Handler on Duty: Johannes Ullrich
Threat Level: green
Podcast Detail
SANS Stormcast Thursday, July 23rd, 2026: Rondo and Geoserver; Oracle Patches; Checkpoint 0-day; OpenAI vs Huggingface
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10020.mp3
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
Rondo Meets Geoserver
https://isc.sans.edu/diary/Rondo%20Meets%20Geoserver/33176
Oracle July Patch Update
https://www.oracle.com/security-alerts/cpujul2026.html
OpenAI and Hugging Face partner to address security incident during model evaluation
https://openai.com/index/hugging-face-model-evaluation-security-incident/
Checkpoint July 2026 Security Advisory (CVE-2026-16232)
https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Application Security: Securing Web Apps, APIs, and Microservices | Online | British Summer Time | Jul 27th - Aug 1st 2026 |
| Application Security: Securing Web Apps, APIs, and Microservices | Las Vegas | Sep 21st - Sep 25th 2026 |
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Apps, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Apps, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 20th 2027 |
Podcast Transcript
Hello and welcome to the Thursday, July 23rd, 2026 edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich, recording today from Jacksonville, Florida. And this episode is brought to you by the SANS.edu undergraduate certificate program in Applied Cybersecurity. Going over our web honeypot logs today, I saw two things that I talked about in the past, the first time at least I've seen them together, and that's GeoServer and the Rondo Botnet. Now GeoServer is one of those big Java applications that helps you process geolocation data. It's often used for geographic information systems to essentially prepare maps for various purposes. I don't think there are a ton of them exposed on the internet, but I guess sufficient systems that they are worthwhile scanning by those botnets. The vulnerability being attacked here is an older one. 2024 is when that vulnerability was originally made public. It's an expat expression evaluation issue. Now, the botnet that's scanning for it is the Rondo botnet. And Rondo is sort of one of those, I would say a little bit old-fashioned, funny kind of botnets. It has this Chicago rap theme to it. And if you're currently going to the website where it originally pulled down the bash script, well, you're getting sort of the typical for this botnet sort of advertisement for this Chicago rapper. No idea how they're related. If it's just a fan that wrote the botnet or how this exactly happened. But yes, of course, the site is still compromised because it now hosts that video. So sometimes these botnets, if you're not requesting the file from an IP address that's currently being scanned, well, you're getting different responses back. There's also sort of that little HTML comment on the top. You won't find it here. So I guess maybe that's directed at people like me that would like to get the SH file that's supposed to be downloaded. Well, after getting more than 400 vulnerabilities patched in the Linux kernel late last week, today we got the July critical patch update from Oracle. Now, even after changing their patch cycle from quarterly to monthly, well, we see AI doing its work here. And we got patches for 1,449 different vulnerabilities. Now, this being Oracle, of course, there are many, many different products involved in this particular update. I noticed quite a few updates for JD Edwards. So if you're running that, that may be of interest. And then also a lot of updates for some of the sort of Oracle Commerce, Oracle Communications Cloud products. So definitely you have to also check, you know, which components here you have installed. There's really too much here to sort of go over every single patch that, or even sort of do a summary that does it somewhat justice. And the one patch or the one vulnerabilities have stuck out to me was a 9.9 vulnerability in Oracle's database. So this is just the straightforward Oracle database. Definitely something to take a close look at if you are running Oracle database. Well, and then we got a little bit, sort of resolution from OpenAI. What exactly happened in the hugging face case? So according to OpenAI, they did test their latest model, GPT-5 .6 Sol. And the intent was to test it against an internal benchmark inside a sandbox. And apparently the model escaped and then decided to attack hugging face. Now, I don't see hugging face as a competitor to OpenAI in any way. So I don't think it was an attack against the competitor. To me, this sounds very much like a publicity stunt and that this escape was maybe not all that accidental, given how much sort of press Anthropic got with their fatal model and some of the exploit discoveries around that. Maybe OpenAI wanted to do a little bit better and did sort of that escape from the jail in order to attack another AI related website. Checkpoint released its July security advisory. Now, they're stating that they're also using AI in order to find vulnerabilities. They're patching three vulnerabilities here, at least three that they're listing. But they also state that they applied various hardening techniques and such that are not necessarily sort of pointed out as vulnerabilities. They're calling this a jumbo patch and it applies to the firewall product as well as to their admin console products. Now, there's one vulnerability here that's worth pointing out. It's an authentication bypass with a smart console login. This has a CVS score of 9.3 and is already exploited in the wild. They're saying there was a handful of customers that was affected by this. I'm not sure how many customers fit into a hand. But anyway, definitely do apply it. And now, given that the patch is out and of course the patch will be diffed and there's already an exploit available. Probably won't take too long to see more widespread exploitation of this vulnerability. Well, and this is it for today. So thanks for listening. Thanks for liking. Thanks for subscribing and talk to you again tomorrow. Bye. Bye. Bye. Bye.





