logo

SANS ISC Diary

ID: d8fc01a8-3ac9-5b71-b7c5-0e5eac74e481

STIX ID: identity--d8fc01a8-3ac9-5b71-b7c5-0e5eac74e481

Feed Type: rss

Earliest post: 2024-11-19

Latest post: 2026-09-18

Real-time threat observations, incident reports, malware behavior, and network security analysis from the SANS Internet Storm Center community of analysts and practitioners.

01/01/2020
09/21/2026
Title Date Published Describes IncidentAuthorVisible
HTTP QUERY Method: The Grey Zone Between GET And POST., (Fri, Sep 18th)2026-09-18TrueTrue
LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)2026-09-17TrueTrue
Scans Targeting Hospitality Applications, (Wed, Sep 16th)2026-09-16TrueTrue
Apple Updates Everything, (Mon, Sep 14th)2026-09-14TrueTrue
The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)2026-09-11TrueTrue
Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)2026-09-10TrueTrue
Scans for Proxmox Servers, (Wed, Sep 9th)2026-09-09TrueTrue
Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)2026-09-06TrueTrue
Honeypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)2026-09-03TrueTrue
Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)2026-09-01TrueTrue
The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary, (Mon, Aug 31st)2026-08-31TrueTrue
Some Malicious PE Stats, (Thu, Aug 27th)2026-08-28TrueTrue
A polymorphic phishing page (that occasionally breaks itself), (Thu, Aug 27th)2026-08-27TrueTrue
Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th)2026-08-25TrueTrue
DOUBLECUP's PNG Payload, (Mon, Aug 24th)2026-08-24TrueTrue
Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays, (Fri, Aug 21st)2026-08-21TrueTrue
Simple Scans for Cloud Metadata Service, (Wed, Aug 19th)2026-08-19TrueTrue
Apple Patches iOS and macOS, (Mon, Aug 17th)2026-08-17TrueTrue
Apple Screen Sharing Security, (Mon, Aug 17th)2026-08-17TrueTrue
Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI, (Wed, Aug 12th)2026-08-13TrueTrue
Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)2026-08-11TrueTrue
Scans for Solana (Surfpool?) Endpoints, (Mon, Aug 10th)2026-08-10TrueTrue
22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary], (Thu, Aug 6th)2026-08-06TrueTrue
Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)2026-08-05TrueTrue
Botnet Hunting for Vulnerabilities in Diagnostic Tools, (Tue, Aug 4th)2026-08-04TrueTrue
Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)2026-08-02TrueTrue
Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)2026-08-01TrueTrue
Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner [Guest Diary], (Thu, Jul 30th)2026-07-30TrueTrue
Apple Patches Everything (July 2026), (Wed, Jul 29th)2026-07-29TrueTrue
AutoIT Payload Injector , (Tue, Jul 28th)2026-07-28TrueTrue
Java Spring Boot "heapdump" scans, (Mon, Jul 27th)2026-07-27TrueTrue
Scans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th)2026-07-26TrueTrue
When the "Autonomous Attacker" Is Your Own AI Model, (Thu, Jul 23rd)2026-07-23TrueTrue
Rondo Meets Geoserver, (Wed, Jul 22nd)2026-07-22TrueTrue
WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)2026-07-20TrueTrue
Scans for Hikvision Intelligent Security API, (Sun, Jul 19th)2026-07-19TrueTrue
Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)2026-07-14TrueTrue
Someone Is Scanning for Your MCP Servers and AI Assistant Credentials, (Mon, Jul 13th)2026-07-13TrueTrue
"Comment stuffing" in an HTML phishing attachment as a mechanism for evading AI-based detection?, (Fri, Jul 10th)2026-07-10TrueTrue
_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary], (Tue, Jul 7th)2026-07-09TrueTrue
Why Ask Credentials If There Are Secret Codes?, (Wed, Jul 1st)2026-07-01TrueTrue
June 2026 Apple Updates, (Tue, Jun 30th)2026-06-30TrueTrue
What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th)2026-06-25TrueTrue
Linux Process Name Masquerading, (Wed, Jun 24th)2026-06-24TrueTrue
CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration., (Tue, Jun 23rd)2026-06-23TrueTrue
Webshells Remain Popular, (Mon, Jun 22nd)2026-06-22TrueTrue
eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address, (Fri, Jun 19th)2026-06-19TrueTrue
The Behavior of Coordinated SSH Brute Force Attacks over the last three months [Guest Diary], (Wed, Jun 17th)2026-06-18TrueTrue
The browser blind spot: Why your security tool may not be blocking what you think it is [Guest Diary], (Wed, Jun 17th)2026-06-17TrueTrue
From a VHDX File to a Remcos RAT, (Tue, Jun 16th)2026-06-16TrueTrue

1–50 of 200