# SANS Stormcast Thursday, April 30th, 2026: Odd Requests; MSFT LNK Bug Exploited; Secure Boot Fix; TLS Updates; SAP npm malware (#) Page: https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820/sans-stormcast-thursday-april-30th-2026-odd-requests-msft-lnk-bug-exploited-secure-boot-fix-tls-updates-sap-npm-malware Text version: https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820/sans-stormcast-thursday-april-30th-2026-odd-requests-msft-lnk-bug-exploited-secure-boot-fix-tls-updates-sap-npm-malware.md Podcast: [SANS Internet Storm Center's Daily Network Security News Podcast](https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820) Published: 2026-04-30T00:35:16+00:00 Episode link: https://mp3.sans.edu/sans-stormcast-thursday-april-30th-2026-odd-requests-msft-lnk-bug-exploited-secure-boot-fix-tls-updates-sap-npm-malware Audio file: https://traffic.libsyn.com/secure/securitypodcast/9912.mp3?dest-id=448030 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820/episodes/sans-stormcast-thursday-april-30th-2026-odd-requests-msft-lnk-bug-exploited-secure-boot-fix-tls-updates-sap-npm-malware Duration seconds: 364 ## Resource SANS Stormcast Thursday, April 30th, 2026: Odd Requests; MSFT LNK Bug Exploited; Secure Boot Fix; TLS Updates; SAP npm malware Today's Odd Web Requests https://isc.sans.edu/diary/Today%27s%20Odd%20Web%20Requests/32934 Incomplete Patch of APT28's Zero-Day Leads to CVE-2026-32202 https://www.akamai.com/blog/security-research/2026/apr/incomplete-patch-apt28s-zero-day-cve-2026-32202 Assess Secure Boot status with Microsoft Defender https://techcommunity.microsoft.com/blog/MicrosoftDefenderATPBlog/assess-secure-boot-status-with-microsoft-defender/4510356 Deprecating Legacy TLS and Endpoints for POP and IMAP in Exchange Online https://techcommunity.microsoft.com/blog/exchange/deprecating-legacy-tls-and-endpoints-for-pop-and-imap-in-exchange-online/4515201 SAP Related npm Packages Compromised https://www.stepsecurity.io/blog/a-mini-shai-hulud-has-appeared keywords: npm; SAP; TSL; POP; IMAP; microsoft; defender; apt28; web ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820/episodes/sans-stormcast-thursday-april-30th-2026-odd-requests-msft-lnk-bug-exploited-secure-boot-fix-tls-updates-sap-npm-malware/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820/sans-stormcast-thursday-april-30th-2026-odd-requests-msft-lnk-bug-exploited-secure-boot-fix-tls-updates-sap-npm-malware.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.