Want More XWorm?, (Wed, Mar 4th)
2026-03-05T01:23:49Z•3f569162d591a5ce7eb241af7204273099852130d0551ab982a2ee6d3adae31c
CVE-2024-4040CVE-2025-31161CVE-2025-54309CrushFTPXWormbruteforcehoneypotinfosecmalwarephishingrtfwiresharkzero-day
What happened
SANS ISC diary roundup (late Feb–early Mar 2026) describing multiple events: a new wave of XWorm multi-technology malware with evolving delivery techniques; brute-force scans targeting CrushFTP and reminders of serious CrushFTP vulnerabilities (CVE-2024-4040, CVE-2025-31161) including an actively exploited zero-day (CVE-2025-54309); Wireshark 4.6.4 security fixes; techniques for ZIP files inside RTF; a FedEx-themed phishing/malware delivery; and a guest diary on running honeypots with AI assistance.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 3f569162d591a5ce7eb241af7204273099852130d0551ab982a2ee6d3adae31c
- Enrichment time
- 2026-03-05T01:23:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.