SANS Stormcast Friday, May 29th, 2026: @sans_edu research; Honeypot Log; VPN “Toad”; Silent Ransom Group
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 29 May 2026
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, May 29th, 2006 edition of the Sands International Stormers |
| 0:11.0 | Stormcast. My name is Johannes Ulrich, recording today from Jacksonville, Florida. And this episode |
| 0:17.8 | is brought you by the Sands.eduedu grad certificate program in cyber security engineering. |
| 0:24.5 | At the beginning of each podcast, I always highlight one of the programs of our college, sance.edu. |
| 0:31.3 | Today, we also release another volume of our research review journal. This journal collects some of the best papers that |
| 0:41.1 | students have written over the last year, so certainly something worthwhile browsing through, |
| 0:48.2 | in particular if you're interested, maybe in the program itself, to see what our master's degree |
| 0:52.7 | students are coming up with. |
| 0:55.9 | And Guy today took a quick snapshot of his honeypot and looked at, well, what kind of activity |
| 1:02.3 | there was this last year. And no surprise, there was plenty of activity. It sort of started |
| 1:08.9 | for Guy in October, really, for real, and part |
| 1:13.3 | of course on some maintenance here on the Honeypot. Ghee is maintaining a little seam that |
| 1:20.5 | actually can be installed on top of our honeypot, then can be used to create these kind of |
| 1:25.8 | summaries. What kind of surprised me here in the summaries is that when we're looking at the file |
| 1:33.1 | uploads that happen via Cowrie, so these are people connecting via S-H or Telnet. |
| 1:37.6 | Well, there's actually a non-negligible number of PowerShell scripts that were uploaded to these Linux, essentially |
| 1:47.1 | Honeybots. Not sure if this was just sort of, you know, by mistake, or if they're counting on |
| 1:51.4 | Windows systems running as age, or maybe, well, a lot of the more modern Linux distributions |
| 1:56.5 | also at least come optionally with PowerShell as well. So maybe they count on that. |
| 2:02.6 | Not sure if the particular PowerShell scripts uploaded to these systems would work on |
| 2:09.3 | default PowerShell installs on Linux. |
| 2:13.1 | And then we got an interesting backdoor in a popular VPN extension for Google Chrome and Edge. |
... |
Transcript will be available on the free plan in 20 days. Upgrade to see the full transcript now.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

