Handler on Duty: Guy Bruneau
Threat Level: green
Podcast Detail
SANS Stormcast Thursday, September 10th, 2026: Proxmox Scans; MSFT Defender, Gogole Chorme, and FortiPAM Vulns.
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10088.mp3
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
Scans for Proxmox Servers
https://isc.sans.edu/diary/Scans%20for%20Proxmox%20Servers/33324
Next Nightmare Eclipse Vulnerability
https://github.com/MSNightmare/ShieldCrash/blob/main/README.md
Google Chrome Updates
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html
FortiPAM Vulnerability
https://amibeingpwned.com/blog/fortinet-pam-vuln
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Application Security: Securing Web Applications, APIs, and Microservices | Las Vegas | Sep 21st - Sep 25th 2026 |
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 19th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Orlando | Apr 12th - Apr 16th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Mountain | Apr 21st - Apr 25th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Baltimore | May 17th - May 21st 2027 |
Podcast Transcript
Hello and welcome to the Thursday, September 10th, 2026 edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich, recording today from Jacksonville, Florida. And this episode is brought to you by the SANS.edu Graduate Certificate Program in Purple Team Operations. In diaries today, I'm writing about some brute forcing that I'm seeing more and more against Proxmox servers. I think there are two reasons behind this increase. First of all, about a week ago, there was like a vulnerability being announced in an older version of Proxmox and SH sort of authentication bypass of vulnerability. Now, again, this was an older version, no longer supported, shouldn't really be a big deal, but probably still a lot of exposed servers out there. And the second one, I think, is that we have more and more users switching away from VMware, which was a traditional target when attackers were looking for vulnerable virtualization systems. Well, now they got Proxmox here to play around with. What I'm seeing is not exploitation of a specific vulnerability, but essentially just brute forcing. Now, Proxmox is pretty good, actually, when it comes to sort of different authentication options. You have multi-factor authentication, you have pass keys. So definitely there are ways to protect yourself against brute forcing if you must keep the admin interface exposed. Still, you probably don't want to do this. And as it has become traditional following Microsoft's Patch Tuesday, we of course get nightmare eclipses zero day Wednesday. The latest vulnerability here is the shield crash, and it's actually not a fundamentally new vulnerability. It's shield break, but it does expand this older vulnerability to bypass the fix that Microsoft has implemented for this. Again, it's always tricky to keep these anti-malware systems free from these privilege escalation vulnerabilities. And I'm sure we probably have a bunch more to come. In one article, I saw that this is like the 11th Saturday that Nightmare Eclipse has published now. I haven't counted myself, but sounds like about the right number. And Google released security updates for Google Chrome, fixing a total of 230 security fixes. There is one vulnerability that already has been exploited in the wild. It's a memory buffer overrun in V8, the JavaScript engine. Nothing that special for Google Chrome. That's the type of vulnerability that usually happens in V8. Now, you still need to break out of the sandbox, which typically is another exploit. They didn't indicate if the exploits seen in the wild actually are taking advantage of any kind of sandbox escape to compromise the system outside of the browser. Google also indicated they will be shifting their update cycle slightly. You'll now get weekly security updates and only every other week there will be actually a major version update or a feature update being released. And if you're using FortiPAM, that's FortiNET's Privilege Access Management, then well, you must update pretty quickly because there is an interesting vulnerability that allows a NetHacker to specify what proxy is being used by the Chrome extension. If an NetHacker does so, then all requests of the user are being sent to the attacker's proxy. There are kind of three pieces to it. First, the attacker needs to set up a web listener at a particular URL. That's pretty straightforward. Next, they need to send a request to the extension, which, well, has an authentication field. But if the authentication token, which should be a JWT token, is not the right format, so basically just a random string, then it's just accepted. So there is no failure being used here if you're actually not presenting a valid token at all. Finally, there is a pop-up where the user is then able to reject the request. But with some simple JavaScript, it's possible to auto-approve this pop-up. Now, in order to fix this vulnerability, you must update the extension, the browser extension, but you also must update your FortiPAM server component. So both must be updated in order to prevent this problem. Well, and that's it for today. There were a couple other things about Palo Alto had some updates and a couple others, but really just too many vulnerabilities these days. I hope I picked the right ones. Also note that on Monday we'll have a major Apple update. That's when they're going to release the 27 versions of their operating systems. Thanks and talk to you again tomorrow. Bye.





