DShield (Cowrie) Honeypot Stats and When Sessions Disconnect, (Mon, Mar 30th)
2026-03-30T19:23:52Z•3024e42f29a8f486a427c5b95c7e50dd66d155be390befbcef5d52c1abead6d6
Apple patchesArechClient2AstraZenecaCowrieDShieldDatabricksLiteLLMNetSupportPyPI compromiseRemcosSectopSmartApeSGStealCTeamPCPTelnyxVectdata leakhoneypotiOSmacOSpatch managementransomwaresupply-chaintelemetry
What happened
Feed of SANS ISC diary entries (late March 2026) covering multiple active threats and telemetry: an ongoing TeamPCP supply‑chain campaign with multiple updates noting PyPI compromises (LiteLLM, Telnyx), a Vect ransomware mass affiliate program and dual ransomware operations, reported data release (AstraZeneca) and Databricks investigating an alleged compromise; Apple March 2026 security updates addressing ~85 vulnerabilities across macOS/iOS/tvOS/watchOS/visionOS (no active exploitation reported); SmartApeSG campaign distributing multiple RATs (Remcos, NetSupport, StealC, Sectop/ArechClient2);
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 3024e42f29a8f486a427c5b95c7e50dd66d155be390befbcef5d52c1abead6d6
- Enrichment time
- 2026-03-30T19:23:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.