SANS Internet Storm Center
sans-isc · B · active
https://isc.sans.edu/diaryarchive.html
Daily diaries by handler community; strong technical signal. (v2.55: rss_url verified — use `python3 tools/fetch_source.py feed https://isc.sans.edu/rssfeed.xml [N]`) | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → feed https://isc.sans.edu/rssfeed.xml 5 (then webfetch the diary URL https://isc.sans.edu/diary/rss/<id> for body) — or webfetch diaryarchive.html. AVOID: Nothing major — both feed and per-diary WebFetch work. Stormcast podcast items have empty bodies; filter to actual diary entries.. | 2026-07-05 admiralty audit: B — ISC handler community, original daily technical diaries, strong signal. Live and fresh; active retained. Filter out empty Stormcast podcast items.
Cited in 17 entries
Citation cadence
Citation days per ISO week (8 weeks of coverage span, total 15).
- AI as operator, not target: this week's research showed adversaries using AI to run attacks faster, evade AI defences, and generate tooling2026-07-12
- 'Comment stuffing' — HTML phishing attachments padded to ~2.5 MB to dilute or exhaust AI/NLP email scanners2026-07-10
- SANS ISC: Linux process-name masquerading via prctl(PR_SET_NAME) and how to detect it2026-06-27
- SonicWall CVE-2024-40766: why patched firewalls keep falling to Akira and Fog2026-06-23
- eBanking phishing hides its landing-page address in IPv4-mapped IPv6 notation to slip past URL scanners2026-06-22
- Shai-Hulud / Miasma supply-chain worm lineage — open-sourced, ported to PyPI, and a 1,500-package AUR wave2026-06-14
- CVE-2026-47291 — Microsoft June Patch Tuesday: HTTP.sys pre-auth RCE (CVSS 9.8) headlines the largest-ever release (198 CVEs)2026-06-10
- TeamPCP open-sources its Mini Shai-Hulud framework, spawning a new "Phantom Gyp" derivative2026-06-09
- SANS ISC: WeTransfer-delivered JavaScript stages a steganographic image loader ("Evil MSI background") on Cloudflare Workers and R22026-06-07
- SANS ISC: SVG phishing wave abuses a non-standard MIME type to slip past WAF/email pattern-matching2026-06-03
- SmartApeSG ClickFix stages an unnamed RAT that pivots to a weaponised NetSupport Manager2026-06-01
- SANS ISC — Akira ransomware kill chain reconstructed entirely from SSLVPN syslog and Windows EVTX, no EDR2026-05-28
- TeamPCP / Mini Shai-Hulud — framework open-sourced, Microsoft PyPI SDK trojanised with a wiper stage, forged Sigstore badges2026-05-26
- ACR Stealer distributed through counterfeit Claude AI download pages promoted by malicious search ads2026-05-26
- Mini Shai-Hulud / TrapDoor — the supply-chain worm goes cross-ecosystem, open-source and destructive2026-05-25
- Looking ahead — 2026-W222026-05-25
- TeamPCP / Shai-Hulud — first copycat wave (Phantom Bot + SSH/cloud stealers), Checkmarx Jenkins plugin trojanised again, PCPJack rival worm hits exposed cloud services2026-05-19