SANS Stormcast Monday, March 30th, 2026: More TeamPCP: telnyx; Netscaler Exploit; macOS ClickFix Fix; Windows Smart Install
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 30 March 2026
⏱️ 8 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Monday, March 30th, |
| 0:07.8 | 2006 edition of the Sands International Storm Centers. |
| 0:11.8 | Stormcast, my name is Johannes Ulrich. |
| 0:14.1 | We're recording today from Orlando, Florida. |
| 0:17.9 | And this episode is brought you by the sands.edu graduate certificate program |
| 0:21.9 | in incident response. Yes, and team PCP is still keeping us busy. The latest update here |
| 0:29.9 | from Ken is that they have now a number of additional libraries being compromised, one of them |
| 0:37.2 | being Telnix. |
| 0:38.9 | Telnix is a voice over IP platform, so basically it allows you to automate phone calls |
| 0:44.4 | and various chatbots and such. Of course, this is a prime target to be then integrated |
| 0:49.7 | with respective AI tools, AI chatbots, and the like. |
| 0:54.2 | And, well, that's exactly sort of where to compromise hits. |
| 0:57.8 | They did compromise a Python library that is actually used to interface these tools with Telnix's Rest API. |
| 1:06.8 | Now, in this case, the actor wasn't able to compromise the GitHub repository. |
| 1:12.6 | Instead, they compromised the Pi Pi account for Telnix and as a result, we're able to publish a new version. |
| 1:21.6 | So in this particular case, version pinning should have protected you. |
| 1:25.6 | And yes, only if you download the new compromised version, |
| 1:29.9 | then you have a problem. |
| 1:31.2 | Slightly different payloads for Windows and Linux or MacOS in this case. |
| 1:36.4 | And another sort of interesting add-on is that some of the malicious code |
| 1:41.3 | is being transported as a wave file. So that way it makes it a little bit more |
| 1:47.5 | difficult to attack. Also, there are now more and more links between the team PCP crew and various |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

