ISC Stormcast For Tuesday, September 8th, 2026 https://isc.sans.edu/podcastdetail/10084, (Tue, Sep 8th)
2026-09-08T19:23:40Z•b752931766e739056120438e75d78899da3da6aa7f752150f90d2955ddafa677
AI securityAstarothGuildmaMikroTikSANS ISCSSH authentication bypassaccount creationactively exploited vulnerabilitycoding-agent securityhoneypotmalwarenetwork devicespersistencephishing
What happened
SANS Internet Storm Center feed containing a critical, actively exploited MikroTik vulnerability that enables SSH authentication bypass. Attackers are adding accounts to compromised devices for persistence, so affected systems should be treated as compromised and patched immediately. The feed also discusses Guildma/Astaroth malware, honeypot observations, and risks from exposed AI coding-agent infrastructure.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- b752931766e739056120438e75d78899da3da6aa7f752150f90d2955ddafa677
- Enrichment time
- 2026-09-08T19:23:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.