What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th)
2026-06-26T01:23:47Z•fb564732b83f2d1698eb01b1e88a20f4344267a5b5db773d1aa14e5a225a85d5
CVE-2024-40766IPv4-mapped IPv6SANS ISCSSH brute forceT1036Velvet Ante‑banking phishingpatch vs configurationphishingpodcastprocess name masqueradingrootkitthreat intelligencewebshell repositorywebshells
What happened
SANS ISC diary RSS feed (mid‑June 2026) collecting short posts and podcasts addressing multiple operational threats and observations: automated cybercrime/port monitoring, Linux process‑name masquerading (technique mapped to MITRE ATT&CK T1036 and used by groups such as Velvet Ant), continued prevalence of webshells (including a recently published variant), an e‑banking phishing campaign abusing IPv4‑mapped IPv6 addresses, coordinated SSH brute‑force activity over the prior three months, and a note about CVE-2024-40766 where the patch fixed the bug but configuration issues remained. Several of
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- fb564732b83f2d1698eb01b1e88a20f4344267a5b5db773d1aa14e5a225a85d5
- Enrichment time
- 2026-06-26T01:23:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.