Podcast Detail

SANS Stormcast Thursday, October 8th, 2026: Atlassian Vulnerabilities; ccTLD Compormise; Outlook blocking .msix

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10128.mp3

Podcast Logo
Atlassian Vulnerabilities; ccTLD Compormise; Outlook blocking .msix
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

Podcast Transcript

 Hello and welcome to the Thursday, October 8, 2026
 edition of the SANS Internet Storm Center's Stormcast. My
 name is Johannes Ullrich, recording today from
 Jacksonville, Florida. And this episode is brought to you
 by the SANS.edu Undergraduate Certificate Program in Applied
 Cybersecurity. Well, and in Diaries Today, I wrote up some
 scans that we're seeing against an Atlassian
 vulnerability that has just been patched. October 5th is
 when Atlassian did publish the patches. Well, we also now
 have a write-up from Watchtower as of yesterday
 with details regarding the vulnerability and proof-of
 -concept exploit strings. And exactly these proof-of-concept
 exploit strings are what we are seeing in our honeypot
 logs. So these are not yet what I would call sort of full
 -fledged exploits. But in this case, it's a little bit tricky
 to see those full-fledged exploits. So just to describe
 the vulnerability a little bit. First of all, the
 indicator of the attack here is that you have two colons in
 the URL. The vulnerability here is based on these two
 colons then being replaced with a slash. Because, well,
 Atlassian figured to sanitize some of its URLs, it replaces
 a slash with two colons. But then also has a feature to
 undo this obfuscation. And that's exactly sort of what's
 hitting here. And that, of course, bypasses a lot of the
 traditional filters for directory traversal. With this
 vulnerability, an attacker is able to read arbitrary files.
 The problem is the attacker must know what file to read.
 There is no way to sort of get a simple directory listing or
 something like this using this vulnerability. So these
 initial attacks are looking for web.xml or in one case for
 a bitbucket for URL rewrite .xml. These are files that are
 always present in these products. And that's sort of
 why they are being selected. Similar to how attackers often
 use Etsy password in order to sort of play an experiment
 with directory traversal attacks. However, Etsy
 password doesn't work in this case. Because the
 vulnerability is restricted to the actual application's
 directory. So there is no way to break out of this
 application's directory. Either way, get this patched.
 It affects multiple products. So Jera, Bitbucket, Confluence
 are the ones that we have seen the exploit strings for. Check
 with Atlassian that you get everything patched. And yes,
 again, as usual, a good watchtower write-up. If you
 want to know more details about how this vulnerability
 works and, well, what went wrong here. And well, yet
 again, we had some country -level, top-level domains
 compromised or the registrar for these top-level domains.
 In fact, it was .gh, .sl, and .as. That's for Ghana, Sierra
 Leone, and American Samoa. Now, the problem, of course,
 with DNS is that DNS is also a security protocol, even
 though, well, it doesn't call itself that. But once the
 attacker was able to compromise DNS for these top
 -level domains, they were able to get TLS certificates for a
 number of domains hosted within these countries.
 Affected were also local Google sites, for example. And
 as a result, Google Chrome did add affected certificates to
 its block list. So they should show up as revoked now. This
 is sadly something that keeps happening, that random country
 -level registrars are being compromised. Now, they're
 actually in some ways sometimes less secure than
 some of the newer, some of these vanity domain names.
 Because, well, they're just older. So from the beginning
 of the Internet, they were often handed to some private
 companies without a lot of oversight and such. So that
 way, they often end up getting compromised. And, of course,
 what attackers usually try to do once they compromise one of
 these country-level domains, that they select a couple of
 popular websites and then redirect them to phishing or
 malware sites. And apparently, something along these lines
 happened here as well. Luckily, the attack didn't
 last terribly long, but long enough for attackers to obtain
 these invalid certificates. And users of Cisco Nexus
 switches and, well, NXOS, please look at the latest
 updates released by Cisco today and yesterday. Well,
 there are about nine different vulnerabilities being patched,
 a couple of them critical. The critical vulnerabilities
 appear to affect specifically the operation, administration,
 and maintenance feature, OAM, either for VXLAN or for MPLS.
 So if you're using that, definitely make sure that
 you're updating. That sort of enables exploitation of the
 vulnerability. But either way, there's a couple of remote
 code execution vulnerabilities here that do not require any
 authentication. But they do require that the attacker is
 able to send compromised packets to the switch, which,
 depending on where your switch is located, what your
 architecture looks like, may or may not be possible. And
 Microsoft is whacking the mole again and blocking two
 additional extensions from being downloaded from Outlook,
 MSIX and MSIX Bundle. Both of these extensions are
 associated with install packages, so essentially
 executables that you shouldn't just receive via email and
 download and then run. I guess Microsoft could just stop it
 and block all extensions and force people to use plain text
 email, as they're supposed to do anyway. But not quite there
 yet, but we are two extensions closer. Well, and that's it
 for today. Thanks for listening. Thanks for liking.
 Thanks for subscribing. Thanks for recommending. And also
 take a look at the classes I'll be teaching in the near
 future in the show notes. Thanks and talk to you again
 tomorrow. Bye. Bye.