meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Thursday, July 2nd, 2026: MetaMask Phishing; Adobe Patches; Google Chrome Patches; Apple Hide-My-Email Vuln

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9755 Ratings

🗓️ 2 July 2026

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Thursday, July 2nd, 2026: MetaMask Phishing; Adobe Patches; Google Chrome Patches; Apple Hide-My-Email Vuln

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, July 2nd, 2026 edition of the Sands Inlet Storm Center's Stormcast.

0:13.2

My name is Johannes Ulrich, recording today from Riyadh, Saudi Arabia.

0:18.4

And this episode is brought you by the sands.edu created certificate program

0:22.5

in Purple Team Operations. That is a reminder, there will be no podcast tomorrow on Friday,

0:30.3

part because of July 4th, not so, because of my travel schedule. Xavier came across a real

0:36.7

interesting fishing email. Now, this particular

0:40.0

phishing email targets Meta Mask. Meta Mask is an app and a browser extension used for

0:46.6

crypto coins or cryptocoin wallet, and of course, with that an attractive target. But the approach

0:52.8

they're taking here for fishing is a little bit different.

0:56.1

Now, Minamask, like many websites, particularly if they're crypto coin related, does require and

1:01.8

encourage to use multi-factor authentication. So that basically renders some of the simple fishing

1:09.1

attempts useless. But in this particular case, the attacker is going after a secret phrase the user establishes

1:17.6

in order to reset their authentication option.

1:22.6

So when you're signing up for Mehta Mask, as part of the signup process, this secret phrase is established.

1:27.8

It's not used to usually log in.

1:30.6

It's used more as a password recovery token as a backup in case you're losing your username

1:38.3

and second factor.

1:39.8

And that's exactly what the attacker is abusing here.

1:43.2

So essentially the password reset feature.

1:48.0

The problem here, of course, is how do you securely recover an account if the second factor is lost?

1:56.0

A lot of websites and such are relying on a type of sort of one-time password or a secret random string that's established when you're setting up the second factor.

2:08.7

And that, of course, is still fissurable as this particular attempt shows.

...

Transcript will be available on the free plan in 2 days. Upgrade to see the full transcript now.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.