Podcast Detail

SANS Stormcast Monday, September 28th, 2026: Macfinger Details; NetScaler 0-Day; KiteWorks 0-Day; ShinyHunters and PeopleSoft

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10112.mp3

Podcast Logo
Macfinger Details; NetScaler 0-Day; KiteWorks 0-Day; ShinyHunters and PeopleSoft
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

Podcast Transcript

 Hello and welcome to the Monday, September 28th, 2026
 edition of the SANS Internet Storm Center's Stormcast. My
 name is Johannes Ullrich, recording today from
 Jacksonville, Florida. And this episode is brought to you
 by the SANS.edu Undergraduate Certificate Program in
 Cybersecurity Fundamentals. On Friday, Brad posted a diary
 that's a follow-up to a diary he actually posted a couple
 days earlier. That diary dealt with the MacFinger ClickFix
 campaign and back then Brad identified the eventual
 payload being installed as the Atomic macOS dealer or AMOS.
 Well, it turns out that this wasn't quite right or at least
 Brad isn't certain if it was this particular Steeler or
 maybe a new variant of it or maybe something somewhat
 different that sort of took some inspirations from AMOS
 Steeler. A couple differences here that Brad points out is
 that this Steeler, for example, does use WebSocket in
 order to exfiltrate data. Another sort of little odd
 thing about this Steeler is that it comes in two versions.
 It comes in the ARM and the x86-64 version. It does not
 come as a unified binary that you could use in macOS in
 order to essentially support both architectures. Well, the
 attacker then also exfiltrates data via post requests, but
 the bulk of the command control appears to be
 happening via the WebSocket connection, which may be done
 to evade some data leakage protection products. Well, if
 you need more details, indicators of compromise,
 specifically to the InfoSteeler that was detected
 here, please refer to Brad's diary. Well, the big story
 this weekend was certainly the exploitation of two unpatched
 vulnerabilities in Citrix Netscaler ADC and Citrix
 Netscaler Gateway. This originally sort of emerged as
 sort of a rumor on Friday. Apparently, an information
 security agency in the Netherlands did advise its
 constituency to turn off any Citrix Netscalers on Sunday.
 Citrix then released a patch fixing a total of eight
 vulnerabilities and stating that two of these
 vulnerabilities, both remote code execution
 vulnerabilities, are currently being exploited. The other six
 vulnerabilities aren't really all that harmless either. So
 if you have, for example, HTTP request smuggling, which then
 could be used to essentially attack systems behind Citrix
 Netscaler. Also, feature policy bypass due to improper
 HTTP URL-based expression usage. This is the lowest one
 according to CVSS score with 7.0. But we have a few 8.8
 ones, including one that's sort of interesting here.
 Yeah, there is a TCP initial sequence number prediction of
 vulnerability. Now, in this case, you need to have the TCP
 configuration enabled in Netscaler ADC or Netscaler
 Gateway again. So get these patched, get these patched
 quickly. I don't want to recommend anybody just turn
 off Netscaler just because I know that these are usually
 systems that protect a number of different web applications
 and like. So disabling them is probably going to cause some
 significant disruption of your business. But on the other
 hand, ransomware is going to disrupt your business too. So
 carefully, way off the pros and cons here. And yes,
 definitely, this is a patch that you probably want to rush
 out if you're using Citrix Netscaler. And talking about
 shutting down servers, Kiteworks urged its customers
 to shut down servers on Saturday. So yes, this news is
 coming a bit late. But if you didn't get the message, you
 may want to check in with Kiteworks to see what exactly
 happened there, because I couldn't really find a lot of
 details. The main source here is Heise.de, the German IT
 news outlet. They got a hold of an email that Kiteworks
 sent to customers. And yes, it specified a very specific six
 hour window on Saturday where you should shut down your
 Kiteworks server. Again, this is a secure messaging
 platform. So certainly a critical piece of IT
 infrastructure. Kiteworks did state to Heise that this was
 due to a zero day attack. Now I'm not sure how shutting it
 down for six hours is supposed to help here, whether or not
 there was a patch deployed afterwards. I didn't found an
 indication for this. But again, this may have just been
 communicated to customers directly and not via any
 public channels. So please double check with Kiteworks.
 And Mandiant is reporting that Shiny Hunters continues to
 target Oracle PeopleSoft. And they're targeting June 2026
 vulnerability. But they are now bypassing web application
 firewalls. So remember, if you're using a web application
 firewall to protect yourself from exploitation, it's
 usually time limited protection attackers will find
 ways around it. And the workaround here appears to be
 pretty straightforward and simple, where they're just URL
 encoding one of the letters in the URL, something that
 actually most web application firewalls that I'm aware of
 should be able to handle. But apparently there are
 sufficient number of firewalls that don't. And that leads
 sort of to a renewed search of exploitation of PeopleSoft by
 Shiny Hunters. Well, and this is it for today. So thanks for
 listening. Thanks for liking. Thanks for recommending this
 podcast. As always, special thanks for leaving good
 comments on your favorite podcast platform. And that's
 it for today. And talk to you again tomorrow. Bye.