-
ISC Stormcast For Friday, August 28th, 2026 https://isc.sans.edu/podcastdetail/10072, (Fri, Aug 28th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
-

A polymorphic phishing page (that occasionally breaks itself), (Thu, Aug 27th)
As I’ve mentioned before in some of my diaries, from time to time, I like to go over phishing messages that get caught in my various spam traps or sent to us here at the Internet Storm Center. After looking at enough phishing messages, one quickly gets used to seeing the same lures, the same…
-
ISC Stormcast For Thursday, August 27th, 2026 https://isc.sans.edu/podcastdetail/10070, (Thu, Aug 27th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
-

Who Has Admin Rights in your Entra ID Directory?, (Wed, Aug 26th)
A common thing that folks should “worry” about in Entra (or any platform really) is “who has rights to administer”? Who can delete or change key things, or modify them in ways that might not be obvious (accidentally or on purpose). Yes, we trust our people, but if they’ve moved on to other roles or…
-
ISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, (Wed, Aug 26th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
-
Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th)
It is pretty obvious that hostnames can replace IP addresses. Pretty much any software accepting an IP address will also accept a hostname as an argument. Last week, I wrote about scans for the cloud metadata service listening at 169.254.169.254. These scans attempted to exploit Server Side Request Forgery (SSRF) vulnerability. One way to prevent…
-
ISC Stormcast For Tuesday, August 25th, 2026 https://isc.sans.edu/podcastdetail/10066, (Tue, Aug 25th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
-

DOUBLECUP’s PNG Payload, (Mon, Aug 24th)
New malware that uses steganography always gets my attention, but I was disappointed when I looked at the latest DOUBLECUP write-up. It doesn’t use real steganography: You can see the PowerShell payload as cleartext: it has not been encoded into the pixels of the image. It’s even not embedded in the image (like inside the…
-
ISC Stormcast For Monday, August 24th, 2026 https://isc.sans.edu/podcastdetail/10064, (Mon, Aug 24th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
-
Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st)
In every MFA rollout, there will come a time where you think you are closing in on “done”, and some automation to list what’s left would be handy. Something quicker than scrolling through the web interface through thousands of accounts … This is that method. Also, remember when we discussed yesterday about the beta graph…

