ISC Stormcast For Tuesday, March 10th, 2026 https://isc.sans.edu/podcastdetail/9842, (Tue, Mar 10th)

2026-03-10T13:23:51Za69fdce981a44b17ad0d58ddea56a5dbd708672f7182df6aab3921aeacd86e2d
ECHbruteforce-scanscrushftpencrypted-client-hellointrusion-detectionisc-sansmalwareopportunistic-scanningpodcastrsssecurity-advisorytlsxwormyara-x

What happened

An ISC (SANS) Diary RSS feed (Mar 3–10, 2026) listing multiple short posts and podcast items. Key technical entries include: discussion of Encrypted Client Hello (ECH) RFCs; YARA‑X 1.14.0 release; a guest diary on distinguishing targeted intrusions from opportunistic scanning; a new wave of XWorm multi‑technology malware; and reports of brute‑force scans against CrushFTP alongside a recap of prior CrushFTP vulnerabilities (notably CVE‑2024‑4040, CVE‑2025‑31161 and the July 2025 zero‑day CVE‑2025‑54309 that was actively exploited).

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
a69fdce981a44b17ad0d58ddea56a5dbd708672f7182df6aab3921aeacd86e2d
Enrichment time
2026-03-10T13:23:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.