Botnet Hunting for Vulnerabilities in Diagnostic Tools, (Tue, Aug 4th)
2026-08-05T01:23:40Z•c8c18ea3877248eaa49cb30faf155d51f0cb5e8c4d5e2da03b687ccbe3dc8ea7
AI-service-impersonationAMOS-stealerApple-security-updatesSANS-ISCSSH-botbotnetcryptocurrency-miningdiagnostic-toolsinfostealermacosphishingreconnaissancevulnerability-scanning
What happened
SANS Internet Storm Center entries report active vulnerability scanning of diagnostic-tool URLs, Atomic macOS (AMOS) stealer infections, phishing campaigns impersonating AI service providers, an SSH bot that profiles host hardware before deploying a cryptocurrency miner, and recent Apple security updates. The feed also includes Stormcast episodes and a zipdump.py metadata-encoding discussion.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- c8c18ea3877248eaa49cb30faf155d51f0cb5e8c4d5e2da03b687ccbe3dc8ea7
- Enrichment time
- 2026-08-05T01:23:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.