Normal view
Today β 11 August 2026SANS Internet Storm Center, InfoCON: green
-
SANS Internet Storm Center, InfoCON: green
- ISC Stormcast For Tuesday, August 11th, 2026 https://isc.sans.edu/podcastdetail/10046, (Tue, Aug 11th)
Scans for Solana (Surfpool?) Endpoints, (Mon, Aug 10th)
10 August 2026 at 12:24
Solana is a crypto platform known for speed. Developers like it to develop distributed applications or to implement crypto payments. To interact with the blockchain, APIs are provided for developers. These APIs will either "speak" JSON or gRPC. One implementation often used for development is "surfpool," which is used to test programs before deploying them to a Solana network.
Yesterday β 10 August 2026SANS Internet Storm Center, InfoCON: green
-
SANS Internet Storm Center, InfoCON: green
- ISC Stormcast For Monday, August 10th, 2026 https://isc.sans.edu/podcastdetail/10044, (Mon, Aug 10th)
Before yesterdaySANS Internet Storm Center, InfoCON: green
-
SANS Internet Storm Center, InfoCON: green
- Linux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th)
Linux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th)
7 August 2026 at 03:22
UNIX systems (including Linux) are well-known to record a lot of activities in many different locations. But there is one domain where they definitely lack of "modern"Β logging: shells. Most shells provide an historization of the typed commands through a flat file in the $HOME directory (ex: $HOME/.bash_history). They suffer of multiple problems:
-
SANS Internet Storm Center, InfoCON: green
- ISC Stormcast For Friday, August 7th, 2026 https://isc.sans.edu/podcastdetail/10042, (Fri, Aug 7th)
-
SANS Internet Storm Center, InfoCON: green
- ISC Stormcast For Thursday, August 6th, 2026 https://isc.sans.edu/podcastdetail/10040, (Thu, Aug 6th)
-
SANS Internet Storm Center, InfoCON: green
- 22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary], (Thu, Aug 6th)
22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary], (Thu, Aug 6th)
5 August 2026 at 20:15
[This is a Guest Diary by Daryl Jiminez, an ISC intern as part of the SANS.edu BACS program]
-
SANS Internet Storm Center, InfoCON: green
- Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)
Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)
5 August 2026 at 13:56
When you learn that a compromised package executed on one of your build hosts, muscle memory takes over: revoke the npm token, rotate the GitHub PAT, cycle the cloud keys. That reflex has been correct in almost every supply-chain incident I have worked. In theΒ keyv/cacheableΒ compromise that has been unfolding since yesterday, it is the one thing you should not do first β because revoking the stolen token is exactly what arms the payload.
-
SANS Internet Storm Center, InfoCON: green
- ISC Stormcast For Wednesday, August 5th, 2026 https://isc.sans.edu/podcastdetail/10038, (Wed, Aug 5th)
-
SANS Internet Storm Center, InfoCON: green
- Botnet Hunting for Vulnerabilities in Diagnostic Tools, (Tue, Aug 4th)
Botnet Hunting for Vulnerabilities in Diagnostic Tools, (Tue, Aug 4th)
4 August 2026 at 08:46
This morning, I noticed specific sources "hunting" for vulnerabilities in URLs that I haven't noticed before. All of these URLs appear to be associated with diagnostic tools:
-
SANS Internet Storm Center, InfoCON: green
- ISC Stormcast For Tuesday, August 4th, 2026 https://isc.sans.edu/podcastdetail/10036, (Tue, Aug 4th)
-
SANS Internet Storm Center, InfoCON: green
- ISC Stormcast For Monday, August 3rd, 2026 https://isc.sans.edu/podcastdetail/10034, (Mon, Aug 3rd)
Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)
2 August 2026 at 00:05
Introduction
-
SANS Internet Storm Center, InfoCON: green
- Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)
Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)
1 August 2026 at 03:22
Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.
zipdump.py: Metadata Encoding, (Fri, Jul 31st)
31 July 2026 at 05:22
I was asked for help with a problem similar to the following.
-
SANS Internet Storm Center, InfoCON: green
- ISC Stormcast For Friday, July 31st, 2026 https://isc.sans.edu/podcastdetail/10032, (Fri, Jul 31st)
-
SANS Internet Storm Center, InfoCON: green
- ISC Stormcast For Thursday, July 30th, 2026 https://isc.sans.edu/podcastdetail/10030, (Thu, Jul 30th)
-
SANS Internet Storm Center, InfoCON: green
- Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner [Guest Diary], (Thu, Jul 30th)
Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner [Guest Diary], (Thu, Jul 30th)
29 July 2026 at 20:42
[This is a Guest Diary by Adam Cann, an ISC intern as part of the SANS.edu BACS program]
Apple Patches Everything (July 2026), (Wed, Jul 29th)
29 July 2026 at 03:32
I am a bit late with this summary, but this weekΒ Apple released updates to allΒ its operating systems and Safari. The Safari update, as usual, targets macOS prior to macOS 26. macOS updates covered the two older versions (14 and 15), while other operating system patches only covered the current 26 versions.