SANS Stormcast Thursday, April 30th, 2026: Odd Requests; MSFT LNK Bug Exploited; Secure Boot Fix; TLS Updates; SAP npm malware
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 30 April 2026
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, April 30th, 20th, 26 edition of the Sands Internet Storm Center's Stormcast. |
| 0:13.0 | My name is Johannes Ulrich, recording today from Jacksonville, Florida. |
| 0:18.2 | And this episode is brought you by the sands.edu bachelor's degree program in |
| 0:23.3 | applied cyber security. In diaries today, nothing too special. They're too odd web requests that |
| 0:30.6 | sort of caught my eyes and that came in via our honeypots. The first one is a request that appears to be going after the Broadcom API Gateway. |
| 0:42.7 | Don't think that's an exploit as is. |
| 0:45.3 | I think there's really more some kind of fingerprinting or reconnaissance scan. |
| 0:49.8 | Similar, the second one. |
| 0:51.5 | The second one is going after what I believe, according to the URL, |
| 0:56.3 | to be ESP 32 devices. Saw something here that this may be used to flash firmware on those |
| 1:03.6 | devices. If anybody has any more experience with either ESP 32 or the Procom API Gateway, let me know if there is more |
| 1:13.0 | to these particular endpoints and whether there could be some kind of attack being performed |
| 1:19.1 | via just these individual requests. |
| 1:23.2 | And then we got an update to Microsoft's Patch Tuesday this month. |
| 1:27.5 | This update comes from Akamai in the forum of Akamai stating and showing that one of the |
| 1:34.3 | vulnerabilities being addressed in this month's update has already been exploited before |
| 1:40.8 | Microsoft actually released the update. |
| 1:44.6 | This was not indicated in Microsoft's updates, |
| 1:47.3 | so it was not labeled as already exploited. |
| 1:49.9 | Since then, Microsoft has updated its guidance, |
| 1:53.3 | and now also states that this vulnerability is already being exported |
| 1:57.6 | or had been exploited before the patch was released. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

