SANS Internet Storm Center

isc.sans.edu · EN

SANS Internet Storm Center - Cooperative Cyber Security Monitor

Latest posts

  1. ISC Stormcast For Friday, September 25th, 2026 https://isc.sans.edu/podcastdetail/10110, (Fri, Sep 25th)

    · isc.sans.edu
  2. One URL, Three Different Tricks, (Thu, Sep 24th)

    · isc.sans.edu

    Yesterday, we received a phishing email with an interesting link. At first sight, it looks like garbage, but every piece of it has been carefully crafted to confuse basic security controls. Here is the defanged link:

  3. ISC Stormcast For Thursday, September 24th, 2026 https://isc.sans.edu/podcastdetail/10108, (Thu, Sep 24th)

    · isc.sans.edu
  4. Macfinger ClickFix campaign, (Tue, Sep 22nd)

    · isc.sans.edu

    Introduction

  5. ISC Stormcast For Wednesday, September 23rd, 2026 https://isc.sans.edu/podcastdetail/10106, (Wed, Sep 23rd)

    · isc.sans.edu
  6. The Truth about GET and HTTP Standards, (Tue, Sep 22nd)

    · isc.sans.edu

    On Friday, Xavier talked about the newly introduced HTTP Query method. This new method was introduced to allow "GET" requests that include a body. The main reason for this was that GET requests typically do not contain a body. But what if they do?

  7. LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)

    · isc.sans.edu

    At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially remarkable – it asked the recipient to review some attached requirements and provide a price quotation for a fiber optic system and appeared to…

  8. ISC Stormcast For Tuesday, September 22nd, 2026 https://isc.sans.edu/podcastdetail/10104, (Tue, Sep 22nd)

    · isc.sans.edu
  9. TerminalFix: PNG Steganography, (Mon, Sep 21st)

    · isc.sans.edu

    Microsoft Security Research published an interesting blog post "TerminalFix campaign deploys a reverse tunnel through multistage intrusion" about a malware campaign. The aspect that I want to take a closer look at, is the fact that the threat actors used PNG files with steganography. I reached out…

  10. ISC Stormcast For Monday, September 21st, 2026 https://isc.sans.edu/podcastdetail/10102, (Mon, Sep 21st)

    · isc.sans.edu
  11. HTTP QUERY Method: The Grey Zone Between GET And POST., (Fri, Sep 18th)

    · isc.sans.edu

    In June 2026 the IETF published RFC 10008[1], defining a new HTTP method: "QUERY". The HTTP protocol faced already by changes (HTTP/2, HTTP/3) but it&#x27s the first new standard HTTP verb since "PATCH" in 2010!

In the directory since 25 Sept 2026 · last checked 25 Sept 2026 · RSS

Report a problem with this feed