Please turn JavaScript on

SANS Internet Storm Center, InfoCON: green

Following SANS Internet Storm Center, InfoCON: green's news feed is very easy. Subscribe using the "follow" button on the top right and if you want to, choose the updates by topic or tag.

We will deliver them to your inbox, your phone, or you can use follow.it like your own online RSS reader. You can unsubscribe whenever you want with one click.

Keep up to date with SANS Internet Storm Center, InfoCON: green!

SANS Internet Storm Center, InfoCON: green: SANS.edu Internet Storm Center - SANS Internet Storm Center

Is this your feed? Claim it!

Publisher:  Unclaimed!
Message frequency:  1.47 / day

Message History

I identified an attacker using a semi-autonomous coding agent to run an offensive operation: finding poorly secured LLM resale gateways, acquiring API access through ordinary web flaws and account farming, validating the resulting inference capacity, and aggregating it behind a single gateway of their own.

What I captured was not simply credential theft, but an


Read full story
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Read full story

[This is a Guest Diary by Aaron Ng, an ISC intern as part of the SANS.edu BACS program]

Following a RedTail Linux Payload from DShield to Dynamic Analysis

During monitoring of my DShield honeypot, I observed an attacker uplo...


Read full story
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Read full story

About a week ago, Proxmox published an advisory revealing a vulnerability in older versions of Proxmox VE, its flagship Virtual Environment product. The vulnerability only affects version 7, which has not been supported for a couple of years now.

But it appears that the vulnerability may have caught the attention of some attackers and researchers. We do see a bump in ...


Read full story