ISC Stormcast For Thursday, March 5th, 2026 https://isc.sans.edu/podcastdetail/9836, (Thu, Mar 5th)
2026-03-05T19:23:55Z•78f0899ceecec3885da133094f2c53a9acf97306b4df7339f402d1143d20b134
CVE-2024-4040CVE-2025-31161CVE-2025-54309CrushFTPISC StormcastRTFWiresharkXWormZIPbruteforceguest-diaryincident-responsemalwarephishingthreat-hunting
What happened
Collection of ISC SANS diary entries (early March 2026) covering a range of operational security topics: a new wave of XWorm multi-technology malware and evolving delivery techniques; brute-force scans targeting CrushFTP with references to prior serious vulnerabilities (CVE-2024-4040, CVE-2025-31161) and the actively exploited July 2025 zero-day (CVE-2025-54309); Wireshark 4.6.4 release addressing multiple vulnerabilities and bugs; phishing campaign delivering malware via fake FedEx notifications; a how-to on extracting ZIPs from RTFs; and guidance on differentiating targeted intrusions from ‘
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 78f0899ceecec3885da133094f2c53a9acf97306b4df7339f402d1143d20b134
- Enrichment time
- 2026-03-05T19:23:55Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.