Differentiating Between a Targeted Intrusion and an Automated Opportunistic Scanning [Guest Diary], (Wed, Mar 4th)
2026-03-05T07:23:47Z•7f4a72c78187adf6292b3ba3ad15a072c6d74bdead646e10ce9e7ef7efc04a97
CVE-2024-4040CVE-2025-31161CVE-2025-54309CrushFTPRTFWiresharkXWormZIPbruteforceintrusion-detectionmalwarephishingscan-vs-targetedthreat-huntingvulnerabilities
What happened
ISC Diary roundup (Mar 2–5, 2026): Highlights include a new wave of XWorm multi-technology malware observed in the wild, a guest diary on distinguishing targeted intrusions from opportunistic scanning, and reports of bruteforce scanning activity against CrushFTP (context: prior serious flaws including template-injection and auth-bypass). CrushFTP’s recent history includes CVE-2024-4040, CVE-2025-31161 and an actively exploited July 2025 zero-day (CVE-2025-54309). A Wireshark 4.6.4 release addresses three vulnerabilities and multiple bugs. Other entries cover phishing delivery (FedEx-themed) of
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 7f4a72c78187adf6292b3ba3ad15a072c6d74bdead646e10ce9e7ef7efc04a97
- Enrichment time
- 2026-03-05T07:23:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.