably want to rush out if you're using Citrix Netscaler. And talking about shutting down servers, Kiteworks urged its customers to shut down servers on Saturday. So yes, this news is coming a bit late. But if you didn't get the message, you may want to check in with Kiteworks to see what exactly happened there, because I couldn't really find a lot of details. The main source here is Heise.de, the German IT news outlet. They got a hold of an email that Kiteworks sent to customers. And yes, it specified a very specific six hour window on Saturday where you should shut down your Kiteworks server. Again, this is a secure messaging platform. So certainly a critical piece of IT infrastructure. Kiteworks did state to Heise that this was due to a zero day attack. Now I'm not sure how shutting it down for six hours is supposed to help here, whether or not there was a patch deployed afterwards. I didn't found an indication for this. But again, this may have just been communicated to customers directly and not via any public channels. So please double check with Kiteworks. And Mandiant is reporting that Shiny Hunters continues to target Oracle PeopleSoft. And they're targeting June 2026 vulnerability. But they are now bypassing web application firewalls. So remember, if you're using a web application firewall to protect yourself from exploitation, it's usually time limited protection attackers will find ways around it. And the workaround here appears to be pretty straightforward and simple, where they're just URL encoding one of the letters in the URL, something that actually most web application firewalls that I'm aware of should be able to handle. But apparently there are sufficient number of firewalls that don't. And that leads sort of to a renewed search of exploitation of PeopleSoft by Shiny Hunters. Well, and this is it for today. So thanks for listening. Thanks for liking. Thanks for recommending this podcast. As always, special thanks for leaving good comments on your favorite podcast platform. And that's it for today. And talk to you again tomorrow. Bye.





