meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Tuesday, May 26th, 2026: VBA in MSFT Access; NPM Stealer; PHP Laravel Compromise; Google API Key Lag;

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 26 May 2026

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Tuesday, May 26th, 2026: VBA in MSFT Access; NPM Stealer; PHP Laravel Compromise; Google API Key Lag;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, May 26, 2006 edition of the Sands Internet Storm Center's Stormcast.

0:12.6

My name is Johannes Ulrich and the time I'm recording from Jacksonville, Florida.

0:17.9

And this episode is brought you by the Sands.edu graduate certificate program in cyber security

0:23.7

leadership. Microsoft Access, well, that's a database. I had a couple of run-ins within the past,

0:30.2

in the distant past, luckily. Did he got interested into Microsoft Access now because, well, it may be used to actually execute

0:40.7

Visual Basic for application code. Yes, the dot MDB files that Microsoft Access runs on

0:48.2

may contain Visual Basic for applications, and with that could be used to infiltrate systems, to basically

0:58.0

execute malicious code, just like with any other Microsoft product that does execute VBA.

1:05.3

So in order to help us out here and help us analyze some of these scripts that may contain,

1:12.1

that may be contained in these dot MDB files, DDA is offering here some help,

1:17.9

a little bit sort of reverse analysis on the MDB files, how to extract some of these

1:23.6

Visual Basic for Application scripts. Microsoft does not offer really any documentation here,

1:29.3

and DDA will also in the future present a couple more complex examples,

1:35.2

how to extract the VBA code from these Microsoft Access Database files.

1:43.0

Well, and then we got more reverse analysis tricks here over the weekend, this time from

1:48.7

Xavier.

1:49.7

Xavier looked at, well, decoding stack strings.

1:53.1

Stack strings is an obfuscation technique that's often found in malware.

1:57.4

In order to avoid using specific strings that of course could easily be

2:01.7

identified with signatures. The attacker uses basically dynamically created strings where

2:08.2

one byte at a time is copied into the stack in order to assemble a particular string.

2:14.4

And that's of course a little bit of pain to analyze. So Xavier took a look at

...

Transcript will be available on the free plan in 18 days. Upgrade to see the full transcript now.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.