
SANS Internet Storm Center Stormcast - September 18, 2026: Malware Analysis, Isabel Framework Vulnerability, CISA Updates, and Unbound DNS Flaws
This Friday, September 18th, 2026 edition of the SANS Internet Storm Center Stormcast covers several cybersecurity developments. Yan analyzed malware that led to a loss of loader instance, involving obfuscated JavaScript and PowerShell that exchange information via environment variables, with the JavaScript creating an encryption key used to decrypt part of the PowerShell. The Isabel framework, used to control PBX phone systems via web applications, contained a hard-coded JWT key that allowed authentication bypass and remote code execution on linked Asterisk servers, with exploitation already observed in the wild by Shadow Server Foundation. CISA published a document on using cyber decoys to strengthen detection and response, providing frameworks for deploying decoys in organizations. CISA announced it will sunset its weekly vulnerability bulletin on September 28th, with the final edition published at month's end, shifting focus to risk-based approaches like the known exploit list. Unbound fixed two heap-based buffer overflows, one potentially leading to unauthenticated remote code execution related to DNSSEC, involving compressed records that can create oversized records filling buffers.