ISC Stormcast For Wednesday, September 23rd, 2026 https://isc.sans.edu/podcastdetail/10106, (Wed, Sep 23rd)
2026-09-23T07:23:40Z•0aa6bae4cc4b610a04023ee9f890b959b28f77b966690baca55705104e138fcf
ClickFixHTTP QUERYLausivLoaderMacfingerPNG steganographySANS ISCTerminalFixmalspammultistage malwarephishingreverse tunnelsocial engineeringthreat intelligence
What happened
SANS Internet Storm Center RSS entries covering September 17–23, 2026. Key security topics include the Macfinger ClickFix campaign, LausivLoader malware delivered through targeted malspam and multistage payload passing, and TerminalFix activity using PNG steganography and reverse tunneling. The feed also discusses the newly defined HTTP QUERY method and related standards; no specific vulnerability exploitation is identified in the provided metadata.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 0aa6bae4cc4b610a04023ee9f890b959b28f77b966690baca55705104e138fcf
- Enrichment time
- 2026-09-23T07:23:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.