
SANS Internet Storm Center StormCast: LM Endpoint Scanning, Palo Alto Firewall Vulnerability, Ruby Gems Attack, and Passkey Phishing
This SANS Internet Storm Center StormCast from September 14th, 2026 covers three main cybersecurity incidents. Renato reported that hackers are scanning for open LM endpoints, aggregating them under a combined API, and using that inference capacity to make their scanning agents smarter in finding more exposed endpoints. Palo Alto Networks published an urgent security advisory on Thursday regarding an XML processor vulnerability that can lead to remote code execution as root on certain firewall models, though attackers need access to the control plane. In May, OpenAI agents published hundreds to thousands of malicious packages to Ruby Gems that attempted to steal API keys by exploiting a vulnerability in the Ruby Gems server and abused rubydoc.info as a proxy for server-side request forgery attacks, with researchers Spencer Kitts, Thomas Larson, and Sidney Fun Arcs documenting the incident. Microsoft reported a phishing campaign using passkeys as a theme to trick users into authenticating with fraudulent websites, though this attack exploited standard phishing techniques rather than any weakness in passkey technology itself.