Handler on Duty: Johannes Ullrich
Threat Level: green
Podcast Detail
SANS Stormcast Wednesday, July 22nd, 2026: Captive Portals; Critical Serv-U and Zimbra Update; Apple Hide-My-Email fix
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10018.mp3
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
Captive Portal Detection
https://isc.sans.edu/diary/Captive%20Portal%20Detection/33172
Critical SolarWinds Serv-U Update
https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm
Zimbra Update with Critical Security Fixes
https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/
Apple Fixed Hide My E-Mail Leak
https://www.404media.co/apple-fixes-hide-my-email-vulnerability-after-404-media-coverage/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Application Security: Securing Web Apps, APIs, and Microservices | Online | British Summer Time | Jul 27th - Aug 1st 2026 |
| Application Security: Securing Web Apps, APIs, and Microservices | Las Vegas | Sep 21st - Sep 25th 2026 |
| Application Security: Securing Web Apps, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
Podcast Transcript
Hello and welcome to the Wednesday July 22nd, 2026 edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich recording today from Jacksonville, Florida. And this episode is brought to you by the SANS.edu Bachelor's degree program in Applied Cybersecurity. Well today I figured let's move away from WordPress if you are running it if you aren't patched that you're compromised and well with that move on to something well less threat related and that's how different operating systems do detect if they are behind a captive portal. Anybody who has ever used any kind of public Wi-Fi network probably has observed these captive portals some kind of login screen that you have to go through in order to connect to the internet. So to support this very common practice operating systems and browsers have implemented a couple different methods how they are detected if they are behind such a captive portal and then of course also how to direct the user to the correct URL in order to sign in. This traffic sometimes shows up sort of as odd and unexplained traffic in the network because users don't really consciously visit these URLs. It's also HTTP traffic because for the captive portal to then redirect the user well can't be HTTPS because then the certificate check would fail. So summarized here a couple of the URLs being used by the major operating systems as well as Firefox and Chrome who do sort of their own little trick in order to figure out if they are behind such a captive portal. And then we got an interesting update from SolarWinds for their Serv-U product. This update does fix 16 different vulnerabilities. 15 of them so all but one are rated critical with a CVSS score of 9.1. The one vulnerability that I think is particularly interesting is 2026 28304. It's an arbitrary code execution vulnerability. And for all the other vulnerability it states that the user must be like administrator access or must have a domain account or like well nothing like this in this particular vulnerability. So I assume it's unauthenticated and it allows execution of code remotely as root. They're saying the impact is lower for Windows deployments. I'm not really that familiar with Serv-U to know what the difference here is. Obviously there is no root user on Windows. Maybe they have a little bit more privilege separation or such to not become an administrator on Windows. But definitely you must apply this update if you have SolarWinds Serv-U exposed given how quickly attackers are these days developing new exploits. An open source webmail project Zimbra did release a new update to its product. This update fixes a number of interesting security vulnerabilities. The most critical one here is a command injection vulnerability in the SNMP monitoring component. Now in order to be vulnerable you have to actually enable SNMP notifications and this was already disclosed like back in June but now is rolled into this update. I hope you don't allow SNMP in and out of your network but well I've seen worse things happening in the past. So that's I think the first thing you should check and then definitely apply this update. The other updates are a number of cross-site scripting issues which are always interesting and exploitable often for these kind of webmail systems. In particular if the export can be delivered via an email. The other vulnerabilities I don't really consider that extraordinary dangerous because many of them or all the others really require some kind of authenticated access. And a couple of weeks ago I did mention that Apple's Hide My Email system had a vulnerability that leaked the actual user's email address if an oversized email was sent to the Hide My Email address. Well a 404 media who originally reported about this vulnerability now states that the vulnerability has been fixed. Apparently it has already been fixed a couple weeks ago there was no official announcement about this from Apple but 404 media now was able to confirm it's fixed. Well and this is it for today so thanks for listening, thanks for liking, thanks for subscribing and sharing to this podcast and as always talk to you again tomorrow. Bye!





