Handler on Duty: Jim Clausing
Threat Level: green
Podcast Detail
SANS Stormcast Friday, October 9th, 2026: AI Agent Forensics; AI-Assisted Attack on South Korean Banks; IDN Typosquatting; Cisco Finesse SSRF (CVE-2026-20362)
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10130.mp3
AI Agent Forensics; AI-Assisted Attack on South Korean Banks; IDN Typosquatting; Cisco Finesse SSRF (CVE-2026-20362)
00:00
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
In today's episode: new scripts for reconstructing AI agent activity during forensic investigations, an attacker's Claude chat history recovered after breaches at South Korean financial institutions, internationalized domain name (IDN) lookalikes that still get past Chrome, and an unpatched Cisco Finesse server-side request forgery (SSRF) vulnerability.
Reconstructing AI Agent Activity: Two New Scripts for Forensic Review
Jim Clausing released two scripts that turn the logs left behind by the OpenCode and Hermes AI agents into searchable JSON, so incident responders can see what an AI agent did on an attacker's or a victim's system.
https://isc.sans.edu/diary/Reconstructing%20AI%20Agent%20Activity%3A%20Two%20New%20Scripts%20for%20Forensic%20Review/33410
Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance
While investigating breaches at South Korean financial institutions, CrowdStrike recovered the attacker's CLAUDE.md file and Claude chat history, a rare look at how a low-skill "prompt kiddie" uses AI to run an attack.
https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/
Turning IDN Edge Cases into Typosquats
Attackers can still register convincing lookalike domains using Unicode characters that resemble Latin letters but are not on Chrome's list of known confusables. One test domain impersonating Apple displayed in Chrome but not in Safari.
https://haveibeensquatted.com/blog/turning-idn-edge-cases-into-typosquats
Cisco Finesse SSRF Vulnerability (CVE-2026-20362)
Cisco disclosed an unauthenticated server-side request forgery vulnerability in the Cisco Finesse web-based management interface, rated High (CVSS 7.2). Details are already public, there is no workaround, and fixed releases are not expected until January or February 2027.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-finesse-ssrf-mmSuyugS
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Eastern | Feb 8th - Feb 12th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 19th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Orlando | Apr 12th - Apr 16th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Mountain | Apr 21st - Apr 25th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Baltimore | May 17th - May 21st 2027 |
Podcast Transcript
Hello and welcome to the Friday, October 9th, 2026 edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich, recording today from Jacksonville, Florida. And this episode is brought to you by the SANS.edu Undergraduate Certificate Program in Applied Cybersecurity. Well, attackers these days like AI agents. They may use them on their own system in order to orchestrate the attack and conduct some of the attack activity. But they may also interact with AI agents on the victim's host in order to breach additional systems or just to figure out what a particular victim was doing with this AI agent and what this agent may have access to. So Jim Clausing wrote two scripts that allow you to reconstruct the activity that these AI agents performed. This is pulled from logs these AI agents leave behind, but then represented in a more easily parsable, searchable JSON format. The two examples that Jim has is OpenCode and Hermes as two agents that his scripts are covering. And yes, he used, of course, these tools also to create those scripts. And if you run any AI agents, maybe they can help you figure out how to better monitor their activities. In particular, for I think these days, any kind of forensics investigations, you probably want to look at how AI agents were involved. And again, don't forget that the victim side's AI agent may also be an interesting source of logs here, not just the attackers, which, of course, you may not always have access to. So as I just mentioned that usually we don't have access to the AI agent or chat logs from the attacker, well, CrowdStrike got lucky. Recently, some South Korean financial institutions were attacked and in part successfully breached by an attacker. And investigating the attack, CrowdStrike, on one of the systems involved in the attack, came across the CLAUDE.md file of the attacker. And with that also then gained access to essentially the attacker's chat history with Claude. Well, it really shows that instead of click kiddies or script kiddies, we now have prompt kiddies. This attacker was definitely not sophisticated, but it gives an interesting insight in the mindset of the attacker and how these attackers operate. Hopefully also helping defenders better understand these attacks and better protect against them. But also for pen testers, sort of a scenario to consider if you're thinking about emulating a particular type of attacker. And then international domain names are in the news again as a form of typosquatting where you can come up with lookalike domain names. This is a problem that's really one of those whack-a-mole problems between browsers and attackers. So the initial problem was that I can just replace one letter in a domain name with a lookalike Unicode letter and then basically impersonate any arbitrary domain. Now, this was then eliminated by browsers like Google Chrome, not allowing the mix of different character sets. So you can't mix a Latin letter A with a Cyrillic letter A. Now, then of course attackers came up with domain names that used all, let's say, Cyrillic letters. And that way, of course, it slipped through these checks. Now, the next step was where Chrome again, sort of leading this, did eliminate lookalike letters, these confusables. They're known confusable letters. So there's a list of them that's built in the browser and they're used to check for these type of attacks. Well, the latest round now is that there are letters that are close, but not officially confusables. So that way, it's still possible to get a fairly good lookalike domain name, but it's not detected by Google Chrome. And Google Chrome is here the major sort of browser they investigated. Safari, as the other big browser, is usually much more forgiving and likely to display these international character sets. Interestingly, the one sort of test domain name they registered that impersonates Apple, does actually not show up in Safari, but it does work in Google Chrome. So we'll see what the next round here is, if the list of confusable letters will be expanded. But of course, there's sort of a sliding scale here, where a letter may be considered confusable or not. And that, of course, also depends often on how operating systems and fonts display these letters. And Cisco published an advisory regarding Cisco Finesse. Now, this advisory is only rated as high. It's yet another server-side request forgery. I think yesterday we had SonicWall with one of these vulnerabilities. In this case, however, the impact is limited. It only allows limited access to sensitive information. However, there is no patch available, and details about the vulnerability have already been made public. This is why Cisco did publish this advisory, but looks like it may take until early next year for a patch to be made available. Cisco does not offer any workarounds until then. Well, and that's it for today. So thanks again for listening. Thanks for liking. Thanks for subscribing to this podcast. And talk to you again on Monday. Bye.





