SANS Stormcast Tuesday, January 20th, 2026: Scans Against LLMs; NTLM Rainbow Table; OOB MSFT Patch
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 20 January 2026
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Tuesday, January 20, 2006 edition of the Sands Internet Storm Center's Stormcast. |
| 0:11.0 | My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida. |
| 0:16.0 | And this episode is brought you by the Sands.edu graduate certificate program in cyber security |
| 0:23.0 | leadership. And did he and his honeypot observed, well, an attacker hunting for large language |
| 0:29.4 | models, more and more companies and also individuals are running their internal large language |
| 0:36.6 | models. And, well, some of them are exposing them |
| 0:39.5 | onto the Internet, and this is what the hackers are after. |
| 0:43.1 | There are a couple reasons for that. |
| 0:45.3 | First of all, of course, they could just use those models instead of the public and potentially |
| 0:51.0 | more costly ones in order to run their queries. |
| 0:55.3 | They could also possibly then exploit additional weaknesses in it, |
| 0:59.2 | in particular if an individual or a company did add their own sort of internal knowledge base |
| 1:05.8 | to the large language model. |
| 1:08.3 | They may be able to enumerate that and then figure out exactly, |
| 1:12.8 | you know, what kind of secrets or so may be stored in that particular model. |
| 1:18.9 | So a couple of possibilities here don't exactly know what they're after. |
| 1:24.1 | There are a couple other reports as well of people finding these scans in their logs. |
| 1:32.1 | But, yeah, you probably don't want to expose these models to the public without any odd occasion. |
| 1:39.5 | That's really just setting yourself up for at least a fairly costly compute bill. |
| 1:45.1 | And Mandy and the part of Google, of course, now did release a rainbow table of possible |
| 1:51.2 | net NTLM version 1 hashes. |
| 1:54.7 | Now, this is nothing really sort of super groundbreaking or such. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

