POPULARITY
Categories
From Best Buy to Cybersecurity: Curiosity, Confidence, and Finding Your Place in TechIn this episode of No Password Required: Next Gen, Yazzel interviews Karina Rosario, Applications SOP Writer at ThreatLocker. Karina shares how her curiosity about technology led her from working at Best Buy and Geek Squad to earning her bachelor's degree in cybersecurity and beginning her career in the industry.From building a strong IT foundation to learning how important networking can be, Karina keeps it real about what it actually takes to break into cybersecurity. She talks about why a career in cyber is a “slow burn,” the value of taking chances on yourself, and how experiences from outside of cybersecurity can become some of the most valuable skills in your career.Outside of cyber mode, Karina brings plenty of personality to the conversation, from being a Nintendo and Fortnite fan to imagining her own cybersecurity sidekick in the world of Kim Possible. She also opens up about being a first-generation college graduate and her goal of becoming a voice for young women and girls entering cybersecurity.Karina's story is a reminder that there is no single path into cybersecurity. Sometimes the experiences you least expect can become the foundation for where you're headed next.Find Karina on LinkedIn here: https://www.linkedin.com/in/karina-r-3088691b9/Presented by ThreatLocker Supported by DerscannerChapters: 00:00 Introduction to Karina and Her Role at ThreatLocker03:00 Journey into Cybersecurity: Education and Inspiration05:51 Skills and Qualities for Success in Cybersecurity09:05 Personal Interests and Hobbies Outside of Work12:02 Empowering Women in Cybersecurity and Future Aspirations
Internet users increasingly interact through emerging digital platforms and communities, which create complex online safety, security and privacy challenges that aredifficult to navigate. This talk will present insights from our research to understand the rising online safety landscape and improve online safety governance. I will first present our work characterizing online community responses to globalized scam-driven human trafficking, which received a Best Paper Award at ACM CHI 2026. Scam-driven cross-border human trafficking has become a long-standing societal crisis in Asia. Through our analysis of community responses on RedNote, a major Chinese social media platform, we identify several key challenges, including cultural values that can both enable trafficking and hinder survivors' recovery. Although online communities develop and share protective strategies, these efforts are complicated by uncertainty about the reliability of available support and difficulties in cross-border coordination. I will discuss the implications of these findings for prevention, platform governance, and international cooperation against scam-driven trafficking. Building on this work, I will then highlight opportunities for more proactive approaches to governing digital platforms and online communities, drawing on insights from our parallel research efforts. Finally, I will reflect on methodological lessons from our research and motivate discussion about future opportunities for studying and improving online safety, security and privacy in emerging digital environments. About the speaker: Jingjie Li is a Lecturer (Assistant Professor) in the School of Informatics, University of Edinburgh. His work spans privacy, security, and online safety,with the goal of seamlessly integrating these principles into emerging human-centered technologies such as smart homes, augmented and virtual reality, and AI-enabled systems. He published impactful work at premier conferences in security and privacy (IEEE S&P, USENIX Security, and ACM CCS), human-computer interaction (ACM CHI and ACM CSCW), and computer systems (IEEE/ACM ISCA, IEEE TMC and IEEE TVLSI). His interdisciplinary work received multiple best paper awards and has informed industry development and policymaking with key stakeholders across countries. Before joining the University of Edinburgh, Jingjie obtained a Ph.D. degree from the University of Wisconsin-Madison in 2023. For more information, please visit his homepage: www.jingjieli.me
Alex Bores, elected assembly member for the 73rd District of New York, a computer scientist, and co-founder of Who Decides, an effort to align the Democratic message on AI, joins Chris this week. Together, they sort through the Hugging Face incident, in which AI agents went rogue, and what it tells us about where we are with AI right now. And the answer is ... in a strange place. Because what's come to light about what happened in an Open AI testing environment back in May sounds like science fiction. This conversation includes imagining AI agents as teenagers leaving secret notes in a supply closet, a modern day John Henry battling a swarm trying to take over a German-language Wikipedia page, an InfoSec presentation that left jaws on the floor, and the development of an almost cultural convention among AI agents that persisted after it had ceased to be useful. "There are people that are like, 'Don't engage in this narrative. It's science fiction,'" says Bores. "I actually think engage and wrestle with all that weirdness. You're gonna find things beyond science fiction that might hold the solution for how we end up doing this safely." Sign up for MS NOW Premium on Apple Podcasts to listen to this show and other MS podcasts without ads. You'll also get exclusive bonus content from this and other shows. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
HTTP QUERY Method: The Grey Zone Between GET and POST https://isc.sans.edu/diary/HTTP%20QUERY%20Method%3A%20The%20Grey%20Zone%20Between%20GET%20And%20POST./33352 Simple MacOS Docker Escape https://www.accomplish.ai/blog/escaping-dockers-hypervisor/ CVE-2026-77179 Brevo ClickFix Compromise https://status.brevo.com/incidents/01M2QBC4EZ24ZACW6SWQYVW8N3/write-up LastPass (and other) lookalike GitHub Repo and Kernel Module Infostealer https://blog.lastpass.com/posts/lastpass-delphos-report-rapuncel-infostealer My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
In this month's special edition of the 2GT Podcast, I sit down with Lester Nichols, a long-time 2GT fan and the author of the Cybersecurity Architect's Handbook — 2nd Edition. And to be clear, this isn't a sponsored interview; Lester sent a copy with no strings attached, and once I started reading it, I had to get him on the show.Lester walks us through his path from pre-med student to senior security architect — including the time an Access database he built for an anesthesiologist exposed a skimming biller, and how Norwich University's information assurance program launched his career. We dig into what makes the 2nd Edition "transformational" rather than just an update: a full rewrite of every chapter, the fight to keep the foundational chapters the publisher wanted cut, labs that now build progressively on each other (ending in a human-in-the-middle AI automation exercise), and a combined 1,400+ pages of book, labs, and supplemental material — all using free, open-source tooling you can replicate in a #homelab.Beyond the book, the conversation gets big: the record Microsoft month and what AI-assisted vulnerability discovery means for patch management, supply chain attacks from SolarWinds to 7-Zip, why zero trust is still very much valid in a post-AI world (trust levels, segmentation, thinking the what-ifs), China's quantum claims and the legacy systems hiding in every enterprise's closet, all-in-one firewall failures, and honest, career-long advice for people new to InfoSec — fundamentals, burnout, and beating imposter syndrome. Links to the book, Lester's GitHub, and his blog can be found here:https://secdoc.tech/https://github.com/secdochttps://github.com/secdoc/Recommended_Readinghttps://github.com/secdoc/soc-pipeline-publichttps://www.amazon.com/Cybersecurity-Architects-Handbook-architects-enterprise/dp/180610539X/https://github.com/secdoc/devsecops-pipeline-publicSend us Fan MailSupport the showThis video is brought to you by us! Check out HomeLab Gear here: https://homelabgear.shop/Visit our website here: https://2guystek.tv/ for all things 2GT! And thank you so much for listening!
