logo

TSUBAME Report Overflow (Apr-Jun 2025)

ID: 1e52fd12-91c4-579a-9eab-d6ba15378a19

STIX ID: report--1e52fd12-91c4-579a-9eab-d6ba15378a19

Feed Name: JPCERT Blog

Date Published: 2025-10-28

Date Updated: 2026-04-19

Author: 鹿野 恵祐 (Keisuke Shikano)

...
...

This TSUBAME Overflow report reviews April–June 2025 internet threat monitoring, noting a significant mid-to-late June drop in unique Iranian source IPs likely linked to cyber attacks and government-imposed connectivity restrictions during the Israel–Iran conflict. Overseas sensors observed higher packet volumes than Japan with both peaking in April, and common scanning targeted ports such as 22/TCP, 23/TCP, 80/TCP, 443/TCP, 8080/TCP, and 8728/TCP across regions. No special alerts or IoCs were issued; the report advises continued vigilance for widespread scanning.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.