Podcast Detail

SANS Stormcast Thursday, August 20th, 2026: Cloud Metadata Scans; Oracle and Netscaler Patches; Fake Ransomware Rescuers

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10060.mp3

Podcast Logo
Cloud Metadata Scans; Oracle and Netscaler Patches; Fake Ransomware Rescuers
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

Simple Scans for Cloud Metadata Service
https://isc.sans.edu/diary/Simple%20Scans%20for%20Cloud%20Metadata%20Service/33260

Oracle Critical Security Patch Update Advisory - August 2026
https://www.oracle.com/security-alerts/cspuaug2026.html

NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939

Beware of Ransomware Rescuers
https://www.guidepointsecurity.com/blog/beware-ransom-busters/

My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich

Podcast Transcript

 Hello and welcome to the Thursday, August 20th, 2026
 edition of the SANS Internet Storm Center's Stormcast. My
 name is Johannes Ullrich, recording today from
 Jacksonville, Florida. And this episode is brought to you
 by the SANS.edu graduate certificate program in cyber
 defense operations. Today I wrote about a scan that we are
 seeing lately and actually a few thousand events related to
 this scan that probes cloud metadata services via server
 -side request forgery. Cloud metadata services, they are
 implemented in all big cloud providers. You also are being
 used to basically have a simple REST-based interface
 that provides metadata about the system, like for example,
 MAC addresses and the like, but it can also provide
 credentials and that's what attackers are usually after.
 And based on the URL, yes, this attacker here as well.
 The question with this particular attack is what
 vulnerability they are targeting. The attack looks
 like a textbook server-side request forgery, just URL
 equals and then the URL they're trying to access. It's
 possible that there's popular software that is vulnerable to
 this sort of the most straightforward server-side
 request forgery, but it might be maybe more sort of a little
 bit of phishing expedition trying to find vulnerable
 systems that may just use some demo software or where a
 developer maybe just experiment a little bit with
 sort of URL fetching of particular data and they're
 just hunting for that. But if anybody has any insight as to
 the specific vulnerability they may be looking for,
 please let me know. And Oracle released its Credible Security
 Patch update for August. This update fixes 943 different
 vulnerabilities across 75 different products. Now, a
 while ago, Oracle sort of changed its patch release
 cycle. In addition to the quarterly Credible Patch
 update, we now have the Critical Security Patch update
 once a month. The last Credible Patch update had
 something like 1400 different vulnerabilities being
 addressed. The last security patch update was only sort of
 around 300. So we certainly see an increase here. However,
 it's across 75 different products. The one product that
 I sort of noted is the Fusion Middleware. That's something
 that we have seen being exploited in the past. So
 certainly one of those products to pay attention to.
 And it had one vulnerability with a CVSS score of 10 and
 then several looked like a couple dozen or so with 9.9
 and 9.8 CVSS scores. So that's certainly something that you
 probably want to prioritize if you are running it in your
 environment. Well, we haven't heard from Citrix in a while,
 but yes, we do have a new advisory here that's
 noteworthy. This advisory fixes two vulnerabilities in
 Netscaler ADC as well as Netscaler Gateway. The first
 vulnerability is a memory overflow vulnerability. Well,
 as I say, it leads to unpredictable behavior or
 denial of service. I'm not sure if unpredictable behavior
 also includes some kind of remote code execution, but
 they rate it with a CVSS score of 8.8. The second
 vulnerability looks more interesting. It's a path
 traversal vulnerability that can lead to authentication
 bypass and is scored with 9.3. Now for this vulnerability to
 be actually exploitable, you must configure your gateway as
 a gateway. So something like the SL VPN or a proxy has to
 be enabled. Definitely get this addressed. Like I said,
 we have had a lot of interest from ransomware actors and
 such in vulnerabilities against the Citrix gateways in
 the past. So definitely make sure you get this patched. And
 GuidePoint Security published a blog post with an
 interesting new way how ransomware actors are
 operating. Apparently what's happening here is that after a
 company is affected by ransomware, a recovery company
 is reaching out to them, in particular a recovery company
 called Ransom Busters, assisting in actually
 negotiating the ransomware payment or recovery from the
 ransomware. Since this contact issue happens before anything
 about the particular attack has become public, they assume
 that it's the ransomware actor himself reaching out here. And
 I think it should be somewhat obvious also to the victim
 here that this contact is coming from someone affiliated
 with the ransomware actor. In my opinion, this may be a
 little bit a trick on the side of ransomware actors to
 essentially allow companies, allow victims to pay the money
 without actually paying a ransom. Because in this case,
 they're just paying a consulting fee and they're
 getting their keys back because Ransom Busters
 apparently knows how to recover the encryption keys.
 And they're then able to decrypt their data. Well, and
 that's it for today. So thanks for listening. Thanks for
 liking this podcast. Thanks for recommending it. Thanks
 for any feedback you may have and talk to you again
 tomorrow. Bye.