
SANS Internet Storm Center Stormcast: Mac Finger Campaign, Terraform Supply Chain Attack, MikroTik and F5 Vulnerabilities
This September 24th, 2026 SANS Internet Storm Center Stormcast covers four cybersecurity developments. Brad analyzed a ClickFix campaign called Mac Finger that uses compromised legitimate sites to deliver an info stealer to Mac users through malicious scripts pasted into terminals. Iikido published research on the craft algo campaign, a supply chain attack using malicious Terraform providers that employ typo-squatting to mimic popular Docker-related providers and only load Go module remote admin tools when specific Docker container names and network IDs are present. The Polisher detailed two vulnerabilities in MikroTik RouterOS's custom SSH daemon that were recently patched by MikroTik, including a rekey authentication bypass and an exploit using the username -ash2 or minus2 to redirect input from the client. Watchtower released analysis of an F5 BIG-IP vulnerability involving a buffer overflow in the auth header triggered by over 16 kilobytes of data, which was patched by adding a length check before copying data into the buffer.