meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Thursday, April 16th, 2026: AI Credential Scans; Microsoft Update Issues; RDP Warnings; GitHub Action Vulns;

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 16 April 2026

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Thursday, April 16th, 2026: AI Credential Scans; Microsoft Update Issues; RDP Warnings; GitHub Action Vulns;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, April 16th, 2006 edition of the Sands

0:09.8

Inanded Storm Center's Stormcast. My name is Johannes Ulrich, recording today from Stockholm, Germany.

0:16.0

And this episode is brought you by the Sands.edu credit certificate program in Purple Team Operations.

0:24.4

Configuration files containing secrets are a common target for attackers today.

0:29.4

Typically attackers are scanning web servers for commonly used configuration files like.env.

0:36.4

Gie noted in his honeypod logs that attackers are now more and more scanning for files

0:42.6

associated with AI tools.

0:44.5

For example, attackers are scanning four files associated with OpenClaw, Clod, and Open AI.

0:52.2

Just like any configuration files, these files should not be kept in a document

0:56.4

route at hackers will usually use the credentials contained in these files to steal tokens,

1:02.8

which can lead to rather large invoices from these AI vendors. So make sure that, first of all,

1:10.1

the secrets are probably protected,

1:11.8

but in addition, well, set up the right billing alerts and limits for your particular

1:17.1

AI tools. So that way you're at least being alerted and hopefully are limiting the damage

1:23.8

that's done in case some of these secrets will eventually be.

1:28.3

And then we got some postscripts to yesterday's Microsoft Patch Tuesday.

1:34.3

Microsoft states that some devices with an un-recommended BitLocker Group policy configuration

1:41.3

might require to enter their BitLlocker recovery key on the first

1:46.4

restart after installing this update.

1:48.9

So what Microsoft's saying here is that you may have to enter your bitlocker key, which

1:53.2

of course a lot of people don't necessarily have just sitting around there, hopefully, and

1:57.5

it can be a little bit difficult to get to.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.