Handler on Duty: Xavier Mertens
Threat Level: green
Podcast Detail
SANS Stormcast Thursday, September 24th, 2026: Macfinger ClickFix; Malicious Terraform; MikroTik and F5 Big IP Vulnerability Details
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10108.mp3
Macfinger ClickFix; Malicious Terraform; MikroTik and F5 Big IP Vulnerability Details
00:00
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
Macfinger ClickFix Campaign
https://isc.sans.edu/diary/Macfinger%20ClickFix%20campaign/33360
Graphalgo campaign spreads to Terraform providers and Go Modules
https://www.aikido.dev/blog/graphalgo-terraform-go-modules
MikroTik vulnerabilities technical analysis,
https://cert.pl/en/posts/2026/09/mikrotrick-technical-analysis/
F5 Big-IP Vulnerability Details CVE-2026-94127
https://labs.watchtowr.com/is-this-a-joke-in-the-auth-header-f5-big-ip-unauth-heap-overflow-to-rce-cve-2026-94127/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Eastern | Feb 8th - Feb 12th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 19th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Orlando | Apr 12th - Apr 16th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Mountain | Apr 21st - Apr 25th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Baltimore | May 17th - May 21st 2027 |
Podcast Transcript
Hello and welcome to the Thursday, September 24th, 2026 edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich, recording today from Las Vegas, Nevada. And this episode is brought to you by the SANS.edu Graduate Certificate Program in Cloud Security. Well, to start out with, we have a diary by Brad today, again, doing some interesting malware analysis using network traffic. This particular sample is part of a click fix campaign that Brad calls MacFinger. The name comes from, well, this particular campaign targeting Macs and using some fingerprinting in order to figure out if they are actually targeting here or are connected to a Mac. Now, the click fix campaign itself uses a number of compromised sites, nothing really all that special on this end. But then it includes the actual capture that implements the click fix campaign again from legitimate but compromised sites, a trick that attackers like to use in order to bypass some reputation filters that defenders may have deployed. Once the victim is falling for the click fix campaign and copy pasting the script into the terminal, the exploitation starts and ends up with an info stealer in the end. Aikido published a blog post detailing a very specific supply chain attack. They call it the Craft Algo campaign. And the first thing that's odd, different about this campaign is that it actually takes advantage of malicious Terraform providers. Now, these Terraform providers will load Go modules that implement a remote admin tool, but they'll only load these Go modules if there is a very specific Docker container name and network ID present on the system. Only the SHA-56 hash is included in the malware, so it's unclear what this exact name is. But Aikido assumes that this attack was supposed to target a very specific organization. Now, why would someone install these malicious Terraform providers? The reason here is typosquatting that they mimic very popular Docker-related Terraform providers. If you're interested in more details, please refer to the Aikido blog. And the Polish cert has published a detailed write-up regarding two vulnerabilities that MicroTik recently patched in its router OS. If you remember, I talked about this when it was first reported that there was a vulnerability in MicroTik's router OS, specifically in the SH daemon that is delivered as part of a router OS, that allowed for an authentication bypass via SH and complete compromise of the router. Now, MicroTik did release patches, but no details about what exactly happened. The Polish cert is now filling this gap and they discovered two distinct vulnerabilities. One is a re -key during the authentication process with the SH server that bypasses authentication. The other part, and that's actually sort of the neatest part here I find in some ways, is in order to exploit this vulnerability, a username of dash two or minus two was used. Well, it turns out that that actually redirects the input to the SH daemon from the client. So that's another part here of the authentication bypass. Interesting write-up and definitely if you're running MicroTik, make sure you're up to date. Remember, this was also an SH daemon that's unique to MicroTik. So this is not a standard SH implementation like DropBear or OpenSH that they're deploying as part of a router OS. And yesterday I talked about an exploited vulnerability that was patched in F5's Big-IP devices. Well, today, we got the, as usual, quite entertaining write-up from WatchTowr about this vulnerability. The problem is, well, in hindsight, relatively straightforward. It's a buffer overflow in the auth header. You need a bit more than 16 kilobytes of data in order to trigger this buffer overflow. And WatchTowr, in reversing the patch released, basically found that they had no length check on that value at all. And the patch was essentially just adding this length check to the value before it's being copied into the buffer. The auth header can be quite large sometimes depending on what kind of tokens you use. So 16 kilobytes may not be that outrageous last actually a little bit longer than 16 kilobytes. But anyway, no matter the link, you still have to check that you're not copying any more than that into the respective buffer. Well, and that's it for today. So thanks again for listening, for subscribing, for liking. And yeah, also, if you have a minute, then please leave a good comment on your favorite podcast platform, like Apple Podcasts or whatever you're using to listen to this podcast. Thanks and talk to you again tomorrow. Bye. Bye.





