Handler on Duty: Johannes Ullrich
Threat Level: green
Podcast Detail
SANS Stormcast Wednesday, October 7th, 2026: RMM Tools; libHEIF RCE; Sonicwall SMA1000, OpenSSH updates, DNSSEC KSK Rollover
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10126.mp3
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
More RMM Tools In the Wild
https://isc.sans.edu/diary/More%20RMM%20Tools%20In%20the%20Wild/33400
WORDPRESS LIBHEIF RCE
https://fortbridge.co.uk/research/wordpress-libheif-rce/
SONICWALL SMA1000 SERIES APPLIANCES Vulnerabilities CVE-2026-102255, CVE-2026-102256, CVE-2026-102257, CVE-2026-102258
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017
OpenSSH 10.6 Released
https://seclists.org/oss-sec/2026/q4/58
DNSSEC Root Key Signing Key Rollover
https://blog.cloudflare.com/root-ksk-2024-rollover/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Eastern | Feb 8th - Feb 12th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 19th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Orlando | Apr 12th - Apr 16th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Mountain | Apr 21st - Apr 25th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Baltimore | May 17th - May 21st 2027 |
Podcast Transcript
Hello and welcome to the Wednesday, October 7th, 2026 edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich, recording today from Jacksonville, Florida. And this episode is brought to you by our SANS.edu Bachelor's Degree Program in Applied Cybersecurity. In Diaries today we have Xavier talking about yet another abuse of a valid remote management tool. In this particular case it's a tool by ActionOne called Agent or A1 Agent it's sometimes referred to. This again is a legitimate Windows remote management, remote monitoring tool that sort of includes some VPN-like encryption abilities and the like. Well, really all that an attacker kind of likes to have. And in this case it's being installed via a malicious PDF. The PDF arrives as a fake Adobe update and actually just the other day I was talking to someone that we don't really see many Adobe Flash Player updates anymore. Maybe people understand now that this software no longer exists. Well, this actor here still attempts to do that. It's the usual fake PDF invoice that you're getting here. Xavier talks a little bit about how to analyze this sample and it uses this action item where you can basically open a URL as you open the PDF in order to then direct the victim to the next site. The first stage of the malware in this case a simple Visual Basic script that will then download the actual malware or well actually not malware here. I guess in this case the actual remote management tool. So as I said before, monitor these remote management tools and make sure that any traffic you are seeing comes from approved legitimate tools. Again, you can't really trust too much into antivirus and endpoint detection here because they often don't flag these tools because they're valid software. And Fort Bridge showed how vulnerability in libHEIF can be used for remote code execution. Now, libHEIF is for the HEIF or HEIF file format that has become popular. I think Apple sort of started that file format. And lately, that's why I mentioned this particular issue. There have been a number of vulnerabilities tied to vulnerabilities in the HEIF parsers like libHEIF. So it's definitely something to keep an eye on if you are parsing HEIF images. If you're using any open source or commercial libraries for that matter, not sure what exactly exists here in the commercial space. Definitely watch for updates. There's a lot of effort currently in finding these type of vulnerabilities in HEIF implementations. And the insecure security appliance of the day is SonicWall's SMA-1000, the friend of the show. We had him quite a few times before. This time it's a CVSS score 10 vulnerability. It's a server-side request forgery vulnerability that does allow an unauthenticated user to essentially perform arbitrary actions. Not a ton of detail here. It sort of also talks about alternate control path or so. Doesn't mention a different sort of URL string bypass or anything like that. But the way the server-side request forgery vulnerabilities typically work is that you have an internal service listening on loopback. Because it's listening on loopback, well, it doesn't really do any kind of authentication access control. And you can use the server -side request forgery vulnerability to use the front -end as a proxy to reach these internal services. And OpenSSH released version 10.6. This version does, of course, fix vulnerabilities. But the reason I mention it is not a specific vulnerability. Nothing really too critical here. But two additional remarks that come with this release. One is the OpenSSH project. Like everybody is receiving a lot of submissions that were created by AI. So you will see more frequent releases of OpenSSH to address these vulnerabilities. And secondly, they're also pointing out, and I think that's a real good point. People receiving these bug reports often complain about duplicate reports. But what they're saying is that, well, the real problem here is since they get duplicate reports, these vulnerabilities are now really not that hard to find. So if they get these reports, it means others probably that didn't report it also have that information. And so delaying patches really doesn't buy you any time here. And that's, you know, again, why they're moving forward with a more accelerated release schedule. They're not suggesting a specific rhythm here or anything like this. They are just saying that releases will be published more frequently. And well, since DNS is my favorite internet protocol, I must mention that October 11th, the key signing key for the root zone is going to change. This is only the second time that this key has been updated. First time actually turned out to be a little bit messy. Since then, they did make a lot of improvements with automatic key rotation and things like that. The key has been published for, I think, over a year now. I'll link to a blog post by Cloudflare that has additional details on how to check if your resolver is ready for this new key. Well, and that's it for today. So thanks for listening. Thanks for liking. Thanks for subscribing. By the way, next week I will be in Amsterdam. So if anybody is at the SANS event in Amsterdam, look me up. And that's it for today. Talk to you again tomorrow. Bye. All right. Bye. Bye. Bye. Bye, bye. Bye. Bye. Bye, bye. Bye. Bye. Bye. Bye. Bye. Bye.





