threat-intel Some Malicious PE Stats, (Thu, Aug 27th) A security researcher used a Python script leveraging the pefile library to analyze a large dataset of malware samples from Malware Bazaar. By examining PE file headers, including the undocumented Rich Header and .NET CLR metadata, he identified trends in compiler usage and revealed that 32-bit PE files remain prevalen… SANS Internet Storm Center · 2d ago Medium compilerrich headerpe file
threat-intel ISC Stormcast For Friday, August 28th, 2026 https://isc.sans.edu/podcastdetail/10072, (Fri, Aug 28th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions with sophisticated spear-phishing attacks. The campaigns leveraged compromised credentials and utilized a… SANS Internet Storm Center · 3d ago High phishingcredential theftspear-phishing
threat-intel Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th) Attackers are increasingly using hostname-based IP address obfuscation, specifically leveraging services like 1u.ms to bypass security measures. This tactic is used to exploit vulnerabilities like Server Side Request For… SANS Internet Storm Center · 5d ago Medium ssrfdnsobfuscation
vulnerability Wireshark 4.6.8 Released, (Sun, Aug 16th) Wireshark, a widely used network protocol analyzer, released version 4.6.8, addressing 28 vulnerabilities and 25 bugs. This update significantly improves the security posture of the tool, mitigating potential risks assoc… SANS Internet Storm Center · Aug 16, 2026 Medium wiresharkvulnerabilitynetwork analysis
threat-intel ISC Stormcast For Thursday, August 13th, 2026 https://isc.sans.edu/podcastdetail/10050, (Thu, Aug 13th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in legacy systems. The threa… SANS Internet Storm Center · Aug 13, 2026 Medium phishingvulnerabilitycybersecurity
vulnerability Microsoft Plugs Nearly 400 Security Holes Microsoft released a massive update bundle addressing 398 security vulnerabilities, including one actively exploited and two previously disclosed flaws. Despite the sheer volume of fixes, only one of these vulnerabilitie… Krebs on Security · Aug 11, 2026 High CVE-2026-68820CVE-2026-62832CVE-2026-72971patch tuesdayvulnerabilityai
threat-intel Scans for Solana (Surfpool?) Endpoints, (Mon, Aug 10th) The SANS Internet Storm Center is observing a scanning campaign targeting Solana infrastructure, likely conducted by automated tools. These scans are attempting to enumerate Solana API endpoints and potentially extract c… SANS Internet Storm Center · Aug 10, 2026 Medium solanascanningreconnaissance
threat-intel ISC Stormcast For Wednesday, August 5th, 2026 https://isc.sans.edu/podcastdetail/10038, (Wed, Aug 5th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions and a concerning trend of sophisticated phishing attacks leveraging leaked credentials. The report emphas… SANS Internet Storm Center · Aug 5, 2026 High phishingcredential-stuffingbec
threat-intel ISC Stormcast For Wednesday, July 29th, 2026 https://isc.sans.edu/podcastdetail/10028, (Wed, Jul 29th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques to steal credentials. The threat landscape is evolving rapi… SANS Internet Storm Center · Jul 29, 2026 High phishingcredential-stealingbusiness-application
threat-intel ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions and a concerning trend of Log4j exploitation attempts. The threat landscape remains volatile, with attack… SANS Internet Storm Center · Jul 24, 2026 Medium phishinglog4jbec
threat-intel ISC Stormcast For Wednesday, July 15th, 2026 https://isc.sans.edu/podcastdetail/10008, (Wed, Jul 15th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in legacy systems. The threa… SANS Internet Storm Center · Jul 15, 2026 Medium phishingvulnerabilityemail
vulnerability Wireshark 4.6.7 Released, (Sat, Jul 11th) Wireshark, a widely used network protocol analyzer, released a security update addressing 12 vulnerabilities and 16 bugs. This update is crucial for maintaining network security and protecting against potential exploits. SANS Internet Storm Center · Jul 11, 2026 Medium wiresharkvulnerabilitynetwork analysis
threat-intel Adding some Automation to the favicon.ico method of Host Recon, (Mon, Jun 29th) This SANS Internet Storm Center article details a technique for host reconnaissance using favicon.ico files. The author demonstrates a workflow to identify hosts by extracting the favicon hash value from a website and qu… SANS Internet Storm Center · Jun 29, 2026 Low CAreconnaissancefaviconshodan
threat-intel Linux Process Name Masquerading, (Wed, Jun 24th) This SANS Internet Storm Center diary details a technique used by attackers, specifically the Velvet Ant Chinese group, to mask process names in Linux systems. Attackers modify the ‘comm’ and ‘cmdline’ entries in the /pr… SANS Internet Storm Center · Jun 24, 2026 Medium CHprocess_namemasqueradinglinux
threat-intel Agentic AI: The Weapon That No Longer Needs a Warrior This article discusses the rise of "Agentic AI" in offensive cyber operations, where AI systems autonomously execute attacks without direct human control. Previously, AI acted as a tool assisting humans in crafting attac… The Hacker News · Jun 23, 2026 High USaiautomationphishing
malware Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites A security incident has been discovered affecting over 1.2 million WordPress sites using the PushEngage, OptinMonster, and TrustPulse plugins. An attacker tampered with the plugins' JavaScript files, creating backdoors t… The Hacker News · Jun 15, 2026 High CVE-2026-10795USwordpresscdnbackdoor
threat-intel Claude Fable 5 Doesn't Change the Mythos Security Story This article discusses Anthropic's release of Claude Fable 5 and Mythos 5 AI models, highlighting concerns about their potential to exploit vulnerabilities in software. While Anthropic has implemented safeguards like saf… Dark Reading · Jun 12, 2026 High USaicybersecurityvulnerability
threat-intel Trump AI Order Seeks Voluntary Frontier Model Testing This executive order from the Trump administration aims to bolster federal cybersecurity and prepare for the risks associated with frontier AI models like Anthropic’s Claude Mythos. The order establishes a voluntary fram… Dark Reading · Jun 5, 2026 Medium aicybersecurityfrontier models
ransomware Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites A critical vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin has been exploited by threat actors, allowing for remote code execution and potential site compromise. Attackers have been actively targe… The Hacker News · Jun 5, 2026 Critical CVE-2026-3300MDwordpressvulnerabilityremote code execution
threat-intel Credit card theft campaign abuses Stripe to host stolen payment info A Magecart campaign is exploiting Stripe's infrastructure to steal credit card data from online stores. The attackers leverage Google Tag Manager to deliver the malicious code, bypassing standard security measures. This… BleepingComputer · Jun 4, 2026 High magecartcredit card theftstripe