SANS Stormcast Wednesday, June 3rd, 2026: SVG Phishing; Android Patches; Poly Voice Vuln; Ivanti Neurons Priv Escelation
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 3 June 2026
⏱️ 4 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Wednesday, June 3, 2026 edition of the Sands Internet Storm Center's Stormcast. |
| 0:12.6 | My name is Johannes Ulrich, recording today from Jacksonville, Florida. |
| 0:16.8 | And this episode is brought you by the Sands.edu credit certificate program in cyber security |
| 0:24.0 | engineering. Savier today wrote about a new wave of phishing emails that contain SVG files. |
| 0:31.9 | SVG files typically open in the browser, and that's the intent here. The SVG file format, well, it's really meant to sort of embed images inside HTML, XML. |
| 0:43.5 | It's an XML format that basically contains vector graphics. |
| 0:47.7 | However, in this particular case, well, it doesn't actually contain any graphics. |
| 0:52.7 | Instead, inside of the SVG tag, |
| 0:55.8 | we do have good old JavaScript. So the intent here is really to use the SVG file as sort |
| 1:02.4 | of a vessel in order to smuggle JavaScript into an environment, hopefully not have it |
| 1:09.3 | inspected by any kind of content inspection, |
| 1:12.4 | and with that essentially to redirect the user to a fishing page. |
| 1:18.9 | Interesting technique and definitely very calmly used lately, |
| 1:24.1 | so if you want to look at the details of Xavier's analysis, take a look at the diary in the show notes. |
| 1:31.8 | And Google today published its June update for Android, and with that patched one vulnerability |
| 1:38.3 | that's apparently already being exploited, or, as Google puts it, maybe under limited targeted exploitation. |
| 1:46.5 | This is an elevation of privilege vulnerability in Framework. |
| 1:51.0 | One interesting observation here is last month in May, we only had sort of one listed |
| 1:57.8 | vulnerability, and this was the result of Google stating that they will no longer really explain |
| 2:03.8 | every single warnability they address, but only, well, those that they consider important |
| 2:09.0 | enough. |
| 2:09.4 | Now, all the vulnerabilities being listed today are critical or high, and we do have, well, |
... |
Transcript will be available on the free plan in 25 days. Upgrade to see the full transcript now.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

