Handler on Duty: Johannes Ullrich
Threat Level: green
Podcast Detail
SANS Stormcast Tuesday, September 15th, 2026: Apple Updates; Homebrew Update; MSFT OOB Patch; Telegram Vuln
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10094.mp3
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
Apple Updates Everything
https://isc.sans.edu/diary/Apple%20Updates%20Everything/33336
Homebrew 7 Released
https://brew.sh/2026/09/13/homebrew-7.0.0/
Microsoft Out-of-Band Patch
https://support.microsoft.com/en-us/servicing/os/windows-11/2026/09/kb5129195-windows-11-24h2-25h2-security-update
Telegram XSS Vulnerability
https://expatch.com/writeups/telegram-html-export-xss.html
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Application Security: Securing Web Applications, APIs, and Microservices | Las Vegas | Sep 21st - Sep 25th 2026 |
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 19th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Orlando | Apr 12th - Apr 16th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Mountain | Apr 21st - Apr 25th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Baltimore | May 17th - May 21st 2027 |
Podcast Transcript
Hello and welcome to the Tuesday, September 15th, 2026 edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich, recording today from Jacksonville, Florida. And this episode is brought to you by the SANS.edu Graduate Certificate Program in Cloud Security. Well, today was one of the few days where we knew there was a big Apple update going to come. It was Apple's sort of annual big update where they released the next major version of their operating systems. This time we are up for iOS and macOS 27. With that, of course, we also got, aside from a lot of features, we got fixes for vulnerabilities. 261 vulnerabilities. Now, overall, this isn't sort of terribly out of range for Apple. It is a record, but we had like, you know, around 200 before. Well, on average, I would say more like around 100. So definitely more than normal, even though not an explosion like we have seen like with Microsoft and Oracle. As far as the vulnerabilities go, nothing that sort of terribly sticks out here. Nothing that was already exploited before today. Now, for everybody who isn't willing to make the leap to the 27 version of the operating system, there is also a 26.7 version that is just a bug fix, security fix release, and does not include any new features. So definitely consider that if you want to hold off a little bit. And that's usually recommended with any major update like this. As far as sort of known issues go, well, if you use Little Snitch, the third-party firewall for macOS, they released an update a couple weeks ago that specifically stated you should apply it before upgrading to 27. Objective-C, they have a couple of additional utilities like BlockBlock, for example, is one that came out with a new release that improved macOS 27 compatibility. So definitely something that you also want to apply. I applied it after upgrading and haven't seen any bad effects there yet. Other issues, haven't really seen any sort of specific issues. There may be a problem with some of the Microsoft single sign-on handovers. I've run into it with one particular site where Safari is having issues. Other browsers after upgrading have not had any issues. Of course, Safari also was updated as part of this release. So again, this affects all the operating systems from Apple iOS, macOS, iPadOS, VisionOS, watchOS, all of them, and tvOS all got updates. So apply them. But like I said, you can still sort of go with the 26.7 version if you want to stay a little bit on the safe end. And with the new version of macOS, we also got a new version of Homebrew. Homebrew is a system, so much like apt, yum, and some of these package managers that you're familiar with in the Linux world to install various open source packages. And as any of these ecosystems, of course, they're battling with supply chain issues. Well, this new version, version 7, has some specific fixes kind of that make it easier, for example, to scan for dependencies and also a new feed being offered by Homebrew that can be used to essentially identify malicious or backdoored or compromised, I should probably say, dependencies. So definitely a step forward. There's also now a GUI for those of you who like it, haven't looked at the GUI myself yet. There are a couple similar projects, of course, out there. I think Homebrew is probably the biggest one. What I sort of always liked about Homebrew is that it usually does not require you to run commands as root, just in very few exceptions where root access is required. Another related issue is now sometimes when you're downloading a package from Homebrew, it needs to be compiled. So you need to have a compiler, typically Xcode. I have not seen sort of a simple update yet for Xcode 27. The latest in the App Store is still 26. I believe there is one if you need it for download from the developer website with Apple. Not sure how long it'll take for the sort of official Xcode update to show up in the App Store. And Microsoft today released an out-of-band update. Now there is a security issue being addressed here, but that isn't really what makes this particular update interesting. It fixes two complaints users had with last Tuesday's patch Tuesday update. Apparently for some users, remote desktop services was unstable. So that's one of the fixes. The other fix that's being addressed here is audio issues that came up on some Windows systems. So definitely that's sort of why this particular update was released. The security update is a refinement of a patch that was released I think back in March to patch a particular case that wasn't covered by the earlier patch. So really just sort of completing the patch from back then. And yes, that's this Windows user mode power service is the elevation of privilege issue that is being addressed here. And then we got an interesting write-up by XPatch.com releasing some details regarding a telegram vulnerability that was patched back in July. What makes this noteworthy is, well, not that we now have sort of an exploit for it, but that you may still be exposed to this vulnerability even after you patch telegram. The problem here is if you're exporting the HTML of a message that you received in telegram, well, due to this vulnerability, it was possible for an attacker to embed JavaScript in that export. Now, if you later open that HTML file, now it's being opened from the local file system. So it's running in a different trust scope of the browser and the JavaScript can execute and even access the local system. So the problem here is if in the past you exported chats from telegram as an HTML archive, those HTML archives may still contain JavaScript, even if you now patched a telegram. Not sure how and if that had been exploited, but the sounds like this kind of vulnerability is relatively straightforward actually to exploit. So even after the patch was released, if you were late patching, you may have had a window there where you were exposed to exploits. Well, and this is it for today. So thanks for listening. Thanks for liking. Thanks for subscribing to this podcast and talk to you again tomorrow. Bye.





