Handler on Duty: Renato Marinho
Threat Level: green
Podcast Detail
SANS Stormcast Wednesday, August 12th, 2026: Microsoft Patch Tuesday; Zoom Vulnerabilities; Mozilla Revokes Key; Rogue Inflight Wifi
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10048.mp3
Microsoft Patch Tuesday; Zoom Vulnerabilities; Mozilla Revokes Key; Rogue Inflight Wifi
00:00
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20August%202026/33236
Zoom Vulnerablities CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415
https://a.security/blog/asecurity-zoomsday
Mozilla Revokes GPG Key
https://blog.mozilla.org/security/2026/08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/
Rogue Inflight Wifi
https://www.bleepingcomputer.com/news/security/delta-probes-wi-fi-deauth-attack-on-flight-carrying-def-con-attendees/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Application Security: Securing Web Apps, APIs, and Microservices | Las Vegas | Sep 21st - Sep 25th 2026 |
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Apps, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Apps, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 20th 2027 |
Podcast Transcript
Hello and welcome to the Wednesday, August 12, 2026 edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich, recording today from Jacksonville, Florida. This episode is brought to you by the SANS.edu Graduate Certificate Program in Industrial Control Systems Security. Well, Microsoft patched Tuesday and imagine that it was another massive patch Tuesday. Now, not quite as bad as last patch Tuesday. In July, we had something over 600 different vulnerabilities being addressed. This time, it's only 400 approximately. I've seen a couple different numbers. Depends on how you count exactly which vulnerabilities you include. 62 of these vulnerabilities are critical. One is already being exploited in a while and two were publicly disclosed, but haven't yet seen in the wild according to Microsoft. Now, I thought a little bit about how to summarize this. I will actually not start with the disclosed and already exploited vulnerabilities because in some ways, I don't think that's really the story here. There are really two vulnerabilities that I think should be at the top of your list and that's the critical vulnerabilities in the DNS server. There are four critical vulnerabilities. DNS servers tend to be more exposed. So that's why I would give them sort of the highest priority and these are remote code execution vulnerabilities. Followed by the critical vulnerability in the DHCP server. DHCP server typically only exposed on the local network. So that's why I give that a little bit a lower priority. And we have sort of the rest of the critical vulnerabilities are pretty concentrated in some common and well-known problem, a piece of software, Office, SharePoint, and RDP. So apply these patches just like you always do. There's nothing really that different. There are more vulnerabilities, but overall the patch process shouldn't really be that affected by it. And we also have an interesting critical vulnerability in quick, the new transport layer protocol. And that one, I have probably the hardest time right now sort of really guessing, you know, how severe this one is, how likely it is going to be exploited, but definitely would put it here on the list of things to patch. Now, as far as the already exploited vulnerability goes, this is a Windows container isolation issue. I don't really see it as sort of, you know, top of the list as far as criticality goes. The already known ones, the one that really kind of stuck out here was the vulnerability that's known as Legacy Hive. I talked about it, I think, last week when it sort of was disclosed. It essentially allows privilege escalation. It's one of these nightmare eclipse vulnerabilities. So definitely, you know, address this one, but it's just a privilege escalation vulnerability, which probably, you know, we have tons more to worry about. So that's why I give that really not sort of the big emphasis that we usually give these already disclosed, already exploited vulnerabilities. So in short, yes, a lot of vulnerabilities, patch them, that's really the only thing you can do, the only thing that you should do. And there's nothing here, other than maybe the DNS vulnerability, where I sort of would really sort of emphasize speed on patching, go through your process, and hopefully, you know, we're able to shrink that down enough, so you'll be done with these updates by the time the next patch Tuesday comes around. And I'm pretty sure by then, you know, Microsoft will just say, hey, they're done patching them. And at least as interesting as Microsoft vulnerabilities are three vulnerabilities that were patched in Zoom. These are three memory allocation vulnerabilities that allow for full remote code execution. In order to exploit this vulnerability, the attacker and the victim have to join the same Zoom call. So the attacker would essentially then send the exploit traffic to the victim and achieve remote code execution. So patches are available, but also an exploit, at least the draft, proof of concept, whatever you want to call it, of an exploit. A security, the company that found this vulnerability has a very detailed blog post with details how to exploit this vulnerability. So while I don't think they really release of a full working exploit, there's enough information here to develop an exploit if someone is halfway skilled in doing so. And again, all platforms are affected. The exploit they're discussing here in their blog is actually for macOS, but Windows, Android, iOS, they say whatever platform runs Zoom is potentially vulnerable. And Mozilla announced yesterday that they revoked the signing key used to create GPG signatures for Firefox and Thunderbird. Apparently, the secret key was accidentally committed to a private GitHub repository. While private GitHub repositories are supposed to be private, well, they're not really secure enough to leave a cryptographic key like this in the repository. So they did the right thing and revoked the key. The problem now becomes, well, when do you actually need the key? So who does this affect? It's really mostly Linux users, I would expect. It does affect RPM packages. So if you're using a distribution that uses RPM, then you are affected. If you are downloading Linux tarballs, basically source packages, then you are affected because then you may manually validate the signatures of these tarballs that you're downloading. So that's really sort of the only groups that are affected by this particular problem. If you are affected, well, there is, of course, an updated key available. The old key would have expired in about seven months, I think they said. That thing was like March next year or so is when they were supposed to release a new key anyway. But that's still far enough out where you probably don't want to go without patches for that time in particular in software like Firefox and Thunderbird. Well, a group of individuals apparently returning from DEF CON yesterday did cut some of the ethics talks a little bit short and sort of got caught up in the excitement. But either way, they couldn't help themselves and launched a DEAuth attack on a Delta flight against the in-flight wireless. I usually don't really talk a lot about just opinions and such, but some of the comments I've seen online provoked me kind of to say a little bit more about this particular incident. In information security, there are a lot of laws, a lot of regulations and compliance and such, but there's sort of one rule of his quality, don't be an a-hole rule. And these individuals certainly violated it. So regardless of what you think about skills that are really not required to launch an attack like this, they really just made their life and the life of others harder. They didn't learn anything from this attack and nobody exposed to the attack really learned anything. What we may have learned is that actually in-flight WiFi is monitored a little bit better than we thought and Delta did respond to the attack fairly quickly. They disabled the in-flight WiFi, which of course, given the short response time and such, is probably the right and only thing they could do. And the flight was then created by law enforcement as it arrived in Atlanta. So if you got any neat toys while you were at DEFCON or if you're ordering them now because you saw them being advertised in a particular talk or so at DEFCON, remember it's always nice to play, but don't hurt anybody else. I think this particular these days a little bit difficult for some people because we see all these AI models that really are behaving grossly irresponsible. And look at it this way, you know, you may not be a better hacker than OpenAI or Anthropic or I think Kimi was it today, but you can be better human and try to see it that way. And don't cause more pain for innocent bystanders. Well, and this is it for today. So thanks for listening. Thanks for liking. Thanks for recommending this podcast and talk to you again tomorrow. Bye. Bye. Okay. Thank you.





