Podcast Detail

SANS Stormcast Friday, October 9th, 2026: AI Agent Forensics; AI-Assisted Attack on South Korean Banks; IDN Typosquatting; Cisco Finesse SSRF (CVE-2026-20362)

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10130.mp3

Podcast Logo
AI Agent Forensics; AI-Assisted Attack on South Korean Banks; IDN Typosquatting; Cisco Finesse SSRF (CVE-2026-20362)
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

In today's episode: new scripts for reconstructing AI agent activity during forensic investigations, an attacker's Claude chat history recovered after breaches at South Korean financial institutions, internationalized domain name (IDN) lookalikes that still get past Chrome, and an unpatched Cisco Finesse server-side request forgery (SSRF) vulnerability.

Reconstructing AI Agent Activity: Two New Scripts for Forensic Review
Jim Clausing released two scripts that turn the logs left behind by the OpenCode and Hermes AI agents into searchable JSON, so incident responders can see what an AI agent did on an attacker's or a victim's system.
https://isc.sans.edu/diary/Reconstructing%20AI%20Agent%20Activity%3A%20Two%20New%20Scripts%20for%20Forensic%20Review/33410

Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance
While investigating breaches at South Korean financial institutions, CrowdStrike recovered the attacker's CLAUDE.md file and Claude chat history, a rare look at how a low-skill "prompt kiddie" uses AI to run an attack.
https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/

Turning IDN Edge Cases into Typosquats
Attackers can still register convincing lookalike domains using Unicode characters that resemble Latin letters but are not on Chrome's list of known confusables. One test domain impersonating Apple displayed in Chrome but not in Safari.
https://haveibeensquatted.com/blog/turning-idn-edge-cases-into-typosquats

Cisco Finesse SSRF Vulnerability (CVE-2026-20362)
Cisco disclosed an unauthenticated server-side request forgery vulnerability in the Cisco Finesse web-based management interface, rated High (CVSS 7.2). Details are already public, there is no workaround, and fixed releases are not expected until January or February 2027.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-finesse-ssrf-mmSuyugS

My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich

Podcast Transcript

 Hello and welcome to the Friday, October 9th, 2026
 edition of the SANS Internet Storm Center's Stormcast. My
 name is Johannes Ullrich, recording today from
 Jacksonville, Florida. And this episode is brought to you
 by the SANS.edu Undergraduate Certificate Program in Applied
 Cybersecurity. Well, attackers these days like AI agents.
 They may use them on their own system in order to orchestrate
 the attack and conduct some of the attack activity. But they
 may also interact with AI agents on the victim's host in
 order to breach additional systems or just to figure out
 what a particular victim was doing with this AI agent and
 what this agent may have access to. So Jim Clausing
 wrote two scripts that allow you to reconstruct the
 activity that these AI agents performed. This is pulled from
 logs these AI agents leave behind, but then represented
 in a more easily parsable, searchable JSON format. The
 two examples that Jim has is OpenCode and Hermes as two
 agents that his scripts are covering. And yes, he used, of
 course, these tools also to create those scripts. And if
 you run any AI agents, maybe they can help you figure out
 how to better monitor their activities. In particular, for
 I think these days, any kind of forensics investigations,
 you probably want to look at how AI agents were involved.
 And again, don't forget that the victim side's AI agent
 may also be an interesting source of logs here, not just
 the attackers, which, of course, you may not always
 have access to. So as I just mentioned that usually we
 don't have access to the AI agent or chat logs from the
 attacker, well, CrowdStrike got lucky. Recently, some
 South Korean financial institutions were attacked and
 in part successfully breached by an attacker. And
 investigating the attack, CrowdStrike, on one of the
 systems involved in the attack, came across the
 CLAUDE.md file of the attacker. And with that also then gained
 access to essentially the attacker's chat history with
 Claude. Well, it really shows that instead of click kiddies
 or script kiddies, we now have prompt kiddies. This attacker
 was definitely not sophisticated, but it gives an
 interesting insight in the mindset of the attacker and
 how these attackers operate. Hopefully also helping
 defenders better understand these attacks and better
 protect against them. But also for pen testers, sort of a
 scenario to consider if you're thinking about emulating a
 particular type of attacker. And then international domain
 names are in the news again as a form of typosquatting where
 you can come up with lookalike domain names. This is a
 problem that's really one of those whack-a-mole problems
 between browsers and attackers. So the initial
 problem was that I can just replace one letter in a domain
 name with a lookalike Unicode letter and then basically
 impersonate any arbitrary domain. Now, this was then
 eliminated by browsers like Google Chrome, not allowing
 the mix of different character sets. So you can't mix a Latin
 letter A with a Cyrillic letter A. Now, then of course
 attackers came up with domain names that used all, let's
 say, Cyrillic letters. And that way, of course, it
 slipped through these checks. Now, the next step was where
 Chrome again, sort of leading this, did eliminate lookalike
 letters, these confusables. They're known confusable
 letters. So there's a list of them that's built in the
 browser and they're used to check for these type of
 attacks. Well, the latest round now is that there are
 letters that are close, but not officially confusables. So
 that way, it's still possible to get a fairly good lookalike
 domain name, but it's not detected by Google Chrome. And
 Google Chrome is here the major sort of browser they
 investigated. Safari, as the other big browser, is usually
 much more forgiving and likely to display these international
 character sets. Interestingly, the one sort of test domain
 name they registered that impersonates Apple, does
 actually not show up in Safari, but it does work in
 Google Chrome. So we'll see what the next round here is,
 if the list of confusable letters will be expanded. But
 of course, there's sort of a sliding scale here, where a
 letter may be considered confusable or not. And that,
 of course, also depends often on how operating systems and
 fonts display these letters. And Cisco published an
 advisory regarding Cisco Finesse. Now, this advisory is
 only rated as high. It's yet another server-side request
 forgery. I think yesterday we had SonicWall with one of
 these vulnerabilities. In this case, however, the impact is
 limited. It only allows limited access to sensitive
 information. However, there is no patch available, and
 details about the vulnerability have already
 been made public. This is why Cisco did publish this
 advisory, but looks like it may take until early next year
 for a patch to be made available. Cisco does not
 offer any workarounds until then. Well, and that's it for
 today. So thanks again for listening. Thanks for liking.
 Thanks for subscribing to this podcast. And talk to you again
 on Monday. Bye.