Handler on Duty: Xavier Mertens
Threat Level: green
Podcast Detail
SANS Stormcast Tuesday, October 6th, 2026: cowrie tty Logs; Another Netscaler 0-Day; Exchange Patch
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10124.mp3
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
TTY Logs and the Data it Captures
https://isc.sans.edu/diary/TTY%20Logs%20and%20the%20Data%20it%20Captures/33396
Citrix Netscaler SAML Vulnerability (0-Day) CVE-2026-88779
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174
https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/
Microsoft Exchange September 2026 V2 Update CVE-2026-96940
https://techcommunity.microsoft.com/blog/exchange/released-september-2026-v2-exchange-server-security-updates/4561718
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Eastern | Feb 8th - Feb 12th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 19th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Orlando | Apr 12th - Apr 16th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Mountain | Apr 21st - Apr 25th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Baltimore | May 17th - May 21st 2027 |
Podcast Transcript
Hello and welcome to the Tuesday, October 6, 2026 edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich, recording today from Jacksonville, Florida. And this episode is brought to you by the SANS.edu Bachelor's Degree Program in Applied Cybersecurity. And in today's diary, Guy is taking a look at the Kaori TTY Logs. So these TTY Logs essentially capture the interaction of the attacker with the honeypot. And Kaori comes with some neat tools to, for example, play them back. That's one of the tools, at least when I first started working with Kaori, I thought was real neat and helpful. But if you have a lot of logs, as you tend to have, if you're running the honeypot for a while, then you probably want to query them a little more efficiently in summarizing them. And that's what Guy is going over here. Now Guy is creating and maintaining this scene that's sort of part of our honeypot. It uses Elasticsearch, so we can use Elasticsearch queries to basically figure out what is happening. One type of command that attackers really like is playing and manipulating the cron tab. So what that's usually used for is, first of all, to figure out if there are any cron jobs already running for particular users. That could indicate a prior compromise or could be abused, but also to gain persistence on a system. Attackers love to schedule cron jobs. So that's sort of one of the things that Guy is looking at. And then also some of the other events that were created in the TTY Logs, like, for example, attackers fingerprinting honeypots or changing the environment to suit their purposes. Also, another very common thing that's being done by attackers is trying to remove competing scripts from prior compromises. It's also a repeating pattern in these TTY Logs. So if you're running Cowry, if you're interested in what Guy is doing here with Elasticsearch and such, well, take a look at the diary from today. And following with our motto for the last few episodes that every day is zero day, it's Netscaler's turn again. Yes, I double -checked. It's a new vulnerability in Netscaler. This time only denial of service. It's not a remote code execution or an authentication bypass issue, even though it does affect SAML. So if you have Citrix Netscaler configured as a SAML identity provider or as a relying party, you may be vulnerable. And yes, it's already exploited. It doesn't state so in the advisory, but Citrix did publish a separate blog post with a couple of additional details. It is a buffer overflow, but then again, not all buffer overflows are exploitable for an actual remote code execution, but often then lead to a denial of service. So this does make sense. Anyway, double-check and yes, patch Netscaler again. And Microsoft on Friday published another update for Exchange. They call this the September 2026 version 2 update, and it does patch one more vulnerability that didn't get covered in the September patch Tuesday update. Now, there's one vulnerability again that's being addressed here. This vulnerability is a privilege escalation vulnerability that is being addressed. It's not yet exploited, but it states in the notes about this vulnerability that exploitation or exploitability is more likely for this vulnerability. So it's not that terribly difficult to exploit it. Definitely get taken care of this. Of course, patching Exchange can always be a little bit tricky. They also mention, I think, some issues with calendar files that this update introduces. So there's some known issues here that you should review before applying the update. And then last week, we also got a Debian Linux update, and I didn't cover it back then. I usually don't cover these updates, but I want to give it at least of an honorable mention because a couple of listeners have asked about this. I think it's 1,300 -something vulnerabilities being updated with this particular patch. A lot of these are basically Linux kernel patches that they are porting now into the Debian distribution. They also announced, I think it was a little bit longer, that they're going to release more frequent kernel updates, which, of course, may require more frequent system reboots. So keep that in mind as you're applying these updates. Well, and that's it for today. So thanks again for listening. Thanks for liking. Thanks for subscribing. And special thanks for everybody who is leaving comments about this podcast in your favorite podcast platform. Don't forget, we are available on YouTube if you like the video format. And also like Amazon Alexa and a couple other outlets. Still working on the Google Music podcast. They have some issues because there's also a YouTube channel associated with it. So still trying to work this out. Thanks and talk to you again tomorrow. Bye. Bye. Bye. Bye.





