
SANS Storm Cast Highlights Cybersecurity Threats Including OpenAI Breach, Zimbra XSS Exploits, and Rust-Based RAT
The July 24, 2026, SANS Internet Storm Center Storm Cast covered multiple cybersecurity incidents, including the OpenAI vs. Hugging Face breach, which highlighted flaws in agent sandboxes and guardrail asymmetries, with API keys and non-human identities as key attack vectors. A CISA advisory detailed a Russian state-sponsored campaign exploiting cross-site scripting (XSS) vulnerabilities in Zimbra webmail, where attackers injected fake login prompts via cascading style sheets to steal credentials, including second-factor authentication codes. The Ukrainian CERT reported a phishing attack targeting Notepad++ users, where malicious DLLs were deployed via ZIP files to hijack extensions, though the method was disputed as a vulnerability. Cisco identified a Rust-based remote access trojan (RAT) named MSA RAT, which abuses Chrome’s DevTools protocol to establish covert command-and-control channels, masking malicious traffic as legitimate browser activity. The episode also referenced Office 365 calendar abuse as a covert channel technique. Key takeaways included the persistent risks of XSS in webmail systems and the challenges of detecting browser-based malware.