sans

34 posts tagged with "sans"

AutoIT Payload Injector , (Tue, Jul 28th)

AutoIT Payload Injector , (Tue, Jul 28th)

In the rapidly evolving landscape of cyber threats, it is often the established, legitimate tools that pose the most persistent risks. Automation utilities, designed to streamline administrative tasks, frequently find themselves repurposed by malicious actors due to their inherent trust and…

Apple Patches Everything (July 2026), (Wed, Jul 29th)

Apple Patches Everything (July 2026), (Wed, Jul 29th)

The end of July 2026 brought a familiar but critical workflow for security operations centers worldwide as Apple deployed a sweeping set of security patches across its entire ecosystem. Released slightly later than the usual weekly cadence, this update wave serves as a stark reminder of the…

Scans for Hikvision Intelligent Security API, (Sun, Jul 19th)

Scans for Hikvision Intelligent Security API, (Sun, Jul 19th)

The ubiquity of internet-connected surveillance equipment has turned the video security market into a prime hunting ground for cybercriminals. For years, security professionals have warned about the fragile state of IoT device hygiene, and recent data suggests the situation is deteriorating rather…

Captive Portal Detection, (Tue, Jul 21st)

Captive Portal Detection, (Tue, Jul 21st)

Security operations centers are often flooded with alerts, creating a high-pressure environment where distinguishing between sophisticated attacks and routine network noise is a critical skill. While honeypots serve as excellent traps for malicious actors, they are indiscriminate collectors of…

WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)

WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)

The cybersecurity community is currently on high alert due to the emergence of a critical threat targeting the infrastructure of the internet's most popular content management system. Security researchers have disclosed a severe vulnerability within WordPress Core, a flaw distinct from the typical…

Rondo Meets Geoserver, (Wed, Jul 22nd)

Rondo Meets Geoserver, (Wed, Jul 22nd)

The visibility of threat intelligence relies heavily on what surfaces in network telemetry, and recently, security analysts observed a notable resurgence in malicious activity involving the intersection of the Rondo malware family and GeoServer instances. This specific convergence highlights a…

When the "Autonomous Attacker" Is Your Own AI Model, (Thu, Jul 23rd)

When the "Autonomous Attacker" Is Your Own AI Model, (Thu, Jul 23rd)

The concept of an autonomous attacker often conjures images of sentient machines or nation-state AI bots probing defenses. However, a recent incident serves as a stark reminder that the most disruptive autonomous actor in your network might be one you invited in yourself. In a twist that reads like…

Java Spring Boot "heapdump" scans, (Mon, Jul 27th)

Java Spring Boot "heapdump" scans, (Mon, Jul 27th)

Recent intelligence from the SANS Internet Storm Center has highlighted a concerning trend in the threat landscape, specifically regarding active scanning campaigns targeting Java Spring Boot applications. Security professionals are observing attackers aggressively probing for the presence of a…

Recent DShield SIEM Update, (Tue, Jul 14th)

Recent DShield SIEM Update, (Tue, Jul 14th)

In the rapidly evolving landscape of cybersecurity, having access to timely and actionable threat intelligence is paramount for organizations of all sizes. The SANS Internet Storm Center has long served as a cornerstone for community-driven defense, primarily through its DShield project. For…

More Odd DNS Records: NIMLOC, (Tue, Jul 7th)

More Odd DNS Records: NIMLOC, (Tue, Jul 7th)

Security researchers and network administrators are increasingly observing unusual DNS record types in network traffic, raising questions about their purpose and potential security implications. Following recent attention on NAPTR records and their relationship to Rich Communication Services (RCS),…

RCS and DNS: The NAPTR Record, (Mon, Jul 6th)

RCS and DNS: The NAPTR Record, (Mon, Jul 6th)

The telecommunications landscape is undergoing a significant transformation as Rich Communication Services (RCS) continues to gain momentum across both iOS and Android platforms. This evolution represents a fundamental shift away from the antiquated SMS protocol toward a more robust, feature-rich…

My Stack Simulator, (Wed, Jul 8th)

My Stack Simulator, (Wed, Jul 8th)

In the complex landscape of cybersecurity threats, sometimes the most dangerous vulnerabilities lie in the most fundamental components of computing. The stack, a critical memory structure that programs rely on for basic operations, represents both an essential mechanism for program execution and a…

Wireshark 4.6.7 Released, (Sat, Jul 11th)

Wireshark 4.6.7 Released, (Sat, Jul 11th)

In today's rapidly evolving cybersecurity landscape, network analysis tools remain fundamental to threat detection and incident response. Among these tools, Wireshark stands as a cornerstone protocol analyzer trusted by security professionals worldwide. The recently released version 4.6.7 addresses…

Linux Process Name Masquerading, (Wed, Jun 24th)

Linux Process Name Masquerading, (Wed, Jun 24th)

Process name masquerading represents one of the most persistent challenges in Linux security, allowing malicious actors to hide in plain sight among legitimate system processes. This sophisticated technique undermines a fundamental assumption of system monitoring—that what you see is what you get.…

Webshells Remain Popular, (Mon, Jun 22nd)

Webshells Remain Popular, (Mon, Jun 22nd)

Webshells continue to plague organizations despite their long history in the attacker's toolkit. These malicious scripts, once planted on a compromised web server, provide attackers with persistent remote access and control, making them one of the most dangerous and persistent threats in the…

Microsoft June 2026 Patch Tuesday, (Tue, Jun 9th)

Microsoft June 2026 Patch Tuesday, (Tue, Jun 9th)

Microsoft's June 2026 Patch Tuesday release presents one of the most significant security updates in recent memory, addressing an extensive array of vulnerabilities across its product ecosystem. Security professionals are urged to prioritize this update, which includes patches for 204…

Evil MSI Background: BASE64 Statistical Analysis, (Mon, Jun 15th)

Evil MSI Background: BASE64 Statistical Analysis, (Mon, Jun 15th)

Security researchers have identified the resurgence of a sophisticated malware distribution technique known as the "Evil MSI Background," a threat that leverages seemingly legitimate Microsoft Installer files to conceal malicious payloads. This re-emergence highlights the continued evolution of…

June 2026 Apple Updates, (Tue, Jun 30th)

June 2026 Apple Updates, (Tue, Jun 30th)

Apple's June 2026 update release has caught the attention of cybersecurity professionals due to its unusual staggered approach. The tech giant rolled out security patches for iOS, iPadOS, macOS, and Safari earlier this week, breaking from their typical pattern of simultaneous updates across all…

YARA-X 1.18.0 and 1.19.0 Release, (Sun, Jun 28th)

YARA-X 1.18.0 and 1.19.0 Release, (Sun, Jun 28th)

The security community has received a significant update with the recent releases of YARA-X versions 1.18.0 and 1.19.0, bringing enhanced capabilities to this essential malware analysis tool. For security professionals who rely on pattern matching to identify and classify malicious software, these…

From a VHDX File to a Remcos RAT, (Tue, Jun 16th)

From a VHDX File to a Remcos RAT, (Tue, Jun 16th)

Security researchers have identified a concerning malware delivery method that exploits Windows' native virtual disk handling capabilities to distribute Remcos Remote Access Trojan (RAT). This attack vector demonstrates how threat actors continue to evolve their tactics by leveraging legitimate…