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
LausivLoader analysis, or how to pass data between malware stages https://isc.sans.edu/diary/LausivLoader%20analysis%2C%20or%20how%20to%20pass%20data%20between%20malware%20stages/33348 Issabel Framework Hard-coded JWT Key RCE CVE-2026-89026 https://www.vulncheck.com/advisories/issabel-pbx-hard-coded-jwt-key-rce-via-pbxapi-manager-originate Using Cyber Decoys to Strengthen Detection and Response https://www.cisa.gov/sites/default/files/2026-09/using-cyber-decoys-to-strengthen-detection-and-response_508c.pdf CISA to Sunset Weekly Vulnerability Bulletin on September 28, 2026 https://content.govdelivery.com/accounts/USDHSCISA/bulletins/42b055b Unbound Vulnerability https://nlnetlabs.nl/projects/unbound/security-advisories/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Remote hiring, freely available deepfake tools and harvested identities have created an opportunity that organized criminals are now taking seriously. State-backed operations are training workers to apply for remote roles using stolen credentials and proxy interviewers. The aim is the salary and access to source code, customer data and intellectual property once they are inside. Recruiters are the ones meeting these people first, and in most organizations they are assessing them with a background check and their own judgment while IT, InfoSec and legal are rarely involved. So how seriously should employers be treating this, and what does a credible response look like? My guest this week is Lauren Furey, Principal Product Manager at Proof, where she leads product work on candidate fraud and identity verification. In our conversation, Lauren explains how these attacks work, where hiring processes are most exposed, and what TA teams can do about it. In the interview, we discuss: Bots, deepfakes, identity harvesting and proxy interviewers The criminal motivations behind state-backed infiltration Why the background check is no longer enough on its own How much recruiters overestimate their ability to spot a fake Why remote hiring created the gaps bad actors exploit Building identity continuity through the hiring process Making fraud prevention a shared responsibility with IT and InfoSec The candidate experience trade-off and where to place verification Verifiable credentials and protecting candidates' own identities Practical first steps and what does the future look like? https://www.linkedin.com/in/laurennfurey/ https://www.proof.com Follow this podcast on Apple Podcasts. Follow this podcast on Spotify.
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Scans Targeting Hospitality Applications https://isc.sans.edu/diary/Scans%20Targeting%20Hospitality%20Applications/33344 Cisco Identity Services Engine Authentication Bypass Vulnerability CVE-2026-76460 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5 Acronis Local privilege escalation due to insecure file permissions CVE-2026-87886 https://security-advisory.acronis.com/advisories/SEC-10986 Pixel Update Bulletin September 2026 https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 Dynamic Incident Response (Free E-Book) https://dynamicincidentresponse.com My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
MacOS 27 - First Boot https://isc.sans.edu/diary/MacOS%2027%20-%20First%20Boot/33340 Cisco Secure Email Gateway SQL Injection Vulnerability CVE-2026-76461 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX Detecting and Mitigating Active Directory Compromises https://www.cisa.gov/resources-tools/resources/detecting-and-mitigating-active-directory-compromises Protecting Tokens and Assertions from Forgery, Theft, and Misuse https://nvlpubs.nist.gov/nistpubs/ir/2026/NIST.IR.8587.pdf My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
In the past few years, blockchains have emerged as a new class of decentralized systems with wide-ranging applications. But the promise of blockchains has been marred by hype, speculation, and a plethora of high-profile attacks.The purpose of this talk is to demonstrate, through examples from my research, why blockchain security is challenging. Blockchains operate in a radically new, highly adversarial environment where subtle protocol flaws can be immediately monetized by anonymous actors. This fundamentally intertwines an assortment of fields---cryptography, distributed systems, and mechanism design, among many others. Blockchain security should no longer be thought of from a single lens.In this talk, I will show powerful new attacks, motivated by blockchains, that erode security through the very same tools typically used to build secure protocols. These attacks provide valuable insights on existing, well-studied security and cryptographic models. In turn, this shows why understanding blockchain security has broader utility and how it can serve as a guiding principle when designing secure systems.The first part of my talk challenges assumptions in cryptographic models of knowledge by showing powerful bribery attacks in bribery-resistant voting---fixing these attacks requires a stronger notion of knowledge. The second part will discuss new techniques for collusion using blockchains, and how it impacts incentives and models in accountable cryptography. About the speaker: Mahimna Kelkar is an assistant professor of computer science at Purdue University. His research designs and builds secure systems using techniques from applied cryptography, blockchain technology, and game theory. Before joining Purdue, he received his PhD in computer science from Cornell University and spent a year as a postdoctoral fellow at Columbia University. More details can be found on his websitehttps://mahimnakelkar.github.io/
