meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Thursday, April 2nd, 2026: Script Removing ADS/MotW; Google Chrome 0-Day; iOS/iPadOS 18 Update;

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 2 April 2026

⏱️ 4 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Thursday, April 2nd, 2026: Script Removing ADS/MotW; Google Chrome 0-Day; iOS/iPadOS 18 Update;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, April 2nd, 20206 edition of the Sands International Storm Center's Stormcast.

0:12.7

My name is Johannes Ulrich, recording today from Orlando, Florida.

0:18.2

And this episode is brought you by the sands.edu graduate certificate program in

0:23.0

industrial control systems security. And Xavier today looked at an interesting, malicious script

0:29.8

that in order to obtain persistence, did write a file to the file system, but then removed the zone identifier from the file.

0:40.9

I've talked about this quite often already, the mark of the web.

0:45.6

That appears to be the intent here.

0:49.0

The zone identifier is an alternate data stream in Windows that is used to mark a file that was downloaded from the Internet.

0:57.2

And of course, in instant response, if you're looking for suspicious files,

1:01.2

that's an often an indicator that an analyst may be looking for.

1:06.6

So by removing this indicator, using a quick Power power shell command, the attacker is decreasing

1:13.4

the chance of the file being discovered. And Google released updates for Google Chrome.

1:20.3

This update fixes 21 different vulnerabilities. One of these warnabillies is already being exploited. The exploited

1:30.0

vulnerability is a use after free vulnerability in Dawn. Dawn is the component in Google Chrome

1:36.1

that implements web GPU. So that's the component that is being attacked here, and not the first time that we had

1:45.4

a critical vulnerability in dawn. And Apple has done it again. Apple has released another

1:53.2

operating system update for iOS 18. We are now up to iOS 18.7.7 as well as iPad OS18.7.

2:02.9

The tricker for this update was yet again the Dark Sword attack.

2:07.8

This is an attack that uses vulnerabilities that used to be more the domain of,

2:13.0

well, more sort of state-sponsored matter, but now is more widely used and it can be found on

2:19.7

various websites that then affect these warnable devices. Since in particular these older

2:26.5

devices don't have some of the more modern sort of countermeasures, well, they're particular

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.