Differentiating Between a Targeted Intrusion and an Automated Opportunistic Scanning [Guest Diary], (Wed, Mar 4th)

2026-03-05T07:23:47Z7f4a72c78187adf6292b3ba3ad15a072c6d74bdead646e10ce9e7ef7efc04a97
CVE-2024-4040CVE-2025-31161CVE-2025-54309CrushFTPRTFWiresharkXWormZIPbruteforceintrusion-detectionmalwarephishingscan-vs-targetedthreat-huntingvulnerabilities

What happened

ISC Diary roundup (Mar 2–5, 2026): Highlights include a new wave of XWorm multi-technology malware observed in the wild, a guest diary on distinguishing targeted intrusions from opportunistic scanning, and reports of bruteforce scanning activity against CrushFTP (context: prior serious flaws including template-injection and auth-bypass). CrushFTP’s recent history includes CVE-2024-4040, CVE-2025-31161 and an actively exploited July 2025 zero-day (CVE-2025-54309). A Wireshark 4.6.4 release addresses three vulnerabilities and multiple bugs. Other entries cover phishing delivery (FedEx-themed) of

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
7f4a72c78187adf6292b3ba3ad15a072c6d74bdead646e10ce9e7ef7efc04a97
Enrichment time
2026-03-05T07:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.