SANS Stormcast Thursday, February 19th, 2026: Malware Image Resuse; Dell RecoveryPoint; Admin Center Vuln; DNS-PERSIST-01
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 19 February 2026
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, February 19th, |
| 0:07.4 | 2006 edition of the Sands and the Nett Storm Center's Stormcast. |
| 0:12.3 | My name is Johannes Ulrich, recording today from Jacksonville, Florida. |
| 0:17.1 | And this episode is brought you by the Sandsdot edu graduate certificate program in industrial |
| 0:22.8 | control system security. Well, Xavier continues to be on a role this week with yet another piece |
| 0:30.2 | of malware to analyze. And in this case, it's actually a nice example on how to combine different |
| 0:37.4 | piece of malware with certain actors. |
| 0:40.7 | A week or so ago, Xavier did already talk about a piece of malware that used an MSI |
| 0:47.1 | wallpaper as part of its payload. Now, in that particular case, it was really just used |
| 0:52.4 | sort of to basically half an image to attach a coat to. |
| 0:57.0 | So the image itself, that wallpaper, could have been any other image. |
| 1:02.5 | But what Xavier found is that there's other malware that uses exactly the same image, suggesting that it was created by the same actor. |
| 1:11.4 | Also uses some other similar techniques and such as the Malber that Xavier covered in the past. |
| 1:18.9 | And overall, Xavier found a few hundred of pieces of submissions to a virus total that included this image, not all of them being labeled as malicious. |
| 1:32.0 | And that's where it gets interesting whether or not you should add something benign like this |
| 1:37.3 | image to some form of signature. |
| 1:40.6 | Maybe it's be interesting to sort of highlight certain samples and maybe look at them |
| 1:45.9 | with more detail or included as part of signature, of course not necessarily as the only |
| 1:51.9 | signature to look for malicious activity. |
| 1:56.0 | And yesterday, Dell released an update for Recovery Point for Virtual Machines. |
| 2:01.5 | This update is fixing fixed credential vulnerability, |
| 2:06.8 | so nothing really all too special here, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

