ISC Stormcast For Thursday, June 18th, 2026 https://isc.sans.edu/podcastdetail/9978, (Thu, Jun 18th)

2026-06-18T13:23:44Z94273d8e4abeeaf29edda7b7f50fd8b578a3663612207b49ac7a4dc4d92e831e
botnetbrowser-securitybrute-forcecredential-attackmalicious-archivemalware-deliverymsiransomware-ras? (remcos is RAT)remcossecurity-telemetrysshsteganographythreat-intelvhdxweb-filtering

What happened

ISC SANS Diary highlights from mid-June 2026: a guest analysis of coordinated SSH brute-force attacks over the prior three months, a write-up on browser blind spots where security tools may fail to block threats, and a user report of a malicious ZIP containing a VHDX that auto-mounts on Windows and exposes a JavaScript leading to a Remcos RAT. Additional items include statistical analysis of malicious content hidden in MSI background images and routine ISC Stormcast podcast entries. The collection emphasizes ongoing brute-force activity, malware delivery via archive/virtual-disk artifacts, and

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
94273d8e4abeeaf29edda7b7f50fd8b578a3663612207b49ac7a4dc4d92e831e
Enrichment time
2026-06-18T13:23:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.