
SANS Internet Storm Center Reports on Screen Connect Attacks, GPT Phishing, and iCloud Email Spoofing Vulnerability
This SANS Internet Storm Center Stormcast from October 2nd, 2026 covers three cybersecurity threats. The first involves attackers emailing legitimate copies of Screen Connect remote admin tool pre-configured to connect directly to the attacker upon launch, exploiting features designed for legitimate tech support. The second threat, observed by Huntress, involves abuse of OpenAI's custom GPT feature to deliver phishing messages that direct users to clickfix attacks, where users are tricked into copying and pasting malicious strings into terminals. The third issue involves research by SEC Consult revealing a vulnerability in Apple iCloud that allowed email spoofing by injecting carriage returns without line feeds to confuse the system about the actual from header, enabling attackers to send emails from other users' iCloud identities. SEC Consult originally reported this vulnerability to Apple in 2024, and it has now been patched. A similar issue with Proton Mail using Unicode homograph attacks to impersonate sender names remains unpatched.