DiscoverSANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)SANS Stormcast Thursday, September 18th, 2025: DLL Hooking; Entra ID Actor Tokens; Watchguard and NVidia Patches
SANS Stormcast Thursday, September 18th, 2025: DLL Hooking; Entra ID Actor Tokens; Watchguard and NVidia Patches

SANS Stormcast Thursday, September 18th, 2025: DLL Hooking; Entra ID Actor Tokens; Watchguard and NVidia Patches

Update: 2025-09-18
Share

Description



CTRL-Z DLL Hooking

Attackers may use a simple reload trick to overwrite breakpoints left by analysts to reverse malicious binaries.

https://isc.sans.edu/diary/CTRL-Z%20DLL%20Hooking/32294

Global Admin in every Entra ID tenant via Actor tokens

As part of September s patch Tuesday, Microsoft patched CVE-2025-55241. The discoverer of the vulnerability,

Dirk-jan Mollema has published a blog post showing how this vulnerability could have been exploited.

https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/

WatchGuard Firebox iked Out of Bounds Write Vulnerability CVE-2025-9242

WatchGuard patched an out-of-bounds write vulnerability, which could allow an unauthenticated attacker to compromise the devices.

https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00015

NVidia Triton Inference Server

NVIDIA patched critical vulnerabilities in its Triton Inference Server.

https://nvidia.custhelp.com/app/answers/detail/a_id/5691
Comments 
loading
In Channel
loading
00:00
00:00
1.0x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

SANS Stormcast Thursday, September 18th, 2025: DLL Hooking; Entra ID Actor Tokens; Watchguard and NVidia Patches

SANS Stormcast Thursday, September 18th, 2025: DLL Hooking; Entra ID Actor Tokens; Watchguard and NVidia Patches

Dr. Johannes B. Ullrich