# SANS Stormcast Monday, May 4th, 2026: Malicious Homebrew Ads; Wireshark Update; Digicert False Positive; cPanel Exploited (#) Page: https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820/sans-stormcast-monday-may-4th-2026-malicious-homebrew-ads-wireshark-update-digicert-false-positive-cpanel-exploited Text version: https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820/sans-stormcast-monday-may-4th-2026-malicious-homebrew-ads-wireshark-update-digicert-false-positive-cpanel-exploited.md Podcast: [SANS Internet Storm Center's Daily Network Security News Podcast](https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820) Published: 2026-05-04T00:04:27+00:00 Episode link: https://mp3.sans.edu/sans-stormcast-monday-may-4th-2026-malicious-homebrew-ads-wireshark-update-digicert-false-positive-cpanel-exploited Audio file: https://traffic.libsyn.com/secure/securitypodcast/9916.mp3?dest-id=448030 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820/episodes/sans-stormcast-monday-may-4th-2026-malicious-homebrew-ads-wireshark-update-digicert-false-positive-cpanel-exploited Duration seconds: 467 ## Resource SANS Stormcast Monday, May 4th, 2026: Malicious Homebrew Ads; Wireshark Update; Digicert False Positive; cPanel Exploited Malicious Ad for Homebrew Leads to MacSync Stealer https://isc.sans.edu/diary/Malicious%20Ad%20for%20Homebrew%20Leads%20to%20MacSync%20Stealer/32942 Wireshark Update https://www.wireshark.org/docs/relnotes/wireshark-4.6.5.html Digicert Microsoft Defender False Positive https://www.reddit.com/r/cybersecurity/comments/1t2hfsh/mde_flagging_digi_cert_certificate_as_malicious/ https://bugzilla.mozilla.org/show_bug.cgi?id=2033170 cPanel Exploited https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026 keywords: cpanel; digicert; microsoft; defender; false positive; wireshark; homebrew ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820/episodes/sans-stormcast-monday-may-4th-2026-malicious-homebrew-ads-wireshark-update-digicert-false-positive-cpanel-exploited/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820/sans-stormcast-monday-may-4th-2026-malicious-homebrew-ads-wireshark-update-digicert-false-positive-cpanel-exploited.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.