What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th)
2026-06-25T01:23:46Z•a7dff5dac91d741040f6842626a3bbc2fa17957b2b9409dfe4aabcdbc5703fa4
SANS-ISCT1036Velvet Antipv4-mapped-ipv6linuxmisconfigurationphishingprocess-masqueradingrootkitssh-bruteforcethreat-intelvulnerability-managementwebshell
What happened
SANS ISC diary roundup (Jun 17–25, 2026) covering multiple operational and threat topics: Linux process name masquerading (process spoofing / MITRE ATT&CK T1036) and rootkit implications (mentions Velvet Ant), a discussion about CVE-2024-40766 where the patch fixed the bug but misconfiguration remained, continued prevalence of webshells (new GitHub-published webshell observed), an e-banking phishing campaign using IPv4-mapped IPv6 addresses targeting a Belgian bank, and analysis of coordinated SSH brute-force activity. Several ISC Stormcast podcast entries and guest diaries are included.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- a7dff5dac91d741040f6842626a3bbc2fa17957b2b9409dfe4aabcdbc5703fa4
- Enrichment time
- 2026-06-25T01:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.