threat-intel Scans for Solana (Surfpool?) Endpoints, (Mon, Aug 10th) The SANS Internet Storm Center is observing a scanning campaign targeting Solana infrastructure, likely conducted by automated tools. These scans are attempting to enumerate Solana API endpoints and potentially extract credentials, indicating an effort to map the Solana ecosystem and potentially compromise associated s… SANS Internet Storm Center · Aug 10, 2026 Medium solanascanningreconnaissance
threat-intel WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning A public exploit, dubbed ‘wp2shell,’ is being aggressively used to target vulnerable WordPress installations, leading to widespread scanning and exploitation. Attackers are leveraging two vulnerabilities – CVE-2026-63030… The Hacker News · Jul 21, 2026 High CVE-2026-63030CVE-2026-60137CHDEGBwordpressremote code executionexploit
threat-intel Someone Is Scanning for Your MCP Servers and AI Assistant Credentials, (Mon, Jul 13th) A SANS Internet Storm Center analysis reveals a widespread scanning campaign targeting servers to identify and exploit vulnerabilities related to AI assistants and local Large Language Models (LLMs). The scans are active… SANS Internet Storm Center · Jul 13, 2026 High aillmscanning
threat-intel Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites A cybercrime crew exposed its operations – including tools, logs, and target lists – after leaving a server open for three weeks. The WP-SHELLSTORM operation, which involved planting webshells on vulnerable WordPress and… The Hacker News · Jul 10, 2026 High CVE-2026-3844CVE-2021-29441CVE-2026-3300CHwebshellvulnerabilityexploit
malware What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th) This SANS Internet Storm Center guest diary details an analysis of automated cybercrime activity observed through a honeypot, focusing on the Terrabot IoT botnet. The author, a BACS student, highlights the prevalence of… SANS Internet Storm Center · Jun 25, 2026 Medium CVE-2016-20017CVE-2018-10561CVE-2016-20016USiotbotnetscanning
threat-intel Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents This article details an experiment conducted by AIR Security to demonstrate the vulnerabilities within current skill-scanning methods for AI agent skills within popular marketplaces. The firm created a seemingly harmless… The Hacker News · Jun 23, 2026 Medium USaiagentskills
threat-intel China-linked JDY botnet expands targeting of U.S. military networks A Chinese-linked botnet, JDY, has significantly expanded its targeting of U.S. military networks and associated infrastructure. The botnet, previously associated with Volt Typhoon, utilizes reconnaissance techniques like… BleepingComputer · Jun 10, 2026 High CVE-2026-35616USbotnetreconnaissanceapt
threat-intel AI-Assisted Exploit Development Outpaces Scanner Detection Research from Cogent indicates that AI-assisted exploit development is dramatically accelerating, reducing exploit creation time from 125 days to just 0.5 days using large language models. This creates significant ‘visib… Dark Reading · May 27, 2026 Critical USaiexploitvulnerability