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Apple Updates Everything https://isc.sans.edu/diary/Apple%20Updates%20Everything/33336 Homebrew 7 Released https://brew.sh/2026/09/13/homebrew-7.0.0/ Microsoft Out-of-Band Patch https://support.microsoft.com/en-us/servicing/os/windows-11/2026/09/kb5129195-windows-11-24h2-25h2-security-update Telegram XSS Vulnerability https://expatch.com/writeups/telegram-html-export-xss.html My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Most fault trees get built on gut feeling. Petra Vukmirovic did something rarer: she borrowed the actual math from aviation and nuclear-plant safety engineering and pointed it at AI agents. Petra traded emergency medicine for application security and now heads information security at Numan — and she joins Chris Romeo and Robert Hurlbut to make the case for fault tree analysis (FTA), the deductive method that picks up exactly where threat modeling stops. Petra walks through a "wrong customer refund" AI agent scenario step by step, showing how AND/OR gates and minimal cut sets turn vague worry into ranked, data backed probabilities. They dig into where AI helps build a tree, and where garbage in, garbage out still applies, why "comprehensive test coverage" is a myth, and how attaching real dollar figures to failure paths makes it easier to sell security controls to leadership.This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.About CorgeaCorgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.→ Learn more about CorgeaConnect with Petra Vukmirovic:→ Petra Vukmirovic on LinkedIn→ OWASP Threat Model LibraryMentioned in this episode:→ Adam Shostack: "Stop Trying to 'Manage Risk'" (keynote)→ OWASP Global AppSec USA 2026 (San Francisco, Nov 5–6)Follow the Application Security Podcast:➜ Home: appsecpodcast.com➜ X: @AppSecPodcast➜ LinkedIn: The Application Security Podcast➜ YouTube: @ApplicationSecurityPodcast➜ Instagram: @appsecpodcast➜ Facebook: Application Security PodcastChapters:00:00 Cold open — the math behind where to put your controls01:09 Meet Petra Vukmirovic01:28 Petra's origin story: from ER doctor to AppSec02:50 Career path: engineer to Head of InfoSec at Numan04:18 What is fault tree analysis, and where threat modeling ends06:22 Can AI actually do fault tree analysis?08:12 Walking the "wrong customer refund" agent example12:33 Storing your trees: JSON vs. Markdown16:08 Why conjunctive failures trip up narrow thinking17:27 Top 3 failure modes when agents touch downstream systems19:29 Real story: an agent pushed code to main without approval21:27 Testing: why "comprehensive coverage" is a myth23:54 How rough is rough? Assigning probabilities28:08 Getting started without a six week science project31:35 Using FTA to sell controls and build credibility33:43 The epiphany: FTA is about controls, not faults34:48 The one thing every agentic team should add today35:48 Closing thoughts and OWASP Global AppSec USA preview
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access https://isc.sans.edu/diary/The%20Self-Expanding%20Stolen%20Inference%20Supply%20Chain%3A%20An%20AI%20Agent%20Harvesting%20and%20Re-Serving%20LLM%20Access/33332 CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing https://security.paloaltonetworks.com/CVE-2026-0310 OpenAI agents carried out an undisclosed cyber-attack on RubyGems https://www.rubyhack.ai Passkey-themed social engineering leads to identity and cloud compromise https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Redtail Payload Analysis https://isc.sans.edu/diary/Redtail%20Payload%20Analysis%20%5BGuest%20Diary%5D/33326 Checkpoint Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510 https://community.checkpoint.com/t5/General-Topics/Action-Required-Critical-Security-Advisory-VPN-Vulnerabilities/td-p/281995 Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2 Netscaler ADC Exploit https://x.com/ethicalhack3r/status/2095480651478663393 Sonicwall SMA1000 Attack https://hunt.io/blog/sonicwall-sma1000-uk-council-attack My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Scans for Proxmox Servers https://isc.sans.edu/diary/Scans%20for%20Proxmox%20Servers/33324 Next Nightmare Eclipse Vulnerability https://github.com/MSNightmare/ShieldCrash/blob/main/README.md Google Chrome Updates https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html FortiPAM Vulnerability https://amibeingpwned.com/blog/fortinet-pam-vuln My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
September 2026 Microsoft Patch Tuesday https://isc.sans.edu/diary/September%202026%20Microsoft%20Patch%20Tuesday/33320 Adobe Security Bulletins https://helpx.adobe.com/security/security-bulletin.html Security Advisory Ivanti Neurons for ITSM https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US Fortinet Advisory https://www.fortiguard.com/psirt/FG-IR-26-174 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Modern machine learning systems are only as reliable as the data and pipelines that support them, yet improving their behavior often requires navigating enormous spaces of possible data and system configurations. These systems are complex enough that improving them by changing everything at once is both inefficient and unreliable. This talk explores a simple principle for building smarter data and machine learning systems: identify which intervention is most likely to change the outcome, and act there. I will first introduce DataSift that applies this principle to model behavior, identifying the most influential data to expand the training data when the goal is to improve fairness without sacrificing predictive performance. By combining data valuation, influence functions, and multi-armed bandits, DataSift identifies small, high-impact subsets of candidate data rather than indiscriminately adding data to the training set. Next, I will present PipeLens that applies the same principle to data science pipelines, identifying the components and parameters whose intervention is most likely to repair a malfunctioning pipeline. By learning from successful and failed pipeline executions, PipeLens identifies causally relevant root causes and efficiently searches for interventions that restore pipeline utility. Despite addressing different problems, both systems replace brute-force search with targeted intervention using principled reasoning about influence and causality to determine what to change, why it matters, and how to change it efficiently. About the speaker: Romila Pradhan is an Assistant Professor in the School of Applied & Creative Computing at Purdue University and leads the Responsible DataScience Lab, where she and her students build trustworthy and responsible data-driven decision-making systems. Her research is in the broader areas of databases and data management and is driven by the need to design algorithms and develop solutions that enable system explainability, fairness, and robustness. Her research is supported by NSF, Google, and Underwriters Laboratories. She is a recipient of a Google Research Scholar award and an NSF CAREER award. Romila earned her Ph.D. in Computer Science from Purdue University and graduated with M.S. and B.S. in Mathematics and Computing from the Indian Institute of Technology (IIT) Kharagpur, India.
