SANS Stormcast Tuesday, June 9th, 2026: Azure Repos Infected; Checkpoint VPN 0-Day; Verizon VoLTE missing IPSec integrity prot.
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 755 Ratings
🗓️ 9 June 2026
⏱️ 5 minutes
🔗️ Recording | Apple Podcasts | RSS
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Tuesday, June 9th, 2006 edition of the SANS Internet Storm Center's Stormcast. |
| 0:12.5 | My name is Johannes Ulrich, recorded a day from Jacksonville, Florida. |
| 0:17.4 | And this episode is brought you by the Sands.edu undergraduate certificate program in cyber security fundamentals. |
| 0:25.2 | Well, for a couple weeks now, I keep saying that you should assume compromise when it comes to your supply chain. |
| 0:31.6 | The latest example here is the compromise of several Azure-related Microsoft GitHub repositories. |
| 0:40.7 | I don't know what you want to call this particular warm. |
| 0:42.7 | It's well the same kind of over again after, of course, some of the Chateauulu warms and |
| 0:48.0 | such were made public. |
| 0:50.0 | We've seen many, many variants spring up. |
| 0:52.7 | Step security has a good write-up on what they're calling Myasma Warm, |
| 0:58.1 | and that's the one that hit these Microsoft repositories. |
| 1:01.3 | It hit a total of 72 repositories. |
| 1:05.1 | But remember, they're not just stealing credentials. |
| 1:07.6 | They're also then actively attempting to spread into anybody using code from these affected repositories. |
| 1:15.4 | Now, Microsoft acted quite quickly here and disabled the repositories. |
| 1:22.5 | They didn't really even know why they disabled it, so there was a lot of confusion among developers |
| 1:26.1 | who depended on some of the |
| 1:27.6 | GitHub actions here, which actually was part of the problems. And as a result, their CI-CD pipelines |
| 1:34.5 | failed. Good thing if your CI-CD pipeline fails in this case, because that means, well, you |
| 1:41.0 | were not infected by this particular worm. So, yeah, don't complain too much |
| 1:47.8 | about Microsoft. It was the right quick response in order to prevent further harm from being done. |
| 1:55.9 | Of course, they probably should have done a little bit more ahead of time with hardened configurations and the like, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

