Handler on Duty: Guy Bruneau
Threat Level: green
Podcast Detail
SANS Stormcast Friday, September 11th, 2026: Redtail Analsys (@sans_edu); Checkpoint VPN Patch; Netscaler and Sonicwall Attacks
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10090.mp3
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
Redtail Payload Analysis
https://isc.sans.edu/diary/Redtail%20Payload%20Analysis%20%5BGuest%20Diary%5D/33326
Checkpoint Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510
https://community.checkpoint.com/t5/General-Topics/Action-Required-Critical-Security-Advisory-VPN-Vulnerabilities/td-p/281995
Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
Netscaler ADC Exploit
https://x.com/ethicalhack3r/status/2095480651478663393
Sonicwall SMA1000 Attack
https://hunt.io/blog/sonicwall-sma1000-uk-council-attack
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Application Security: Securing Web Applications, APIs, and Microservices | Las Vegas | Sep 21st - Sep 25th 2026 |
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 19th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Orlando | Apr 12th - Apr 16th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Mountain | Apr 21st - Apr 25th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Baltimore | May 17th - May 21st 2027 |
Podcast Transcript
Hello and welcome to the Friday, September 11th, 2026 edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich, recording today from Jacksonville, Florida. And this episode is brought to you by the SANS.edu Graduate Certificate Program in Cloud Security. In diaries today we have one of our undercredit interns write about a copy of the Red Tail Malware that Aaron Ng here did capture in his honeypot. Now the details are really very nice in this particular analysis, but what I want to point out is the way the analysis was done. This sample was analyzed using a runtime analysis, which tends to be the simpler form and faster form often to figure out what a particular piece of malware does. You essentially just run it. Of course, running malware comes with some complications. You don't want the malware to go out as some of the samples often do and infect other systems. Also, you want to be able to capture all of the activity from this malware and experiment with different runtime options and such. And that's a part of what Aaron did here. But Aaron used an interesting tool that I always highly recommend when you're trying to do this kind of analysis. And that's iNetSim. iNetSim is essentially software that sort of simulates a small internet for you. So you have like no various services that you can enable there that will then mimic the real services that the malware may be connecting to things like DNS servers and such to basically give the malware a little bit more realistic view like it would be connected to the actual internet. And of course, with the advantage to still have the isolation and not having to maintain yourself all these different services that you may need to spin up otherwise if you want to get sort of the same result. So interesting tool if you are doing runtime analysis of malware, iNetSim certainly something that I would recommend. And a couple other solutions too like this, but I find this really sort of simple and it's one of those solutions that does really most of what you need and usually suffices over some very much more complex solutions. And Checkpoint yesterday released a critical security advisory and a patch fixing two vulnerabilities. These vulnerabilities do allow unauthenticated remote code execution, at least the first one. The second one, also a heap-based buffer overflow, doesn't say whether or not it needs authentication to execute any code here. Either way, definitely something that you do want to patch in particular for the first one, the unauthenticated remote code execution vulnerability. Now, Checkpoint also points out that if you have the Checkpoint Live patch feature enabled, then the patch should have already been applied to your system. They rolled it out September 9th. But after spending a lot of time this week on talking about vulnerabilities, let's talk now a little bit about vulnerabilities that are currently being exploited. Cisco just updated the advisory they published in March for its Secure Firewall Management Center. This vulnerability is now being exploited and Cisco does offer some indicators of compromise that you can use to check if your instance was affected by this particular exploit. And Ryan Dewhurst with Pravidian did note on X that they're observing exploitation of Netscaler ADC vulnerability. This vulnerability was originally patched about a month ago, a little bit less than a month ago. Proof of concept exploit was made public a couple days ago. And that's, as Ryan here points out, also is always sort of a basic sign. Once you see a public proof of concept, well, yes, at that point, the vulnerability is widely being exploited. And you always should assume compromise, of course, at this point. And finally, SonicWall SMA 1000. We had recently an already exploited vulnerability being patched there. Hunt.io now published a real nice and detailed walkthrough of an attack that they have seen in the wild against local government in the UK. These walkthroughs are always really helpful because they really show what attackers are doing with these vulnerabilities, how to identify this particular attacker. But then also similar attacks that exploit the same vulnerability, because here you can see what particular evidence, for example, may be left behind on a compromised system. That's always very helpful if you see the full walkthrough in some vendor bulletins like the Cisco one I mentioned earlier. They're very specific indicators of compromise, which, of course, may change from attacker to attacker. And it's not always that obvious what you can use here as a good indicator of compromise beyond sort of that simple file name, hash or IP address that may have been published. Well, and this is it for today. So thanks for listening. Thanks for liking. Thanks for subscribing. Remember, any future teachers of myself will usually be listed in the show notes. So take a look at that. And that's it for today, for this week. Talk to you again on Monday. Bye.