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
numbat - AI agent observability https://isc.sans.edu/diary/numbat%20-%20AI%20agent%20observability/33312 MicroTik SSH 0-Day Exploited https://mikrotik.com/supportsec/september-2026-vulnerability/ https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/ Adobe Commerce - Magento - 0-Day Exploited https://sansec.io/research/stylesmuggler-0day N-Able 4th Hotpatch https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF4_Release_Notes.htm My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Nightmare Eclipse Discloses Several Anti-Malware Privilege Escalation Exploits https://github.com/MSNightmare Plex Update https://forums.plex.tv/t/important-security-update-for-plex-media-server-v1-43-2-and-earlier/942319 Cisco Update https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-smime-disc-dzw4rEdY Sangoma Switchvox Exploit https://horizon3.ai/attack-research/disclosures/cve-2026-9586-sangoma-switchvox-rce/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Sonicwall SMA1000 Exploited Vulnerability Patched https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 SSRF: The Validator Can Lie https://xclow3n.com/post/the-validator-can-lie/ Git Hijack for AI Agents https://www.manifold.security/blog/ai-coding-agents-git-hijack Fronics Deploy Abuse https://www.huntress.com/blog/faronics-deploy-abuse My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Guildma (Astaroth) malware infection from Brazilian Portuguese email https://isc.sans.edu/diary/Guildma%20%28Astaroth%29%20malware%20infection%20from%20Brazilian%20Portuguese%20email/33300 Authentication bypass in EOL Proxmox VE 7 release https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/page-4#post-867929 https://gist.github.com/nebusecurity/65fe90dd673d395b7926278d7eaf5849 Updated Windows Server hotpatch calendar https://learn.microsoft.com/en-us/windows/release-health/windows-server-release-info#windows-server-hotpatch-calendar Virtualizor BGP Hijacking https://www.virtualizor.com/blog/security-incident-bgp-hijacking/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
In this talk, I will provide an overview of our NSF-sponsored award, TianoShield, focused on enhancing the security posture and the software maintenance process of the open-source core of the UEFI Firmware, called EDK II, and maintained by the TianoCore community. The talk will highlight our ongoing collaborations with our industrial partners, including Intel Corporation, Arm, AMI, Insyde Software, GitHub, Phoenix Technologies, Binarly, etc. First, we will discuss our methods and techniques for rapid triaging of existing bug reports that have remained open for a long time due to a lack of resources in the community. Second, we will introduce our security analysis tools and their enhancements for static and dynamic analysis of the UEFI firmware, thus discovering many new vulnerabilities. Finally, we will present our suggestions and improvements for software maintenance, specifically bug handling, and DevOps/DevSecOps practices in TianoCore. A key pillar of TianoShield is leveraging the state of the art in Artificial Intelligence (AI), including Large Language Models (LLMs) for software security and software maintenance. As part of the dissemination practices in TianoShield, we have organized/will organize a full-day workshop, called FirmVuln26, at VulnCon26 in Scottsdale, AZ, in April 2026, and another full-day workshop, called FTA 2026, at ISSTA 2026 in Oakland, CA, in October 2026. The TianoShield project started in October 2025 and is expected to run until September 2027. About the speaker: Dr. Armin Moin is a Tenure-Track Assistant Professor and Director of the Purdue Quantum-Classical AI and Software Engineering (QCASE) Lab at the School of Applied and Creative Computing (ACC) in the Polytechnic Institute at Purdue University in West Lafayette and Indianapolis, Indiana, USA. He previously (2023-2026) held a Tenure-Track Assistant Professor position in the Computer Science (CS) department of the University of Colorado Colorado Springs (UCCS). Before starting his faculty position, he worked as a Postdoctoral Scholar-Employee in the CS Department of the University of California, Santa Barbara (UCSB) in the U.S. and as a Postdoctoral Scholar in the CS Department of the University of Antwerp and FlandersMake in Belgium. Dr. Moin obtained his Ph.D. in CS from the Technical University of Munich (TUM), Germany, one of the world's top universities, in 2022. He also has a Master's in CS and an Executive MBA in Innovation and Business Creation. His research focuses on the intersection of Artificial Intelligence (AI) and Software Engineering (SE), particularly AI4SE and SE4AI, with an emphasis on hybrid quantum-classical computing and software security. Grants from various sources, including the U.S. National Science Foundation (NSF) and the Colorado Office of Economic Development and International Trade (OEDIT), have funded his lab. Besides conducting research and teaching at Purdue University, Dr. Moin reviews top academic conferences and journals. He is passionate about encouraging and empowering students to start their ventures based on what they learn at the university. Please refer to his academic homepage at https://web.ics.purdue.edu/~moin/index.html or his professional profile at https://polytechnic.purdue.edu/profile/moin for more information.
