ISC Stormcast For Monday, March 9th, 2026 https://isc.sans.edu/podcastdetail/9840, (Mon, Mar 9th)
2026-03-09T07:23:52Z•323b62c0363ee5fb07c5678d25d4337357d6fdfb5f8293aeac70d3b2cce50922
bruteforce-scanscrushftpguest-diarymalwarerssrtfsans-iscstormcastthreat-intelvulnerabilitiesxwormyara-x
What happened
SANS ISC diary (entries Mar 2–9, 2026) covering multiple topics of operational interest: YARA-X 1.14.0 released (minor improvements and bug fixes); an active XWorm wave observed — multi-technology malware with evolving delivery techniques; brute-force scanning activity targeting CrushFTP with reminder of prior serious vulnerabilities (CVE-2024-4040, CVE-2025-31161) and an actively exploited July 2025 zero-day (CVE-2025-54309); plus operational guidance items (how-to extract ZIPs from RTFs) and a guest diary on distinguishing targeted intrusions from opportunistic scans. Actionable takeaways:,1
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 323b62c0363ee5fb07c5678d25d4337357d6fdfb5f8293aeac70d3b2cce50922
- Enrichment time
- 2026-03-09T07:23:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.