Podcast Detail

SANS Stormcast Wednesday, September 2nd, 2026: Guildma Update; Proxmox 7 Auth Bypass; Windows Hotpatch; Virtualizor BGP Hack

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10078.mp3

Podcast Logo
Guildma Update; Proxmox 7 Auth Bypass; Windows Hotpatch; Virtualizor BGP Hack
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

Podcast Transcript

 Hello and welcome to the Wednesday, September 2nd, 2026
 edition of the SANS Internet Storm Center's Stormcast. My
 name is Johannes Ullrich, recording today from
 Jacksonville, Florida. And this episode is brought to you
 by the SANS.edu graduate certificate program in cyber
 security engineering. Today's diary comes from Brad updating
 us on Guilma and Astaroth. This malware is targeting
 users in Brazil. The email linking to the malware is
 written in Portuguese and the website hosting the malware
 only allows connections from Brazilian IP addresses.
 Further, the browser must identify as using Brazilian
 Portuguese and have the Brazilian local settings
 applied. Otherwise, you're just getting some benign
 software. The initial download is a zip archive that contains
 a link file. The link file will point to another website,
 download a DLL and then save it as an alternate data
 stream. Further obfuscating what's actually going on and
 probably also attempting to try to evade some anti
 -malware. As usual, Brad walks you through the entire
 installation. What exactly happens on the system,
 indicators of compromise and does of course provide packet
 captures that you can then use to follow the analysis
 yourself. And popular virtualization software vendor
 Proxmox is warning its users that there is currently an
 ongoing campaign against an unpatched vulnerability in
 Proxmox. Now unpatched here is with sort of quotations, a
 little footnote here. It's unpatched in Proxmox. 7.7
 hasn't been supported for the last two years. So it's an old
 end of life version of Proxmox that's affected. If you're
 using Proxmox 8 and 9, 9 being the most recent version, you
 should be good. This is an authentication bypass
 vulnerability that's currently being exploited. Proof of
 concept has also been made available. So exploitation is
 actually rather straightforward. The cause
 here is a problem with libPVE access control and Proxmox
 does recommend that you double check what version of this
 library you may be running as it may not always be in sync
 with the Proxmox version that you're running. So if this
 library has a version of less than 8.0.4, then you
 potentially have a problem. Also, if you apply multi
 -factor authentication, then you are not exploitable if you
 are running a vulnerable version of the library. Well,
 staying with major version updates is always a good idea,
 in particular if the older versions then are no longer
 supported. So definitely you should be running Proxmox 9 by
 now. It has been out for quite a while. Next Tuesday, we are
 expecting Microsoft's Patch Tuesday. Well, we do have
 something a little bit different here. For this Patch
 Tuesday, Microsoft updated its hot patch calendar. Typically,
 you only need to reboot Windows Server once a quarter.
 So the next quarterly reboot would have come up in October,
 but Microsoft now announced that September you'll also
 have to update your servers. This isn't the first time they
 have done it. They've done the same thing in June and July,
 both months you had to reboot your servers. They call this a
 baseline release, which basically can't just simply be
 applied as a hot patch without rebooting. And again, really
 only affects server environments. And Virtualizor,
 a company that distributes cloud management software, was
 the subject of a rather sophisticated routing attack.
 The attacker managed not only to reroute traffic to
 Virtualizor using BGP Hijack, we have seen that quite a bit
 before, but in addition was also able to impersonate
 Virtualizor's software distribution website using a
 valid TLS certificate. That's usually your second line of
 defense here against these machine middle attacks where,
 well, you have TLS that should prevent this. The attacker
 used the machine in the middle attack to distribute malicious
 Virtualizor update packages. The certificate apparently was
 obtained via Let's Encrypt, and well, with Let's Encrypt,
 you can basically get a new certificate if you control the
 website. And that's actually the standard now with pretty
 much all of the public set of authorities. So that's
 essentially what they did here. Now, set of authorities
 do have a proposed countermeasure here where they
 are actually axing the website from different vantage points
 around the internet. So that is supposed to make these BGP
 Hijack attacks more difficult. But in this particular case,
 well, this apparently didn't prevent the attack and the
 attacker was able to distribute a malicious update
 package to Virtualizor customers. Virtualizor says
 that only few of the customers were affected by this. Not
 sure if they have a good count of effective customers, but if
 you're using their product, definitely double check on
 their website for indicators of compromise. Well, and
 that's it for today. Thanks for listening. Thanks for
 liking. Thanks for subscribing. And thanks for
 recommending this podcast. And talk to you again tomorrow.
 Bye.