ISC Stormcast For Friday, March 6th, 2026 https://isc.sans.edu/podcastdetail/9838, (Fri, Mar 6th)
2026-03-07T01:23:50Z•40e3182ccbbaefc675e5c9da0eaf18f5efed1d7fb31cc1618bf5c503e48e051a
CrushFTPRTFSANS-ISCWiresharkXWormZIPbruteforceintrusion-detectionmalwarepodcastscanningvulnerability
What happened
SANS ISC diary (Mar 2–6, 2026) highlights multiple items of operational relevance: a new XWorm wave using multi-technology delivery, a guest piece on distinguishing targeted intrusions from opportunistic scanning, active bruteforce scans against CrushFTP (context: prior serious flaws including CVE-2024-4040, CVE-2025-31161 and the July 2025 zero-day CVE-2025-54309), a Wireshark 4.6.4 release that patches three vulnerabilities and 15 bugs, and a quick how-to on ZIP files embedded in RTFs (useful for malware delivery analysis). Operators should monitor CrushFTP instances for brute-force activity
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 40e3182ccbbaefc675e5c9da0eaf18f5efed1d7fb31cc1618bf5c503e48e051a
- Enrichment time
- 2026-03-07T01:23:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.