threat-intel Recent DShield SIEM Update, (Tue, Jul 14th) The DShield SIEM, a honeypot monitoring system, received a recent update incorporating new features and improved logging capabilities. Specifically, the system now collects TTY logs and integrates Suricata alerts, providing enhanced insights into attacker activity. These additions are designed to improve threat detecti… SANS Internet Storm Center · Jul 15, 2026 Medium honeypotthreat-detectionlog-analysis
threat-intel The Behavior of Coordinated SSH Brute Force Attacks over the last three months [Guest Diary], (Wed, Jun 17th) This report details a three-month analysis of coordinated SSH brute-force attacks conducted using a honeypot system, highlighting a correlation between attack activity and geopolitical events, law enforcement actions, an… SANS Internet Storm Center · Jun 18, 2026 High USIRILsshbrute-forcehoneypot
vulnerability Ivanti Sentry Exploitation Attempts Hitting Honeypots A recently patched vulnerability in Ivanti Sentry, CVE-2026-10520, has been observed attempting exploitation on honeypots, according to Ivanti and CISA. The flaw allows for remote code execution with root privileges via… SecurityWeek · Jun 12, 2026 High CVE-2026-10520USvulnerabilitycommand injectionroot privilege
threat-intel AI-powered honeypots: Turning the tables on malicious AI agents This article details a new approach to cybersecurity utilizing generative AI to create dynamic honeypots. By leveraging AI to simulate vulnerable systems and respond to attacker actions, defenders can actively manipulate… Cisco Talos · Apr 29, 2026 Medium CVE-2014-6271aihoneypotgenerative-ai