ISC Stormcast For Thursday, July 2nd, 2026 https://isc.sans.edu/podcastdetail/9992, (Thu, Jul 2nd)
2026-07-03T13:23:44Z•febbf0b1392f3e62e875f4812b256b5b69c9fc77ceb202808bd7277e001f6f0b
T1036YARA-Xapple-updatescredential-theftcryptocurrencyfavicon-reconlinuxmalware-obfuscationmetamaskpatchingphishingprocess-masqueradingrecontooling
What happened
SANS Internet Storm Center entries (late June–early July 2026) cover multiple operational security topics: a renewed phishing campaign targeting MetaMask (browser/mobile crypto wallet) that solicits credentials/secret codes — continuing prior campaigns and emphasizing the risk of seed/credential theft; Apple released June 2026 security updates for iOS/iPadOS, macOS and Safari (admins should patch promptly); a write-up on Linux process name masquerading (MITRE ATT&CK T1036) explaining how malicious processes can hide by mimicking benign names and referencing real-world actors (Velvet Ant); a YR
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- febbf0b1392f3e62e875f4812b256b5b69c9fc77ceb202808bd7277e001f6f0b
- Enrichment time
- 2026-07-03T13:23:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.