• SANS Stormcast Friday, February 20th, 2026: DynoWiper Analysis; Vibe Passwords; IDE Extension Vulns; Gransstream GXP 1600 Vuln and PoC
    Feb 20 2026

    Under the Hood of DynoWiper
    https://isc.sans.edu/diary/Under%20the%20Hood%20of%20DynoWiper/32730
    Vibe Password Generation: Predictable by Design
    https://www.irregular.com/publications/vibe-password-generation
    Vulnerabilities (CVE-2025-65715, CVE-2025-65716, CVE-2025-65717) in four popular IDE Extensions
    https://www.ox.security/blog/four-vulnerabilities-expose-a-massive-security-blind-spot-in-ide-extensions/
    Grandstream GXP1600 VoIP Phones
    https://www.rapid7.com/blog/post/ve-cve-2026-2329-critical-unauthenticated-stack-buffer-overflow-in-grandstream-gxp1600-voip-phones-fixed/
    Mehr anzeigen Weniger anzeigen
    6 Min.
  • SANS Stormcast Thursday, February 19th, 2026: Malware Image Resuse; Dell RecoveryPoint; Admin Center Vuln; DNS-PERSIST-01
    Feb 19 2026

    Tracking Malware Campaigns With Reused Material
    https://isc.sans.edu/diary/Tracking%20Malware%20Campaigns%20With%20Reused%20Material/32726
    From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day
    https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day
    Windows Admin Center Elevation of Privilege Vulnerability CVE-2026-26119
    https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26119
    DNS-PERSIST-01: A New Model for DNS-based Challenge Validation
    https://letsencrypt.org/2026/02/18/dns-persist-01.html
    Defending Web Apps
    https://www.sans.org/cyber-security-courses/application-security-securing-web-apps-api-microservices
    Mehr anzeigen Weniger anzeigen
    7 Min.
  • SANS Stormcast Wednesday, February 18th, 2026: IR Phishing; Neenadu Android Backdoor; NiFi Bugs; LLMs Phishing; Encrypted RCS
    Feb 18 2026

    Fake Incident Report Used in Phishing Campaign
    https://isc.sans.edu/diary/Fake%20Incident%20Report%20Used%20in%20Phishing%20Campaign/32722
    Divide and conquer: how the new Keenadu backdoor exposed links between major Android botnets https://securelist.com/keenadu-android-backdoor/118913/
    CVE-2026-25903: Apache NiFi: Missing Authorization of Restricted Permissions for Component Updates https://seclists.org/oss-sec/2026/q1/166
    The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time
    https://unit42.paloaltonetworks.com/real-time-malicious-javascript-through-llms/
    Encrypted RCS in iOS/iPadOS
    https://developer.apple.com/documentation/ios-ipados-release-notes/ios-ipados-26_4-release-notes
    Mehr anzeigen Weniger anzeigen
    8 Min.
  • SANS Stormcast Tuesday, February 17th, 2026: 64Bit Malware; Password Manager Weaknesses; OpenClaw Config Theft;
    Feb 17 2026

    2026 64-Bits Malware Trend
    https://isc.sans.edu/diary/2026%2064-Bits%20Malware%20Trend/32718
    A Comparative Security Analysis of Three Cloud-based Password Managers
    https://zkae.io
    Infostealer Infection Targeting OpenClaw Configurations
    https://www.infostealers.com/article/hudson-rock-identifies-real-world-infostealer-infection-targeting-openclaw-configurations/
    Mehr anzeigen Weniger anzeigen
    5 Min.
  • SANS Stormcast Monday, February 16th, 2026: Graph Generator; nslookup and clickfix; Chrome 0-Day; TURN Threats
    Feb 16 2026

    AI-Powered Knowledge Graph Generator & APTs
    https://isc.sans.edu/diary/AI-Powered%20Knowledge%20Graph%20Generator%20%26%20APTs/32712
    nslookup and ClickFix
    https://x.com/MsftSecIntel/status/2022456612120629742
    Google Chrome 0-Day Patch
    https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_13.html
    TURN Security Threats
    https://www.enablesecurity.com/blog/turn-server-security-threats/
    Mehr anzeigen Weniger anzeigen
    6 Min.
  • SANS Stormcast Friday, February 13th, 2026: SSH Bot; OpenSSH MacOS Change; Abused Employee Monitoring
    Feb 13 2026

    Four Seconds to Botnet - Analyzing a Self-Propagating SSH Worm with Cryptographically Signed C2 [Guest Diary]
    https://isc.sans.edu/diary/Four%20Seconds%20to%20Botnet%20-%20Analyzing%20a%20Self%20Propagating%20SSH%20Worm%20with%20Cryptographically%20Signed%20C2%20%5BGuest%20Diary%5D/32708
    OpenSSH Update on MacOS
    https://www.openssh.org/releasenotes.html
    Employee Monitoring and SimpleHelp Software Abused in Ransomware Operations
    https://www.huntress.com/blog/employee-monitoring-simplehelp-abused-in-ransomware-operations
    Mehr anzeigen Weniger anzeigen
    6 Min.
  • SANS Stormcast Thursday, February 12th, 2026: WSL in Malware; Apple and Adobe Patches
    Feb 12 2026

    WSL in the Malware Ecosystem https://isc.sans.edu/diary/32704
    Apple Patches Everything: February 2026
    https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20February%202026/32706
    Adobe Updates
    https://helpx.adobe.com/security/security-bulletin.html
    Mehr anzeigen Weniger anzeigen
    6 Min.
  • SANS Stormcast Wednesday, February 11th, 2026: Microsoft Patch Tuesday; Secure Boot Updates; Fake 7-Zip; FortiSlob
    Feb 11 2026

    Microsoft Patch Tuesday - February 2026
    https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20February%202026/32700
    Refreshing the root of trust
    https://blogs.windows.com/windowsexperience/2026/02/10/refreshing-the-root-of-trust-industry-collaboration-on-secure-boot-certificate-updates/
    Fake 7-Zip downloads are turning home PCs into proxy nodes
    https://www.malwarebytes.com/blog/threat-intel/2026/02/fake-7-zip-downloads-are-turning-home-pcs-into-proxy-nodes
    FortiNet Vulnerabilities
    https://fortiguard.fortinet.com/psirt/FG-IR-25-093 https://fortiguard.fortinet.com/psirt/FG-IR-25-1052
    Mehr anzeigen Weniger anzeigen
    8 Min.