Podcast Detail

SANS Stormcast Thursday, September 17th, 2026: Hospitality Scans; Cisco, Acronis, and Pixel 0-Day; Dynamic Incident Response

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10098.mp3

Podcast Logo
Hospitality Scans; Cisco, Acronis, and Pixel 0-Day; Dynamic Incident Response
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

Scans Targeting Hospitality Applications
https://isc.sans.edu/diary/Scans%20Targeting%20Hospitality%20Applications/33344

Cisco Identity Services Engine Authentication Bypass Vulnerability CVE-2026-76460
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5

Acronis Local privilege escalation due to insecure file permissions CVE-2026-87886
https://security-advisory.acronis.com/advisories/SEC-10986

Pixel Update Bulletin—September 2026
https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01

Dynamic Incident Response (Free E-Book)
https://dynamicincidentresponse.com

My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich

Podcast Transcript

 Hello and welcome to the Thursday, September 17, 2026
 edition of the SANS Internet Storm Center's Stormcast. My
 name is Johannes Ullrich, recording today from
 Jacksonville, Florida. And this episode is brought to you
 by the SANS.edu Graduate Certificate Program in Cyber
 Defense Operations. The last couple days our honeypots got
 hit with a set of requests all coming from the same source
 that indicate a little bit more coordinated but very odd
 attack that targets the hospitality industry. So
 hotels and the like. There's also sort of a little bit
 focus on PBX, so phone systems. The URL that sort of
 made it stick out to me is for a product called PBX in a
 flash hospitality management system. Doesn't really look
 like much like a product when you look at the GitHub repo
 last update about 14 years ago. I think 10 years ago the
 license was updated but none of the code and the code looks
 maybe more like a proof of concept or such because it
 doesn't do any kind of input validation. So lots of SQL
 injection, pretty much any SQL statement in the code base
 that I sort of looked at was suffering from SQL injection.
 I also don't really see any authentication or access
 control in this product. But the intent of the product is
 to help you basically manage PBXs for hotels. There are a
 couple other URLs that are sort of a little bit related
 like UCP and HMS and well slash hotel. Also some more
 standard admin URLs that are being probed by this
 particular actor. What's also unique is the user agent
 phares-sorter. Haven't really seen that one before either.
 So I think right now it's really just odd and sort of
 caught my curiosity. So if anybody has any details about
 these attacks, maybe any insight into what products may
 actually be attacked here. There was also a bug report or
 vulnerability report, I should say, for this PBX in a flash
 product that dated from July. So maybe that sort of got them
 to scan for it. They really don't know. So if you have any
 ideas, please help me out. And Cisco today released an
 advisory alerting its customers that they patched a
 CVSS score 10 vulnerability in the Cisco identity services
 engine. It's an authentication bypass vulnerability. In this
 particular case, the API is not checking all of its
 endpoints, which is a very common problem, of course,
 with APIs. We have had issues like this with Cisco before.
 The identity service engine, as the name implies, it's used
 to essentially manage access to your network devices. So a
 vulnerability here could have far-reaching impact. And that
 also probably justifies the CVSS score of 10. This
 vulnerability has already been exploited. So that makes it
 even worse. As always, don't expose these APIs to the
 public and assume compromise. At this point, Cisco has added
 some indicators of compromise and ways to verify if you were
 attacked to its bulletin. And Acronis, the maker of backup
 software recently published an update fixing some
 vulnerabilities. One of these vulnerabilities is now being
 exploited in the wild. It's a privilege escalation
 vulnerability in their plugin for cPanel and Blesk.
 Privilege escalation vulnerabilities are usually
 not at the top of the list. And I often don't even mention
 them here. But in particular, with cPanel and Blesk, that's
 sort of the systems that you're using to administer
 sort of shared systems that customers may have access to.
 So privilege escalation is certainly a problem for a
 product like this, in particular, if it's already
 being exploited. So make sure you update the updates were
 released five days ago. Well, today's really one of those
 zero days, we do have another one this time in Google's
 Pixel phones. Google did publish its Pixel update
 bulletin for September today. And this update does include a
 fix for their modem code that does prevent an elevation of
 privilege of vulnerability. This includes also the
 September Android updates that were published last week. But
 always a week later, we get then the Pixel specific
 version, which of course does include some of the more
 hardware specific patches like vulnerabilities in the modems
 and other sort of specific hardware devices. Well, if
 you're in instant response, there is a great new free
 ebook that Josh Wright published for SANS. Josh, if
 you're not familiar with him, a great person and great
 instant responses. He's also responsible for our SEC 504
 class that deals a lot with some of the instant response
 aspects. But this particular ebook also introduces some of
 the more modern concepts when it comes to instant response.
 Very well done. And lots of great things that you have
 here. Also lots of contributions from the
 community in this book. So take a look. It's free and the
 link will be in the show notes. Well, and this is it
 for today. So thanks for listening. Thanks for liking.
 Thanks for recommending this podcast and talk to you again
 tomorrow. Bye.