meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Tuesday, April 28th, 2026: More TeamPCP; Citrix XenServer Unpatched Vulns; Phantom RPC;

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 28 April 2026

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Tuesday, April 28th, 2026: More TeamPCP; Citrix XenServer Unpatched Vulns; Phantom RPC;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, April 28, 2026 edition of the Sands Internet Storm Center's Stormcast.

0:13.7

My name is Johannes Ulrich, Rekongn today from Jacksonville, Florida.

0:17.8

And this episode is brought you by the sands.edu graduate certificate program

0:22.8

in industrial control system security. Ken Dutay wrote a quick update on the latest developments

0:30.8

in Team PCP style attacks, and of course, one of the big developments last week was checkmarks, and a couple of the other companies affected by this Bitwarden.

0:42.0

I mentioned both last week. Now for checkmarks, there is one kind of interesting new development that apparently the entire GitHub repository was leaked as part of the attack.

0:56.1

They don't state how severe this is, if there are any secrets in this GitHub repository or not,

1:02.5

but they do state that this all is really sort of just follow-on left over from an attack

1:09.3

that started March 23rd.

1:12.5

So about a month ago, they wrote back then about this attack on March 23rd,

1:18.8

but now they basically linked those two attacks.

1:22.1

And yes, that's sort of one of the big news items here.

1:26.3

Just in general, as far as I current state of supply chain attacks go,

1:32.5

they also have a new blog post by socket.dev,

1:37.0

and they're writing about 73 different OpenVs extensions

1:42.3

that they found that basically linked to Classform,

1:46.0

which is typical credential exfiltration.

1:49.6

So again, you know, more opportunities here for developers to lose their credentials.

1:55.1

And with that, sort of new entry points being found by attackers for additional supply chain

2:00.8

attacks once they hit a developer

2:03.7

for a major package, then of course they can start the cycle all over again.

2:15.0

We have some bad news for users of Citrix Xen Server, or the XAPI, which is the API that comes with XEN server.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.