
SANS Internet Storm Center Stormcast: Phishing Tricks, GitLab Weakness, Mac Malware, and SolarWinds Vulnerabilities
The SANS Internet Storm Center Stormcast for Friday, September 25th, 2026 covers four cybersecurity stories. Xavier analyzed a phishing email using three URL tricks: the user info field with unique username/password per email, an invalid hostname with labels ending in two dashes, and the victim's email address embedded to prefill phishing pages. Aikido discovered a GitLab weakness where email addresses containing secret random strings can be used to send requests to repositories, and users may inadvertently expose these addresses in readme files, allowing attackers to change suffixes like dash-issue to access other features including push or merge requests. Kaspersky found a new version of Mac sync malware that retrieves payloads via iCloud calendar to bypass network defenses and now uses binaries compiled in Objective-C or Swift instead of scripting languages. SolarWinds released updates for SolarWinds Observability addressing two unauthenticated remote code execution vulnerabilities, though one requires non-default insecure configuration and the other requires specific communication modes to be enabled.