Handler on Duty: Rob VandenBrink
Threat Level: green
Podcast Detail
SANS Stormcast Monday, August 24th, 2026: More Entra Powershell; Entra Vulnerability; GitLab Vuln (and PoC); GTA 6 Leak Malware
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10064.mp3
More Entra Powershell; Entra Vulnerability; GitLab Vuln (and PoC); GTA 6 Leak Malware
00:00
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!
https://isc.sans.edu/diary/Who%20Got%20Missed%20in%20the%20MFA%20Rollout%3F%20More%20Powershell%20%2B%20Graph%20%2B%20Entra%20scripting!/33272
Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays
https://isc.sans.edu/diary/Even%20MOAR%20Powershell%2C%20looking%20at%20Entra%20logins%20-%20the%20good%2C%20the%20bad%20and%20the%20password%20sprays/33268
Microsoft Entra ID Remote Code Execution Vulnerability CVE-2026-69836
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836
GitLab Critical Patch Release CVE-2026-19478 CVE-2026-19650
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/
GTA 6 Leak File with Malware
https://x.com/Aidas29506493/status/2091194667073204624
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Application Security: Securing Web Applications, APIs, and Microservices | Las Vegas | Sep 21st - Sep 25th 2026 |
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 20th 2027 |
Podcast Transcript
Hello and welcome to the Monday August 24th, 2026 edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich, recording today from Jacksonville, Florida. And this episode is brought to you by the SANS.edu Bachelor's degree program in Applied Cybersecurity. Well, on Friday, we got two more diaries from Rob showing how to interface PowerShell with EnteraID and how to better collect and summarize some of the events that you are getting out of EnteraID's logging. First one is about multi factor authentication. So the goal here is after you set up and configured multi factor authentication and rolled it out, well, to make sure that you really rolled it out completely and to look in any gaps, any accounts and such that are not yet using multi factor authentication. So really useful to identify these kind of lagging accounts and hopefully get them up to compliance fairly quickly. The second issue here is looking at the Entera logins. And this is like failed as well as valid logins, and then basically enrich that data with additional details. Like for example, IP addresses, the country the login came from, again, looking for some suspicious logins. On Thursday, Rob wrote a similar script where it was about the risk factor of particular logins. So this is sort of more universal and then you define kind of your own risks and your own cautions, which can work quite well if your organization, for example, is more geographically focused. If users usually log in from company systems via VPNs and such, then this will become quite useful. When talking about Microsoft's Entera ID product, on Thursday, Microsoft did publish a bulletin indicating that they did patch remote code execution vulnerability in Entera ID. This was a deserialization vulnerability. Now, what originally sort of caused some confusion was that Microsoft had marked this vulnerability as already being exploited. Later, they reversed this and they're announcing it has not yet been exploited. It's a deserialization vulnerability. So exploitation wouldn't necessarily be sort of out of the question for a vulnerability like this if an external entity discovered this vulnerability. But yes, right now, it doesn't look like it already was exploited. Now, there's nothing you need to do that affected Microsoft's own systems. They are and they have done this repeatedly in last year or so, been more transparent about vulnerabilities like this in their cloud software where they are publishing CVE numbers and bulletins just like for any sort of customer run software vulnerability. And this is just another case of this critical vulnerability. Microsoft patched it. So hopefully they caught this before it was actually exploited successfully. And then we do have an update for GitLab. This fixes two vulnerabilities. The first one is an interesting one. It's a code injection issue via GraphQL directive. This allows an unauthenticated attacker to delete or modify repositories. The modification part here is, of course, particularly tricky that could, I guess, lead them to sort of a full supply chain attack. The second one is a cross-site request forgery. Well, I talked a little bit about these type of attacks last week. And certainly don't underestimate them, but this one is less severe. Now, for the code injection issue, there is also proof of concept exploit code available. Definitely make sure if you're running GitLab on-prem that you're patching this. Well, and if you're at all involved in online gaming, you may have heard about the leak of Grand Theft Auto VI, the latest release of this game. And apparently there is currently an archive going around 113 gigabytes in size, which is a reasonable size for a game like this. But this archive does come with additional goodies in the form of malware. It's a very typical technique. And again, if you are involved in online gaming, you probably have seen this before, where either sort of jailbreaks or cheat codes or any kind of sort of gaming related software is often distributed with a malware attached to it. So be careful what you download and maybe wait for the official release of the game. Well, and that's it for today. So thanks for listening. Thanks for liking. Thanks for subscribing. And talk to you again tomorrow. Bye. Bye.





