meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Friday, March 6th, 2026: Targeted or Not? pac4j-jwt auth bypass; freescout dangerous uploads; MSFT Authenticator vs Graphene OS

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 6 March 2026

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Friday, March 6th, 2026: Targeted or Not? pac4j-jwt auth bypass; freescout dangerous uploads; MSFT Authenticator vs Graphene OS

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Friday, March 6, 2026 edition of the Sands Internet Storm Center's Stormcast. My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida.

0:17.8

And this episode is brought you by the Sands.edu graduate certificate program in cloud security.

0:24.4

Today we got another guest diary from one of our undergraduate interns.

0:28.6

This time it was Joseph Grooons' turn to write up some of his observations from a honeypot.

0:36.6

Now, one of the things about honeypots is that honeypots

0:39.5

are usually easy to identify as a honeypot, and they're not typically getting you sort of

0:45.7

these serodays or targeted exploits, but they're really measuring sort of the background

0:51.3

radiation of the internet, as I sometimes call it, basically sort of all the background noise that you typically end up with from these

0:58.8

ubiquitous scans. And Joseph is going over one particular actor like that.

1:05.1

What you often have happening here is that these individual scanners are then sort of zooming in on a particular type of

1:13.6

exploit, type of artifact they're looking for. Now, where this becomes kind of valuable,

1:19.6

then is also when you're looking at our Honeypot network and the data we publish on the Internet

1:25.1

Storm Center website, if you're getting attacked by an IP address and you wonder,

1:30.3

hey, is this someone that's only attacking me,

1:32.3

or is this someone that is basically scanning the internet

1:36.3

for this particular issue?

1:38.2

Well, just search for the IP address on the Internet Storms Center website

1:41.5

and see what our sensors picked up about that IP address

1:45.4

and whether the activity that you are seeing is different in some ways.

1:51.3

And then sadly we do have another one of those open source library vulnerabilities to talk

1:58.5

about that may send you scrambling to figure out which particular systems

2:03.2

in your network are using this particular library.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.