Podcast Detail

SANS Stormcast Friday, September 11th, 2026: Redtail Analsys (@sans_edu); Checkpoint VPN Patch; Netscaler and Sonicwall Attacks

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10090.mp3

Podcast Logo
Redtail Analsys (@sans_edu); Checkpoint VPN Patch; Netscaler and Sonicwall Attacks
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

Podcast Transcript

 Hello and welcome to the Friday, September 11th, 2026
 edition of the SANS Internet Storm Center's Stormcast. My
 name is Johannes Ullrich, recording today from
 Jacksonville, Florida. And this episode is brought to you
 by the SANS.edu Graduate Certificate Program in Cloud
 Security. In diaries today we have one of our undercredit
 interns write about a copy of the Red Tail Malware that
 Aaron Ng here did capture in his honeypot. Now the details
 are really very nice in this particular analysis, but what
 I want to point out is the way the analysis was done. This
 sample was analyzed using a runtime analysis, which tends
 to be the simpler form and faster form often to figure
 out what a particular piece of malware does. You essentially
 just run it. Of course, running malware comes with
 some complications. You don't want the malware to go out as
 some of the samples often do and infect other systems.
 Also, you want to be able to capture all of the activity
 from this malware and experiment with different
 runtime options and such. And that's a part of what Aaron
 did here. But Aaron used an interesting tool that I always
 highly recommend when you're trying to do this kind of
 analysis. And that's iNetSim. iNetSim is essentially
 software that sort of simulates a small internet for
 you. So you have like no various services that you can
 enable there that will then mimic the real services that
 the malware may be connecting to things like DNS servers and
 such to basically give the malware a little bit more
 realistic view like it would be connected to the actual
 internet. And of course, with the advantage to still have
 the isolation and not having to maintain yourself all these
 different services that you may need to spin up otherwise
 if you want to get sort of the same result. So interesting
 tool if you are doing runtime analysis of malware, iNetSim
 certainly something that I would recommend. And a couple
 other solutions too like this, but I find this really sort of
 simple and it's one of those solutions that does really
 most of what you need and usually suffices over some
 very much more complex solutions. And Checkpoint
 yesterday released a critical security advisory and a patch
 fixing two vulnerabilities. These vulnerabilities do allow
 unauthenticated remote code execution, at least the first
 one. The second one, also a heap-based buffer overflow,
 doesn't say whether or not it needs authentication to
 execute any code here. Either way, definitely something that
 you do want to patch in particular for the first one,
 the unauthenticated remote code execution vulnerability.
 Now, Checkpoint also points out that if you have the
 Checkpoint Live patch feature enabled, then the patch should
 have already been applied to your system. They rolled it
 out September 9th. But after spending a lot of time this
 week on talking about vulnerabilities, let's talk
 now a little bit about vulnerabilities that are
 currently being exploited. Cisco just updated the
 advisory they published in March for its Secure Firewall
 Management Center. This vulnerability is now being
 exploited and Cisco does offer some indicators of compromise
 that you can use to check if your instance was affected by
 this particular exploit. And Ryan Dewhurst with Pravidian
 did note on X that they're observing exploitation of
 Netscaler ADC vulnerability. This vulnerability was
 originally patched about a month ago, a little bit less
 than a month ago. Proof of concept exploit was made
 public a couple days ago. And that's, as Ryan here points
 out, also is always sort of a basic sign. Once you see a
 public proof of concept, well, yes, at that point, the
 vulnerability is widely being exploited. And you always
 should assume compromise, of course, at this point. And
 finally, SonicWall SMA 1000. We had recently an already
 exploited vulnerability being patched there. Hunt.io now
 published a real nice and detailed walkthrough of an
 attack that they have seen in the wild against local
 government in the UK. These walkthroughs are always really
 helpful because they really show what attackers are doing
 with these vulnerabilities, how to identify this
 particular attacker. But then also similar attacks that
 exploit the same vulnerability, because here
 you can see what particular evidence, for example, may be
 left behind on a compromised system. That's always very
 helpful if you see the full walkthrough in some vendor
 bulletins like the Cisco one I mentioned earlier. They're
 very specific indicators of compromise, which, of course,
 may change from attacker to attacker. And it's not always
 that obvious what you can use here as a good indicator of
 compromise beyond sort of that simple file name, hash or IP
 address that may have been published. Well, and this is
 it for today. So thanks for listening. Thanks for liking.
 Thanks for subscribing. Remember, any future teachers
 of myself will usually be listed in the show notes. So
 take a look at that. And that's it for today, for this
 week. Talk to you again on Monday. Bye.