meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Wednesday, May 6th, 2026: Cleartext Passwords in Edge; SSL.com Root Rotation; DAEMONTOOLS Backdoor;

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 6 May 2026

⏱️ 8 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Wednesday, May 6th, 2026: Cleartext Passwords in Edge; SSL.com Root Rotation; DAEMONTOOLS Backdoor;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, May 6, 2026 edition of the Sands Internet Storm Center's

0:10.9

Stormcast. My name is Johannes Ulrich, recording today from Jackson, Florida. And this episode is

0:17.5

brought you by the Sands.edu graduate certificate program in industrial control system security.

0:24.7

Well, in diaries today, we got two kind of news items from Rob. First one affects Microsoft Edge.

0:31.8

Microsoft Edge manages passwords like all browsers pretty much do these days, and well, it stores passwords in an

0:38.6

encrypted file on your system. However, once you start edge, it will load all of these

0:44.5

passwords into the browser's memory and decrypt them, even though you as a user have to sort

0:51.2

of authenticate yourself for each password individually as you use it

0:55.7

to refill these passwords into a website while the passwords are already decrypted in memory.

1:03.8

So as Raw points out, this is sort of more a little bit security theater.

1:08.6

So what's the threat here? Well, at first you may say, well, it's not really a big deal

1:13.3

because in order to gain access to the memory,

1:15.5

you have to be logged in as the user.

1:17.8

If you are having all the privileges of the user,

1:21.3

you can probably do things like capture keystrokes,

1:25.0

load browser extensions and things like this.

1:27.7

So you would have access to the passwords as they're being used.

1:32.0

But the big risk here is that attacker can get bulk access to all of your passwords,

1:38.4

even with timely, very limited access to your system.

1:42.5

The other problem, of course, is that any kind of memory leak and, well,

1:46.2

browser sadly are kind of known for them could be exploited in order to then gain access

1:52.0

to these passwords, given the exact nature of the memory leak, of course.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.