SANS Stormcast Friday, June 5th, 2026: Coreutils for Windows; Cisco Unified Comm Manager Fix and Exploit; OAuth Orphans
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 5 June 2026
⏱️ 6 minutes
🧾️ Download transcript
Summary
Microsoft's Coreutils for Windows
https://isc.sans.edu/diary/Microsoft%27s%20Coreutils%20for%20Windows/33048
Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability CVE-2026-20230
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW
Firmware Update for Acer Connect W6x Router
https://community.acer.com/en/kb/articles/19672
OAuth marketplace apps keep access after publishers vanish
https://www.helpnetsecurity.com/2026/06/04/oauth-marketplace-apps-audit/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, June 5th, 2006 edition of the Sands and its Storm Center's |
| 0:11.2 | Stormcast. My name is Johannes Ulrich, recorded date from Jacksonville, Florida. And this episode |
| 0:18.2 | is brought you by the Sands.edu, create a certificate program in incident response. |
| 0:24.8 | Well, today's diary is not sort of a core security topic, |
| 0:28.0 | but, well, it's about Microsoft's core utilities for Windows, |
| 0:32.1 | and that's a utility that's probably quite useful for many of you if you're used to the Unix |
| 0:39.1 | command line and all of the little tools that usually come with that. |
| 0:44.0 | Well, Windows now does have the same commands available thanks to Microsoft releasing core |
| 0:51.6 | utilities. |
| 0:52.9 | Now the approach they're taking here is a little bit like |
| 0:55.5 | what you often see with BISI Box. That's like, you often used on IoT device and such, |
| 1:01.3 | but you have one binary, but then BSM Links, you can call it under multiple names, and depending |
| 1:09.0 | on what name you use, well, it behaves different. |
| 1:11.6 | It basically then emulates whatever command you're trying to execute. |
| 1:16.3 | That, of course, also has the advantage with just one binary. |
| 1:19.1 | It's a little bit easier to manage this. |
| 1:21.3 | This binary is, of course, properly signed, |
| 1:23.7 | which is another nice advantage over, for example, |
| 1:26.8 | some of the open source solutions and such |
| 1:29.1 | that are a bit more difficult to validate. |
| 1:33.8 | So give it a spin and, well, let us know how you made use of these utilities. |
| 1:40.5 | And Cisco yesterday released a noteworthy patch for a critical vulnerability in Cisco's Unified Communication Manager. |
... |
Transcript will be available on the free plan in 26 days. Upgrade to see the full transcript now.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

