Handler on Duty: Rob VandenBrink
Threat Level: green
Podcast Detail
SANS Stormcast Thursday, August 20th, 2026: Cloud Metadata Scans; Oracle and Netscaler Patches; Fake Ransomware Rescuers
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10060.mp3
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
Simple Scans for Cloud Metadata Service
https://isc.sans.edu/diary/Simple%20Scans%20for%20Cloud%20Metadata%20Service/33260
Oracle Critical Security Patch Update Advisory - August 2026
https://www.oracle.com/security-alerts/cspuaug2026.html
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939
Beware of Ransomware Rescuers
https://www.guidepointsecurity.com/blog/beware-ransom-busters/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Application Security: Securing Web Apps, APIs, and Microservices | Las Vegas | Sep 21st - Sep 25th 2026 |
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Apps, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Apps, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 20th 2027 |
Podcast Transcript
Hello and welcome to the Thursday, August 20th, 2026 edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich, recording today from Jacksonville, Florida. And this episode is brought to you by the SANS.edu graduate certificate program in cyber defense operations. Today I wrote about a scan that we are seeing lately and actually a few thousand events related to this scan that probes cloud metadata services via server -side request forgery. Cloud metadata services, they are implemented in all big cloud providers. You also are being used to basically have a simple REST-based interface that provides metadata about the system, like for example, MAC addresses and the like, but it can also provide credentials and that's what attackers are usually after. And based on the URL, yes, this attacker here as well. The question with this particular attack is what vulnerability they are targeting. The attack looks like a textbook server-side request forgery, just URL equals and then the URL they're trying to access. It's possible that there's popular software that is vulnerable to this sort of the most straightforward server-side request forgery, but it might be maybe more sort of a little bit of phishing expedition trying to find vulnerable systems that may just use some demo software or where a developer maybe just experiment a little bit with sort of URL fetching of particular data and they're just hunting for that. But if anybody has any insight as to the specific vulnerability they may be looking for, please let me know. And Oracle released its Credible Security Patch update for August. This update fixes 943 different vulnerabilities across 75 different products. Now, a while ago, Oracle sort of changed its patch release cycle. In addition to the quarterly Credible Patch update, we now have the Critical Security Patch update once a month. The last Credible Patch update had something like 1400 different vulnerabilities being addressed. The last security patch update was only sort of around 300. So we certainly see an increase here. However, it's across 75 different products. The one product that I sort of noted is the Fusion Middleware. That's something that we have seen being exploited in the past. So certainly one of those products to pay attention to. And it had one vulnerability with a CVSS score of 10 and then several looked like a couple dozen or so with 9.9 and 9.8 CVSS scores. So that's certainly something that you probably want to prioritize if you are running it in your environment. Well, we haven't heard from Citrix in a while, but yes, we do have a new advisory here that's noteworthy. This advisory fixes two vulnerabilities in Netscaler ADC as well as Netscaler Gateway. The first vulnerability is a memory overflow vulnerability. Well, as I say, it leads to unpredictable behavior or denial of service. I'm not sure if unpredictable behavior also includes some kind of remote code execution, but they rate it with a CVSS score of 8.8. The second vulnerability looks more interesting. It's a path traversal vulnerability that can lead to authentication bypass and is scored with 9.3. Now for this vulnerability to be actually exploitable, you must configure your gateway as a gateway. So something like the SL VPN or a proxy has to be enabled. Definitely get this addressed. Like I said, we have had a lot of interest from ransomware actors and such in vulnerabilities against the Citrix gateways in the past. So definitely make sure you get this patched. And GuidePoint Security published a blog post with an interesting new way how ransomware actors are operating. Apparently what's happening here is that after a company is affected by ransomware, a recovery company is reaching out to them, in particular a recovery company called Ransom Busters, assisting in actually negotiating the ransomware payment or recovery from the ransomware. Since this contact issue happens before anything about the particular attack has become public, they assume that it's the ransomware actor himself reaching out here. And I think it should be somewhat obvious also to the victim here that this contact is coming from someone affiliated with the ransomware actor. In my opinion, this may be a little bit a trick on the side of ransomware actors to essentially allow companies, allow victims to pay the money without actually paying a ransom. Because in this case, they're just paying a consulting fee and they're getting their keys back because Ransom Busters apparently knows how to recover the encryption keys. And they're then able to decrypt their data. Well, and that's it for today. So thanks for listening. Thanks for liking this podcast. Thanks for recommending it. Thanks for any feedback you may have and talk to you again tomorrow. Bye.





