logo

SANS ISC Diary

ID: d8fc01a8-3ac9-5b71-b7c5-0e5eac74e481

STIX ID: identity--d8fc01a8-3ac9-5b71-b7c5-0e5eac74e481

Feed Type: rss

Earliest post: 2024-11-19

Latest post: 2026-06-12

Real-time threat observations, incident reports, malware behavior, and network security analysis from the SANS Internet Storm Center community of analysts and practitioners.

01/01/2020
06/13/2026
Title Date Published Describes IncidentAuthorVisible
Microsoft June 2026 Patch Tuesday, (Tue, Jun 9th)2026-06-09TrueTrue
TeamPCP Supply Chain Campaign: Activity Through 2026-06-07, (Mon, Jun 8th)2026-06-08TrueTrue
The Evil MSI Background is Back!, (Fri, Jun 5th)2026-06-05TrueTrue
New Wave Of Phishing Emails with SVG Files, (Tue, Jun 2nd)2026-06-02TrueTrue
Unidentified RAT pushes NetSupport RAT, (Mon, Jun 1st)2026-06-01TrueTrue
Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs, (Wed, May 27th)2026-05-27TrueTrue
Possible ACR Stealer From Page Impersonating Claude, (Tue, May 26th)2026-05-26TrueTrue
TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th)2026-05-25TrueTrue
TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th)2026-05-25TrueTrue
Wireshark 4.6.6 Released, (Sun, May 24th)2026-05-24TrueTrue
An Example of Stack String in High Level Language, (Sat, May 23rd)2026-05-23TrueTrue
Cross-Platform NPM Stealer, (Fri, May 22nd)2026-05-22TrueTrue
TeamPCP Supply Chain Campaign: Activity Through 2026-05-17, (Mon, May 18th)2026-05-18TrueTrue
[Guest Diary] New Malware Libraries means New Signatures, (Fri, May 15th)2026-05-15TrueTrue
Simple bypass of the link preview function in Outlook Junk folder, (Thu, May 14th)2026-05-14TrueTrue
[GUEST DIARY] Tearing apart website fraud to see how it works., (Wed, May 13th)2026-05-13TrueTrue
Microsoft May 2026 Patch Tuesday, (Tue, May 12th)2026-05-12TrueTrue
Apple Patches Everything, (Mon, May 11th)2026-05-11TrueTrue
Another Universal Linux Local Privilege Escalation (LPE) Vulnerability: Dirty Frag, (Fri, May 8th)2026-05-08TrueTrue
Cleartext Passwords in MS Edge? In 2026?, (Mon, May 4th)2026-05-05TrueTrue
TeamPCP Weekly Analysis: 2026-W18 (2026-04-27 through 2026-05-03), (Mon, May 4th)2026-05-04TrueTrue
Wireshark 4.6.5 Released, (Sun, May 3rd)2026-05-03TrueTrue
Danger of Libredtail [Guest Diary], (Wed, Apr 29th)2026-04-30TrueTrue
Today's Odd Web Requests, (Wed, Apr 29th)2026-04-29TrueTrue
HTTP Requests with X-Vercel-Set-Bypass-Cookie Header, (Tue, Apr 28th)2026-04-28TrueTrue
TeamPCP Supply Chain Campaign: Update 008 - 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns, (Mon, Apr 27th)2026-04-27TrueTrue
Apple Patches Exploited Notification Flaw, (Thu, Apr 23rd)2026-04-23TrueTrue
[Guest Diary] Beyond Cryptojacking: Telegram tdata as a Credential Harvesting Vector, Lessons from a Honeypot Incident, (Wed, Apr 22nd)2026-04-22TrueTrue
A .WAV With A Payload, (Tue, Apr 21st)2026-04-21TrueTrue
Handling the CVE Flood With EPSS, (Mon, Apr 20th)2026-04-20TrueTrue
Lumma Stealer infection with Sectop RAT (ArechClient2), (Fri, Apr 17th)2026-04-17TrueTrue
[Guest Diary] Compromised DVRs and Finding Them in the Wild, (Thu, Apr 16th)2026-04-15TrueTrue
Scanning for AI Models, (Tue, Apr 14th)2026-04-15TrueTrue
Microsoft Patch Tuesday April 2026., (Tue, Apr 14th)2026-04-14TrueTrue
Scans for EncystPHP Webshell, (Mon, Apr 13th)2026-04-13TrueTrue
Obfuscated JavaScript or Nothing, (Thu, Apr 9th)2026-04-10TrueTrue
Number Usage in Passwords: Take Two, (Thu, Apr 9th)2026-04-09TrueTrue
TeamPCP Supply Chain Campaign: Update 007 - Cisco Source Code Stolen via Trivy-Linked Breach, Google GTIG Tracks TeamPCP as UNC6780, and CISA KEV Deadline Arrives with No Standalone Advisory, (Wed, Apr 8th)2026-04-08TrueTrue
A Little Bit Pivoting: What Web Shells are Attackers Looking for?, (Tue, Apr 7th)2026-04-07TrueTrue
How often are redirects used in phishing in 2026?, (Mon, Apr 6th)2026-04-06TrueTrue
TeamPCP Supply Chain Campaign: Update 006 - CERT-EU Confirms European Commission Cloud Breach, Sportradar Details Emerge, and Mandiant Quantifies Campaign at 1,000+ SaaS Environments, (Fri, Apr 3rd)2026-04-03TrueTrue
Attempts to Exploit Exposed "Vite" Installs (CVE-2025-30208), (Thu, Apr 2nd)2026-04-02TrueTrue
Malicious Script That Gets Rid of ADS, (Wed, Apr 1st)2026-04-01TrueTrue
TeamPCP Supply Chain Campaign: Update 005 - First Confirmed Victim Disclosure, Post-Compromise Cloud Enumeration Documented, and Axios Attribution Narrows, (Wed, Apr 1st)2026-04-01TrueTrue
Application Control Bypass for Data Exfiltration, (Tue, Mar 31st)2026-03-31TrueTrue
TeamPCP Supply Chain Campaign: Update 004 - Databricks Investigating Alleged Compromise, TeamPCP Runs Dual Ransomware Operations, and AstraZeneca Data Released, (Mon, Mar 30th)2026-03-30TrueTrue
DShield (Cowrie) Honeypot Stats and When Sessions Disconnect, (Mon, Mar 30th)2026-03-30TrueTrue
TeamPCP Supply Chain Campaign: Update 003 - Operational Tempo Shift as Campaign Enters Monetization Phase With No New Compromises in 48 Hours, (Sat, Mar 28th)2026-03-28TrueTrue
TeamPCP Supply Chain Campaign: Update 002 - Telnyx PyPI Compromise, Vect Ransomware Mass Affiliate Program, and First Named Victim Claim, (Fri, Mar 27th)2026-03-27TrueTrue
TeamPCP Supply Chain Campaign: Update 001 - Checkmarx Scope Wider Than Reported, CISA KEV Entry, and Detection Tools Available, (Thu, Mar 26th)2026-03-26TrueTrue

1–50 of 148