ISC Stormcast For Tuesday, March 10th, 2026 https://isc.sans.edu/podcastdetail/9842, (Tue, Mar 10th)
2026-03-10T13:23:51Z•a69fdce981a44b17ad0d58ddea56a5dbd708672f7182df6aab3921aeacd86e2d
ECHbruteforce-scanscrushftpencrypted-client-hellointrusion-detectionisc-sansmalwareopportunistic-scanningpodcastrsssecurity-advisorytlsxwormyara-x
What happened
An ISC (SANS) Diary RSS feed (Mar 3–10, 2026) listing multiple short posts and podcast items. Key technical entries include: discussion of Encrypted Client Hello (ECH) RFCs; YARA‑X 1.14.0 release; a guest diary on distinguishing targeted intrusions from opportunistic scanning; a new wave of XWorm multi‑technology malware; and reports of brute‑force scans against CrushFTP alongside a recap of prior CrushFTP vulnerabilities (notably CVE‑2024‑4040, CVE‑2025‑31161 and the July 2025 zero‑day CVE‑2025‑54309 that was actively exploited).
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- a69fdce981a44b17ad0d58ddea56a5dbd708672f7182df6aab3921aeacd86e2d
- Enrichment time
- 2026-03-10T13:23:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.