SANS Stormcast Friday, April 3rd, 2026: Vite Exploits; OpenSSH 10.3; Claude Code Vuln
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 3 April 2026
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, April 3rd, 2006 edition of the Sands Internet Storms Centers. |
| 0:11.0 | Stormcast, my name is Johannes Ulrich, recording today from Orlando, Florida. |
| 0:17.0 | And this episode is brought you by the Sands.edu graduate certificate program in incident response. |
| 0:25.3 | Today I noticed in our honeypots that we are seeing some scans for a vulnerability in the developer tool Veed. |
| 0:34.3 | This vulnerability was discovered by OffSec last July and now apparently is being exploited. |
| 0:42.2 | It's fairly straightforward to exploit vulnerability, even though I doubt that there will be a lot of |
| 0:48.3 | exposed systems. Typically, this particular tool listens on port 5173. |
| 0:55.1 | Well, this is not where the scans are going to. |
| 0:57.7 | These scans are going to standard HTTP ports. |
| 1:01.5 | So that's the first thing that made me a little bit think that maybe they're looking for someone |
| 1:06.6 | who may be misconfigured this particular tool. |
| 1:09.9 | The problem with the tool is that it does provide |
| 1:13.0 | access to files on the local file system via simple HTTP requests. All you need is a prefix slash |
| 1:20.7 | at FS slash and that will then basically just map to the file system disregarding the document route or any settings like this. |
| 1:30.3 | However, there is some access control as is provided that basically limits this access to certain directories. |
| 1:37.2 | However, the vulnerability discovered last July does allow arbitrary access as long as the URL ends in question mark, question mark, |
| 1:46.3 | raw question mark. So that particular suffix essentially then bypasses the access control. |
| 1:53.7 | If you're running Veed, please make sure that you are running it securely, that you're not |
| 1:59.7 | exposing it, and that you're also running the |
| 2:02.7 | latest version. And by the way, this tool, well, it's pronounced feed, but it's really sort of a |
| 2:07.9 | French tool and this spelling is VITE. So some people may pronounce it like VIDI or something like that. |
| 2:25.0 | And Open SSH version 10.3 has been released and with that number of security issues were addressed. None of these security issues I would consider critical or something that |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

