SANS Stormcast: Daily Cyber Security News · Johannes Ullrich

SANS Stormcast Friday, March 6th, 2026: Targeted or Not? pac4j-jwt auth bypass; freescout dangerous uploads; MSFT Authenticator vs Graphene

March 6, 2026·7 min
Johannes Ullrich opens the March 6, 2026 SANS Internet Storm Center Stormcast from Jacksonville, Florida, noting the episode is sponsored by SANS.edu's cloud security graduate certificate program. He introduces a guest diary by Joseph Gruen, an undergraduate intern who analyzed honeypot data. Ullrich explains that honeypots are generally identifiable as honeypots and therefore attract background internet scanning rather than targeted or zero-day attacks. He describes how individual actors scanning the internet zoom in on specific exploit types or artifacts. He explains the practical value of the ISC's published sensor data: defenders can search an attacking IP on the ISC website to determine whether the activity they're seeing is unique to their network or part of a broad internet-wide scan. He then transitions to the PAC4J JWT vulnerability, discovered by CodeAnt, an AI code review company. He provides context on JWT — JSON web tokens — as a commonly used format for delivering digitally signed authentication data used in OAuth and other auth flows. He explains the vulnerability: the PAC4J library contains bad logic that allows an unsigned JWT to be submitted and, when wrapped in a signature generated with the public key, treated as fully valid. He describes this as a variant of algorithm confusion attacks. He notes that CodeAnt published the full steps for exploiting this vulnerability. He addresses the instinct to mitigate by keeping public keys secret, explaining why this doesn't work — standards like OpenID require public keys to be publicly accessible. Patching is the correct fix. He then covers FreeScout, an open-source help desk and shared mailbox platform with a remote code execution vulnerability in its file upload handling. The flaw is extension-based filtering, which Ullrich characterizes as a classic failure mode. Unicode whitespace characters can be inserted to bypass the .htaccess-based filters and achieve unrestricted file upload leading to code execution. He recommends storing uploads outside the document root as the only reliable mitigation. Finally, he revisits a previous story about Microsoft tightening Authenticator's device integrity checks. The unintended consequence is that GrapheneOS — a respected, more secure Android fork — is not recognized as standard Android, causing Authenticator to refuse to run on it. Ullrich closes with thanks to listeners and a note that the next episode will be on Monday.
Listen to the show on