ISC Stormcast For Thursday, March 5th, 2026 https://isc.sans.edu/podcastdetail/9836, (Thu, Mar 5th)

2026-03-05T19:23:55Z78f0899ceecec3885da133094f2c53a9acf97306b4df7339f402d1143d20b134
CVE-2024-4040CVE-2025-31161CVE-2025-54309CrushFTPISC StormcastRTFWiresharkXWormZIPbruteforceguest-diaryincident-responsemalwarephishingthreat-hunting

What happened

Collection of ISC SANS diary entries (early March 2026) covering a range of operational security topics: a new wave of XWorm multi-technology malware and evolving delivery techniques; brute-force scans targeting CrushFTP with references to prior serious vulnerabilities (CVE-2024-4040, CVE-2025-31161) and the actively exploited July 2025 zero-day (CVE-2025-54309); Wireshark 4.6.4 release addressing multiple vulnerabilities and bugs; phishing campaign delivering malware via fake FedEx notifications; a how-to on extracting ZIPs from RTFs; and guidance on differentiating targeted intrusions from ‘

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
78f0899ceecec3885da133094f2c53a9acf97306b4df7339f402d1143d20b134
Enrichment time
2026-03-05T19:23:55Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.