Handler on Duty: Didier Stevens
Threat Level: green
Podcast Detail
SANS Stormcast Monday, August 17th, 2026: MacOS Screen Sharing; GeoServer Patch; SAP Exploited;
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10054.mp3
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
macOS Screen Sharing Vulnerability Exploited
https://advisories.ncsc.nl/2026/ncsc-2026-0280.html
GeoServer Patch
https://geoserver.org/announcements/vulnerability/2026/08/14/geoserver-3-0-1-released.html
Recent SAP Commerce Cloud Vuln Exploited
https://x.com/DefusedCyber/status/2088240809355153647
ChainDrop npm Worm
https://medium.com/governed-at-the-source/the-chaindrop-npm-worm-august-2026-how-444-packages-were-compromised-without-a-single-npm-b0c9e5a4c387
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Application Security: Securing Web Apps, APIs, and Microservices | Las Vegas | Sep 21st - Sep 25th 2026 |
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Apps, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Apps, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 20th 2027 |
Podcast Transcript
Hello and welcome to the Monday August 17th, 2026 edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich recording today from Jacksonville, Florida. And this episode is brought to you by the SANS.edu undergraduate certificate program in Applied Cybersecurity. Well, let's start today with two vulnerabilities that I've already talked about, but there are a couple updates to them. So first of all, the Apple vulnerability in screen sharing. This one was patched a little bit less than two weeks ago. And yes, it's actively being exploited now, according to the Dutch Information Security Agency. We have seen detailed descriptions, proof of concept exploits, so no real surprise that this is now being exploited. Definitely make sure that you patch this vulnerability. It's also probably a good idea to review how you're using screen sharing. It should never really be exposed to a network. I can see where people use it sort of in their home networks and such, but then don't turn it off as they connect to external public networks as they're traveling. So that's certainly a risk here that you need to be aware of. The second vulnerability is the vulnerability in GeoServer. So this was an unauthenticated SQL injection vulnerability. It does not affect the default configuration, but yes, it's also already being exploited. Not sure how common the configuration that enables this issue is actually. The GeoServer patch here has been released now, but there is at least at this point, I believe, no CVE number for it. They're still waiting for one to be issued. And Cyber Intel Company Defused states in an ex-post that they have seen active exploitation against an SAP vulnerability, a remote code execution in SAP Commerce Cloud. This was patches part of Patch Tuesday. SAP also tends to release patches on Patch Tuesday. So a couple of days after the patch was released, this was already exploited. Definitely at this point do assume compromise, even though Diffused hasn't made public sort of any details about what they're seeing. So not quite clear what the payload, for example, is like and what an attacker is trying to accomplish with these scans. And yes, supply chain attacks keep evolving. The latest example is a worm referred to as Chaintrop by Microsoft. Others have picked up this particular name for this worm. There's a good write-up now by Abby Kearns with ActiveState about this particular incident. At the time of Abby writing this particular article, 444 packages were compromised. And as pointed out in the blog post, it did use a different activation method than what we typically have seen in these worms. Typically, they used the NPM configuration file in order to run any post-install scripts that then ran the malicious code. Well, a lot of security tools are now scanning these configuration files and are warning the user or blocking these install scripts. Instead, what this particular worm does is that it comes with a settings file for IDEs. In this particular case, Visual Studio Code, as well as for a cursor, I believe. And in these configuration files, you can execute code as this particular file or the files in this library are being opened by the IDE. So I talked about this particular vector before. This is certainly something you do want to take a look at. Remember, if your IDE asks you whether or not you trust a particular directory as you're opening as a project or such, well, definitely be aware that the reason for this pop-up is that code in configuration files may be executed as soon as you open these files. And apparently, this was quite successful here. And as all the other worms, it does steal NPM and GitHub credentials. Well, and that's it for today. Thanks for liking. Thanks for subscribing and recommending this podcast. And remember, I will be teaching our Defending Web Application class in September in Vegas. And then in October in Amsterdam, I'll be teaching our Intrusion Detection class. So that's it for today. Thanks and talk to you again tomorrow. Bye.





