meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Tuesday, June 16th, 2026: BASE64 Statistics; Cisco SD-WAN Exploited; AMD TSME Disabled; Poisoning Deep Research Agents

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9755 Ratings

🗓️ 16 June 2026

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Tuesday, June 16th, 2026: BASE64 Statistics; Cisco SD-WAN Exploited; AMD TSME Disabled; Poisoning Deep Research Agents

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, June 16th,

0:07.4

2006 edition of the Sands International Storm Center's Stormcast.

0:12.4

My name is Johannes Ulrich, recording today from Jacksonville, Florida.

0:17.7

And this episode is brought you by the Sands.edu underwrite certificate program in applied cyber security.

0:25.9

Well, I always love DDA's follow-up diaries to any kind of malware that Xavier discovered earlier.

0:32.3

Saville last week discovered this malware that was sort of hidden inside this MSI wallpaper.

0:40.3

While the DEA now shows us how to use his base 64 decode tools in order to essentially figure out

0:48.3

how the particular string here or the malware is encoded and how to extract it from the image. This is kind of a little bit

0:56.3

interesting here. It's B-604 encoded, but there are two letters swapped. The A's are swapped for the

1:04.3

number symbol. And then the string is also basically just used in reverse. So it starts with the equal equal symbol, which, well, usually you have at the end of the base 64 encoded string.

1:17.6

So interesting little trick here and the DDA walks us also through some of the dead end that he ran into using these tools,

1:26.6

which is obvious I I think, more realistic

1:28.4

and also more educational, because you may run into those same dead ends yourself and they

1:34.7

will show you how to overcome these dead ends. And Cisco released advisory and a fix

1:41.4

to address a vulnerability in the Cisco Catalyst SDWAN manager.

1:47.9

This vulnerability is an arbitrary file right vulnerability, and of course with that can lead to

1:53.2

arbitrary code execution. Now, why is this only rated as a medium by Cisco?

1:59.4

The main reason here is that this requires valid

2:04.3

credentials, so you have to be authenticated in order to exploit the vulnerability, even though

2:10.5

this CFSS score of 6.5, maybe a little bit low here. The other thing that makes me talk about this vulnerability is that it's already being

2:20.6

exploited in the wild.

2:22.8

Cisco does have an addition kind of at the end of the advisory stating that as of June,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.