What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th)
2026-06-27T19:23:51Z•a4a07ec31d8801d7030fb0c099067069db99b1c71245c6597c70536d4346cbaa
CVE-2024-40766MITRESANS-ISCT1036Velvet Antipv4-mapped-ipv6ipv6linuxmalware-obfuscationphishingprocess-masqueradingrootkitssh-bruteforcevulnerability-managementwebshells
What happened
Collection of ISC SANS diary entries (June 2026) covering: Linux process name masquerading (malicious processes replacing their visible names to evade detection — mapped to MITRE ATT&CK T1036; example actor: Velvet Ant); continued prevalence of webshells with a newly observed GitHub-published variant; an eBanking phishing campaign that delivered via IPv4-mapped IPv6 addresses (novel addressing/evasion detail); analysis of coordinated SSH brute-force activity over three months; and a note about CVE-2024-40766 where the patch fixed the bug but a configuration issue remained. Also includes daily
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- a4a07ec31d8801d7030fb0c099067069db99b1c71245c6597c70536d4346cbaa
- Enrichment time
- 2026-06-27T19:23:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.