meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Wednesday, January 7th, 2026: Tailsnitch Review; D-Link DSL EoL Vuln; TOTOLINK Unpatched Vuln

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 7 January 2026

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Wednesday, January 7th, 2026: Tailsnitch Review; D-Link DSL EoL Vuln; TOTOLINK Unpatched Vuln

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, January 7th, 2026 edition of the Sands Internet Storm Centers.

0:11.4

Stormcast, my name is Johannes Ulrich, recording today from Jacksonville, Florida.

0:17.3

And this episode is brought you by the Sands.edu master's degree program in information security engineering.

0:25.6

Yesterday, I briefly mentioned the tool tail snitch.

0:29.0

Just got across it yesterday and I thought it was interesting in particular since yesterday I talked sort of about KBMs and remote access that often uses tailscale VPNs.

0:39.3

Well, today I took a little bit time to closer look at tail snitch, and it's a pretty impressive

0:45.2

and useful tool. So the goal of tail snitch is to audit your tailscale configuration.

0:53.3

Tailscale itself, it's a pretty solid system as far as VPNs go,

0:58.2

but of course a lot of it also depends on how you configure it,

1:02.1

and tail snitch will point out some of the possible misconfigurations

1:07.9

that you're running into.

1:10.2

And yes, it does this very well.

1:12.6

It's very comprehensive the tool.

1:15.0

In my case, it found two systems that I had that had an old version of tail scale running.

1:20.6

So basically, but the auto update wasn't configured correctly fixed that.

1:25.8

And that's something nice to point out.

1:28.0

It also points out things like, for example, access tokens that you issued and set to not

1:34.5

expire.

1:35.6

In my case, I intentionally did it that way.

1:39.6

Overall, what I also find is that the severity levels it assigns I think are rather reasonable.

1:46.4

A lot of tools like this tend to sort of, you know, a little bit overhype kind of some of the

1:52.0

configuration issues that they're detecting.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.