meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Thursday, May 7th, 2026: .DE DNSEC Fail; PAN OS 0-Day Patched;

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 7 May 2026

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Thursday, May 7th, 2026: .DE DNSEC Fail; PAN OS 0-Day Patched;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, May 7th, 2006 edition of the Sands Internet Stormsiders.

0:11.2

Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:16.9

And this episode is brought you by the Sands.edu undergraduate certificate program in cyber security fundamentals.

0:25.0

Well, it's not DNS. There's no way it's DNS. And in the end, it was DNS.

0:31.2

This good old DNS haiku again became true yesterday with the dot-de-de, the German country top-level domain.

0:42.6

Apparently what happened here was a DNSSEC issue.

0:46.9

DNSSEC, as I have often said, is one of those protocols that, well, they actually let the

0:52.4

security people develop the protocol.

0:54.0

You always complain that protocols aren't secure enough because security. those protocols that, well, but they actually let the security people develop the protocol.

0:59.3

You always complain that protocols aren't secure enough because security people never sort of get a say in the development until it's too late. Well, Dinesek, I think, is sort of an example

1:04.8

where it went the other way around. And as a result, it's a pretty complex protocol, lots of moving parts, lots of things that can go wrong,

1:13.5

and then, well, in the sense of good security, if it goes wrong, it usually just stops working.

1:19.9

So it's one of those, you know, fail-closed kind of systems, and that's kind of what happened here with the.de zone.

1:30.4

The problem apparently was key rotation, like with all cryptographic systems, you need to rotate your keys ever so often,

1:39.0

which then also means that you need to change signatures.

1:42.7

Well, Dinesek has a mechanism for this,

1:45.5

where you first basically make a new key life.

1:48.5

You advertise a new key,

1:49.6

and the old key remains valid and also remains accessible.

1:54.3

But then you start updating signatures.

1:58.3

Apparently something here went wrong.

2:00.0

They haven't really released any

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.