Handler on Duty: Jan Kopriva
Threat Level: green
Podcast Detail
SANS Stormcast Thursday, September 17th, 2026: Hospitality Scans; Cisco, Acronis, and Pixel 0-Day; Dynamic Incident Response
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10098.mp3
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
Scans Targeting Hospitality Applications
https://isc.sans.edu/diary/Scans%20Targeting%20Hospitality%20Applications/33344
Cisco Identity Services Engine Authentication Bypass Vulnerability CVE-2026-76460
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5
Acronis Local privilege escalation due to insecure file permissions CVE-2026-87886
https://security-advisory.acronis.com/advisories/SEC-10986
Pixel Update Bulletin—September 2026
https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01
Dynamic Incident Response (Free E-Book)
https://dynamicincidentresponse.com
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Application Security: Securing Web Applications, APIs, and Microservices | Las Vegas | Sep 21st - Sep 25th 2026 |
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 19th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Orlando | Apr 12th - Apr 16th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Mountain | Apr 21st - Apr 25th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Baltimore | May 17th - May 21st 2027 |
Podcast Transcript
Hello and welcome to the Thursday, September 17, 2026 edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich, recording today from Jacksonville, Florida. And this episode is brought to you by the SANS.edu Graduate Certificate Program in Cyber Defense Operations. The last couple days our honeypots got hit with a set of requests all coming from the same source that indicate a little bit more coordinated but very odd attack that targets the hospitality industry. So hotels and the like. There's also sort of a little bit focus on PBX, so phone systems. The URL that sort of made it stick out to me is for a product called PBX in a flash hospitality management system. Doesn't really look like much like a product when you look at the GitHub repo last update about 14 years ago. I think 10 years ago the license was updated but none of the code and the code looks maybe more like a proof of concept or such because it doesn't do any kind of input validation. So lots of SQL injection, pretty much any SQL statement in the code base that I sort of looked at was suffering from SQL injection. I also don't really see any authentication or access control in this product. But the intent of the product is to help you basically manage PBXs for hotels. There are a couple other URLs that are sort of a little bit related like UCP and HMS and well slash hotel. Also some more standard admin URLs that are being probed by this particular actor. What's also unique is the user agent phares-sorter. Haven't really seen that one before either. So I think right now it's really just odd and sort of caught my curiosity. So if anybody has any details about these attacks, maybe any insight into what products may actually be attacked here. There was also a bug report or vulnerability report, I should say, for this PBX in a flash product that dated from July. So maybe that sort of got them to scan for it. They really don't know. So if you have any ideas, please help me out. And Cisco today released an advisory alerting its customers that they patched a CVSS score 10 vulnerability in the Cisco identity services engine. It's an authentication bypass vulnerability. In this particular case, the API is not checking all of its endpoints, which is a very common problem, of course, with APIs. We have had issues like this with Cisco before. The identity service engine, as the name implies, it's used to essentially manage access to your network devices. So a vulnerability here could have far-reaching impact. And that also probably justifies the CVSS score of 10. This vulnerability has already been exploited. So that makes it even worse. As always, don't expose these APIs to the public and assume compromise. At this point, Cisco has added some indicators of compromise and ways to verify if you were attacked to its bulletin. And Acronis, the maker of backup software recently published an update fixing some vulnerabilities. One of these vulnerabilities is now being exploited in the wild. It's a privilege escalation vulnerability in their plugin for cPanel and Blesk. Privilege escalation vulnerabilities are usually not at the top of the list. And I often don't even mention them here. But in particular, with cPanel and Blesk, that's sort of the systems that you're using to administer sort of shared systems that customers may have access to. So privilege escalation is certainly a problem for a product like this, in particular, if it's already being exploited. So make sure you update the updates were released five days ago. Well, today's really one of those zero days, we do have another one this time in Google's Pixel phones. Google did publish its Pixel update bulletin for September today. And this update does include a fix for their modem code that does prevent an elevation of privilege of vulnerability. This includes also the September Android updates that were published last week. But always a week later, we get then the Pixel specific version, which of course does include some of the more hardware specific patches like vulnerabilities in the modems and other sort of specific hardware devices. Well, if you're in instant response, there is a great new free ebook that Josh Wright published for SANS. Josh, if you're not familiar with him, a great person and great instant responses. He's also responsible for our SEC 504 class that deals a lot with some of the instant response aspects. But this particular ebook also introduces some of the more modern concepts when it comes to instant response. Very well done. And lots of great things that you have here. Also lots of contributions from the community in this book. So take a look. It's free and the link will be in the show notes. Well, and this is it for today. So thanks for listening. Thanks for liking. Thanks for recommending this podcast and talk to you again tomorrow. Bye.





