logo

SANS ISC Diary

ID: d8fc01a8-3ac9-5b71-b7c5-0e5eac74e481

STIX ID: identity--d8fc01a8-3ac9-5b71-b7c5-0e5eac74e481

Feed Type: rss

Earliest post: 2024-11-19

Latest post: 2026-07-10

Real-time threat observations, incident reports, malware behavior, and network security analysis from the SANS Internet Storm Center community of analysts and practitioners.

01/01/2020
07/10/2026
Title Date Published Describes IncidentAuthorVisible
Why Ask Credentials If There Are Secret Codes?, (Wed, Jul 1st)2026-07-01TrueTrue
June 2026 Apple Updates, (Tue, Jun 30th)2026-06-30TrueTrue
What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th)2026-06-25TrueTrue
Linux Process Name Masquerading, (Wed, Jun 24th)2026-06-24TrueTrue
CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration., (Tue, Jun 23rd)2026-06-23TrueTrue
Webshells Remain Popular, (Mon, Jun 22nd)2026-06-22TrueTrue
eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address, (Fri, Jun 19th)2026-06-19TrueTrue
The Behavior of Coordinated SSH Brute Force Attacks over the last three months [Guest Diary], (Wed, Jun 17th)2026-06-18TrueTrue
The browser blind spot: Why your security tool may not be blocking what you think it is [Guest Diary], (Wed, Jun 17th)2026-06-17TrueTrue
From a VHDX File to a Remcos RAT, (Tue, Jun 16th)2026-06-16TrueTrue
Evil MSI Background: BASE64 Statistical Analysis, (Mon, Jun 15th)2026-06-15TrueTrue
Microsoft June 2026 Patch Tuesday, (Tue, Jun 9th)2026-06-09TrueTrue
TeamPCP Supply Chain Campaign: Activity Through 2026-06-07, (Mon, Jun 8th)2026-06-08TrueTrue
The Evil MSI Background is Back!, (Fri, Jun 5th)2026-06-05TrueTrue
New Wave Of Phishing Emails with SVG Files, (Tue, Jun 2nd)2026-06-02TrueTrue
Unidentified RAT pushes NetSupport RAT, (Mon, Jun 1st)2026-06-01TrueTrue
Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs, (Wed, May 27th)2026-05-27TrueTrue
Possible ACR Stealer From Page Impersonating Claude, (Tue, May 26th)2026-05-26TrueTrue
TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th)2026-05-25TrueTrue
TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th)2026-05-25TrueTrue
Wireshark 4.6.6 Released, (Sun, May 24th)2026-05-24TrueTrue
An Example of Stack String in High Level Language, (Sat, May 23rd)2026-05-23TrueTrue
Cross-Platform NPM Stealer, (Fri, May 22nd)2026-05-22TrueTrue
TeamPCP Supply Chain Campaign: Activity Through 2026-05-17, (Mon, May 18th)2026-05-18TrueTrue
[Guest Diary] New Malware Libraries means New Signatures, (Fri, May 15th)2026-05-15TrueTrue
Simple bypass of the link preview function in Outlook Junk folder, (Thu, May 14th)2026-05-14TrueTrue
[GUEST DIARY] Tearing apart website fraud to see how it works., (Wed, May 13th)2026-05-13TrueTrue
Microsoft May 2026 Patch Tuesday, (Tue, May 12th)2026-05-12TrueTrue
Apple Patches Everything, (Mon, May 11th)2026-05-11TrueTrue
Another Universal Linux Local Privilege Escalation (LPE) Vulnerability: Dirty Frag, (Fri, May 8th)2026-05-08TrueTrue
Cleartext Passwords in MS Edge? In 2026?, (Mon, May 4th)2026-05-05TrueTrue
TeamPCP Weekly Analysis: 2026-W18 (2026-04-27 through 2026-05-03), (Mon, May 4th)2026-05-04TrueTrue
Wireshark 4.6.5 Released, (Sun, May 3rd)2026-05-03TrueTrue
Danger of Libredtail [Guest Diary], (Wed, Apr 29th)2026-04-30TrueTrue
Today's Odd Web Requests, (Wed, Apr 29th)2026-04-29TrueTrue
HTTP Requests with X-Vercel-Set-Bypass-Cookie Header, (Tue, Apr 28th)2026-04-28TrueTrue
TeamPCP Supply Chain Campaign: Update 008 - 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns, (Mon, Apr 27th)2026-04-27TrueTrue
Apple Patches Exploited Notification Flaw, (Thu, Apr 23rd)2026-04-23TrueTrue
[Guest Diary] Beyond Cryptojacking: Telegram tdata as a Credential Harvesting Vector, Lessons from a Honeypot Incident, (Wed, Apr 22nd)2026-04-22TrueTrue
A .WAV With A Payload, (Tue, Apr 21st)2026-04-21TrueTrue
Handling the CVE Flood With EPSS, (Mon, Apr 20th)2026-04-20TrueTrue
Lumma Stealer infection with Sectop RAT (ArechClient2), (Fri, Apr 17th)2026-04-17TrueTrue
[Guest Diary] Compromised DVRs and Finding Them in the Wild, (Thu, Apr 16th)2026-04-15TrueTrue
Scanning for AI Models, (Tue, Apr 14th)2026-04-15TrueTrue
Microsoft Patch Tuesday April 2026., (Tue, Apr 14th)2026-04-14TrueTrue
Scans for EncystPHP Webshell, (Mon, Apr 13th)2026-04-13TrueTrue
Obfuscated JavaScript or Nothing, (Thu, Apr 9th)2026-04-10TrueTrue
Number Usage in Passwords: Take Two, (Thu, Apr 9th)2026-04-09TrueTrue
TeamPCP Supply Chain Campaign: Update 007 - Cisco Source Code Stolen via Trivy-Linked Breach, Google GTIG Tracks TeamPCP as UNC6780, and CISA KEV Deadline Arrives with No Standalone Advisory, (Wed, Apr 8th)2026-04-08TrueTrue
A Little Bit Pivoting: What Web Shells are Attackers Looking for?, (Tue, Apr 7th)2026-04-07TrueTrue

1–50 of 159