SANS Stormcast Friday, May 22nd, 2026: Selective HTTP Proxying; More GitHub Repo Trouble; MSFT Defender Patches;

SANS Internet StormCast

SANS Stormcast Friday, May 22nd, 2026: Selective HTTP Proxying; More GitHub Repo Trouble; MSFT Defender Patches;

SANS Internet StormCastMay 22, 2026

Why It Matters

Understanding how to isolate application traffic helps security teams reduce noise and focus on targeted analysis, while awareness of the GitHub Actions supply‑chain attack underscores the need for strict credential hygiene and repository monitoring. The highlighted patches from Microsoft and Cisco address high‑severity vulnerabilities that could lead to system compromise, making timely updates essential for protecting enterprise environments.

Key Takeaways

  • Proxifier works only on macOS and Windows; Linux alternatives exist.
  • Linux uses env vars, iptables, or namespaces for selective proxying.
  • GitHub Actions attacks exfiltrate API keys, tokens, and private keys.
  • Microsoft Defender update patches Red Sun and Undefend exploits.
  • Cisco Secure Workload API bypass CVSS 10, requires immediate patch.

Pulse Analysis

The episode opens with a deep dive into selective HTTP proxying. While Proxifier remains a macOS and Windows‑only solution, the host outlines three Linux workarounds: setting HTTP_PROXY/HTTPS_PROXY environment variables, leveraging iptables for user‑specific redirection, and employing network namespaces to isolate an application’s network stack. These techniques let analysts capture traffic from a single program without drowning in system‑wide noise, a practical tip for reverse engineers and red‑team operators.

The conversation then shifts to a fresh wave of GitHub repository compromises. Attackers harvest previously leaked credentials to inject malicious GitHub Actions that trigger on pushes, pulls, or external calls. Once active, the actions silently siphon AWS, Google, and other cloud secrets—API keys, JWTs, private SSH keys—sending them to IP 216.126.225.129. This supply‑chain style breach underscores the need for strict secret management, action provenance checks, and continuous monitoring of repository activity.

Finally, the host reviews two critical vendor updates. Microsoft Defender’s latest patch addresses the Red Sun and Undefend privilege‑escalation exploits, automatically rolling out via its regular update cadence. Meanwhile, Cisco disclosed a CVSS 10 authentication bypass in the Secure Workload REST API, granting unauthenticated users full admin rights. Organizations running the workload must apply the emergency fix and isolate the API from public networks. Together, these alerts illustrate how rapid patching, layered network controls, and vigilant credential hygiene remain essential pillars of modern cybersecurity strategy.

Episode Description

Selective HTTP Proxying in Linux

https://isc.sans.edu/diary/Selective%20HTTP%20Proxying%20in%20Linux/33002

https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows/

https://x.com/fabian_bader/status/2057198207243804881

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csw-pnbsa-g8WEnuy

Show Notes

Comments

Want to join the conversation?

Loading comments...