Podcast Detail

SANS Stormcast Wednesday, October 7th, 2026: RMM Tools; libHEIF RCE; Sonicwall SMA1000, OpenSSH updates, DNSSEC KSK Rollover

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10126.mp3

Podcast Logo
RMM Tools; libHEIF RCE; Sonicwall SMA1000, OpenSSH updates, DNSSEC KSK Rollover
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

More RMM Tools In the Wild
https://isc.sans.edu/diary/More%20RMM%20Tools%20In%20the%20Wild/33400

WORDPRESS LIBHEIF RCE
https://fortbridge.co.uk/research/wordpress-libheif-rce/

SONICWALL SMA1000 SERIES APPLIANCES Vulnerabilities CVE-2026-102255, CVE-2026-102256, CVE-2026-102257, CVE-2026-102258
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017

OpenSSH 10.6 Released
https://seclists.org/oss-sec/2026/q4/58

DNSSEC Root Key Signing Key Rollover
https://blog.cloudflare.com/root-ksk-2024-rollover/

My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich

Podcast Transcript

 Hello and welcome to the Wednesday, October 7th, 2026
 edition of the SANS Internet Storm Center's Stormcast. My
 name is Johannes Ullrich, recording today from
 Jacksonville, Florida. And this episode is brought to you
 by our SANS.edu Bachelor's Degree Program in Applied
 Cybersecurity. In Diaries today we have Xavier talking
 about yet another abuse of a valid remote management tool.
 In this particular case it's a tool by ActionOne called Agent
 or A1 Agent it's sometimes referred to. This again is a
 legitimate Windows remote management, remote monitoring
 tool that sort of includes some VPN-like encryption
 abilities and the like. Well, really all that an attacker
 kind of likes to have. And in this case it's being installed
 via a malicious PDF. The PDF arrives as a fake Adobe update
 and actually just the other day I was talking to someone
 that we don't really see many Adobe Flash Player updates
 anymore. Maybe people understand now that this
 software no longer exists. Well, this actor here still
 attempts to do that. It's the usual fake PDF invoice that
 you're getting here. Xavier talks a little bit about how
 to analyze this sample and it uses this action item where
 you can basically open a URL as you open the PDF in order
 to then direct the victim to the next site. The first stage
 of the malware in this case a simple Visual Basic script
 that will then download the actual malware or well
 actually not malware here. I guess in this case the actual
 remote management tool. So as I said before, monitor these
 remote management tools and make sure that any traffic you
 are seeing comes from approved legitimate tools. Again, you
 can't really trust too much into antivirus and endpoint
 detection here because they often don't flag these tools
 because they're valid software. And Fort Bridge
 showed how vulnerability in libHEIF can be used for
 remote code execution. Now, libHEIF is for the HEIF or
 HEIF file format that has become popular. I think Apple
 sort of started that file format. And lately, that's why
 I mentioned this particular issue. There have been a
 number of vulnerabilities tied to vulnerabilities in the HEIF
 parsers like libHEIF. So it's definitely something to keep
 an eye on if you are parsing HEIF images. If you're using
 any open source or commercial libraries for that matter, not
 sure what exactly exists here in the commercial space.
 Definitely watch for updates. There's a lot of effort
 currently in finding these type of vulnerabilities in
 HEIF implementations. And the insecure security appliance of
 the day is SonicWall's SMA-1000, the friend of the show.
 We had him quite a few times before. This time it's a CVSS
 score 10 vulnerability. It's a server-side request forgery
 vulnerability that does allow an unauthenticated user to
 essentially perform arbitrary actions. Not a ton of detail
 here. It sort of also talks about alternate control path
 or so. Doesn't mention a different sort of URL string
 bypass or anything like that. But the way the server-side
 request forgery vulnerabilities typically work
 is that you have an internal service listening on loopback.
 Because it's listening on loopback, well, it doesn't
 really do any kind of authentication access control.
 And you can use the server -side request forgery
 vulnerability to use the front -end as a proxy to reach these
 internal services. And OpenSSH released version 10.6. This
 version does, of course, fix vulnerabilities. But the
 reason I mention it is not a specific vulnerability.
 Nothing really too critical here. But two additional
 remarks that come with this release. One is the OpenSSH
 project. Like everybody is receiving a lot of submissions
 that were created by AI. So you will see more frequent
 releases of OpenSSH to address these vulnerabilities. And
 secondly, they're also pointing out, and I think
 that's a real good point. People receiving these bug
 reports often complain about duplicate reports. But what
 they're saying is that, well, the real problem here is since
 they get duplicate reports, these vulnerabilities are now
 really not that hard to find. So if they get these reports,
 it means others probably that didn't report it also have
 that information. And so delaying patches really
 doesn't buy you any time here. And that's, you know, again,
 why they're moving forward with a more accelerated
 release schedule. They're not suggesting a specific rhythm
 here or anything like this. They are just saying that
 releases will be published more frequently. And well,
 since DNS is my favorite internet protocol, I must
 mention that October 11th, the key signing key for the root
 zone is going to change. This is only the second time that
 this key has been updated. First time actually turned out
 to be a little bit messy. Since then, they did make a
 lot of improvements with automatic key rotation and
 things like that. The key has been published for, I think,
 over a year now. I'll link to a blog post by Cloudflare that
 has additional details on how to check if your resolver is
 ready for this new key. Well, and that's it for today. So
 thanks for listening. Thanks for liking. Thanks for
 subscribing. By the way, next week I will be in Amsterdam.
 So if anybody is at the SANS event in Amsterdam, look me
 up. And that's it for today. Talk to you again tomorrow.
 Bye. All right. Bye. Bye. Bye. Bye, bye. Bye. Bye. Bye, bye.
 Bye. Bye. Bye. Bye. Bye. Bye.