Handler on Duty: Jim Clausing
Threat Level: green
Podcast Detail
SANS Stormcast Thursday, October 8th, 2026: Atlassian Vulnerabilities; ccTLD Compormise; Outlook blocking .msix
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10128.mp3
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
Scans for Atlassian vulnerablity (CVE-2026-21589)
https://isc.sans.edu/diary/Scans%20for%20Atlassian%20vulnerablity%20%28CVE-2026-21589%29/33406
.gh, .sl and .as ccTLD Compromise
https://blog.google/security/chromes-response-to-recent-cctld-registry-hijacks/
Cisco Nexus 3000 and 9000 Series Switches Remote Code Execution Vulnerabilities
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ngoam-rce-LWKQ4BU
Outlook Blocking MSIX Files
https://www.bleepingcomputer.com/news/microsoft/microsoft-outlook-to-block-msix-attachments-used-in-attacks/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Eastern | Feb 8th - Feb 12th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 19th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Orlando | Apr 12th - Apr 16th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Mountain | Apr 21st - Apr 25th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Baltimore | May 17th - May 21st 2027 |
Podcast Transcript
Hello and welcome to the Thursday, October 8, 2026 edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich, recording today from Jacksonville, Florida. And this episode is brought to you by the SANS.edu Undergraduate Certificate Program in Applied Cybersecurity. Well, and in Diaries Today, I wrote up some scans that we're seeing against an Atlassian vulnerability that has just been patched. October 5th is when Atlassian did publish the patches. Well, we also now have a write-up from Watchtower as of yesterday with details regarding the vulnerability and proof-of -concept exploit strings. And exactly these proof-of-concept exploit strings are what we are seeing in our honeypot logs. So these are not yet what I would call sort of full -fledged exploits. But in this case, it's a little bit tricky to see those full-fledged exploits. So just to describe the vulnerability a little bit. First of all, the indicator of the attack here is that you have two colons in the URL. The vulnerability here is based on these two colons then being replaced with a slash. Because, well, Atlassian figured to sanitize some of its URLs, it replaces a slash with two colons. But then also has a feature to undo this obfuscation. And that's exactly sort of what's hitting here. And that, of course, bypasses a lot of the traditional filters for directory traversal. With this vulnerability, an attacker is able to read arbitrary files. The problem is the attacker must know what file to read. There is no way to sort of get a simple directory listing or something like this using this vulnerability. So these initial attacks are looking for web.xml or in one case for a bitbucket for URL rewrite .xml. These are files that are always present in these products. And that's sort of why they are being selected. Similar to how attackers often use Etsy password in order to sort of play an experiment with directory traversal attacks. However, Etsy password doesn't work in this case. Because the vulnerability is restricted to the actual application's directory. So there is no way to break out of this application's directory. Either way, get this patched. It affects multiple products. So Jera, Bitbucket, Confluence are the ones that we have seen the exploit strings for. Check with Atlassian that you get everything patched. And yes, again, as usual, a good watchtower write-up. If you want to know more details about how this vulnerability works and, well, what went wrong here. And well, yet again, we had some country -level, top-level domains compromised or the registrar for these top-level domains. In fact, it was .gh, .sl, and .as. That's for Ghana, Sierra Leone, and American Samoa. Now, the problem, of course, with DNS is that DNS is also a security protocol, even though, well, it doesn't call itself that. But once the attacker was able to compromise DNS for these top -level domains, they were able to get TLS certificates for a number of domains hosted within these countries. Affected were also local Google sites, for example. And as a result, Google Chrome did add affected certificates to its block list. So they should show up as revoked now. This is sadly something that keeps happening, that random country -level registrars are being compromised. Now, they're actually in some ways sometimes less secure than some of the newer, some of these vanity domain names. Because, well, they're just older. So from the beginning of the Internet, they were often handed to some private companies without a lot of oversight and such. So that way, they often end up getting compromised. And, of course, what attackers usually try to do once they compromise one of these country-level domains, that they select a couple of popular websites and then redirect them to phishing or malware sites. And apparently, something along these lines happened here as well. Luckily, the attack didn't last terribly long, but long enough for attackers to obtain these invalid certificates. And users of Cisco Nexus switches and, well, NXOS, please look at the latest updates released by Cisco today and yesterday. Well, there are about nine different vulnerabilities being patched, a couple of them critical. The critical vulnerabilities appear to affect specifically the operation, administration, and maintenance feature, OAM, either for VXLAN or for MPLS. So if you're using that, definitely make sure that you're updating. That sort of enables exploitation of the vulnerability. But either way, there's a couple of remote code execution vulnerabilities here that do not require any authentication. But they do require that the attacker is able to send compromised packets to the switch, which, depending on where your switch is located, what your architecture looks like, may or may not be possible. And Microsoft is whacking the mole again and blocking two additional extensions from being downloaded from Outlook, MSIX and MSIX Bundle. Both of these extensions are associated with install packages, so essentially executables that you shouldn't just receive via email and download and then run. I guess Microsoft could just stop it and block all extensions and force people to use plain text email, as they're supposed to do anyway. But not quite there yet, but we are two extensions closer. Well, and that's it for today. Thanks for listening. Thanks for liking. Thanks for subscribing. Thanks for recommending. And also take a look at the classes I'll be teaching in the near future in the show notes. Thanks and talk to you again tomorrow. Bye. Bye.





