Podcast Detail

SANS Stormcast Wednesday, August 12th, 2026: Microsoft Patch Tuesday; Zoom Vulnerabilities; Mozilla Revokes Key; Rogue Inflight Wifi

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10048.mp3

Podcast Logo
Microsoft Patch Tuesday; Zoom Vulnerabilities; Mozilla Revokes Key; Rogue Inflight Wifi
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

Podcast Transcript

 Hello and welcome to the Wednesday, August 12, 2026
 edition of the SANS Internet Storm Center's Stormcast. My
 name is Johannes Ullrich, recording today from
 Jacksonville, Florida. This episode is brought to you by
 the SANS.edu Graduate Certificate Program in
 Industrial Control Systems Security. Well, Microsoft
 patched Tuesday and imagine that it was another massive
 patch Tuesday. Now, not quite as bad as last patch Tuesday.
 In July, we had something over 600 different vulnerabilities
 being addressed. This time, it's only 400 approximately.
 I've seen a couple different numbers. Depends on how you
 count exactly which vulnerabilities you include.
 62 of these vulnerabilities are critical. One is already
 being exploited in a while and two were publicly disclosed,
 but haven't yet seen in the wild according to Microsoft.
 Now, I thought a little bit about how to summarize this. I
 will actually not start with the disclosed and already
 exploited vulnerabilities because in some ways, I don't
 think that's really the story here. There are really two
 vulnerabilities that I think should be at the top of your
 list and that's the critical vulnerabilities in the DNS
 server. There are four critical vulnerabilities. DNS
 servers tend to be more exposed. So that's why I would
 give them sort of the highest priority and these are remote
 code execution vulnerabilities. Followed by
 the critical vulnerability in the DHCP server. DHCP server
 typically only exposed on the local network. So that's why I
 give that a little bit a lower priority. And we have sort of
 the rest of the critical vulnerabilities are pretty
 concentrated in some common and well-known problem, a
 piece of software, Office, SharePoint, and RDP. So apply
 these patches just like you always do. There's nothing
 really that different. There are more vulnerabilities, but
 overall the patch process shouldn't really be that
 affected by it. And we also have an interesting critical
 vulnerability in quick, the new transport layer protocol.
 And that one, I have probably the hardest time right now
 sort of really guessing, you know, how severe this one is,
 how likely it is going to be exploited, but definitely
 would put it here on the list of things to patch. Now, as
 far as the already exploited vulnerability goes, this is a
 Windows container isolation issue. I don't really see it
 as sort of, you know, top of the list as far as criticality
 goes. The already known ones, the one that really kind of
 stuck out here was the vulnerability that's known as
 Legacy Hive. I talked about it, I think, last week when it
 sort of was disclosed. It essentially allows privilege
 escalation. It's one of these nightmare eclipse
 vulnerabilities. So definitely, you know, address
 this one, but it's just a privilege escalation
 vulnerability, which probably, you know, we have tons more to
 worry about. So that's why I give that really not sort of
 the big emphasis that we usually give these already
 disclosed, already exploited vulnerabilities. So in short,
 yes, a lot of vulnerabilities, patch them, that's really the
 only thing you can do, the only thing that you should do.
 And there's nothing here, other than maybe the DNS
 vulnerability, where I sort of would really sort of emphasize
 speed on patching, go through your process, and hopefully,
 you know, we're able to shrink that down enough, so you'll be
 done with these updates by the time the next patch Tuesday
 comes around. And I'm pretty sure by then, you know,
 Microsoft will just say, hey, they're done patching them.
 And at least as interesting as Microsoft vulnerabilities are
 three vulnerabilities that were patched in Zoom. These
 are three memory allocation vulnerabilities that allow for
 full remote code execution. In order to exploit this
 vulnerability, the attacker and the victim have to join
 the same Zoom call. So the attacker would essentially
 then send the exploit traffic to the victim and achieve
 remote code execution. So patches are available, but
 also an exploit, at least the draft, proof of concept,
 whatever you want to call it, of an exploit. A security, the
 company that found this vulnerability has a very
 detailed blog post with details how to exploit this
 vulnerability. So while I don't think they really
 release of a full working exploit, there's enough
 information here to develop an exploit if someone is halfway
 skilled in doing so. And again, all platforms are
 affected. The exploit they're discussing here in their blog
 is actually for macOS, but Windows, Android, iOS, they
 say whatever platform runs Zoom is potentially
 vulnerable. And Mozilla announced yesterday that they
 revoked the signing key used to create GPG signatures for
 Firefox and Thunderbird. Apparently, the secret key was
 accidentally committed to a private GitHub repository.
 While private GitHub repositories are supposed to
 be private, well, they're not really secure enough to leave
 a cryptographic key like this in the repository. So they did
 the right thing and revoked the key. The problem now
 becomes, well, when do you actually need the key? So who
 does this affect? It's really mostly Linux users, I would
 expect. It does affect RPM packages. So if you're using a
 distribution that uses RPM, then you are affected. If you
 are downloading Linux tarballs, basically source
 packages, then you are affected because then you may
 manually validate the signatures of these tarballs
 that you're downloading. So that's really sort of the only
 groups that are affected by this particular problem. If
 you are affected, well, there is, of course, an updated key
 available. The old key would have expired in about seven
 months, I think they said. That thing was like March next
 year or so is when they were supposed to release a new key
 anyway. But that's still far enough out where you probably
 don't want to go without patches for that time in
 particular in software like Firefox and Thunderbird. Well,
 a group of individuals apparently returning from DEF
 CON yesterday did cut some of the ethics talks a little bit
 short and sort of got caught up in the excitement. But
 either way, they couldn't help themselves and launched a
 DEAuth attack on a Delta flight against the in-flight
 wireless. I usually don't really talk a lot about just
 opinions and such, but some of the comments I've seen online
 provoked me kind of to say a little bit more about this
 particular incident. In information security, there
 are a lot of laws, a lot of regulations and compliance and
 such, but there's sort of one rule of his quality, don't be
 an a-hole rule. And these individuals certainly violated
 it. So regardless of what you think about skills that are
 really not required to launch an attack like this, they
 really just made their life and the life of others harder.
 They didn't learn anything from this attack and nobody
 exposed to the attack really learned anything. What we may
 have learned is that actually in-flight WiFi is monitored a
 little bit better than we thought and Delta did respond
 to the attack fairly quickly. They disabled the in-flight
 WiFi, which of course, given the short response time and
 such, is probably the right and only thing they could do.
 And the flight was then created by law enforcement as
 it arrived in Atlanta. So if you got any neat toys while
 you were at DEFCON or if you're ordering them now
 because you saw them being advertised in a particular
 talk or so at DEFCON, remember it's always nice to
 play, but don't hurt anybody else. I think this particular
 these days a little bit difficult for some people
 because we see all these AI models that really are
 behaving grossly irresponsible. And look at it
 this way, you know, you may not be a better hacker than
 OpenAI or Anthropic or I think Kimi was it today, but
 you can be better human and try to see it that way. And
 don't cause more pain for innocent bystanders. Well, and
 this is it for today. So thanks for listening. Thanks
 for liking. Thanks for recommending this podcast and
 talk to you again tomorrow. Bye.
 Bye. Okay. Thank you.