Podcast Detail

SANS Stormcast Friday, September 18th, 2026: LousivLaoder Analysis; Issabel Framework 0-Day; Cyber Decoys; CISA Vuln Bulletin; Unbound Vulnerability

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10100.mp3

Podcast Logo
LousivLaoder Analysis; Issabel Framework 0-Day; Cyber Decoys; CISA Vuln Bulletin; Unbound Vulnerability
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

Podcast Transcript

 Hello and welcome to the Friday, September 18th, 2026
 edition of the SANS Internet Storm Center's Stormcast. My
 name is Johannes Ullrich, recording today from
 Jacksonville, Florida. And this episode is brought to you
 by the SANS.edu Graduate Certificate Program in
 Penetration Testing and Ethical Hacking. In diaries
 today, we have Jan analyze some interesting piece of
 malware that led him to an instance of loss of loader.
 What happened here was, first of all, a somewhat targeted
 email arriving. Luckily, the email was detected by anti
 -malware and also would have been blocked by, well, your
 usual DKM and SPF precautions, which the sender domain had
 enabled properly. But where it got interesting was when Jan
 actually analyzed the malware itself. And there are two
 components to the malware that are playing together. The
 first component is obfuscated JavaScript. And Jan does a
 great job in sort of showing how to de-obfuscate this
 JavaScript. And then some PowerShell is being called.
 But the JavaScript and the PowerShell are exchanging
 information via environment variables. So this certainly
 sort of throws a wrench into a lot of reverse engineering
 pipelines and such. Because first, you need to go through
 the JavaScript, which actually will then create an encryption
 key that is used to then decrypt part of the
 PowerShell. Well, yesterday I talked about tags and scans
 for a fairly obscure PBX control framework. Today we
 have news of a much more popular framework, the ISSABEL
 framework, which is used to control PBXs, basically phone
 systems, via web applications. Well, this particular
 framework contained a hard -coded JWT key, so basically
 the secret key being used to sign these JSON web tokens.
 With that key, it was possible to essentially bypass
 authentication. The result was that you could actually
 execute arbitrary code on any kind of asterisk server that
 was linked to an ISSABEL framework frontend. A patch
 has been submitted to this, but exploitation has already
 been observed in the wild by the Shadowserver Foundation.
 And one of my favorite things in security and defense, of
 course, is deception with honeypots, honey tokens, or,
 well, any number of decoys. CISA published an interesting
 document about using cyber decoys to strengthen detection
 and response. That's the title of the document. And what it
 essentially does is it sort of goes through the process that
 you should follow if you're planning to deploy decoys.
 Now, again, I'm a huge fan of this concept overall. The part
 that has often been missing is sort of an enterprise-wide
 framework, particularly for larger organizations, for
 enterprises, to deploy these kind of decoys. And there have
 been a number of products that try to do this. None of them,
 I think, really sort of took off. My personal opinion is
 always that one reason why decoys are often not deployed
 or then discontinued after they're being deployed is,
 well, two little false positives. You don't really
 see them working unless they actually get hit by an attack.
 But either way, if you're interested in decoys, if you
 want to sort of have a more structured process in
 deploying them, well, this document really has some nice
 ideas and sort of frameworks to actually follow. And we
 have another victim of the ever-increasing number of
 vulnerabilities. CISA decided to sunset its weekly
 vulnerability bulletin. This was a list basically of all
 vulnerabilities. And, well, that, of course, has become
 rather unwieldy lately. So what CISA is now saying is,
 well, they're no longer going to publish this. The final one
 will be on September 28th, so end of the month. And beyond
 that, they're referring to the more risk-based approaches
 like the known exploit list and other feats, of course,
 that CISA publishes to essentially identify
 vulnerabilities that matter. Interesting approach, of
 course, and I completely understand why a list of all
 these vulnerabilities may no longer really be all that
 feasible. Since, of course, we still have our at-risk
 newsletter, and we intend to continue to maintain that for
 now. We have sort of made some adjustments to it over the
 last year to, again, try to prioritize rank
 vulnerabilities better to sort of have the ones that matter
 sort of bubble more to the top. And Unbound fixed two
 heap-based buffer overflows in its software. One of them may
 lead to unauthenticated remote code execution. Both of these
 vulnerabilities are related to DNSSEC, and the first one that
 may lead to remote code execution is one of those
 decompression issues where you have these compressed records.
 If they're pointing to themselves, you actually can
 end up with an overly large record that then fills the
 buffer. Sounds a little bit similar to like an older
 Microsoft DNS vulnerability that was like in a SICK
 record. I think not the DNSSEC, but sort of a
 precursor record. So maybe a little bit related to that.
 Either way, try to get this patched. Unbound is a DNS
 resolver often used sort of in small gateways and such. So
 IoT-style devices. That's where you often find Unbound.
 As a result, some of these devices don't always have
 strong protections against the exploitation of buffer
 overflows like address space, random layouts, and things
 like this. So that's why you really want to patch this and
 make sure that you are up to date, that your firmware for
 your router is up to date. Well, and that's it for today.
 Thanks for listening. Thanks for liking. Thanks for
 recommending. Thanks for subscribing. Next week, I'll
 be in Vegas at our science conference. I'll be teaching
 our Defending Web Application class. Actually, completely
 newly redone version of that class. So hope to see some of
 you there. I'll have plenty of stickers with me. Also spread
 some of them around. And we'll, as always, talk to you
 again on Monday. Bye. overall Thank you.
 Bye. Bye.