YARA-X 1.14.0 Release, (Sat, Mar 7th)

2026-03-09T01:23:49Z92d2aeb5539ad7f2298e2cd76675803b13112dafb59a595d551bc8c721112dd9
bruteforcecrushftpintrusion-detectionmalwarertfsecurity-podcastvulnerabilitywiresharkxwormyara-xzero-dayzip

What happened

SANS ISC diary roundup (early March 2026) covering multiple security items: YARA-X 1.14.0 released (minor improvements/bugfixes); Wireshark 4.6.4 released (fixes three vulnerabilities and 15 bugs); reports of brute‑force scanning against CrushFTP with references to prior serious vulnerabilities including CVE-2024-4040, CVE-2025-31161 and the actively exploited July 2025 zero-day CVE-2025-54309; a fresh wave of XWorm activity (multi-technology malware); and short how‑tos/podcasts on RTF/ZIP handling and differentiating targeted intrusions vs opportunistic scanning. Actionable takeaways: patch/h

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
92d2aeb5539ad7f2298e2cd76675803b13112dafb59a595d551bc8c721112dd9
Enrichment time
2026-03-09T01:23:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.