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary https://isc.sans.edu/diary/The%20Coding-Agent%20Trap%3A%20When%20a%20%22Free%22%20LLM%20Endpoint%20Is%20the%20Adversary/33298 PaperCut Public Exploit Available https://github.com/rapid7/metasploit-framework/pull/21842 TerminalFix Campaign; https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Some Malicious PE Stats https://isc.sans.edu/diary/Some%20Malicious%20PE%20Stats/33292 PaperCut Releases Two Preliminary Patches for Exploited Vulnerability https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ DLink Vulnerabliities https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10513 Watchguard Patches https://psirt.watchguard.com My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
A polymorphic phishing page (that occasionally breaks itself) https://isc.sans.edu/diary/A%20polymorphic%20phishing%20page%20%28that%20occasionally%20breaks%20itself%29/33290 Chinese Implants in the Supply Chain https://www.vulncheck.com/blog/zbt-darklantern-speakingstone?_sp=1068fa46-3d91-427e-8120-aa6d8bda2912.1787865822277 Data Became Code: We Ran Code Inside Fortune 500s Using Files They Published for AI Agents https://medium.com/@alonhertz1/data-became-code-we-ran-code-inside-fortune-500s-using-files-they-published-for-ai-agents-0cd67ffbbffc Papercut Security Advisory https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Who Has Admin Rights in your Entra ID Directory? https://isc.sans.edu/diary/Who%20Has%20Admin%20Rights%20in%20your%20Entra%20ID%20Directory%3F/33284 Ubiquity Unifi Patches https://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9 Log4J FilteredObjectInputStream Vulnerability https://github.com/joanbono/log4j2-4255-exploit https://jeffmcjunkin.com/posts/log4j2-fois-marshalledobject/ Sleepwalker Malware https://r136a1.dev/2026/08/24/sleepwalker-a-passive-backdoor-with-its-own-command-language/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Obfuscating IP Addresses as Hostnames https://isc.sans.edu/diary/Obfuscating%20IP%20Addresses%20as%20Hostnames/33280 Microsoft Paint and Photos Embed Server-Issued GUIDs as Invisible Watermarks in Locally-Generated Images https://xusheng.dev/posts/reversing/mspaint_invisible_watermark/main/ FTP Banners The New Dead Drop Resolver Delivering Novel RATs https://socradar.io/blog/ftp-banners-new-dead-drop-resolver-rats/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
DOUBLECUP's PNG Payload https://isc.sans.edu/diary/DOUBLECUP%27s%20PNG%20Payload/33274 AliExpress WebAudio fingerprinting https://blog.laserphile.com/2026/08/aliexpress-webpage-keeping-multipoint.html Expired DMARC Reporting Domain Exposed 86 Domains https://www.sh.consulting/blog/abandoned-dmarc-reporting-domain Android Car Malware https://securelist.com/android-head-unit-malware/121106/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
In this episode of Unsecurity Podcast, Megan Larkins, Brad Nigh, and April Meyer dig into one of the biggest issues facing healthcare today: cybersecurity as a business, operational, and patient safety risk.April breaks down what healthcare organizations should watch as the proposed HIPAA security rule evolves, why the industry still struggles with basics like multi-factor authentication, encryption, asset management, and documentation, and how recent breaches have made the need for action impossible to ignore.The conversation also explores the real-world challenges of medical devices, third-party dependencies, legacy systems, and network segmentation—plus what regulators are likely to expect when audits begin.Whether you work in healthcare or support organizations that do, this episode offers a practical roadmap for reducing risk now instead of waiting for final rule clarity.Be sure to like, subscribe, and hit the notification bell for more insightful episodes. #UnsecurityPodcast #Cybersecurity #hipaa #hipaacompliance #healthcare #informationsecurity #businessWe want to hear from you! Reach out at unsecurity@frsecure.com and follow us for more: LinkedIn: https://www.linkedin.com/company/frsecure/Instagram: https://www.instagram.com/frsecureofficial/Facebook: https://www.facebook.com/frsecure/BlueSky: https://bsky.app/profile/frsecure.bsky.socialAbout FRSecure:https://frsecure.com/FRSecure is a mission-driven information security consultancy headquartered in Minneapolis, MN. Our team of experts is constantly developing solutions and training to assist clients in improving the measurable fundamentals of their information security programs. These fundamentals are lacking in our industry, and while progress is being made, we can't do it alone. Whether you're wondering where to start or looking for a team of experts to collaborate with you, we are ready to serve.
