Quick Howto: ZIP Files Inside RTF, (Mon, Mar 2nd)

2026-03-04T21:36:50Z60b2121a00863ec533c811353118257a4685407eb689a6b72eaf340ddaf10e9a
AI-assisted-threat-huntingCLAIR-modelRTFcritical-infrastructurehoneypotmalwareopen-redirectphishingsecurity-blogvulnerability-advisorywiresharkzip-in-rtf

What happened

Collection of SANS ISC diary items (late Feb–early Mar 2026). Highlights include: Wireshark 4.6.4 release (fixes three vulnerabilities and 15 bugs), a how-to note on ZIP files embedded in RTFs and extracting URLs from RTFs, a phishing campaign delivering malware via a fake FedEx email, a guest diary on running a honeypot with AI assistance, a conceptual CLAIR model for mapping critical infrastructure interdependencies, and a discussion on the continued relevance and risks of open redirects. Several items are informational/podcast notices (ISC Stormcast).

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
60b2121a00863ec533c811353118257a4685407eb689a6b72eaf340ddaf10e9a
Enrichment time
2026-03-04T21:36:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Quick Howto: ZIP Files Inside RTF, (Mon, Mar 2nd) · Baitaphish