meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Wednesday, July 22nd, 2026: Captive Portals; Critical Serv-U and Zimbra Update; Apple Hide-My-Email fix

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9755 Ratings

🗓️ 22 July 2026

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Wednesday, July 22nd, 2026: Captive Portals; Critical Serv-U and Zimbra Update; Apple Hide-My-Email fix

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, July 22nd, 2006 edition of the Sands Internet Storm Centers.

0:12.5

Stormcast, my name is Johannes Ulrich, recording today from Jacksonville, Florida.

0:18.4

And this episode is brought you by the sands.edu bachelor's degree program

0:22.8

in Applied Cybersecurity. Well, today, I figured let's move away from WordPress. If you're running it,

0:30.5

if you aren't patched it, you're compromised. And, well, with that, move on to something well,

0:36.7

less threat related

0:38.5

and that's how different operating systems do detect

0:42.6

if they are behind a captive portal.

0:46.2

Anybody who has ever used any kind of public Wi-Fi network

0:49.8

probably has observed these captive portals,

0:52.7

some kind of login screen that you have to go through

0:56.0

in order to connect to the internet. So to support this very common practice, operating systems

1:03.0

and browsers have implemented a couple different methods, how they are detected if they are

1:10.0

behind such a captive portal, and then of course

1:13.7

also how to direct the user to the correct URL in order to sign in. This traffic sometimes

1:22.3

shows up sort of as odd and unexplained traffic in your network because users don't really consciously visit these URLs.

1:31.0

It's also HTTP traffic because for the captive portal to then redirect the user,

1:37.4

well, can't be HTTP because then the certificate check would fail.

1:42.9

So summarized here, a couple of the URLs being used by the major operating systems,

1:48.1

as well as Firefox and Chrome, who do sort of their own little trick in order to figure out

1:55.3

if they are behind such a captive portal.

1:59.4

And then we got an interesting update from Solar Winds for their Surf Hugh product.

...

Transcript will be available on the free plan in 22 days. Upgrade to see the full transcript now.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.