SANS Stormcast Monday, July 27th, 2026: ESAFENET CDG Scans; DNS Poisoning; macOS Gatekeeper bypass; GitHub and PyPi updates
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 755 Ratings
🗓️ 27 July 2026
⏱️ 7 minutes
🔗️ Recording | Apple Podcasts | RSS
🧾️ Download transcript
Summary
Scans for ESAFENET CDG 3 Document Management System Weak Logins
https://isc.sans.edu/diary/Scans%20for%20ESAFENET%20CDG%203%20Document%20Management%20System%20Weak%20Logins/33184
DNS Poisoning Tactics Expand to Hospitality Wi-Fi
https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/
Silent Replacement of Trusted macOS App Executables
https://mysk.blog/2026/07/23/macos-overwrite-app-executables/
GitHub and PyPi Defense updates
https://github.blog/security/supply-chain-security/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates/
https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days/
https://www.bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Monday, July 27th, 20206 edition of the Sands |
| 0:10.9 | and that's Storm Center's Stormcast. My name is Johannes Ulrich, recorded |
| 0:15.3 | from Jacksonville, Florida by teaching online this week in London. And this episode is brought you by the sands.edu undergraduate certificate program |
| 0:25.8 | in cyber security fundamentals. |
| 0:29.4 | This weekend, I noticed some scans for ESAFNet CDG 3. |
| 0:34.0 | This is not the first time we saw scans for this particular product. A couple years ago, |
| 0:40.0 | cross-ed scripting vulnerability was discovered in the product, and we saw some scans around that time. |
| 0:46.7 | There are really sort of three vulnerabilities that are commonly being quoted for this particular product. |
| 0:54.3 | One is the cross-ed scripting vulnerability, |
| 0:57.3 | then there's a SQL injection vulnerability, |
| 0:59.5 | and the one that we see scans right now for |
| 1:02.5 | is for hard-coded passwords. |
| 1:04.9 | That's probably the most straightforward one to exploit |
| 1:07.8 | when it comes to e-safnet CDG. This is a product mainly focusing on the Chinese |
| 1:14.4 | market, all their website and such is in Chinese. Now, the product itself builds itself as a secure |
| 1:22.3 | document management, the leakage prevention system. The vulnerability is, well, well, the fixed passport stuff is pretty bad, |
| 1:32.7 | but I think are sort of in line with what we typically see with these kind of expensive products |
| 1:39.4 | that are proposing to be more secure than others, |
| 1:44.3 | but, well, still have some of the same vulnerabilities. |
| 1:49.1 | And Relya Quest has a good write-up of some recent attacks |
| 1:52.8 | that supposedly were perpetrated by some Russian threat actors |
| 1:57.8 | that targeted hospitality Wi-Fi gateways. So they're going after the gateway, |
... |
Transcript will be available on the free plan in 27 days. Upgrade to see the full transcript now.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

