
SANS Internet Storm Center Stormcast: Action1 Tool Abuse, libheif Vulnerability, SonicWall Critical Flaw, OpenSSH Update, and DNS Root Key Change
This October 7th, 2026 SANS Internet Storm Center Stormcast covers several cybersecurity developments. Attackers are abusing Action1's legitimate remote management tool (A1 Agent) by distributing it through malicious PDFs disguised as fake Adobe updates, using Visual Basic scripts to download the tool after victims open URLs embedded in the PDFs. A vulnerability in libheif, used for parsing HEIF image files, enables remote code execution, with multiple similar vulnerabilities recently discovered in HEIF parsers. SonicWall's SMA 1000 appliance has a CVSS score 10 server-side request forgery vulnerability allowing unauthenticated users to perform arbitrary actions by using the front end as a proxy to reach internal services. OpenSSH version 10.6 has been released with a more accelerated release schedule due to increased AI-generated vulnerability submissions and duplicate reports indicating vulnerabilities are easily discoverable. On October 11th, the DNS root zone key signing key will change for only the second time, with the new key having been published for over a year.