Podcast Detail

SANS Stormcast Thursday, July 23rd, 2026: Rondo and Geoserver; Oracle Patches; Checkpoint 0-day; OpenAI vs Huggingface

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10020.mp3

Podcast Logo
Rondo and Geoserver; Oracle Patches; Checkpoint 0-day; OpenAI vs Huggingface
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS
Application Security: Securing Web Apps, APIs, and MicroservicesOnline | British Summer TimeJul 27th - Aug 1st 2026
Application Security: Securing Web Apps, APIs, and MicroservicesLas VegasSep 21st - Sep 25th 2026
Network Monitoring and Threat Detection In-DepthAmsterdamOct 12th - Oct 17th 2026
Application Security: Securing Web Apps, APIs, and MicroservicesWashingtonDec 14th - Dec 18th 2026
Application Security: Securing Web Apps, APIs, and MicroservicesOnline | India Standard TimeMar 15th - Mar 20th 2027

Podcast Transcript

 Hello and welcome to the Thursday, July 23rd, 2026
 edition of the SANS Internet Storm Center's Stormcast. My
 name is Johannes Ullrich, recording today from
 Jacksonville, Florida. And this episode is brought to you
 by the SANS.edu undergraduate certificate program in Applied
 Cybersecurity. Going over our web honeypot logs today, I saw
 two things that I talked about in the past, the first time at
 least I've seen them together, and that's GeoServer and the
 Rondo Botnet. Now GeoServer is one of those big Java
 applications that helps you process geolocation data. It's
 often used for geographic information systems to
 essentially prepare maps for various purposes. I don't
 think there are a ton of them exposed on the internet, but I
 guess sufficient systems that they are worthwhile scanning
 by those botnets. The vulnerability being attacked
 here is an older one. 2024 is when that vulnerability was
 originally made public. It's an expat expression evaluation
 issue. Now, the botnet that's scanning for it is the Rondo
 botnet. And Rondo is sort of one of those, I would say a
 little bit old-fashioned, funny kind of botnets. It has
 this Chicago rap theme to it. And if you're currently going
 to the website where it originally pulled down the
 bash script, well, you're getting sort of the typical
 for this botnet sort of advertisement for this Chicago
 rapper. No idea how they're related. If it's just a fan
 that wrote the botnet or how this exactly happened. But
 yes, of course, the site is still compromised because it
 now hosts that video. So sometimes these botnets, if
 you're not requesting the file from an IP address that's
 currently being scanned, well, you're getting different
 responses back. There's also sort of that little HTML
 comment on the top. You won't find it here. So I guess maybe
 that's directed at people like me that would like to get the
 SH file that's supposed to be downloaded. Well, after
 getting more than 400 vulnerabilities patched in the
 Linux kernel late last week, today we got the July critical
 patch update from Oracle. Now, even after changing their
 patch cycle from quarterly to monthly, well, we see AI doing
 its work here. And we got patches for 1,449 different
 vulnerabilities. Now, this being Oracle, of course, there
 are many, many different products involved in this
 particular update. I noticed quite a few updates for JD
 Edwards. So if you're running that, that may be of interest.
 And then also a lot of updates for some of the sort of Oracle
 Commerce, Oracle Communications Cloud products.
 So definitely you have to also check, you know, which
 components here you have installed. There's really too
 much here to sort of go over every single patch that, or
 even sort of do a summary that does it somewhat justice. And
 the one patch or the one vulnerabilities have stuck out
 to me was a 9.9 vulnerability in Oracle's database. So this
 is just the straightforward Oracle database. Definitely
 something to take a close look at if you are running Oracle
 database. Well, and then we got a little bit, sort of
 resolution from OpenAI. What exactly happened in the
 hugging face case? So according to OpenAI, they did
 test their latest model, GPT-5 .6 Sol. And the intent was to
 test it against an internal benchmark inside a sandbox.
 And apparently the model escaped and then decided to
 attack hugging face. Now, I don't see hugging face as a
 competitor to OpenAI in any way. So I don't think it was
 an attack against the competitor. To me, this sounds
 very much like a publicity stunt and that this escape was
 maybe not all that accidental, given how much sort of press
 Anthropic got with their fatal model and some of the exploit
 discoveries around that. Maybe OpenAI wanted to do a little
 bit better and did sort of that escape from the jail in
 order to attack another AI related website. Checkpoint
 released its July security advisory. Now, they're stating
 that they're also using AI in order to find vulnerabilities.
 They're patching three vulnerabilities here, at least
 three that they're listing. But they also state that they
 applied various hardening techniques and such that are
 not necessarily sort of pointed out as
 vulnerabilities. They're calling this a jumbo patch and
 it applies to the firewall product as well as to their
 admin console products. Now, there's one vulnerability here
 that's worth pointing out. It's an authentication bypass
 with a smart console login. This has a CVS score of 9.3
 and is already exploited in the wild. They're saying there
 was a handful of customers that was affected by this. I'm
 not sure how many customers fit into a hand. But anyway,
 definitely do apply it. And now, given that the patch is
 out and of course the patch will be diffed and there's
 already an exploit available. Probably won't take too long
 to see more widespread exploitation of this
 vulnerability. Well, and this is it for today. So thanks for
 listening. Thanks for liking. Thanks for subscribing and
 talk to you again tomorrow. Bye. Bye.
 Bye. Bye.