
SANS Internet Storm Center Stormcast: HTTP Query Method, Docker Escape, Cloudflare API Compromise, and LastPass GitHub Impersonation
🎬 The September 21st, 2026 SANS Internet Storm Center Stormcast covers three main security topics. First, a new HTTP query method for REST APIs that allows request bodies unlike GET requests, which are limited to 4-8 kilobytes in most browsers, though this creates caching issues as proxies may not consider the body when caching. Second, a Docker escape exploit on Mac that requires only three lines of bash code, where an attacker creates a file and directory, keeps the file open while deleting it, then replaces the folder with a symlink to access host files; fixes were released in late August and early September. Third, attackers compromised Bravo's Cloudflare API key to inject malicious JavaScript into customer websites, displaying ClickFix-style captures that installed malware on victim systems. Additionally, LastPass reported being one of 40 companies impersonated on GitHub, where fake repositories distributed malware containing a Microsoft-signed kernel driver that disabled anti-malware products and stole credentials.