ISC Stormcast For Thursday, September 17th, 2026 https://isc.sans.edu/podcastdetail/10098, (Thu, Sep 17th)
2026-09-17T07:23:41Z•01517f6a96c0fc74e834b28f4834b6011b13c62c5c5e109345fe5bece4328e1e
AI agentsApple security updatesLLM API abuseRedtail malwareSANS ISCcloud service abusecredential and account farminghospitality applicationsmacOSnetwork reconnaissancepayload analysisthreat intelligencevulnerability management
What happened
SANS Internet Storm Center entries covering scans against hospitality applications, macOS 27 first-boot network behavior, Apple’s September 2026 security updates addressing 261 vulnerabilities, an AI-assisted operation harvesting and aggregating stolen LLM inference access, and analysis of the Redtail malware payload. The collection includes both defensive vulnerability intelligence and active threat activity involving exposed services, account farming, and malware.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 01517f6a96c0fc74e834b28f4834b6011b13c62c5c5e109345fe5bece4328e1e
- Enrichment time
- 2026-09-17T07:23:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.