SANS Stormcast Friday, September 18th, 2026: LousivLaoder Analysis; Issabel Framework 0-Day; Cyber Decoys; CISA Vuln Bulletin; Unbound Vulnerability
LausivLoader analysis, or how to pass data between malware stages https://isc.sans.edu/diary/LausivLoader%20analysis%2C%20or%20how%20to%20pass%20data%20between%20malware%20stages/33348 Issabel Framework Hard-coded JWT Key RCE CVE-2026-89026 https://www.vulncheck.com/advisories/issabel-pbx-hard-coded-jwt-key-rce-via-pbxapi-manager-originate Using Cyber Decoys to Strengthen Detection and Response https://www.cisa.gov/sites/default/files/2026-09/using-cyber-decoys-to-strengthen-detection-and-response_508c.pdf CISA to Sunset Weekly Vulnerability Bulletin on September 28, 2026 https://content.govdelivery.com/accounts/USDHSCISA/bulletins/42b055b Unbound Vulnerability https://nlnetlabs.nl/projects/unbound/security-advisories/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich