Hello and welcome to the Monday August 24th, 2026 edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich, recording today from Jacksonville, Florida. And this episode is brought to you by the SANS.edu Bachelor's degree program in Applied Cybersecurity. Well, on Friday, we got two more diaries from Rob showing how to interface PowerShell with EnteraID and how to better collect and summarize some of the events that you are getting out of EnteraID's logging. First one is about multi factor authentication. So the goal here is after you set up and configured multi factor authentication and rolled it out, well, to make sure that you really rolled it out completely and to look in any gaps, any accounts and such that are not yet using multi factor authentication. So really useful to identify these kind of lagging accounts and hopefully get them up to compliance fairly quickly. The second issue here is looking at the Entera logins. And this is like failed as well as valid logins, and then basically enrich that data with additional details. Like for example, IP addresses, the country the login came from, again, looking for some suspicious logins. On Thursday, Rob wrote a similar script where it was about the risk factor of particular logins. So this is sort of more universal and then you define kind of your own risks and your own cautions, which can work quite well if your organization, for example, is more geographically focused. If users usually log in from company systems via VPNs and such, then this will become quite useful. When talking about Microsoft's Entera ID product, on Thursday, Microsoft did publish a bulletin indicating that they did patch remote code execution vulnerability in Entera ID. This was a deserialization vulnerability. Now, what originally sort of caused some confusion was that Microsoft had marked this vulnerability as already being exploited. Later, they reversed this and they're announcing it has not yet been exploited. It's a deserialization vulnerability. So exploitation wouldn't necessarily be sort of out of the question for a vulnerability like this if an external entity discovered this vulnerability. But yes, right now, it doesn't look like it already was exploited. Now, there's nothing you need to do that affected Microsoft's own systems. They are and they have done this repeatedly in last year or so, been more transparent about vulnerabilities like this in their cloud software where they are publishing CVE numbers and bulletins just like for any sort of customer run software vulnerability. And this is just another case of this critical vulnerability. Microsoft patched it. So hopefully they caught this before it was actually exploited successfully. And then we do have an update for GitLab. This fixes two vulnerabilities. The first one is an interesting one. It's a code injection issue via GraphQL directive. This allows an unauthenticated attacker to delete or modify repositories. The modification part here is, of course, particularly tricky that could, I guess, lead them to sort of a full supply chain attack. The second one is a cross-site request forgery. Well, I talked a little bit about these type of attacks last week. And certainly don't underestimate them, but this one is less severe. Now, for the code injection issue, there is also proof of concept exploit code available. Definitely make sure if you're running GitLab on-prem that you're patching this. Well, and if you're at all involved in online gaming, you may have heard about the leak of Grand Theft Auto VI, the latest release of this game. And apparently there is currently an archive going around 113 gigabytes in size, which is a reasonable size for a game like this. But this archive does come with additional goodies in the form of malware. It's a very typical technique. And again, if you are involved in online gaming, you probably have seen this before, where either sort of jailbreaks or cheat codes or any kind of sort of gaming related software is often distributed with a malware attached to it. So be careful what you download and maybe wait for the official release of the game. Well, and that's it for today. So thanks for listening. Thanks for liking. Thanks for subscribing. And talk to you again tomorrow. Bye. Bye.