
SANS Internet Storm Center Stormcast: Critical Vulnerabilities and Active Exploits - September 11, 2026
The SANS Internet Storm Center Stormcast for Friday, September 11th, 2026 covers several cybersecurity topics. An intern analyzed a Red Tail malware sample captured in a honeypot using runtime analysis with InetSim, a tool that simulates internet services like DNS servers to provide isolated malware testing environments. Checkpoint released a critical security advisory on September 10th patching two vulnerabilities, including an unauthenticated remote code execution flaw and a heap-based buffer overflow, with patches automatically deployed via their live patch feature on September 9th. Cisco updated a March advisory for its Secure Firewall Management Center regarding a vulnerability now being actively exploited, providing indicators of compromise for detection. Previdian observed exploitation of a Netscaler ADC vulnerability that was patched less than a month ago, with exploitation increasing after a proof of concept was published days earlier. Hunt.io published a detailed walkthrough of an attack against a UK local government exploiting a SonicWall SMA 1000 vulnerability, demonstrating attacker techniques and evidence left on compromised systems beyond simple file hashes or IP addresses.