Handler on Duty: Renato Marinho
Threat Level: green
Podcast Detail
SANS Stormcast Monday, August 31st, 2026: Malware Statistics; PaperCut Update; Watchguard and DLink Patches;
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10074.mp3
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
Some Malicious PE Stats
https://isc.sans.edu/diary/Some%20Malicious%20PE%20Stats/33292
PaperCut Releases Two Preliminary Patches for Exploited Vulnerability
https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/
DLink Vulnerabliities
https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10513
Watchguard Patches
https://psirt.watchguard.com
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Application Security: Securing Web Applications, APIs, and Microservices | Las Vegas | Sep 21st - Sep 25th 2026 |
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 19th 2027 |
Podcast Transcript
Hello and welcome to the Monday, August 31, 2026 edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich, recording today from New York City, New York. And this episode is brought to you by the SANS.edu Graduate Certificate Program in Purple Team Operations. On Friday, Xavier took a look at malicious PE file. These portable ex-tribal files that are commonly used by Windows have the nice advantage of containing quite a bit of metadata in the header. This metadata can then be used in order to figure out, for example, what compiler is being used. Now in the past, Xavier has looked, for example, at statistics of 64 bits versus 32 bit malware. Turns out, still, the vast majority is 32 bits. But that's a kind of logic, given that there is really no big advantage for malware to actually run in 64 bits. As far as the compilers being used and the languages being used, the vast majority does use C, C++ and the standard Microsoft compilers in order to compile the code. Go, Rust, some of these other languages, are still sort of fractions of a percent of the malware that Xavier looked at. So really not significant at this point. Of course, significant maybe in other ways. We have seen some sort of more advanced malware, for example, using Go that in particular does attempt to evade some of the other detection mechanisms that aren't really all that familiar and tuned to malware written in Go. This was a rather large stash of malware that Xavier looked at. Overall, there were something like 23 million files. 600,000 approximately turned out to be valid PE files. These files were retrieved from the Abuse .ch Matter Bazaar. And on Friday, I talked about ongoing exploitation against PaperCut and that there is no real patch available for it. Well, the folks at PaperCut were busy at work over the weekend. They did publish two emergency updates and do recommend that you apply them. So emergency patch release 2 that was published on the 28th is the one that you should have applied by now. But probably the original advice of just disabling access to PaperCut if you can do so or constraining what IP addresses can access PaperCut that is still valid. Still something that you should follow. There are a total of two vulnerabilities that are being addressed here in this patch. The first one is an unsafe dynamic class loading vulnerability. That's sort of a reflective one where the data is being loaded from the database. In order to get that data into the database, the attacker then exploits a second vulnerability and that's an improper access control vulnerability in the web management interface. So those two vulnerabilities work together here to in the end lead to arbitrary code execution on PaperCut and that's what's being currently exploited. And late last week WatchGuard released patches for 27 vulnerabilities. There is one kind of vulnerability that I'm a little bit concerned about and this is a buffer overflow in the Ike-D implementation. So Ike, that's your key exchange for IPsec and pretty much has to be exposed if you're using IPsec and often you're using like a VPN because you can't easily restrict IP addresses. So definitely something to be aware of. It affects Fireware OS. Patches are available. I'm not aware of any exploits out there but something that you do definitely want to patch. And finally we got patches from D-Link for their DIR -X1860 routers. So these patches affect two vulnerabilities that are being addressed here. The first vulnerability is pretty interesting. It's an unauthenticated administrator password modification. Now it does require that the attacker has access to the JSON RPC interface which shouldn't be of course exposed. The second one is a wireless configuration information disclosure. So that could affect any passwords and such that you need for Wi-Fi access. Definitely I would consider the first one to be the critical one here. And like I said, just make sure that you please don't expose this stuff to the world. Well and this is it for today. So thanks for listening. Thanks for liking. Thanks for recommending this podcast. As always you can find links to classes I'll be teaching in the near future in the show notes. So thanks and talk to you again tomorrow. Bye. Bye.