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting! https://isc.sans.edu/diary/Who%20Got%20Missed%20in%20the%20MFA%20Rollout%3F%20More%20Powershell%20%2B%20Graph%20%2B%20Entra%20scripting!/33272 Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays https://isc.sans.edu/diary/Even%20MOAR%20Powershell%2C%20looking%20at%20Entra%20logins%20-%20the%20good%2C%20the%20bad%20and%20the%20password%20sprays/33268 Microsoft Entra ID Remote Code Execution Vulnerability CVE-2026-69836 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836 GitLab Critical Patch Release CVE-2026-19478 CVE-2026-19650 https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/ GTA 6 Leak File with Malware https://x.com/Aidas29506493/status/2091194667073204624 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses https://isc.sans.edu/diary/Using%20Microsoft%20Graph%20and%20Powershell%20to%20Mine%20for%20Information%20-%20Stale%20Accounts%20and%20Licenses/33264 Using Microsoft Graph and Powershell - Risk Detection Commands https://isc.sans.edu/diary/Using%20Microsoft%20Graph%20and%20Powershell%20-%20Risk%20Detection%20Commands/33266 Keycloak Vulnerability https://github.com/keycloak/keycloak/issues/51833 https://www.keycloak.org/2026/08/keycloak-2672-released CRYPTOGRAPHIC CONTEXT INJECTION ATTACK https://adversa.ai/blog/cryptographic-context-injection-grok-data-theft/ N-able password manager https://amibeingpwned.com/blog/solar-winds-part-2-avoided?_sp=75fd154a-e34f-41d0-8624-7c285776c13d.1787263544340 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Industrial Talk is talking to Gareth Paterson, SR. Cybersecurity Consultant at Prism Infosec about "Cybersecurity Penetration Testing". The conversation promotes the Barcelona Cybersecurity Congress from November 3-5, 2023, emphasizing the importance of cybersecurity in the connected world. Scott Mackenzie, the host of the Industrial Talk podcast, interviews Gareth Paterson from Prism Infosec about cybersecurity challenges and solutions. Gareth discusses the evolution of cybersecurity, the importance of proactive measures, and the role of penetration testing in identifying vulnerabilities. He highlights the significance of social engineering and physical security, and the impact of AI on cybersecurity. Gareth also shares a case study where a client's vulnerability was missed due to a lack of understanding of their specific concerns. Outline Barcelona Cybersecurity Congress Promotion Speaker 1 promotes the Barcelona Cybersecurity Congress, emphasizing its importance and urging listeners to mark their calendars for November 3-5.The event is described as a must-attend for cybersecurity professionals, offering networking opportunities with experts from around the world.Scott mentions their own participation in the event, highlighting the significance of cybersecurity in the connected world.The conversation shifts to the importance of cybersecurity and the need for continuous innovation and protection in the industry. Introduction to Industrial Talk Podcast Scott welcomes listeners to the Industrial Talk podcast, celebrating industry professionals and their contributions to innovation and problem-solving.The guest for the episode, Gareth Paterson from Prism Infosec, is introduced, with a focus on cybersecurity.Scott emphasizes the importance of data collection and protection in the connected world, setting the stage for the main discussion. Discussion on Cybersecurity and Industry Innovation Scott reiterates the importance of cybersecurity and the need for continuous innovation to stay ahead of threats.The conversation touches on the challenges of keeping up with technological advancements and the importance of consistent storytelling.Scott shares insights on the importance of being real and authentic in communication, both in personal interactions and professional settings.The discussion highlights the need for perseverance and consistency in telling one's story, drawing parallels to maintaining a fitness routine. Gareth Paterson's Background and Role at Prism Infosec Gareth Paterson introduces himself as the Technical Testing Lead at Prism Information Security, sharing his background in the British Army.Gareth explains his transition from military service to penetration testing, describing it as "legal computer hacking."The conversation delves into the challenges and rewards of his role, including the frustration of finding vulnerabilities and the importance of supporting clients.Gareth discusses the various services offered by Prism Infosec, including vulnerability assessments, penetration testing, and red teaming. Challenges in Cybersecurity and the Importance of Proactive Measures Gareth highlights the constant evolution of cybersecurity threats and the need for continuous learning and adaptation.The discussion covers the importance of proactive measures in cybersecurity, contrasting reactive approaches with those that prioritize prevention.Gareth shares an example of a client who had been regularly tested but lacked understanding of their specific concerns, leading to missed vulnerabilities.The conversation emphasizes the need for tailored cybersecurity solutions that address specific client needs and threats. The Role of Social Engineering and Physical Security in Cybersecurity Gareth expresses his passion for social engineering and physical security, describing it as his favorite aspect of cybersecurity.The discussion covers the importance of educating employees and implementing policies to prevent common security breaches.Gareth shares insights on the challenges of maintaining security in a constantly changing network environment.The conversation highlights the role of regular checks, audits, and testing in ensuring ongoing security and addressing new vulnerabilities. The Impact of AI on Cybersecurity and Organizational Security Gareth discusses the rapid adoption of AI in various tools and systems, likening it to the advent of computers in the 1980s.The conversation covers the potential risks of AI, including the need for proper control and education to prevent misuse.Gareth shares an example of a hacker exploiting an AI system to gain access to sensitive information, emphasizing the importance of isolation and control.The discussion highlights the need for organizations to manage their AI systems effectively to prevent unauthorized access and data breaches. Final Thoughts and Contact Information Gareth provides his contact information, encouraging listeners to reach out via LinkedIn for further discussions on cybersecurity.Scott expresses gratitude for the conversation and emphasizes the importance of cybersecurity in the connected world.The episode concludes with a reminder of the Barcelona Cybersecurity Congress and the importance of staying informed and proactive in cybersecurity.Scott reiterates the need for continuous storytelling and awareness in maintaining a strong cybersecurity posture. If interested in being on the Industrial Talk show, simply contact us and let's have a quick conversation. Finally, get your exclusive free access to the Industrial Academy and a series on “Why You Need To Podcast” for Greater Success in 2026. All links designed for keeping you current in this rapidly changing Industrial Market. Learn! Grow! Enjoy! GARETH PATERSON'S CONTACT INFORMATION: Personal LinkedIn: https://www.linkedin.com/in/gareth-paterson/ Company LinkedIn: https://www.linkedin.com/company/prism-infosec-ltd-cybersecurity/ Company Website: https://prisminfosec.com/ PODCAST VIDEO: https://youtu.be/7maQqWSh4So THE STRATEGIC REASON "WHY YOU NEED TO PODCAST": OTHER GREAT INDUSTRIAL RESOURCES: NEOM: https://www.neom.com/en-us Hexagon: https://hexagon.com/ Arduino: https://www.arduino.cc/ Fictiv: https://www.fictiv.com/ Hitachi Vantara: https://www.hitachivantara.com/en-us/home.html Industrial Marketing Solutions: https://industrialtalk.com/industrial-marketing/ Industrial Academy: https://industrialtalk.com/industrial-academy/ Industrial Dojo: https://industrialtalk.com/industrial_dojo/ We the 15: https://www.wethe15.org/ YOUR INDUSTRIAL DIGITAL TOOLBOX: LifterLMS: Get One Month Free for $1 – https://lifterlms.com/ Active Campaign: Active Campaign Link Social Jukebox: https://www.socialjukebox.com/ Business Beatitude the Book Do you desire a more joy-filled, deeply-enduring sense of accomplishment and success? Live your business the way you want to live with the BUSINESS BEATITUDES...The Bridge connecting sacrifice to success. YOU NEED THE BUSINESS BEATITUDES! TAP INTO YOUR INDUSTRIAL SOUL, RESERVE YOUR COPY NOW! BE BOLD. BE BRAVE. DARE GREATLY AND CHANGE THE WORLD. GET THE BUSINESS BEATITUDES!
