
SANS Internet Storm Center StormCast: Honeypot User Agents, FortiMail Vulnerability, GitLab AI Gateway Flaw, and macOS Disk Access Restrictions
This SANS Internet Storm Center StormCast from October 5th, 2026 covers several cybersecurity topics. The episode discusses unusual user agent strings detected in honeypots, including those from commercial scanners and research organizations, noting that 40-50 different organizations are currently conducting internet-wide scans. Fortinet released an update for FortiMail to fix a path traversal vulnerability involving null byte characters that allows unauthenticated attackers to write arbitrary files and achieve remote code execution, linked to the identity-based encryption (IBE) feature. GitLab released a critical update for its on-premise AI gateway to address a vulnerability allowing attackers to manipulate workflows and potentially execute code. Apple announced plans to review and restrict how applications request full disk access permissions in future macOS versions, citing risks to user data and data belonging to people communicating with users, particularly from messaging applications.