ISC Stormcast For Thursday, July 2nd, 2026 https://isc.sans.edu/podcastdetail/9992, (Thu, Jul 2nd)

2026-07-03T19:24:06Zd64c6584d8f3cbff311d76bc6db0838b24ed1e79250da67f80203be6b028c2f6
MITRE ATT&CKT1036Velvet Antappleautomated-cybercrimeautomationcrypto-walletcryptocurrencyfavicon.icohost-reconiosmacosmalwaremetamaskpentestphishingprocess-masqueradingrootkitsafarisecurity-updatessocial-engineeringthreat-intelyarayara-x

What happened

Aggregation of ISC SANS diary entries (late June–early July 2026). Highlights include: a phishing campaign targeting MetaMask cryptocurrency wallet (credential/secret-code lures); Apple’s June 2026 security updates for iOS/iPadOS/macOS and Safari; YARA-X 1.18.0 and 1.19.0 releases (minor improvements and bug fixes); a technical writeup on Linux process name masquerading (malware evasion, mapped to MITRE ATT&CK T1036 and citing threat actors such as Velvet Ant); automation techniques for favicon.ico-based host reconnaissance useful in pentesting; and a guest diary assessing automated cybercrime

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
d64c6584d8f3cbff311d76bc6db0838b24ed1e79250da67f80203be6b028c2f6
Enrichment time
2026-07-03T19:24:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.