Please turn JavaScript on

SANS Internet Storm Center, InfoCON: green

Following SANS Internet Storm Center, InfoCON: green's news feed is very easy. Subscribe using the "follow" button on the top right and if you want to, choose the updates by topic or tag.

We will deliver them to your inbox, your phone, or you can use follow.it like your own online RSS reader. You can unsubscribe whenever you want with one click.

Keep up to date with SANS Internet Storm Center, InfoCON: green!

SANS Internet Storm Center, InfoCON: green: SANS.edu Internet Storm Center - SANS Internet Storm Center

Is this your feed? Claim it!

Publisher:  Unclaimed!
Message frequency:  1.5 / day

Message History

I have not done this type of diary in a while: What traffic will you see from a system on boot, before a user logs in? I just took a quick look at macOS 27 "Golden Gate" to see what traffic you should expect. Here are some of the highlights:

I captured about 300 packets. This was likely inflated for this particular system as it connected via Wi-Fi and wired network in...


Read full story
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Read full story

Today, Apple released its annual update across all its operating systems. With that, Apple not only released new features but also patched 261 different vulnerabilities. This is the most vulnerabilities Apple has ever patched, but the increase is not as significant as other vendors' "post-AI" patch releases.

In addition to the major "27" version, Apple also released ...


Read full story
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Read full story

I identified an attacker using a semi-autonomous coding agent to run an offensive operation: finding poorly secured LLM resale gateways, acquiring API access through ordinary web flaws and account farming, validating the resulting inference capacity, and aggregating it behind a single gateway of their own.

What I captured was not simply credential theft, but an


Read full story