Handler on Duty: Didier Stevens
Threat Level: green
Podcast Detail
SANS Stormcast Monday, September 21st, 2026: HTTP Query; Docker Escape; Brevo ClickFix Attack; LastPass Fake GitHub Repo
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10102.mp3
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
HTTP QUERY Method: The Grey Zone Between GET and POST
https://isc.sans.edu/diary/HTTP%20QUERY%20Method%3A%20The%20Grey%20Zone%20Between%20GET%20And%20POST./33352
Simple MacOS Docker Escape
https://www.accomplish.ai/blog/escaping-dockers-hypervisor/ CVE-2026-77179
Brevo ClickFix Compromise
https://status.brevo.com/incidents/01M2QBC4EZ24ZACW6SWQYVW8N3/write-up
LastPass (and other) lookalike GitHub Repo and Kernel Module Infostealer
https://blog.lastpass.com/posts/lastpass-delphos-report-rapuncel-infostealer
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 19th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Orlando | Apr 12th - Apr 16th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Mountain | Apr 21st - Apr 25th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Baltimore | May 17th - May 21st 2027 |





