Why It's So Hard to Stop Rising Malicious TDS Traffic
Cybersecurity vendors say threat actors' abuse of traffic distribution systems (TDS) is becoming more complex and sophisticated — and much harder to detect and block.
Some new Data Feeds, and a little "incident"., (Thu, Mar 20th)
Our API (https://isc.sans.edu/api) continues to be quite popular. One query we see a lot is lookups for individual IP addresses. Running many queries as you go through a log may cause you to get locked out by our rate limit. To help with that, we now...
Ukraine Defense Sector Under Attack Via Dark Crystal RAT
The UNC-200 threat group, active since last summer, has been utilizing the Signal messaging app to social engineer targets into downloading an infostealing remote access Trojan.
Today, connectivity is no longer a form of aid; instead, it’s often necessary to even receive aid. Beneficiary registration, digital cash, relief benefits, and social service applications all require secure connectivity— and Cisco helps deliver this...
ICS hijacking possible with critical mySCADA myPRO vulnerabilities
Abusing the security issues, which arise from inadequate user input sanitization, could enable threat actors to facilitate system command injections, arbitrary code execution, and eventual ICS hijacking.
Novel Arcane infostealer facilitates extensive data pilfering
Attackers eventually used YouTube and Discord to promote the bogus cracked software downloader ArcanaLoader to facilitate the distribution of Arcane malware.