Podcast Detail

SANS Stormcast Thursday, September 10th, 2026: Proxmox Scans; MSFT Defender, Gogole Chorme, and FortiPAM Vulns.

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10088.mp3

Podcast Logo
Proxmox Scans; MSFT Defender, Gogole Chorme, and FortiPAM Vulns.
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

Podcast Transcript

 Hello and welcome to the Thursday, September 10th, 2026
 edition of the SANS Internet Storm Center's Stormcast. My
 name is Johannes Ullrich, recording today from
 Jacksonville, Florida. And this episode is brought to you
 by the SANS.edu Graduate Certificate Program in Purple
 Team Operations. In diaries today, I'm writing about some
 brute forcing that I'm seeing more and more against Proxmox
 servers. I think there are two reasons behind this increase.
 First of all, about a week ago, there was like a
 vulnerability being announced in an older version of Proxmox
 and SH sort of authentication bypass of vulnerability. Now,
 again, this was an older version, no longer supported,
 shouldn't really be a big deal, but probably still a lot
 of exposed servers out there. And the second one, I think,
 is that we have more and more users switching away from
 VMware, which was a traditional target when
 attackers were looking for vulnerable virtualization
 systems. Well, now they got Proxmox here to play around
 with. What I'm seeing is not exploitation of a specific
 vulnerability, but essentially just brute forcing. Now,
 Proxmox is pretty good, actually, when it comes to
 sort of different authentication options. You
 have multi-factor authentication, you have pass
 keys. So definitely there are ways to protect yourself
 against brute forcing if you must keep the admin interface
 exposed. Still, you probably don't want to do this. And as
 it has become traditional following Microsoft's Patch
 Tuesday, we of course get nightmare eclipses zero day
 Wednesday. The latest vulnerability here is the
 shield crash, and it's actually not a fundamentally
 new vulnerability. It's shield break, but it does expand this
 older vulnerability to bypass the fix that Microsoft has
 implemented for this. Again, it's always tricky to keep
 these anti-malware systems free from these privilege
 escalation vulnerabilities. And I'm sure we probably have
 a bunch more to come. In one article, I saw that this is
 like the 11th Saturday that Nightmare Eclipse has
 published now. I haven't counted myself, but sounds
 like about the right number. And Google released security
 updates for Google Chrome, fixing a total of 230 security
 fixes. There is one vulnerability that already has
 been exploited in the wild. It's a memory buffer overrun
 in V8, the JavaScript engine. Nothing that special for
 Google Chrome. That's the type of vulnerability that usually
 happens in V8. Now, you still need to break out of the
 sandbox, which typically is another exploit. They didn't
 indicate if the exploits seen in the wild actually are
 taking advantage of any kind of sandbox escape to
 compromise the system outside of the browser. Google also
 indicated they will be shifting their update cycle
 slightly. You'll now get weekly security updates and
 only every other week there will be actually a major
 version update or a feature update being released. And if
 you're using FortiPAM, that's FortiNET's Privilege Access
 Management, then well, you must update pretty quickly
 because there is an interesting vulnerability that
 allows a NetHacker to specify what proxy is being used by
 the Chrome extension. If an NetHacker does so, then all
 requests of the user are being sent to the attacker's proxy.
 There are kind of three pieces to it. First, the attacker
 needs to set up a web listener at a particular URL. That's
 pretty straightforward. Next, they need to send a request to
 the extension, which, well, has an authentication field.
 But if the authentication token, which should be a JWT
 token, is not the right format, so basically just a
 random string, then it's just accepted. So there is no
 failure being used here if you're actually not presenting
 a valid token at all. Finally, there is a pop-up where the
 user is then able to reject the request. But with some
 simple JavaScript, it's possible to auto-approve this
 pop-up. Now, in order to fix this vulnerability, you must
 update the extension, the browser extension, but you
 also must update your FortiPAM server component. So both must
 be updated in order to prevent this problem. Well, and that's
 it for today. There were a couple other things about Palo
 Alto had some updates and a couple others, but really just
 too many vulnerabilities these days. I hope I picked the
 right ones. Also note that on Monday we'll have a major
 Apple update. That's when they're going to release the
 27 versions of their operating systems. Thanks and talk to
 you again tomorrow. Bye.