Wireshark 4.6.5 Released, (Sun, May 3rd)
2026-05-04T01:23:57Z•b949315ced77dbba0b10f75bbc10d0b42927646796a699bcf268c9032e4d0ce9
Bitwarden-CLICVE-2026-33634CanisterSprawlCheckmarx-KICSMacSyncPyPISANDCLOCKTeamPCPUNC6780X-Vercel-Set-Bypass-CookiehomebrewhoneypotmacOSmalicious-adnpm-wormpatchingreconsupply-chainvulnerabilitieswiresharkxinference
What happened
SANS ISC diary roundup: Wireshark 4.6.5 was released fixing 43 vulnerabilities (38 CVEs) and 35 bugs — apply the vendor updates. A TeamPCP supply-chain campaign update reports the end of a 26-day pause with three concurrent compromises (Checkmarx KICS, Bitwarden CLI cascade, xinference PyPI), identification of a CanisterSprawl npm worm, and continued credential-monetization activity tied to operators designated UNC6780 (stealer named SANDCLOCK). The update references stolen Cisco source code and calls out CVE-2026-33634 in the context of a lapsed KEV remediation deadline. Other diary items: a恶
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- b949315ced77dbba0b10f75bbc10d0b42927646796a699bcf268c9032e4d0ce9
- Enrichment time
- 2026-05-04T01:23:57Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.