Podcast Detail

SANS Stormcast Wednesday, September 30th, 2026: Wordfence Scans; MikroTik Vulnerability; Poper Blocker Spyware

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10116.mp3

Podcast Logo
Wordfence Scans; MikroTik Vulnerability; Poper Blocker Spyware
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

Podcast Transcript

 Hello and welcome to the Wednesday, September 30th,
 2026 edition of the SANS Internet Storm Center's Stormcast.
 My name is Johannes Ullrich, recording today from Ottawa,
 Canada. And this episode is brought to you by the SANS.edu
 Graduate Certificate Program in Cyber Defense Operations.
 In today's diary we are seeing in our honeypots some requests
 for wordfence-wav.php. This file is typically associated
 with WordFence, a company that is protecting WordPress
 instances. The way WordFence works is essentially a web
 application firewall that is specifically targeting
 WordPress. WordPress and this file wordfence-wav.php is
 installed as part of its more advanced extended protection
 feature. Now there are a couple reasons why attackers
 may scan for this file. Most likely they are trying to find
 sites that are protected by a wordfence or maybe sites that
 were protected by wordfence in the past. So either way they
 are likely trying to evade the wordfence protection by either
 hitting these sites directly without going through the
 proxy or by maybe targeting sites that used to have
 wordfence installed but are no longer using their service.
 And with that of course they may still be relying on that
 protection. If you have any more insight, if you are using
 wordfence or more familiar with this particular file and
 configuration directives around it, let us know. But
 this file does not actually contain any secrets or
 anything that a nethacker could use to gain an advantage
 over the site other than figuring out that it is
 protected by wordfence. So in these days running an ad
 blocker is sort of a must for many users in particular since
 we have often mentioned how advertisements are being used
 to advertise malicious software. However, not all ad
 blockers are created the same. The am I being pwned blog has
 an interesting post about Popper Blocker. Popper Blocker
 advertised itself as an ad blocker and pop-up blocker but
 instead it's really more spyware. It exfiltrates every
 single URL that you're visiting which may make some
 sense if you consider that it may check whether or not
 they're hosting ads. But in addition to that they're also
 exfiltrating all the chats that you're having with some
 of the top AI tools. So definitely malware or spyware
 and violating Google's own policies about this. More
 details in the blog about what it exactly logs. Now one way
 how it probably makes it past some of the tests being run on
 these plugins before they're being added to the Google Play
 Store is that when you first download it it doesn't really
 do much. It then loads a script that it interprets in
 its own custom scripting language and these additional
 scripts that it loads are actually enabling the spyware
 functionality. Looks like more than two million users have
 downloaded it so far and are amazingly happy with it based
 on the 4.8 star rating.
 I think we got a little bit of weird interesting story about
 a MikroTik and router OS. CISA published an advisory
 with a summary of a new vulnerability in router OS.
 CVE 2026 84 411. This vulnerability is distinct from
 vulnerabilities being associated with the MikroTrick
 vulnerabilities released earlier in September. Problem
 is there is no real advisory like this on the MikroTik
 website. Also CISA states that router OS 7.24 is safe, is
 patched which was released in August. So I can only assume
 that this may be a silently patched vulnerability. It is
 critical because HTTP requests can be used before
 authentication to actually trigger an integer underflow
 and with that unauthenticated remote code execution as root.
 So definitely something that you must have on the radar.
 There is also a long term support version of router OS
 which is not yet on 7.24 so it may be vulnerable. But if
 you're running router OS double check that you're
 running the latest version and maybe double check with MikroTik
Maybe by the time I'm publishing this and you're
 listening to this there is some advisory available from
 MikroTik. Well and that's it for today. Thanks for
 listening. Thanks for liking. Thanks for recommending this
 podcast. Thanks for everybody attending my talk here today
 and talk to you again tomorrow. Bye. Bye.