
SANS Stormcast Covers Linux Kernel Process Accounting, Windows Defender Vulnerability, and AI Content Labeling Laws
The August 13, 2026, episode of the SANS Internet Storm Center Stormcast discussed Linux kernel process accounting, a feature that logs terminated processes with details such as process name, executing user, runtime duration, start time, and termination flags (e.g., crashes or kills). The tool acct enables this logging, generating approximately 50MB of logs daily on a Proxmox server, with the advantage of capturing container processes from the host without requiring separate logging inside unprivileged containers. The episode also highlighted an unpatched privilege escalation vulnerability in Windows Defender, dubbed 'Shield Break,' following a prior exploit called 'Rogue Planet,' and a proof-of-concept exploit for a SharePoint vulnerability involving unvalidated JWT signatures. Adobe addressed critical flaws in ColdFusion (CVSS 10 OS command injection) and Commerce (remote code execution and privilege escalation), while new AI content labeling laws in the EU and California prompted companies to implement watermarking techniques, though removal tools are emerging.