DOUBLECUP's PNG Payload, (Mon, Aug 24th)

2026-08-25T01:23:41Z5b253a594f3633c4b05536a92e1fd5e2724cb7c552d46ab57dfb70bd503c463d
169.254.169.254DOUBLECUPIAMM365MFAMicrosoft Entra IDMicrosoft GraphPNG payloadPowerShellSANS ISCcloud identity securitycloud metadata servicecredential theftmalwarepassword sprayingrisk detectionsteganography

What happened

A SANS Internet Storm Center RSS collection covering DOUBLECUP PNG payload delivery, Microsoft Entra/M365 MFA and login-risk monitoring with PowerShell and Graph, stale-account and license enumeration, and cloud metadata service scanning. The material is primarily defensive threat research and cloud identity security guidance; no specific vulnerability identifiers are provided.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
5b253a594f3633c4b05536a92e1fd5e2724cb7c552d46ab57dfb70bd503c463d
Enrichment time
2026-08-25T01:23:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.