meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Tuesday, April 7th, 2026: Redirects in Phishing; Internet Bug Bounty Suspended; Bluehammer; Keycloak MFA Bypass

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 7 April 2026

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Tuesday, April 7th, 2026: Redirects in Phishing; Internet Bug Bounty Suspended; Bluehammer; Keycloak MFA Bypass

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, April 7th, 2026 edition of the Sands Internet Storm Center's Stormcast.

0:12.4

My name is Johannes Ulrich, recording today from Jacksonville, Florida.

0:17.3

And this episode is brought you by the Sands.edu undergraduate certificate program in Applied Cybersecurity Security.

0:25.8

Jan today followed up on a recent diary of mine. In this diary I mentioned that we do see

0:32.2

quite a few attackers that are scanning our honeypots for possible open redirects.

0:38.7

There are a couple reasons why they may be doing this, and one of the suggestions was that

0:44.4

these redirects are being used for fishing, and Jan followed up on that and looked at recent

0:51.1

phishing emails and tried to figure out how many of these recent fishing emails are using open redirects.

0:58.2

So just to be clear about this, an open redirect is a bug vulnerability in a website that allows an attacker to essentially use this website as a conduit in a fishing attack

1:11.6

where the user is first being sent to the harmless website,

1:14.2

which will then automatically redirect the user to the actual fishing website.

1:19.2

This is different from a compromised website

1:21.9

where an attacker did add a redirect like this to the particular website.

1:27.4

So these open redirects are indeed used quite commonly.

1:32.1

Jan found them in about 20 to 30% roughly of different phishing emails that Jan looked at.

1:39.9

And of course, they're dangerous in so far because these websites being used as a redirect here

1:43.8

have usually a good reputation score, not malicious not compromised and with such

1:50.1

can often be unused to sort of serve as an early first hop in the fishing email chain

1:56.1

which does allow it to pass through many email filters.

2:08.3

And Hacker 1 has announced last week that they're suspending their internet bug bounty.

2:14.3

What was special about the internet bug bounty was that it was really trying to solicit bugs and security vulnerabilities really for open source projects.

2:19.0

And then the bounty was actually split between the hacker who found the vulnerability

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.