Podcast Detail

SANS Stormcast Friday, September 4th, 2026: AV Exploits; Plex Update; Cisco Patches; Sangoma Switchvox Exploited

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10082.mp3

Podcast Logo
AV Exploits; Plex Update; Cisco Patches; Sangoma Switchvox Exploited
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

Podcast Transcript

 Hello and welcome to the Friday, September 4th, 2026
 edition of the SANS Internet Storm Center's Stormcast. My
 name is Johannes Ullrich and today I am recording from
 Jacksonville, Florida. And this episode is brought to you
 by the SANS.edu Graduate Certificate Program in
 Penetration Testing and Ethical Hacking. Nightmare
 Eclipse is added again, this time not targeting Microsoft
 but still sticking to the theme of targeting anti
 -malware products. There are three new vulnerabilities and
 exploits released by Nightmare Eclipse. The first one Falcon
 Flank is targeting CrowdStrike and the second one Hard
 Breacher is targeting Kaspersky's Antivirus and then
 we also have a third one, Pretty Prague, that one is
 targeting Avast Antivirus. Antivirus products have this
 hard task of parsing complex structures as they're trying
 to make sense of files whether or not they're malicious or
 not. And at the same time of course in order to not be
 affected by malware themselves, they usually run
 with very high and elevated privileges. So any
 vulnerability in an anti -malware product immediately
 with that becomes a severe privilege escalation
 vulnerability. And we have seen this with the Microsoft
 exploits of course from Nightmare Eclipse in the past
 but overall this is not a new problem. In the past it has
 often been ignored. So if anything let's hope that these
 sort of more public and more newsworthy kind of exploits
 are actually changing a little bit that people are taking
 some of these privilege escalation vulnerabilities in
 anti-malware products more serious and that they get the
 attention they deserve. And Plex released an advisory
 stating that users should immediately update the latest
 and greatest version of Plex that was released earlier this
 week. Sadly we don't really have any details as to what
 the vulnerabilities are. They haven't been able to get CVE
 numbers for them yet but apparently they consider them
 critical enough where they are releasing this advisory.
 Luckily Plex does a decent job in updating itself so there's
 nothing really that you may need to do. You may still want
 to verify that all worked and that you actually got the
 latest version 143.3 and for desktop it's 1.115. The
 problem cases here with Plex particularly on the server
 side are often sort of various NAS devices and such that come
 with Plex installed. That's usually installed as a package
 from the vendor and as Plex points out the vendor may not
 have released an updated package for it yet. They
 recommend that you should then manually update. They don't
 have one of those devices so not sure how difficult that is
 and if that later may then break additional updates that
 are released by the vendor in the form of a package in case
 they sort of customized anything there. And Cisco
 released a couple of interesting advisories. One
 for iOS XR. This fixes a total of seven vulnerabilities. One
 of them has a CVSS score of 9 .8. This one and then at least
 two more do have some of the standard memory management
 flaws so they do have remote code execution potential.
 There is also an update for the secure email appliances
 from Cisco. That particular vulnerability is only rated as
 a medium and it's a denial of service vulnerability in the S
 MIME feature. So if you're sending encrypted email with S
 MIME there are some denial of service conditions here that
 may be triggered. And Horizon 3 is reporting that they're
 seeing active exploitation against Switchvox
 vulnerability. Switchvox is an enterprise voice over IP
 management system. It comes from Sangoma. Sangoma is also
 known for free PBX and as Horizon 3 said well after a
 few critical vulnerabilities in free PBX they took a closer
 look at Switchvox and found some issues there as well. And
 then also saw at least one of these vulnerabilities already
 being exploited. So certainly make sure that you keep this
 product up to date and properly configured. Well and
 that's it for today. So thanks for listening. Thanks for
 liking. Thanks for subscribing. And we'll talk to
 you again on Tuesday, not on Monday, because Monday is a
 holiday here in the US. So
 you you you you