SANS Stormcast: Daily Cyber Security News · Johannes Ullrich

SANS Stormcast Thursday, April 9th, 2026: Honeypot Fingerprinting; Microsoft Locks Developer Accounts; ActiveMQ Vuln;

April 9, 2026·8 min
Johannes Ulrich opens the April 9, 2026 Stormcast by noting there will be no Friday episode due to travel, and that the show is sponsored by the SANS.edu Industrial Control System Security certificate program. The first topic concerns how attackers are fingerprinting medium-interaction honeypots used by SANS, specifically the Python-based web application emulator and Cowrie, which emulates Telnet and SSH. Cowrie is designed to accept arbitrary username and password combinations to observe attacker behavior, and this design choice makes it fingerprint-able: an attacker who logs in successfully with a username like 'Honeypotter' knows they are inside a honeypot. SANS is aware but considers remediation low priority because the honeypots focus on broad internet scanning rather than targeted attacks. The second story concerns Microsoft suspending developer accounts for three security-focused open source projects: WireGuard and Windscribe (VPN tools) and VeraCrypt (disk encryption). All three projects are well-established and privacy-related, and the suspensions prevent them from publishing updates to their Windows applications. Ulrich speculates the most likely cause is Microsoft's April policy changes around driver and bootloader signing, which affect VeraCrypt in particular because full-disk encryption requires a custom bootloader. Older dual-signed and co-signed bootloader solutions are being deprecated, and when the policy goes into full effect in June, systems using VeraCrypt full-disk encryption may fail to boot. With their developer account suspended, VeraCrypt cannot push a compatible update. Ulrich notes no official Microsoft statement had been released, and that Linux and macOS are unaffected — the issue is Windows-specific. He encourages users of these products to monitor the situation closely. The third story covers a Horizon 3 write-up on using Claude (an AI assistant) to find a remote code execution vulnerability in Apache ActiveMQ. The vulnerability involves the Jolokia API; older versions expose it without authentication, allowing unauthenticated RCE, while more recent versions require authentication. Ulrich urges ActiveMQ operators to patch immediately and recommends the Horizon 3 write-up to anyone interested in AI-assisted security research.
Listen to the show on