Skip to content
TrackPodcasts
newsMar 19, 20265:45

SANS Stormcast Friday, March 20th, 2026: Cowrie Strings; MSFT Intune Hardening; Unifi Network Update; (#)

Get every episode summarized

Each time SANS Internet Storm Center's Daily Network Security News Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

About this episode

“One of the questions we often get is whether or not any like, you know, global events are affecting what we are seeing in our logs.”From the transcript
SANS Stormcast Friday, March 20th, 2026: Cowrie Strings; MSFT Intune Hardening; Unifi Network Update; Interesting Cowrie Strings https://isc.sans.edu/diary/Interesting+Message+Stored+in+Cowrie+Logs/32810 Microsoft Intune Hardening Advice https://techcommunity.microsoft.com/blog/intunecustomersuccess/best-practices-for-securing-microsoft-intune/4502117 https://www.cisa.gov/news-events/alerts/2026/03/18/cisa-urges-endpoint-management-system-hardening-after-cyberattack-against-us-organization Unifi Network Update https://community.ui.com/releases/Security-Advisory-Bulletin-062-062/c29719c0-405e-4d4a-8f26-e343e99f931b keywords: unifi; ubiquity; microsoft; intune; cowrie; iran

Hosts & guests

Transcript ready

73 searchable segments. Every word is indexed and playable.

SANS Stormcast Friday, March 20th, 2026: Cowrie Strings; MSFT Intune Hardening; Unifi Network Update; (#)

SANS Internet Storm Center's Daily Network Security News Podcast

0:00
5:45

Full transcript

SANS Internet Storm Center's Daily Network Security News Podcast — SANS Stormcast Friday, March 20th, 2026: Cowrie Strings; MSFT Intune Hardening; Unifi Network Update; (#). Machine-transcribed; use the interactive transcript above to jump the player to any line.

Hello and welcome to the Friday March 20th, 20th, 20th, 26th edition of the Sands, and then it's Storm Suners, Stormcast, my name is Johannes, already, Reconyday from Jacksonville, Florida. And this episode is brought to you by the Sands.edu Credit Certificate Program in Cyber Defense Operations. One of the questions we often get is whether or not any like, you know, global events are affecting what we are seeing in our logs. Now, if you haven't passed often seen like the Sasters and such, for example, being used in scams, Guy had an interesting sort of eventness, a curry honey pot that's a little bit related with what's happening now in Iran, essentially a message that the attacker added to the command line here that was executed in the honey pot that just stays magic payload killer here or leaf empty, and then Iran bought was here.

This is often kind of just use of as a little indicator whether or not the commands are actually properly processed, sometimes sort of strengths like this are being also used to identify honey pots to see what is then actually being returned by the particular shell that they attempt to log into. In this case, it wasn't anything remotely sophisticated, just yet so of another as age brute forcing attack. And sometimes attackers are really also just no using these strengths for notoriety to maybe be recognized or as such. But yes, not everything is sort of nation states if it does mention a nation as part of a string in a payload like this. People are talking about Iran, there was one significant breach that was caused by threat actors associated with Iran, and that was against the medical supply company striker. Now, I typically don't talk about preachers much unless there's sort of a lesson to be

learned or something actionable coming out of it. And that's what we have now Microsoft as well as CISA release guidelines, how to better secure your Microsoft in tune account. So Microsoft in tune is a mobile device management console and you can use it to basically figure out what is installed on mobile devices in your organization. But it also has the remote wipe capability in case, for example, of a physical loss of a device. That's what the attacker abused here. The attacker apparently did wipe something like 200,000, I think was the number I've seen devices associated with striker, which of course is a catastrophic event for the company. Well, there are a couple things that you can do in order to prevent this from happening to yourself. First of all, I think one of the biggest things here is just to make sure there is no phishing happening. So some phishing resistant authentication should happen here, design your admin controls

well. So not every admin needs to be able to delete all 200,000 devices. And then I have an interesting feature called multi admin approval, therefore sensitive changes like wiping devices. You need actually two administrators to come together and approve the event. And that's certainly something that also adds some additional phishing resistance, but also basically just prevents sort of, for example, a compromised workstation or something like this to be then abused to delete all of your devices. So if you're using any system like this, and I think this does not just apply to Microsoft in tune, but other mobile device management systems, definitely take a look and make sure that you have these things properly configured. As far as Iran goes, if this is really the only thing that's happening, it's probably much less than some people were afraid of when it comes to various cyber attacks. And then we got an update from Ubiquity for its Unified Network application.

This update fixes two different vulnerabilities. The first one has a perfect 10 as far as the CVS score goes. It's a path traversal vulnerability that does not require any authentication and could essentially allow an attacker to read arbitrary files, which then may lead to actually compromising the system further. The second vulnerability is a no-sequel injection vulnerability, but it does require authentication. Updates are available for the Unified Network application. You typically run it on your Unified Gateway sometimes on distinct cloud keys or other devices like that. And then of course, the usual advice, don't expose these kinds of more admin interfaces to the public and make sure they're only accessible from the internal network, preferably from specific admin workstations or subnets. Well, that's it for today and just a quick note to this, Sarday, I'll be happy to participate

in the Sands.edu commencement. So ahead of it, congratulations to all of our graduates this year. And that's it for today. Thanks for listening. Thanks for liking. Thanks for commenting and talk to you again on Monday, bye.

More episodes

More from SANS Internet Storm Center's Daily Network Security News Podcast

View all episodes →