SANS Stormcast Thursday, May 28th, 2026: Akira Ransomware; Vaultjacking; Poisoned Chatbot and Search Results;
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 28 May 2026
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, May 28, 2026 edition of the Sands Internet Stormsendors Stormcast. |
| 0:12.8 | My name is Johannes Ulrich, recording today from Jacksonville, Florida. |
| 0:17.7 | And this episode is brought you by the Sands.edu undergraduate certificate program in cyber security fundamentals. |
| 0:25.6 | Well, I assume nobody here likes ransomware, but one thing I do like is a great write-up explaining how to early detect a ransomware. |
| 0:34.6 | Manuel wrote up an Akira ransomware Kill Chain, which essentially walks you through |
| 0:41.5 | the about one week of activity that was conducted by this particular threat actor against a network |
| 0:48.8 | from which Manuel was able to obtain logs. Now, what was interesting is that really there were some early signs that something wasn't |
| 0:58.7 | right, and that was a large number of failed authentication events against the SSL VPN. |
| 1:06.5 | As so often, well, the secure device here, the SL VPN did sort of cause or provide the initial access. |
| 1:14.0 | Now, here in this case, it was basically just credential brute forcing. |
| 1:17.5 | The attacker eventually got lucky and was able to log in. |
| 1:21.7 | So there was no specific exploit used here. |
| 1:25.7 | Next, we then had the internal discovery where the attacker was essentially |
| 1:31.1 | probing the network, sort of trying to connect to Windows shares and doing the usual Who Am I and |
| 1:37.4 | such, so all actually things that are relatively easy to detect if you are properly instrumented, |
| 1:43.9 | and then of course, lateral movement |
| 1:46.0 | via RDP, also a very typical ransomware strategy. Well, in summary, it took them about a week |
| 1:54.5 | to actually start the encryption. So there were actually quite a few sort of early indicators |
| 2:00.1 | that may have helped to then prevent the actual encryption and exfiltration potentially here of the data. |
| 2:10.1 | Manuel walks you through all the different indicators, all the log IDs and such to look for in order to identify this activity in your |
| 2:20.4 | network, hopefully before it gets encrypted by a similar attack. |
| 2:26.4 | Well, I have talked before about phishing resistant authentication. Fishing resistant authentication |
... |
Transcript will be available on the free plan in 18 days. Upgrade to see the full transcript now.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

