Podcast Detail

SANS Stormcast Monday, August 17th, 2026: MacOS Screen Sharing; GeoServer Patch; SAP Exploited;

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10054.mp3

Podcast Logo
MacOS Screen Sharing; GeoServer Patch; SAP Exploited;
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

Podcast Transcript

 Hello and welcome to the Monday August 17th, 2026
 edition of the SANS Internet Storm Center's Stormcast. My
 name is Johannes Ullrich recording today from
 Jacksonville, Florida. And this episode is brought to you
 by the SANS.edu undergraduate certificate program in Applied
 Cybersecurity. Well, let's start today with two
 vulnerabilities that I've already talked about, but
 there are a couple updates to them. So first of all, the
 Apple vulnerability in screen sharing. This one was patched
 a little bit less than two weeks ago. And yes, it's
 actively being exploited now, according to the Dutch
 Information Security Agency. We have seen detailed
 descriptions, proof of concept exploits, so no real surprise
 that this is now being exploited. Definitely make
 sure that you patch this vulnerability. It's also
 probably a good idea to review how you're using screen
 sharing. It should never really be exposed to a
 network. I can see where people use it sort of in their
 home networks and such, but then don't turn it off as they
 connect to external public networks as they're traveling.
 So that's certainly a risk here that you need to be aware
 of. The second vulnerability is the vulnerability in
 GeoServer. So this was an unauthenticated SQL injection
 vulnerability. It does not affect the default
 configuration, but yes, it's also already being exploited.
 Not sure how common the configuration that enables
 this issue is actually. The GeoServer patch here has been
 released now, but there is at least at this point, I
 believe, no CVE number for it. They're still waiting for one
 to be issued. And Cyber Intel Company Defused states in an
 ex-post that they have seen active exploitation against an
 SAP vulnerability, a remote code execution in SAP Commerce
 Cloud. This was patches part of Patch Tuesday. SAP also
 tends to release patches on Patch Tuesday. So a couple of
 days after the patch was released, this was already
 exploited. Definitely at this point do assume compromise,
 even though Diffused hasn't made public sort of any
 details about what they're seeing. So not quite clear
 what the payload, for example, is like and what an attacker
 is trying to accomplish with these scans. And yes, supply
 chain attacks keep evolving. The latest example is a worm
 referred to as Chaintrop by Microsoft. Others have picked
 up this particular name for this worm. There's a good
 write-up now by Abby Kearns with ActiveState about this
 particular incident. At the time of Abby writing this
 particular article, 444 packages were compromised. And
 as pointed out in the blog post, it did use a different
 activation method than what we typically have seen in these
 worms. Typically, they used the NPM configuration file in
 order to run any post-install scripts that then ran the
 malicious code. Well, a lot of security tools are now
 scanning these configuration files and are warning the user
 or blocking these install scripts. Instead, what this
 particular worm does is that it comes with a settings file
 for IDEs. In this particular case, Visual Studio Code, as
 well as for a cursor, I believe. And in these
 configuration files, you can execute code as this
 particular file or the files in this library are being
 opened by the IDE. So I talked about this particular vector
 before. This is certainly something you do want to take
 a look at. Remember, if your IDE asks you whether or not
 you trust a particular directory as you're opening as
 a project or such, well, definitely be aware that the
 reason for this pop-up is that code in configuration files
 may be executed as soon as you open these files. And
 apparently, this was quite successful here. And as all
 the other worms, it does steal NPM and GitHub credentials.
 Well, and that's it for today. Thanks for liking. Thanks for
 subscribing and recommending this podcast. And remember, I
 will be teaching our Defending Web Application class in
 September in Vegas. And then in October in Amsterdam, I'll
 be teaching our Intrusion Detection class. So that's it
 for today. Thanks and talk to you again tomorrow. Bye.