SANS Stormcast Tuesday, March 3rd, 2026: Finding URLs in ZIPs in RTFs; Merkle Tree Certificates; Taming Agentic Browsers
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 3 March 2026
⏱️ 8 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Tuesday, March 3, 2006 edition of the Sands International |
| 0:10.0 | Center's Stormcast. My name is Johannes Ulrich, recording today from Jacksonville, Florida. |
| 0:16.7 | And this episode is brought you by the Sands.edu graduate certificate program in Purple Teams operation. |
| 0:24.4 | When attackers are attempting to obfuscate what they're doing, they often take advantage of compound document formats. |
| 0:33.3 | We're trying to sort of wrap one document into another document type, and then of course |
| 0:39.9 | it becomes more difficult to figure out the actual malicious part. DDA has a quick diary |
| 0:47.3 | up on how to use his tools in order to analyze one particular type of these documents, and that's |
| 0:53.1 | a zip file inside an RTF. Yes, that's legal, |
| 0:57.5 | that's perfectly fine, and of course a particular type of zip file would be a Word document, |
| 1:03.6 | because these Doc X formats, well, they are really just compressed zip files. So the DA is walking |
| 1:10.7 | you here through a particular |
| 1:11.9 | example and showing how to not only extract this sort of mess of convoluted documents, |
| 1:18.6 | but also then extract URLs, for example, which of course could lead you to then additional |
| 1:24.7 | exploit attempts or malicious documents. |
| 1:28.7 | One commenter point out that the document that DDA here happened to use in the blog post, |
| 1:34.5 | which actually also covered by Akamai a week or so ago, |
| 1:38.1 | because it was one of the documents attempting to exploit Microsoft vulnerability that was patched in February. |
| 1:46.6 | So a relatively recent vulnerability was being exploited using this particular document. |
| 1:55.4 | And well, the voyage to finally end up with a quantum safe internet is continuing. And the next challenge here is |
| 2:03.6 | certificates. There are two interesting blog posts that are sort of related to each other, one by Cloudflare, |
| 2:09.3 | one by Google about how to solve this particular challenge. I'll link to the Cloudfair one. |
| 2:15.1 | I like that a little bit better in the explanation, but there's |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

