meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Tuesday, June 23rd, 2026: Webshells; GitHub Actions Update; Fortibleed Update; Private Access Control Tokens

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9755 Ratings

🗓️ 23 June 2026

⏱️ 8 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Tuesday, June 23rd, 2026: Webshells; GitHub Actions Update; Fortibleed Update; Private Access Control Tokens

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, June 23rd, 2006 edition of the Sands Internet Storm Center's Stormcast.

0:12.2

My name is Johannes Ulrich, recording date from Jacksonville, Florida.

0:17.4

And this episode is brought you by the Sands.edu credit certificate program in cyber security leadership.

0:25.5

Web shells. Well, that's a topic that keeps coming up, and Xavier found a new one on GitHub.

0:32.3

These web shells are popping up ever so often. This one claims to be hard to detect or undetectable.

0:39.1

What this usually means it's just too new for signatures to actually have been added

0:43.0

to standard endpoint protection software that's often used to detect web shells.

0:49.4

A better way often to detect web shells is just to look for unauthorized changes than just looking

0:56.8

for signatures. Now, the way they are typically being deployed is that you have some kind of

1:02.9

unauthorized file, upload vulnerability, maybe a remote code execution vulnerability on a web

1:10.1

server, and then very typical, the first thing that an attacker is doing is maybe a remote code execution vulnerability on a web server.

1:16.2

And then very typical, the first thing that NetHacker is doing is using that vulnerability to gain persistent access by uploading a web shell.

1:20.8

So usually a little script in whatever language you're using on your server.

1:26.0

This one, I think, is written in PHP, but they exist for

1:30.7

pretty much any sort of web application language out there. And as a result, well, yeah,

1:37.0

pay attention to these web shells. No matter, you know, if the attacker uses AI or not,

1:42.9

detecting web shells is probably going to

1:44.6

help you either way. And GitHub is making some improvements to the security of its workflows

1:53.2

in order to prevent some of the more common supply chain attacks. The change they made this week is a change to the pull request target.

2:04.5

So when someone submits a pull request with this particular pull request target, you have

2:09.3

the option to initiate workflows. And these workflows do have access to secrets associated

2:14.8

with the repository. Since essentially anybody can initiate a poll request,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.