Podcast Detail

SANS Stormcast Monday, August 31st, 2026: Malware Statistics; PaperCut Update; Watchguard and DLink Patches;

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10074.mp3

Podcast Logo
Malware Statistics; PaperCut Update; Watchguard and DLink Patches;
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

Podcast Transcript

 Hello and welcome to the Monday, August 31, 2026
 edition of the SANS Internet Storm Center's Stormcast. My
 name is Johannes Ullrich, recording today from New York
 City, New York. And this episode is brought to you by
 the SANS.edu Graduate Certificate Program in Purple
 Team Operations. On Friday, Xavier took a look at
 malicious PE file. These portable ex-tribal files that
 are commonly used by Windows have the nice advantage of
 containing quite a bit of metadata in the header. This
 metadata can then be used in order to figure out, for
 example, what compiler is being used. Now in the past,
 Xavier has looked, for example, at statistics of 64
 bits versus 32 bit malware. Turns out, still, the vast
 majority is 32 bits. But that's a kind of logic, given
 that there is really no big advantage for malware to
 actually run in 64 bits. As far as the compilers being
 used and the languages being used, the vast majority does
 use C, C++ and the standard Microsoft compilers in order
 to compile the code. Go, Rust, some of these other languages,
 are still sort of fractions of a percent of the malware that
 Xavier looked at. So really not significant at this point.
 Of course, significant maybe in other ways. We have seen
 some sort of more advanced malware, for example, using Go
 that in particular does attempt to evade some of the
 other detection mechanisms that aren't really all that
 familiar and tuned to malware written in Go. This was a
 rather large stash of malware that Xavier looked at.
 Overall, there were something like 23 million files. 600,000
 approximately turned out to be valid PE files. These files
 were retrieved from the Abuse .ch Matter Bazaar. And on
 Friday, I talked about ongoing exploitation against PaperCut
 and that there is no real patch available for it. Well,
 the folks at PaperCut were busy at work over the weekend.
 They did publish two emergency updates and do recommend that
 you apply them. So emergency patch release 2 that was
 published on the 28th is the one that you should have
 applied by now. But probably the original advice of just
 disabling access to PaperCut if you can do so or
 constraining what IP addresses can access PaperCut that is
 still valid. Still something that you should follow. There
 are a total of two vulnerabilities that are being
 addressed here in this patch. The first one is an unsafe
 dynamic class loading vulnerability. That's sort of
 a reflective one where the data is being loaded from the
 database. In order to get that data into the database, the
 attacker then exploits a second vulnerability and
 that's an improper access control vulnerability in the
 web management interface. So those two vulnerabilities work
 together here to in the end lead to arbitrary code
 execution on PaperCut and that's what's being currently
 exploited. And late last week WatchGuard released patches
 for 27 vulnerabilities. There is one kind of vulnerability
 that I'm a little bit concerned about and this is a
 buffer overflow in the Ike-D implementation. So Ike, that's
 your key exchange for IPsec and pretty much has to be
 exposed if you're using IPsec and often you're using like a
 VPN because you can't easily restrict IP addresses. So
 definitely something to be aware of. It affects Fireware
 OS. Patches are available. I'm not aware of any exploits out
 there but something that you do definitely want to patch.
 And finally we got patches from D-Link for their DIR
 -X1860 routers. So these patches affect two
 vulnerabilities that are being addressed here. The first
 vulnerability is pretty interesting. It's an
 unauthenticated administrator password modification. Now it
 does require that the attacker has access to the JSON RPC
 interface which shouldn't be of course exposed. The second
 one is a wireless configuration information
 disclosure. So that could affect any passwords and such
 that you need for Wi-Fi access. Definitely I would
 consider the first one to be the critical one here. And
 like I said, just make sure that you please don't expose
 this stuff to the world. Well and this is it for today. So
 thanks for listening. Thanks for liking. Thanks for
 recommending this podcast. As always you can find links to
 classes I'll be teaching in the near future in the show
 notes. So thanks and talk to you again tomorrow. Bye. Bye.