SANS Stormcast: Daily Cyber Security News · Johannes Ullrich

SANS Stormcast Wednesday, April 8th, 2026: Pivoting for Webshells; WatchGuard Firebox Patch; Project Glasswing; Kubernetes Misconfigurations

April 8, 2026·6 min
Ulrich opens by noting this episode's tie to his diary entry on web shell pivoting. He investigated four IP addresses associated with Microsoft's cloud infrastructure that scanned SANS sensors for a specific web shell, turkshell.php. He explains that web shells are persistent backdoors installed via remote code execution or arbitrary file upload vulnerabilities, and that a secondary class of attackers — dubbed parasitic — scans for these pre-installed shells, often exploiting weak passwords set by the original attacker. Expanding the investigation to those four IPs, he found they searched for over 280 distinct URLs. Many used WordPress-style file names as camouflage, reflecting the popularity of WordPress as an attack target. He recommends against file-name-based detection given the scale of variants and instead advocates for generic file system monitoring to detect newly created web files. The second segment covers a WatchGuard advisory for Firebox appliances. An authenticated arbitrary file write vulnerability allows attackers to write files to locations where they can later be executed. Though authentication is required, Ulrich considers it a meaningful risk and advises patching and auditing the device for unexpected new files. The third story is about Anthropic's Project Glasswing, released the same day. The initiative uses the Mythos 2 model to provide approximately 30 companies building critical infrastructure software with early vulnerability discovery capabilities. Ulrich frames this as an attempt to give defenders an AI-level head start over attackers who are already using similar models offensively. He expresses hope that proactive AI-assisted discovery could reduce the stream of weekly vulnerability disclosures. Palo Alto and their Unit 42 team are named as participants. The final story draws on a Unit 42 report about a Kubernetes attack. An adversary spear-phished a developer to obtain login credentials, then used them to connect to a Kubernetes API endpoint, deploy a malicious pod, and access CI/CD pipelines that were inadequately isolated from the pod's scope. From there, the attacker harvested credentials from those pipelines. Ulrich highlights fundamental Kubernetes misconfigurations as the root cause and points to the Unit 42 publication as a practical reference for anyone operating containerized infrastructure.
Listen to the show on