SANS Stormcast Thursday, February 26th, 2026: CLAIR Model; Cisco SD-WAN 0-Day; Cortex XDR Abuse; OpenSSL Vuln;
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 26 February 2026
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, February 26, 2006 edition of the Sands |
| 0:09.7 | In its Storm Center's Stormcast. My name is Johannes Ulrich, recording today in Jacksonville, Florida. |
| 0:16.9 | And this episode is brought you by the Sands.edu undergraduate certificate program in Cybersecurity Fundamentals. |
| 0:25.0 | Our diary today comes from Claire Perry, a graduate of our bachelor's degree program, and this diary presents the Claire model. |
| 0:35.2 | What is about is it about critical infrastructure. And typically when you're |
| 0:39.7 | dealing with critical infrastructure, one of the big security models and frameworks that's |
| 0:44.6 | often being used is the Purdue model. The Purdue model is well-established and extremely useful |
| 0:50.6 | to talk about some of these infrastructure security threats. But as Claire Perry here |
| 0:57.7 | points out, the model is very insular in that it's great for you, like as an operator, as a utility, |
| 1:05.2 | to talk about the security of an individual plant, but it kind of ignores the interdependencies because, well, you don't |
| 1:12.3 | control many of them. So it just considers them sort of as inputs to your plant. |
| 1:18.4 | Well, that's sort of what this is attempting to fix here. So this model, this framework, |
| 1:24.6 | is looking very much at interdependencies, like external things, |
| 1:28.6 | like all the way to policies and such that may affect the security of your |
| 1:34.1 | critical infrastructure systems. It's a proposal at this point, so if you have any feedback |
| 1:40.3 | or such, I'm sure Claire is happy to hear about it. |
| 1:45.8 | And Cisco today published an advisory regarding vulnerability affecting Catalyst SD-WAN controllers, |
| 1:53.7 | also I guess formerly known as SD-WAN-V-smart. |
| 1:59.1 | This vulnerability, CVS score of 10 allows an attacker without off occasion |
| 2:05.1 | to gain admin privileges on the device. What makes this even worse is that apparently it has |
| 2:11.9 | been exploited since 2023. So two or three years already out there and being exploited, now discovered and |
| 2:21.4 | finally being patched. Cisco's advisory also lists some indicators of compromise. Definitely |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

