SANS Stormcast Monday, May 4th, 2026: Malicious Homebrew Ads; Wireshark Update; Digicert False Positive; cPanel Exploited
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 4 May 2026
⏱️ 8 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Monday, May 4th, |
| 0:07.3 | 2006 edition of the Sands Internet Storm centers. |
| 0:11.7 | Stormcast, my name is Johannes Ulrich, |
| 0:14.2 | recording today from Jacksonville, Florida. |
| 0:17.7 | And this episode is brought you by the sands.edu graduate certificate program in industrial control systems security. |
| 0:25.1 | And in diaries today, we got one of the excellent malvernalysis diaries from Brad. |
| 0:30.1 | Brad walks us here through an infection with Mack Sink Steeler. |
| 0:35.0 | Now, what makes this particular attack so successful likely is that, well, it takes |
| 0:41.4 | full advantage of the entire Google ecosystem. It starts out with a paid ad on Google. If you're |
| 0:50.2 | searching for HomeProve, you may be seeing links for this particular malicious version of HomePro, which is then also hosted within Google's pages infrastructure. |
| 1:02.7 | So the only URL you're seeing here is business.gov.com, which of course is often not considered malicious. |
| 1:10.6 | Now, if the user then clicks on this link, |
| 1:13.9 | they're then being sent to a fake HomeProop page. |
| 1:18.0 | Now, if you're not familiar with HomePro, |
| 1:19.5 | HomePro is essentially a system |
| 1:21.5 | that allows you to easily install various open source tools, |
| 1:25.8 | so it's very commonly used by Mac users. |
| 1:29.3 | And the page here looks very much like the real thing, only that this one, of course, is hosted within sites.com. |
| 1:38.9 | Now, just like in the real home proof, you're then being asked to sort of copy-paste shell script in order to execute the installer. |
| 1:49.2 | Now, the real version is not obfuscated like the one here. |
| 1:53.9 | Here, you're then basically pasting a base 64 encoded string that then leads to execution |
| 1:59.4 | and will then download additional tools, including |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

