What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th)
2026-06-25T07:23:46Z•088cbc50febddfaef36f1475d9d89ff1240a99c3e466ced4f1cb6818e4d280ab
T1036cve-2024-40766ipv4-mapped-ipv6ipv6linuxmalware-obfuscationmisconfigurationphishingprocess-masqueradingrootkitssh-bruteforcethreat-intelvulnerabilitywebshell
What happened
SANS Internet Storm Center diary roundup (Jun 17–25, 2026) covering several active operational threats and one tracked CVE. Key topics: Linux process-name masquerading (MITRE T1036) used by attackers (example: Velvet Ant) to hide malicious processes or impersonate benign ones; ongoing prevalence and a newly observed webshell (publicly pushed on GitHub); an eBanking phishing campaign leveraging IPv4-mapped IPv6 addressing in URLs; analysis of coordinated SSH brute-force activity over the prior three months; and a note on CVE-2024-40766 where a patch addressed the bug but insecure configuration/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 088cbc50febddfaef36f1475d9d89ff1240a99c3e466ced4f1cb6818e4d280ab
- Enrichment time
- 2026-06-25T07:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.