Handler on Duty: Brad Duncan
Threat Level: green
Podcast Detail
SANS Stormcast Wednesday, September 2nd, 2026: Guildma Update; Proxmox 7 Auth Bypass; Windows Hotpatch; Virtualizor BGP Hack
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10078.mp3
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
Guildma (Astaroth) malware infection from Brazilian Portuguese email
https://isc.sans.edu/diary/Guildma%20%28Astaroth%29%20malware%20infection%20from%20Brazilian%20Portuguese%20email/33300
Authentication bypass in EOL Proxmox VE 7 release
https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/page-4#post-867929
https://gist.github.com/nebusecurity/65fe90dd673d395b7926278d7eaf5849
Updated Windows Server hotpatch calendar
https://learn.microsoft.com/en-us/windows/release-health/windows-server-release-info#windows-server-hotpatch-calendar
Virtualizor BGP Hijacking
https://www.virtualizor.com/blog/security-incident-bgp-hijacking/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Application Security: Securing Web Applications, APIs, and Microservices | Las Vegas | Sep 21st - Sep 25th 2026 |
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 19th 2027 |
Podcast Transcript
Hello and welcome to the Wednesday, September 2nd, 2026 edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich, recording today from Jacksonville, Florida. And this episode is brought to you by the SANS.edu graduate certificate program in cyber security engineering. Today's diary comes from Brad updating us on Guilma and Astaroth. This malware is targeting users in Brazil. The email linking to the malware is written in Portuguese and the website hosting the malware only allows connections from Brazilian IP addresses. Further, the browser must identify as using Brazilian Portuguese and have the Brazilian local settings applied. Otherwise, you're just getting some benign software. The initial download is a zip archive that contains a link file. The link file will point to another website, download a DLL and then save it as an alternate data stream. Further obfuscating what's actually going on and probably also attempting to try to evade some anti -malware. As usual, Brad walks you through the entire installation. What exactly happens on the system, indicators of compromise and does of course provide packet captures that you can then use to follow the analysis yourself. And popular virtualization software vendor Proxmox is warning its users that there is currently an ongoing campaign against an unpatched vulnerability in Proxmox. Now unpatched here is with sort of quotations, a little footnote here. It's unpatched in Proxmox. 7.7 hasn't been supported for the last two years. So it's an old end of life version of Proxmox that's affected. If you're using Proxmox 8 and 9, 9 being the most recent version, you should be good. This is an authentication bypass vulnerability that's currently being exploited. Proof of concept has also been made available. So exploitation is actually rather straightforward. The cause here is a problem with libPVE access control and Proxmox does recommend that you double check what version of this library you may be running as it may not always be in sync with the Proxmox version that you're running. So if this library has a version of less than 8.0.4, then you potentially have a problem. Also, if you apply multi -factor authentication, then you are not exploitable if you are running a vulnerable version of the library. Well, staying with major version updates is always a good idea, in particular if the older versions then are no longer supported. So definitely you should be running Proxmox 9 by now. It has been out for quite a while. Next Tuesday, we are expecting Microsoft's Patch Tuesday. Well, we do have something a little bit different here. For this Patch Tuesday, Microsoft updated its hot patch calendar. Typically, you only need to reboot Windows Server once a quarter. So the next quarterly reboot would have come up in October, but Microsoft now announced that September you'll also have to update your servers. This isn't the first time they have done it. They've done the same thing in June and July, both months you had to reboot your servers. They call this a baseline release, which basically can't just simply be applied as a hot patch without rebooting. And again, really only affects server environments. And Virtualizor, a company that distributes cloud management software, was the subject of a rather sophisticated routing attack. The attacker managed not only to reroute traffic to Virtualizor using BGP Hijack, we have seen that quite a bit before, but in addition was also able to impersonate Virtualizor's software distribution website using a valid TLS certificate. That's usually your second line of defense here against these machine middle attacks where, well, you have TLS that should prevent this. The attacker used the machine in the middle attack to distribute malicious Virtualizor update packages. The certificate apparently was obtained via Let's Encrypt, and well, with Let's Encrypt, you can basically get a new certificate if you control the website. And that's actually the standard now with pretty much all of the public set of authorities. So that's essentially what they did here. Now, set of authorities do have a proposed countermeasure here where they are actually axing the website from different vantage points around the internet. So that is supposed to make these BGP Hijack attacks more difficult. But in this particular case, well, this apparently didn't prevent the attack and the attacker was able to distribute a malicious update package to Virtualizor customers. Virtualizor says that only few of the customers were affected by this. Not sure if they have a good count of effective customers, but if you're using their product, definitely double check on their website for indicators of compromise. Well, and that's it for today. Thanks for listening. Thanks for liking. Thanks for subscribing. And thanks for recommending this podcast. And talk to you again tomorrow. Bye.





