Podcast Detail

SANS Stormcast Friday, September 25th, 2026: Tricky Phishing URL; MacSync Malware Update; SolarWinds Observable Patch

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10110.mp3

Podcast Logo
Tricky Phishing URL; MacSync Malware Update; SolarWinds Observable Patch
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

Podcast Transcript

 Hello and welcome to the Friday, September 25th, 2026
 edition of the SANS Internet Storm Center's Stormcast. My
 name is Johannes Ullrich, recording today from Las
 Vegas, Nevada. And today's episode is brought to you by
 the SANS.edu Graduate Certificate Program in
 Industrial Control Systems Security. First story comes
 from Xavier. Xavier looked at, well, an interesting phishing
 email with a URL that as Xavier analyzed it uses three
 different tricks. Now, first of all, it uses the good old
 user info field, which has often been abused in phishing.
 It's where in old style browsers, you were able to
 prefix a URL with a username and a password. These days,
 they should pretty much be ignored, but well, still works
 in the sense that you still end up at the actual URL that
 follows that username. Now, the first trick here that the
 attacker used was to make the username password part
 actually unique to the particular email. So that
 makes filtering a little bit more difficult. Also, the host
 name is actually invalid. The first label of the host name
 ends in two dashes. Well, host names or labels cannot end in
 two dashes or dashes at all, according to the RFC. But as
 so many things, it will just work. In the end, of course,
 we do have the email address that the particular phishing
 attack went to, which will then be used in order to pre
 fill any phishing page with the right email address and
 often things like logos for the particular trusted domain.
 So it's an interesting URL being used here, something
 that definitely can be blocked, but may not be
 blocked because, well, it may not be recognized even as a
 valid URL, or may be wrongly characterized as the trusted
 host name, not the one that the attacker is actually
 using, due to the use of multiple ad symbols in the
 URL. Well, in second day in a row that we have a story from
 aikido. This particular story affects GitLab. And while
 maybe technically not a vulnerability, it's certainly
 a significant weakness. GitLab allows you to configure an
 email address that can be used to send various requests to
 your GitLab repositories. Now the trick with these email
 addresses is that they include a secret, basically a random
 string, that is the only thing that really authenticates
 these email addresses. What makes the thing even worse is
 that, well, these email addresses have wide reaching
 permissions. Now the email address ends, for example,
 with dash issue, which would allow you to add an issue. But
 by changing this suffix, different features are
 available to anybody who knows the secret string. How would
 an attacker learn about the email address and the secret
 string? Well, apparently, according to aikido, some
 users of GitLab may not properly understand the power
 of these email addresses. And it may be sounding benign to
 the user to provide, for example, as part of a readme,
 an email address with the dash issue suffix to their
 customers in order to allow them to easily report issues
 with the application. On the other hand, it's pretty
 straightforward to then change the suffix to other features
 that are available via via these email addresses, like,
 for example, push or merge requests with the email
 address, just by sending a simple email to the particular
 address. Apparently, it's not possible to limit the from
 address, which wouldn't be all that strong anyway, but still
 a little bit better, or apply other restrictions to the
 addresses once they are defined. And Kaspersky found a
 new version of the Mac sync malware. Now, this malware
 typically spreads via click fix exploits, but has also
 been found to impersonate, for example, crypto coin wallets.
 One particular case, the attacker even set up a
 complete webpage for the crypto coin wallet application
 to make it look more legit. Now, where things get a little
 bit different now is, and I think that's the most
 interesting part of this, that the part of the payload is
 actually retrieved via the iCloud calendar. So by
 retrieving and syncing calendar entries, the payload
 is being retrieved to the system.
 And the other part of the Mac sync is that it is not the
 same as the main thing that you typically find in
 organizations. And even on the host of endpoint defenses, it
 may even evade some of the techniques that they're using,
 because well, it never really sort of is received via the
 network, at least not in a visible way. The other part
 that changed with Mac sync is that it now uses binaries,
 compiled Objective C or Swift code, and no longer just uses
 scripting languages.
 And SolarWinds released update for SolarWinds observability.
 So if you're self hosting this product, you may want to
 consider updating. Now, both vulnerabilities are remote
 code execution vulnerabilities. Neither of
 the vulnerabilities does require authentication.
 However, one requires specific insecure, so known insecure
 configuration that's not default. The other one does
 require specific communication modes to be enabled. I would
 still try to get this patch that just in case that a
 configuration changes later, wouldn't really rely on just
 running the right not vulnerable configuration from
 protecting you here in the longer term. Well, and that's
 it for today. So thanks again for listening. Thanks for
 liking. Thanks for subscribing. Thanks for
 leaving good comments about this podcast in your favorite
 podcast platform. And talk to you again on Monday. Bye.