meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Tuesday, February 10th, 2026: Extracting URLs; Singal Phishing; Ivanti PoC; BeyondTrust RCE; Forticlient SQL Inection

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 10 February 2026

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Tuesday, February 10th, 2026: Extracting URLs; Singal Phishing; Ivanti PoC; BeyondTrust RCE; Forticlient SQL Inection

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, February 10th, 2026 edition of the Sands and at Storm Turner's

0:11.7

Stormcast. My name's Johannes Ulrich, recording today from Jacksonville, Florida.

0:17.2

And this episode is brought you by the Sands.edu crash certificate program in penetration testing and ethical hacking.

0:24.6

And today, 17 years ago, was, well, the first episode of this podcast.

0:30.4

Since then, according to my counting, but it's probably not accurate with re-recordings and stuff like this.

0:36.5

We published 4,160 individual episodes,

0:41.4

a few days' worth of audio material. And just, well, to celebrate this a little bit,

0:47.2

if you were born after February 9, 2009, well, drop me an email and I'll have some stickers for you.

0:56.4

Or just interesting to hear how many listeners are actually younger than the podcast itself.

1:04.2

And DDA has a diary today about an update and, well, a way to better use his famous document analysis tools to extract

1:12.9

URLs from RTF documents. And as an example, DDA here has a malicious document that's

1:20.6

based on a basic fishing email that came with an RTF attachment. Extracting URLs is always super useful because, well, that's often in the next step

1:31.5

that the attacker is trying to pursue.

1:34.2

And of course, we had last week this story about, well, malformed URLs.

1:40.5

And that certainly fits in here, too, that you're also been able to extract some of these

1:45.4

malformed URLs that may not necessarily quite match standard patterns, but are still effective.

1:53.1

And we got, well, a new blog post by Watchtower with details regarding the latest vulnerability

1:59.7

in Ivanti's endpoint manager mobile.

2:03.1

That product, always good for easy-to-exploit vulnerabilities,

2:06.9

and this is not so different here.

2:10.0

Now, it took watchtower a little bit time here to actually walk through all the code,

2:15.7

but in the end, it turns out to be a fairly straightforward OS command injection vulnerability.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.