
SANS StormCast Highlights Cybersecurity Incidents and Tool Updates on August 3, 2026
The August 3, 2026, SANS Internet Storm Center StormCast covered three cybersecurity incidents and a tool update. A researcher named DD enhanced sipdump, a tool that extracts metadata (e.g., filenames, timestamps) from ZIP archives, even if corrupted or encrypted, by adding support for handling encoding issues (ASCII or UTF-8) via brute-force detection. Brad documented an Atomic macOS Stealer (AMOS) infection, where victims were tricked into installing malware disguised as a 'Mac OS toolkit' via a fake domain (getmacouscloud.com); the attack bypassed CAPTCHA by mimicking legitimate software installation prompts, with network traffic samples available for analysis. Xavier reported a phishing campaign targeting OpenAI’s ChatGPT users, where emails falsely claimed failed subscription payments and redirected victims to a fake site harvesting credit card data. Additionally, a vulnerability in Coldcard crypto wallets was highlighted, where a firmware bug caused the device to use MicroPython’s weak pseudorandom number generator instead of its hardware-based one, leading to compromised private keys and stolen cryptocurrency; affected users were advised to transfer funds to new wallets.