
SANS StormCast Highlights Critical Cybersecurity Issues Including SSH Compromises, Dell BIOS Flaws, and Vulnerable JavaScript Library
The August 7, 2026, SANS Internet Storm Center StormCast highlighted three key cybersecurity issues. An SSH compromise study by intern Daryl Jimenez revealed attackers gained persistence in 22 seconds by adding a public key to the authorized_keys file, emphasizing the need for monitoring and centralizing key management. Researchers at Amber Wolf exposed a flaw in Dell BIOS passwords stored in SPI flash memory, where XOR encryption with a 20-byte key and zero-padding allowed easy password retrieval unless a 32-byte password was used. Additionally, a vulnerability in the unmaintained JavaScript library crypt.js affected cryptocurrency wallets, as it failed to generate random keys for three years, prompting users to migrate funds to new wallets. The episode also featured Ricky Banda’s research on benchmarking free-tier LLMs (Gemini, ChatGPT, Claude) as cognitive aids for parsing unstructured cyber threat intelligence, finding they achieved 80% efficacy compared to human analysts but required human oversight to correct hallucinations or misaligned recommendations.