SANS Stormcast Tuesday, May 12th, 2026: Apple Patches; Encrypted RCS; CAPTCHAs; Checkmarx vs TeamPCP;

SANS Internet StormCast

SANS Stormcast Tuesday, May 12th, 2026: Apple Patches; Encrypted RCS; CAPTCHAs; Checkmarx vs TeamPCP;

SANS Internet StormCastMay 12, 2026

Why It Matters

Understanding Apple’s patch cadence and the rollout of encrypted RCS helps users and enterprises protect communications against interception. The CAPTCHA insights illustrate real‑world bot mitigation, while the alert about the compromised Jenkins plugin underscores the need for vigilant supply‑chain security in development environments.

Key Takeaways

  • Apple released patches fixing ~80 vulnerabilities across iOS, iPadOS, macOS
  • iOS update adds encrypted RCS messaging between iPhone and Android
  • Captchas block 99% of bot requests on data‑intensive pages
  • Team PCP published malicious Checkmarx Jenkins AST plugin variant
  • Verify plugin checksums using Checkmarx advisory to ensure safety

Pulse Analysis

Apple’s May 12 patch cycle delivered updates for iOS, iPadOS, macOS Sonoma, tvOS, watchOS and the newly named missionOS, addressing roughly 80 security flaws. While the vulnerability count aligns with the company’s historical average, the breadth of affected platforms underscores the importance of timely patch management for corporate fleets. Enterprises that rely on Apple devices must prioritize rapid deployment to mitigate risks such as privilege escalation and information leakage. The update also bundles minor feature enhancements, but the security fixes remain the headline for IT security teams monitoring the ecosystem.

The same release introduces end‑to‑end encrypted RCS messaging, finally giving Apple users a secure alternative to SMS. Encryption activates when both parties run the latest iOS version or when an iPhone communicates with an Android device running Google’s updated Messenger app. A lock icon and “encrypted” label appear in the conversation window, providing visual confirmation. However, full adoption depends on carrier support, and inconsistent indicators could confuse users. Nonetheless, the feature marks a significant step toward protecting mobile communications against interception and spoofing, a priority for businesses handling sensitive data.

Johannes also reported that the site’s new captcha system blocked 99 % of automated requests, allowing only one out of 300 hits to reach data‑intensive pages. This demonstrates that modern bot‑filtering can preserve bandwidth and protect APIs from abuse. In parallel, Checkmarx’s Jenkins AST plugin faced a supply‑chain attack when Team PCP released a tampered version on the Jenkins Marketplace over a weekend. Users are urged to verify plugin checksums against the Checkmarx advisory and prefer the official API for data access. These incidents highlight the need for layered defenses and vigilant software‑supply monitoring.

Episode Description

Apple Patches Everything

https://isc.sans.edu/diary/Apple%20Patches%20Everything/32976

https://www.apple.com/newsroom/2026/05/end-to-end-encrypted-rcs-messaging-begins-rolling-out-today-in-beta/

https://isc.sans.edu/diary/Why%20we%20use%20CAPTCHAs/32974

https://checkmarx.com/blog/ongoing-security-updates/

Show Notes

Comments

Want to join the conversation?

Loading comments...