SANS Stormcast Thursday, January 29th, 2026: WebLogic AI Slop; Fortinet Patches; WebLogic AI Slop; Fortinet Patches
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 29 January 2026
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, January 29th, 2006 edition of the Sands and the |
| 0:10.8 | Storm Center's Stormcast. My name is Johannes Ulrich, recording today from Jacksonville, Florida. |
| 0:17.5 | And this episode is brought you by the sands.edu undergraduate certificate program in cyber security fundamentals. |
| 0:25.9 | Last week, Oracle published its quality critical patch update, and with that, we also got a patch for WebLogic. |
| 0:34.7 | That patch, I think I pointed out when it was released, wasn't so far noteworthy that first of all, WebLogic. That patch, I think I pointed out when it was released, wasn't so far noteworthy |
| 0:40.2 | that first of all, WebLogic has been exploited many times in the past, and secondly, it |
| 0:46.4 | got a CVSS score of 10, so a perfect score here for possible exploit attractiveness, I guess. |
| 0:56.0 | I should say because compromising web logic using this particular vulnerability |
| 1:01.2 | could lead to a complete system compromise. |
| 1:05.1 | So with an exploit like this, I'm usually periodically kind of trying to find |
| 1:10.3 | an exploit |
| 1:10.9 | attempts in our Honeypot logs and did see one in our logs, but this particular |
| 1:17.3 | exploit attempt didn't really make much sense. It had sort of all the parts that you may |
| 1:23.5 | expect in an exploit like this, but it was highly unlikely that, well, the vulnerability was as trivial as suggested by this exploit. |
| 1:34.4 | So doing a little bit further digging, apparently, at the time when the vulnerability was disclosed by Oracle, |
| 1:42.0 | someone published a GitHub repository with what looks like |
| 1:47.0 | AI generated exploit that apparently doesn't work at all. And we are now seeing this exploit |
| 1:53.2 | being used against basically arbitrary hosts. It's not just being sent against WebLogic, |
| 2:00.3 | but really just random hosts. |
| 2:02.5 | And, well, I guess to some extent, nice if attackers are wasting the time with AI slob like this. |
| 2:09.1 | But on the other hand, what's really happening here is that both defenders and attackers are using AI trying to speed up their development process, |
| 2:20.5 | either of signatures or of attack scripts like what we saw here. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

