DiscoverSANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)SANS Stormcast Monday, July 7th, 2025: interesting usernames; More sudo issues; CitrixBleed2 PoC; Short Lived Certs
SANS Stormcast Monday, July 7th, 2025: interesting usernames; More sudo issues; CitrixBleed2 PoC; Short Lived Certs

SANS Stormcast Monday, July 7th, 2025: interesting usernames; More sudo issues; CitrixBleed2 PoC; Short Lived Certs

Update: 2025-07-07
Share

Description



Interesting ssh/telnet usernames

Some interesting usernames observed in our honeypots

https://isc.sans.edu/diary/A%20few%20interesting%20and%20notable%20ssh%20telnet%20usernames/32080

More sudo trouble

The host option in Sudo can be exploited to execute commands on unauthorized hosts.

https://www.stratascale.com/vulnerability-alert-CVE-2025-32462-sudo-host

CitrixBleed2 PoC Posted (CVE-2025-5777)

WatchTwer published additional details about the recently patched CitrixBleed vulnerability, including a PoC exploit.

https://labs.watchtowr.com/how-much-more-must-we-bleed-citrix-netscaler-memory-disclosure-citrixbleed-2-cve-2025-5777/

Instagram Using Six Day Certificates

Instagram changes their TLS certificates daily and they use certificates that are just about to expire in a week.

https://hereket.com/posts/instagram-single-day-certificates/
Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

SANS Stormcast Monday, July 7th, 2025: interesting usernames; More sudo issues; CitrixBleed2 PoC; Short Lived Certs

SANS Stormcast Monday, July 7th, 2025: interesting usernames; More sudo issues; CitrixBleed2 PoC; Short Lived Certs

Dr. Johannes B. Ullrich