Handler on Duty: Johannes Ullrich
Threat Level: green
Podcast Detail
SANS Stormcast Wednesday, September 30th, 2026: Wordfence Scans; MikroTik Vulnerability; Poper Blocker Spyware
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10116.mp3
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
Scans for Wordfence Protected Websites
https://isc.sans.edu/diary/Scans%20for%20Wordfence%20Protected%20Websites/33382
MikroTik RouterOS Vulnerability (CVE-2026-84411)
https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06
Poper Blocker: The Adblocker That Spies on You
https://amibeingpwned.com/blog/poper-blocker-the-adblocker-that-spies-on-you
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Eastern | Feb 8th - Feb 12th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 19th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Orlando | Apr 12th - Apr 16th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Mountain | Apr 21st - Apr 25th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Baltimore | May 17th - May 21st 2027 |
Podcast Transcript
Hello and welcome to the Wednesday, September 30th, 2026 edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich, recording today from Ottawa, Canada. And this episode is brought to you by the SANS.edu Graduate Certificate Program in Cyber Defense Operations. In today's diary we are seeing in our honeypots some requests for wordfence-wav.php. This file is typically associated with WordFence, a company that is protecting WordPress instances. The way WordFence works is essentially a web application firewall that is specifically targeting WordPress. WordPress and this file wordfence-wav.php is installed as part of its more advanced extended protection feature. Now there are a couple reasons why attackers may scan for this file. Most likely they are trying to find sites that are protected by a wordfence or maybe sites that were protected by wordfence in the past. So either way they are likely trying to evade the wordfence protection by either hitting these sites directly without going through the proxy or by maybe targeting sites that used to have wordfence installed but are no longer using their service. And with that of course they may still be relying on that protection. If you have any more insight, if you are using wordfence or more familiar with this particular file and configuration directives around it, let us know. But this file does not actually contain any secrets or anything that a nethacker could use to gain an advantage over the site other than figuring out that it is protected by wordfence. So in these days running an ad blocker is sort of a must for many users in particular since we have often mentioned how advertisements are being used to advertise malicious software. However, not all ad blockers are created the same. The am I being pwned blog has an interesting post about Popper Blocker. Popper Blocker advertised itself as an ad blocker and pop-up blocker but instead it's really more spyware. It exfiltrates every single URL that you're visiting which may make some sense if you consider that it may check whether or not they're hosting ads. But in addition to that they're also exfiltrating all the chats that you're having with some of the top AI tools. So definitely malware or spyware and violating Google's own policies about this. More details in the blog about what it exactly logs. Now one way how it probably makes it past some of the tests being run on these plugins before they're being added to the Google Play Store is that when you first download it it doesn't really do much. It then loads a script that it interprets in its own custom scripting language and these additional scripts that it loads are actually enabling the spyware functionality. Looks like more than two million users have downloaded it so far and are amazingly happy with it based on the 4.8 star rating. I think we got a little bit of weird interesting story about a MikroTik and router OS. CISA published an advisory with a summary of a new vulnerability in router OS. CVE 2026 84 411. This vulnerability is distinct from vulnerabilities being associated with the MikroTrick vulnerabilities released earlier in September. Problem is there is no real advisory like this on the MikroTik website. Also CISA states that router OS 7.24 is safe, is patched which was released in August. So I can only assume that this may be a silently patched vulnerability. It is critical because HTTP requests can be used before authentication to actually trigger an integer underflow and with that unauthenticated remote code execution as root. So definitely something that you must have on the radar. There is also a long term support version of router OS which is not yet on 7.24 so it may be vulnerable. But if you're running router OS double check that you're running the latest version and maybe double check with MikroTik Maybe by the time I'm publishing this and you're listening to this there is some advisory available from MikroTik. Well and that's it for today. Thanks for listening. Thanks for liking. Thanks for recommending this podcast. Thanks for everybody attending my talk here today and talk to you again tomorrow. Bye. Bye.





