meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Tuesday, June 2nd, 2026: Netlogon Exploit; Unidentified RAT; Windows Netlogon Exploited; RedHat npm Affected; Dashlane Bruteforce Attach

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 2 June 2026

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Tuesday, June 2nd, 2026: Netlogon Exploit; Unidentified RAT; Windows Netlogon Exploited; RedHat npm Affected; Dashlane Bruteforce Attack

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, June 2nd, 2006 edition of the Sands Internet Storms Center's Stormcast.

0:12.7

My name is Johannes Ulrich, recorded today from Jacksonville, Florida.

0:17.8

And this episode is brought you by the Sands.edu created certificate program in cyber security

0:23.7

engineering. In diaries today, we have a post by Brad talking about a new rat or remote access

0:30.5

tool that Brad found. Now, in the end, this particular infection ends up with net support rat, and it starts out with

0:39.1

sort of a standard click fix campaign.

0:42.0

But in the middle, there is an interesting rat that really shows some odd behavior.

0:47.5

For example, it uses HTTP over Port 443, and then it also uses just data over Port 443. That's not TLS. It uses some kind of custom

0:59.6

encoding. So nothing that Brad really sort of found being written up to before. Definitely is

1:07.6

something that also I don't remember seeing particular, seeing just HTTP over Port 443.

1:13.9

Not really sure why if that's supposed to basically fit in with other HGPS traffic.

1:18.7

These days, the bad guys pretty much use HGPS exclusively, just like anybody on the Internet.

1:26.4

So if anybody has any insight here for Brad,

1:29.0

please let us know.

1:31.6

And the Belgium Center for Cybersecurity

1:33.6

is warning that Warnability at Microsoft patched in May,

1:38.1

that's the Windows Net Logon vulnerability,

1:41.2

is already being exploited.

1:43.8

Haven't seen anything official from Microsoft, but they

1:46.8

may be busy consulting with their lawyers about this. So assume it's being compromised, make sure

1:53.5

you are patched in order to exploit this war on a billion. And hacker would actually have to

1:58.7

connect to Port 389 to the LDAB port.

...

Transcript will be available on the free plan in 24 days. Upgrade to see the full transcript now.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.