SANS Stormcast Wednesday, February 18th, 2026: IR Phishing; Neenadu Android Backdoor; NiFi Bugs; LLMs Phishing; Encrypted RCS
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 18 February 2026
⏱️ 8 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Wednesday, February 18th, 2006 edition of the Sands Internet Storm Center's Stormcast. My name is Johannes Ulrich, recording today from Jacksonville, Florida. And this episode is brought you by the sands.edu credit certificate program in incident response. |
| 0:23.0 | This is a quick note for those of you are watching this on YouTube, sorry, no camera today, |
| 0:27.6 | having some little technical issues. Today's diary is coming from Xavier again. He's on a row |
| 0:34.4 | lately, and this latest one is a little bit of different fishing campaign. |
| 0:39.6 | One of the goals of fishing campaigns is always to create some urgency to make you do something quickly |
| 0:46.0 | because, well, there is some kind of emergency. |
| 0:48.7 | And what they're doing here is essentially pretending that there was an incident, |
| 0:52.9 | some odd login to your crypto |
| 0:55.0 | wallet that would cause you to now implement two-factor authentication. Not sure if they just |
| 1:03.5 | assume that you didn't do it or if they think that you may ignore if you already have two-factor |
| 1:09.3 | authentication enabled. This particular phishing email did affect Metamask users. |
| 1:16.0 | No indication here that Metamask is that all involved this. |
| 1:19.2 | So this is not a Metamask breach or anything like this. |
| 1:22.5 | They're just sending this to random people on the internet, |
| 1:25.1 | hoping that they will get some actual Metamask users |
| 1:29.0 | that will then fall for this phishing email. And as usual, cryptocurrency wallets are still |
| 1:36.9 | one of the top targets of these kind of phishing emails. And the Android ecosystem continues to be haunted by devices that come |
| 1:48.2 | reinstalled with malicious firmer. Kaspersky has the latest document incident of this. |
| 1:54.6 | They call it the Kinato Big Door and apparently it was preinstalled on these affected devices and was added during |
| 2:03.8 | the build phase for the firmware. Now, we have seen sort of various picture frames and such |
| 2:09.3 | with compromised firmware in the past, and what often happens is that systems on the production |
| 2:16.1 | lines or so are getting infected and then being used to |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