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Simple Scans for Cloud Metadata Service https://isc.sans.edu/diary/Simple%20Scans%20for%20Cloud%20Metadata%20Service/33260 Oracle Critical Security Patch Update Advisory - August 2026 https://www.oracle.com/security-alerts/cspuaug2026.html NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490 https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939 Beware of Ransomware Rescuers https://www.guidepointsecurity.com/blog/beware-ransom-busters/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
CoSnitch: When Your AI Assistant Becomes Its Own Whistleblower https://www.varonis.com/blog/cosnitch GEEKOM confirms malware was hosted on its website https://videocardz.com/newz/geekom-apologizes-for-hosting-malware-in-driver-package-for-its-mini-pcs Medusa Ransomware Update https://www.cisa.gov/sites/default/files/2026-08/aa25-071a-stopransomware-medusa-ransomware-508c.pdf How Google is Making Private AI Practical with Homomorphic Encryption https://blog.google/security/how-google-is-making-private-ai-practical-with-homomorphic-encryption/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Apple Patches or iOS and macOS https://isc.sans.edu/diary/Apple%20Patches%20iOS%20and%20macOS/33254 Screen Sharing Security https://isc.sans.edu/diary/Apple%20Screen%20Sharing%20Security/33252 Download More RAM: Dismantling Windows Operating System Defenses with Mischievous Memory https://www.usenix.org/system/files/usenixsecurity26-collins.pdf My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
macOS Screen Sharing Vulnerability Exploited https://advisories.ncsc.nl/2026/ncsc-2026-0280.html GeoServer Patch https://geoserver.org/announcements/vulnerability/2026/08/14/geoserver-3-0-1-released.html Recent SAP Commerce Cloud Vuln Exploited https://x.com/DefusedCyber/status/2088240809355153647 ChainDrop npm Worm https://medium.com/governed-at-the-source/the-chaindrop-npm-worm-august-2026-how-444-packages-were-compromised-without-a-single-npm-b0c9e5a4c387 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Watch the full episode on our YouTube channel: youtube.com/@mreapodcastWhat if the biggest source of future listings is already sitting inside our database?Ryan Young leads a team on pace to sell more than 500 homes this year, with roughly 65% to 70% of that business coming from listings. His appointments are also up 40% year over year. He joins us to break down how his team built a database-driven business focused on homeowners, relevant value, and long-term relationships.We also dig into how Ryan is using AI to track engagement, start conversations and hand motivated opportunities back to his team. Since February, the system has generated 726 handoffs and helped create 125 additional appointments. If we want more listings without constantly buying new leads, Ryan's model gives us a clear place to start.Resources:Visit Fello AIFollow Ryan Young on InstagramOrder the Millionaire Real Estate Agent Playbook | Volume 3Connect with Jason:LinkedinProduced by NOVAThis podcast is for general informational purposes only. The views, thoughts, and opinions of the guest represent those of the guest and not Keller Williams Realty, LLC and its affiliates, and should not be construed as financial, economic, legal, tax, or other advice. This podcast is provided without any warranty, or guarantee of its accuracy, completeness, timeliness, or results from using the information.WARNING! You must comply with the TCPA and any other federal, state or local laws, including for B2B calls and texts. Never call or text a number on any Do Not Call list, and do not use an autodialer or artificial voice or prerecorded messages without proper consent. Contact your attorney to ensure your compliance.Any text or materials generated by artificial intelligence (AI) should be reviewed for accuracy and reliability as there may be errors, omissions, or inaccuracies. The use of generative AI is subject to limitations, including the availability and quality of the training data used to train the AI model used. Users should exercise caution and independently verify any information or output generated by the AI system utilized and should apply their own judgment and critical thinking when interpreting and utilizing the outputs of generative AI. Do not input confidential financial or proprietary information into any AI tool unless it provides a secure, isolated environment. This includes a robust InfoSec infrastructure and guarantees from the provider that your data is used exclusively for your purposes and is not used to train the model or shared with others.You must follow the TCPA and all other applicable federal, state, and local laws if you want to leverage AI for use with calls or texts. The TCPA prohibits AI-voice calls unless you have received prior express written consent from the call recipient. AI-initiated text messages must disclose to recipients that they are interacting with AI, not a human. Contact your attorney to ensure your compliance with applicable law.
