news.mlab.sh
Back to the feed
threat-intel

ISC Stormcast For Friday, September 18th, 2026 https://isc.sans.edu/podcastdetail/10100, (Fri, Sep 18th)

Medium
Summary

The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions and a concerning trend of sophisticated BEC (Business Email Compromise) attacks leveraging leaked credentials. The podcast emphasized the need for enhanced vigilance and proactive security measures to combat these evolving threats, particularly focusing on employee awareness training and robust multi-factor authentication.

The SANS Internet Storm Center’s latest Stormcast discussed a notable uptick in malicious email campaigns, primarily targeting the financial sector. The core focus was on a surge in BEC attacks, where attackers are successfully leveraging stolen credentials – often obtained through data breaches – to impersonate executives and initiate fraudulent wire transfers. The podcast noted that these attacks are becoming increasingly sophisticated, utilizing advanced social engineering techniques to build trust with targets and bypass traditional security controls.

Specifically, the ISC noted a trend of attackers utilizing leaked credentials from various breaches to gain access to internal systems and then craft highly personalized emails designed to trick employees into transferring funds. The podcast also touched on the ongoing challenges of detecting and mitigating these attacks, given the volume of legitimate emails and the difficulty in identifying malicious activity in real-time.

Furthermore, the ISC discussed the importance of ongoing employee training to recognize and report suspicious emails, alongside the implementation of stricter access controls and multi-factor authentication to limit the impact of compromised accounts. The podcast stressed that a layered approach to security is essential to effectively combat this evolving threat landscape.

Read the full article at SANS Internet Storm Center