Handler on Duty: Brad Duncan
Threat Level: green
Podcast Detail
SANS Stormcast Friday, September 25th, 2026: Tricky Phishing URL; MacSync Malware Update; SolarWinds Observable Patch
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10110.mp3
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
One URL, Three Different Tricks
https://isc.sans.edu/diary/33366
Send GitLab an email, push to main
https://www.aikido.dev/blog/gitlab-email-push-to-main
macOS MacSync Malware Update
https://securelist.com/macsync-new-version/121383/
SolarWinds Observability Self-Hosted 2026.2.3
https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/hco_2026-2-3_release_notes.htm
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Eastern | Feb 8th - Feb 12th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 19th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Orlando | Apr 12th - Apr 16th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Mountain | Apr 21st - Apr 25th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Baltimore | May 17th - May 21st 2027 |
Podcast Transcript
Hello and welcome to the Friday, September 25th, 2026 edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich, recording today from Las Vegas, Nevada. And today's episode is brought to you by the SANS.edu Graduate Certificate Program in Industrial Control Systems Security. First story comes from Xavier. Xavier looked at, well, an interesting phishing email with a URL that as Xavier analyzed it uses three different tricks. Now, first of all, it uses the good old user info field, which has often been abused in phishing. It's where in old style browsers, you were able to prefix a URL with a username and a password. These days, they should pretty much be ignored, but well, still works in the sense that you still end up at the actual URL that follows that username. Now, the first trick here that the attacker used was to make the username password part actually unique to the particular email. So that makes filtering a little bit more difficult. Also, the host name is actually invalid. The first label of the host name ends in two dashes. Well, host names or labels cannot end in two dashes or dashes at all, according to the RFC. But as so many things, it will just work. In the end, of course, we do have the email address that the particular phishing attack went to, which will then be used in order to pre fill any phishing page with the right email address and often things like logos for the particular trusted domain. So it's an interesting URL being used here, something that definitely can be blocked, but may not be blocked because, well, it may not be recognized even as a valid URL, or may be wrongly characterized as the trusted host name, not the one that the attacker is actually using, due to the use of multiple ad symbols in the URL. Well, in second day in a row that we have a story from aikido. This particular story affects GitLab. And while maybe technically not a vulnerability, it's certainly a significant weakness. GitLab allows you to configure an email address that can be used to send various requests to your GitLab repositories. Now the trick with these email addresses is that they include a secret, basically a random string, that is the only thing that really authenticates these email addresses. What makes the thing even worse is that, well, these email addresses have wide reaching permissions. Now the email address ends, for example, with dash issue, which would allow you to add an issue. But by changing this suffix, different features are available to anybody who knows the secret string. How would an attacker learn about the email address and the secret string? Well, apparently, according to aikido, some users of GitLab may not properly understand the power of these email addresses. And it may be sounding benign to the user to provide, for example, as part of a readme, an email address with the dash issue suffix to their customers in order to allow them to easily report issues with the application. On the other hand, it's pretty straightforward to then change the suffix to other features that are available via via these email addresses, like, for example, push or merge requests with the email address, just by sending a simple email to the particular address. Apparently, it's not possible to limit the from address, which wouldn't be all that strong anyway, but still a little bit better, or apply other restrictions to the addresses once they are defined. And Kaspersky found a new version of the Mac sync malware. Now, this malware typically spreads via click fix exploits, but has also been found to impersonate, for example, crypto coin wallets. One particular case, the attacker even set up a complete webpage for the crypto coin wallet application to make it look more legit. Now, where things get a little bit different now is, and I think that's the most interesting part of this, that the part of the payload is actually retrieved via the iCloud calendar. So by retrieving and syncing calendar entries, the payload is being retrieved to the system. And the other part of the Mac sync is that it is not the same as the main thing that you typically find in organizations. And even on the host of endpoint defenses, it may even evade some of the techniques that they're using, because well, it never really sort of is received via the network, at least not in a visible way. The other part that changed with Mac sync is that it now uses binaries, compiled Objective C or Swift code, and no longer just uses scripting languages. And SolarWinds released update for SolarWinds observability. So if you're self hosting this product, you may want to consider updating. Now, both vulnerabilities are remote code execution vulnerabilities. Neither of the vulnerabilities does require authentication. However, one requires specific insecure, so known insecure configuration that's not default. The other one does require specific communication modes to be enabled. I would still try to get this patch that just in case that a configuration changes later, wouldn't really rely on just running the right not vulnerable configuration from protecting you here in the longer term. Well, and that's it for today. So thanks again for listening. Thanks for liking. Thanks for subscribing. Thanks for leaving good comments about this podcast in your favorite podcast platform. And talk to you again on Monday. Bye.





