YARA-X 1.18.0 and 1.19.0 Release, (Sun, Jun 28th)
2026-06-29T01:23:46Z•b1b8d0abf2b969b226a8a847189de97f981919cb868539c98a49c416b95e53b7
CVE-2024-40766IPv4-mapped-IPv6IPv6Linux process masqueradingMITRE ATT&CK T1036SANS ISCYARAYARA-XeBankingmalware obfuscationpatch-misconfigurationphishingpodcastprocess masqueradingreleaserootkitwebshellwebshells
What happened
SANS ISC diary entries (late June 2026) covering multiple security topics: YARA‑X releases (1.18.0 and 1.19.0) with improvements and bug fixes; a detailed writeup on Linux process name masquerading (malware obfuscation, MITRE ATT&CK T1036) and related rootkit concerns; continued prevalence of webshells including a recently observed/new GitHub-published variant; an eBanking phishing campaign using an IPv4‑mapped IPv6 address targeting a Belgian bank; and a note on CVE-2024-40766 where the vendor patch fixed the bug but configuration issues remained. Several ISC Stormcast podcast entries were/om
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- b1b8d0abf2b969b226a8a847189de97f981919cb868539c98a49c416b95e53b7
- Enrichment time
- 2026-06-29T01:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.