
SANS StormCast Highlights New Linux Forensics Tool, macOS Vulnerability, and Critical Patches
The August 10, 2026, SANS Internet Storm Center StormCast covered multiple cybersecurity updates, including a new Linux forensics tool called Atuin, designed to improve bash history logging by replacing flat text files with a SQLite database. Atuin records additional details such as command start/end times, user context, working directory, and allows configurable exclusions (e.g., commands containing 'password'). The episode also highlighted a critical unauthenticated screen-sharing vulnerability in macOS 26 and prior versions, patched by Apple, which could enable remote access if screen sharing was enabled. Additionally, Ivanti released a second hotfix for actively exploited vulnerabilities in its Central product, while Metabase addressed a SQL injection flaw in its API/session/reset_password endpoint, with ongoing exploitation reported. The host noted that syslog-based command logging was an alternative but warned of unencrypted transmission risks unless TLS was used. Indicators of compromise for Ivanti and incident response guidance for Metabase were referenced in advisories.