SANS Stormcast Tuesday, May 19th, 2026: New libssh in Malware; Exchange 0-Day; MSFT Authenticator Update
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 19 May 2026
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Tuesday, May 19th, |
| 0:07.4 | 2006 edition of the Sands Internet Storms Centers. |
| 0:12.0 | Stormcast, my name is Johannes Ulrich, |
| 0:14.6 | recording today from Jacksonville, Florida. |
| 0:18.0 | And this episode is brought you by the sands.edu graduate certificate program in |
| 0:22.6 | cybersecurity leadership. Let's start out today with today's diary, and that comes again from |
| 0:29.7 | one of our Sands undercredit interns. Gokul Prima Tanga Tanga well wrote this particular diary about, well, the ever-present SSH bots. |
| 0:41.0 | Bots that are brute-forcing usernames and passwords for SSH, |
| 0:45.3 | and then they often install modified authorized keys files, |
| 0:49.5 | which, of course, then act as a backdoor for the attacker. |
| 0:53.8 | Now, the one thing that Gokul here is looking at |
| 0:57.5 | is a very well-established chain of these S-H-Bots |
| 1:03.0 | that always is leaving behind the same authorized keys files. |
| 1:06.8 | That's sort of one of the indicators of compromise here. |
| 1:08.8 | But Gokul dot some subtle, well, modification to the binary being used to do the scanning in that it updated to a new LibSH. |
| 1:21.7 | LibSH is the base library that implements SSH, and then we also have these hash values. |
| 1:29.3 | Now, hash is written here with two S's, basically H-A-S-S-H, which basically identifies the |
| 1:37.5 | S-H connection details, and with that often identifies the matter. |
| 1:42.7 | But that now changed with the switch to the new lip SSH. |
| 1:48.2 | And, well, what this really means is don't be too specific on your indicators of compromise. |
| 1:54.0 | If you're seeing a lot of outbound asage connection, |
| 1:57.3 | there is a good chance that you have a system in your network |
... |
Transcript will be available on the free plan in 12 days. Upgrade to see the full transcript now.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

