YARA-X 1.14.0 Release, (Sat, Mar 7th)
2026-03-09T01:23:49Z•92d2aeb5539ad7f2298e2cd76675803b13112dafb59a595d551bc8c721112dd9
bruteforcecrushftpintrusion-detectionmalwarertfsecurity-podcastvulnerabilitywiresharkxwormyara-xzero-dayzip
What happened
SANS ISC diary roundup (early March 2026) covering multiple security items: YARA-X 1.14.0 released (minor improvements/bugfixes); Wireshark 4.6.4 released (fixes three vulnerabilities and 15 bugs); reports of brute‑force scanning against CrushFTP with references to prior serious vulnerabilities including CVE-2024-4040, CVE-2025-31161 and the actively exploited July 2025 zero-day CVE-2025-54309; a fresh wave of XWorm activity (multi-technology malware); and short how‑tos/podcasts on RTF/ZIP handling and differentiating targeted intrusions vs opportunistic scanning. Actionable takeaways: patch/h
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 92d2aeb5539ad7f2298e2cd76675803b13112dafb59a595d551bc8c721112dd9
- Enrichment time
- 2026-03-09T01:23:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.