meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Tuesday, February 24th, 2026: Malicious JPEG Analysis; Calibre Vuln; jsPDF object injection; Roundcube Exploited

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 24 February 2026

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Tuesday, February 24th, 2026: Malicious JPEG Analysis; Calibre Vuln; jsPDF object injection; Roundcube Exploited

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, February 24, 2026 edition of the Sands and the Net Storm Center's Stormcast.

0:13.1

My name is Johannes Ulrich, recording today from Jacksonville, Florida.

0:18.1

And this episode is brought you by the sense.edu bachelor's degree program in applied

0:24.7

cybersecurity. Well, in diaries today, we have a malware analysis diary from Jan. Jan looked at,

0:31.4

well, as you called it, yet another malicious JPEG file, an image in this case, but what actually arrived initially and

0:40.5

Jan focused a little bit more on the downloader here. It was, well, a good old compressed,

0:45.8

sip compressed JavaScript file. Once decompressed, there was over a megabyte of data. However,

0:53.8

most of the data was garbage.

0:55.4

So first obfuscation technique here where the attacker is just adding some random garbage to the file

1:02.2

in order to extend its size, make it a little bit more difficult to sort of analyze it,

1:08.1

sometimes also full than anti-malbar engines into not actually looking at the file.

1:14.9

Well, once all of that was removed, there were only a couple kilobytes left.

1:20.0

Actually, in the end, only about a dozen or so lines that Jan actually had to deobuscate further.

1:27.0

And, well, that's where he ended up with your standard downloader.

1:31.8

That would then download an image with attached scripts.

1:34.9

That would then in the end end up installing the REMCO-RAT, well, remote access tool.

1:43.0

So overall, fairly standard malware. A couple lessons here

1:48.2

from this one. The from was actually faked and would not make it past properly configured.

1:55.9

D-Mark, D-KM-KM-SPF. So those techniques are definitely very useful. Often, even simple stuff like this

2:05.5

gets missed by some anti-malmer engines, so having that extra layer of basically fairly

2:10.6

straightforward and simple defenses like DMARC certainly can make a difference here.

2:17.3

And if you're using caliber in order to read e-books, well, pay attention.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.