Handler on Duty: Xavier Mertens
Threat Level: green
Podcast Detail
SANS Stormcast Friday, September 18th, 2026: LousivLaoder Analysis; Issabel Framework 0-Day; Cyber Decoys; CISA Vuln Bulletin; Unbound Vulnerability
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10100.mp3
LousivLaoder Analysis; Issabel Framework 0-Day; Cyber Decoys; CISA Vuln Bulletin; Unbound Vulnerability
00:00
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
LausivLoader analysis, or how to pass data between malware stages
https://isc.sans.edu/diary/LausivLoader%20analysis%2C%20or%20how%20to%20pass%20data%20between%20malware%20stages/33348
Issabel Framework Hard-coded JWT Key RCE CVE-2026-89026
https://www.vulncheck.com/advisories/issabel-pbx-hard-coded-jwt-key-rce-via-pbxapi-manager-originate
Using Cyber Decoys to Strengthen Detection and Response
https://www.cisa.gov/sites/default/files/2026-09/using-cyber-decoys-to-strengthen-detection-and-response_508c.pdf
CISA to Sunset Weekly Vulnerability Bulletin on September 28, 2026
https://content.govdelivery.com/accounts/USDHSCISA/bulletins/42b055b
Unbound Vulnerability
https://nlnetlabs.nl/projects/unbound/security-advisories/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Application Security: Securing Web Applications, APIs, and Microservices | Las Vegas | Sep 21st - Sep 25th 2026 |
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 19th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Orlando | Apr 12th - Apr 16th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Mountain | Apr 21st - Apr 25th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Baltimore | May 17th - May 21st 2027 |
Podcast Transcript
Hello and welcome to the Friday, September 18th, 2026 edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich, recording today from Jacksonville, Florida. And this episode is brought to you by the SANS.edu Graduate Certificate Program in Penetration Testing and Ethical Hacking. In diaries today, we have Jan analyze some interesting piece of malware that led him to an instance of loss of loader. What happened here was, first of all, a somewhat targeted email arriving. Luckily, the email was detected by anti -malware and also would have been blocked by, well, your usual DKM and SPF precautions, which the sender domain had enabled properly. But where it got interesting was when Jan actually analyzed the malware itself. And there are two components to the malware that are playing together. The first component is obfuscated JavaScript. And Jan does a great job in sort of showing how to de-obfuscate this JavaScript. And then some PowerShell is being called. But the JavaScript and the PowerShell are exchanging information via environment variables. So this certainly sort of throws a wrench into a lot of reverse engineering pipelines and such. Because first, you need to go through the JavaScript, which actually will then create an encryption key that is used to then decrypt part of the PowerShell. Well, yesterday I talked about tags and scans for a fairly obscure PBX control framework. Today we have news of a much more popular framework, the ISSABEL framework, which is used to control PBXs, basically phone systems, via web applications. Well, this particular framework contained a hard -coded JWT key, so basically the secret key being used to sign these JSON web tokens. With that key, it was possible to essentially bypass authentication. The result was that you could actually execute arbitrary code on any kind of asterisk server that was linked to an ISSABEL framework frontend. A patch has been submitted to this, but exploitation has already been observed in the wild by the Shadowserver Foundation. And one of my favorite things in security and defense, of course, is deception with honeypots, honey tokens, or, well, any number of decoys. CISA published an interesting document about using cyber decoys to strengthen detection and response. That's the title of the document. And what it essentially does is it sort of goes through the process that you should follow if you're planning to deploy decoys. Now, again, I'm a huge fan of this concept overall. The part that has often been missing is sort of an enterprise-wide framework, particularly for larger organizations, for enterprises, to deploy these kind of decoys. And there have been a number of products that try to do this. None of them, I think, really sort of took off. My personal opinion is always that one reason why decoys are often not deployed or then discontinued after they're being deployed is, well, two little false positives. You don't really see them working unless they actually get hit by an attack. But either way, if you're interested in decoys, if you want to sort of have a more structured process in deploying them, well, this document really has some nice ideas and sort of frameworks to actually follow. And we have another victim of the ever-increasing number of vulnerabilities. CISA decided to sunset its weekly vulnerability bulletin. This was a list basically of all vulnerabilities. And, well, that, of course, has become rather unwieldy lately. So what CISA is now saying is, well, they're no longer going to publish this. The final one will be on September 28th, so end of the month. And beyond that, they're referring to the more risk-based approaches like the known exploit list and other feats, of course, that CISA publishes to essentially identify vulnerabilities that matter. Interesting approach, of course, and I completely understand why a list of all these vulnerabilities may no longer really be all that feasible. Since, of course, we still have our at-risk newsletter, and we intend to continue to maintain that for now. We have sort of made some adjustments to it over the last year to, again, try to prioritize rank vulnerabilities better to sort of have the ones that matter sort of bubble more to the top. And Unbound fixed two heap-based buffer overflows in its software. One of them may lead to unauthenticated remote code execution. Both of these vulnerabilities are related to DNSSEC, and the first one that may lead to remote code execution is one of those decompression issues where you have these compressed records. If they're pointing to themselves, you actually can end up with an overly large record that then fills the buffer. Sounds a little bit similar to like an older Microsoft DNS vulnerability that was like in a SICK record. I think not the DNSSEC, but sort of a precursor record. So maybe a little bit related to that. Either way, try to get this patched. Unbound is a DNS resolver often used sort of in small gateways and such. So IoT-style devices. That's where you often find Unbound. As a result, some of these devices don't always have strong protections against the exploitation of buffer overflows like address space, random layouts, and things like this. So that's why you really want to patch this and make sure that you are up to date, that your firmware for your router is up to date. Well, and that's it for today. Thanks for listening. Thanks for liking. Thanks for recommending. Thanks for subscribing. Next week, I'll be in Vegas at our science conference. I'll be teaching our Defending Web Application class. Actually, completely newly redone version of that class. So hope to see some of you there. I'll have plenty of stickers with me. Also spread some of them around. And we'll, as always, talk to you again on Monday. Bye. overall Thank you. Bye. Bye.





