meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Tuesday, July 14th, 2026: MCP/AI Related Scans; Improve Router Hygiene; OAuth Client ID Spoofing; Veeam Vuln;

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9755 Ratings

🗓️ 14 July 2026

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Tuesday, July 14th, 2026: MCP/AI Related Scans; Improve Router Hygiene; OAuth Client ID Spoofing; Veeam Vuln;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, July 14th, 2026 edition of the Sands in the Storm Center's Stormcast.

0:13.0

My name is Johannes Ulrich, recorded a day from Washington, DC.

0:18.0

And this episode is brought you by the Sands.edu graduate certificate program in cyber security

0:24.5

engineering. Manuel today wrote up an interesting trend that he has been observing in a site that

0:31.1

he is watching. Well, it's just a basic web server, but more and more, it is being hit by requests for MCP connections, so the

0:40.8

model control protocol that's commonly used with AI, as well as requests for AI credentials.

0:47.8

Now for a long time we have seen a lot of requests for like no dot ENV files and the like

0:52.9

essentially files that typically contain credentials.

0:55.8

But what Manuel is seeing and that sort of matches our global data as well, more and more

1:00.5

of these scans are looking for credentials specifically associated with AI models.

1:06.6

With the goal, of course, being that some of these credentials could be abused by the attacker to gain access to free to the attacker AI tokens.

1:16.8

Now, the MCP connection attempts are also interesting.

1:20.5

First of all, many of them are just checking for the presence of the slash MCP URL.

1:26.0

Of course, if there's a 404 coming back, the URL doesn't exist,

1:28.8

and the attacker knows that this is not at least the right access for the API.

1:35.1

Well, but a couple of requests that Manuel observed also contained the full MCP-compliant

1:40.9

payload to initiate new connections. So definitely attackers are looking for these services to again likely abuse them for their own purposes.

1:53.0

And SISA, together with a few other self-information security related federal organizations and the the FBI has published some guidance on

2:03.2

how to better protect your routers.

2:06.0

Now, the routers we're talking about here are more sort of the ISP enterprise routers, not

2:11.1

your home router, which of course is often the target of attacks.

2:15.0

The guidance here is specific to exploits that have been observed

...

Transcript will be available on the free plan in 14 days. Upgrade to see the full transcript now.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.