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI https://isc.sans.edu/diary/Using%20Gemma4%20with%20Ollama%20-%20Testing%20File%20Hash%20Analysis%20and%20Recommendations%20with%20AI/33242 CPU Privilege Escalation https://github.com/xoreaxeaxeax/smiiiiiiiiiiiiiiii https://github.com/xoreaxeaxeax/skitter-creek-bath-salts GeoServer Vulnerability https://x.com/q1uf3ng/status/2087490992723407096 Windows USB Driver Vulnerability https://x.com/0xedh/status/2085842285481062887 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Linux Kernel Process Accounting https://isc.sans.edu/diary/Linux%20Kernel%20Process%20Accounting/33240 ShieldBreak - Windows Defender 0day vulnerability https://git.projectnightcrawler.dev/NightmareEclipse/ShieldBreak/src/branch/main Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040) https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/ California law puts digital fingerprints on AI fakes https://digital-strategy.ec.europa.eu/en/policies/eu-icons-labelling-ai-generated-content https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Microsoft Patch Tuesday https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20August%202026/33236 Zoom Vulnerablities CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415 https://a.security/blog/asecurity-zoomsday Mozilla Revokes GPG Key https://blog.mozilla.org/security/2026/08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/ Rogue Inflight Wifi https://www.bleepingcomputer.com/news/security/delta-probes-wi-fi-deauth-attack-on-flight-carrying-def-con-attendees/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Scans for Solana (Surfpool?) Endpoints https://isc.sans.edu/diary/Scans%20for%20Solana%20%28Surfpool%3F%29%20Endpoints/33230 Why AI-generated vulnerability patches still require expert human review https://1password.com/blog/why-ai-generated-patches-still-require-human-review?_sp=15ec2845-9e6c-4d15-8ac5-fe9bc1fe4c08.1786396502013 Gunra Ransomware https://www.cisa.gov/sites/default/files/2026-08/aa26-222a-stopransomware-gunra-ransomware_508c.pdf Neo4J/GraphQL Vulnerability CVE-2026-5423 https://github.com/neo4j/graphql/security/advisories/GHSA-fcpg-3fw5-vc65 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Linux Shell Forensic: Let s Dive Into Atuin! https://isc.sans.edu/diary/Linux+Shell+Forensic+Lets+Dive+Into+Atuin/33226 Apple Patches macOS Screen Sharing Vulnerability https://support.apple.com/en-us/148170 More N-Able N-Central Issues https://www.n-able.com/blog/n-central-security-update-august-6-2026 Metabase Unauthenticated SQL injection https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary] https://isc.sans.edu/diary/22+Seconds+to+Compromise+How+Automated+SSH+Actors+Move+From+Login+to+Persistence+Before+You+Can+Blink+Guest+Diary/33220 Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/ Ill Bloom: Crypto Wallet Vulnerability https://illbloom.org Benchmarking Free-Tier Large Language Models as Cognitive Aids for Operationalizing Unstructured Cyber Threat Intelligence https://www.sans.edu/cyber-research/benchmarking-free-tier-large-language-models-cognitive-aids-operationalizing-unstructured-cyber-threat-intelligence My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm https://isc.sans.edu/diary/Don%27t%20Revoke%20That%20Token%20Yet%3A%20Inside%20the%20keyv%20cacheable%20npm%20Worm/33218 IP and DNS Leaks in WebKit Affecting Proxy Browsers and Apple iCloud Private Relay https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/?ref=404media.co COLDCARD Issues https://x.com/threatinsight/status/2084328552481112429 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Botnet Hunting for Vulnerabilities in Diagnostic Tools https://isc.sans.edu/diary/Botnet%20Hunting%20for%20Vulnerabilities%20in%20Diagnostic%20Tools/33214 Inside Greatness: Telegram-Distributed M365 AiTM PhaaS https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing A Deep Dive Into the Latest XCSSET Version https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/ Strengthening NuGet Supply Chain Security: Reducing API Key Lifetime https://devblogs.microsoft.com/dotnet/strengthening-nuget-supply-chain-security-reducing-api-key-lifetime/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
AUR packages adoption disabled https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/DRDEU3JUSC72CB265XHXPFA3DFSLXPBP/ Apple's iCloud File Sharing Left Ex-Employees With Access to Secret Documents https://www.macrumors.com/2026/08/03/apple-icloud-sharing-ex-employees/ Pass the Passkey: A Novel Attack Surface in Passwordless Authentication https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
zipdump.py Metadata Encoding https://isc.sans.edu/diary/zipdumppy+Metadata+Encoding/33202/ Atomic MacOS (AMOS) stealer infection https://isc.sans.edu/diary/Atomic%20MacOS%20%28AMOS%29%20stealer%20infection/33208 Phishing Campaigns Targeting AI Solutions Providers https://isc.sans.edu/diary/Phishing+Campaigns+Targeting+AI+Solutions+Providers/33206/ Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner https://isc.sans.edu/diary/Reconnaissance%20First%3A%20An%20SSH%20Bot%20That%20Sizes%20Up%20Your%20Hardware%20Before%20Deploying%20a%20Miner%20%5BGuest%20Diary%5D/33198 Cisco Secure Firewall Management Center Software Static Credential Vulnerability Exploited CVE-2026-20316 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh Inconsistent Group Chats https://www.usenix.org/conference/usenixsecurity26/presentation/gegenhuber https://www.heise.de/en/news/Encrypted-but-wrong-Group-chats-vulnerable-to-manipulated-content-11384112.html My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Apple Patch Summary / Postscript https://isc.sans.edu/diary/Apple%20Patches%20Everything%20%28July%202026%29/33196 IPMI Admin Password Hash Leak https://lavahq.io/research/bmc-exposure-alert Patches for VMWare https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 OpenWRT Patch, odhcpd vulnerability CVE-2026-53921 https://github.com/openwrt/odhcpd/security/advisories/GHSA-7fwx-hhrg-3496 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
AutoIT Payload Injector https://isc.sans.edu/diary/AutoIT%20Payload%20Injector%20/33192 Apple Security Update https://support.apple.com/en-us/100100 SourTrade: Browser-Assembled Malware Delivered Through Malvertising https://blog.confiant.com/p/sourtrade-browser-assembled-malware NGINX Exploit CVE-2026-42530, CVE-2026-42533 https://github.com/DepthFirstDisclosures/Nginx-Rift/tree/main My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich