Talk With an Expert

Internet Storm Center Tech Corner

SANS Internet Storm Center StormCast Tuesday, June 10, 2025

Octosql; Mirai vs. Wazuh; DNS4EU; Wordpress Fair Package Manager

https://isc.sans.edu/podcastdetail/9486

OctoSQL & Vulnerability Data

OctoSQL is a neat tool to query files in different formats using SQL. This can, for example, be used to query the JSON vulnerability files from CISA or NVD and create interesting joins between different files.

https://isc.sans.edu/diary/OctoSQL+Vulnerability+Data/32026

Mirai vs. Wazuh

The Mirai botnet has now been observed exploiting a vulnerability in the open-source EDR tool Wazuh.

https://www.akamai.com/blog/security-research/botnets-flaw-mirai-spreads-through-wazuh-vulnerability

DNS4EU

The European Union created its own public recursive resolver to offer a public resolver compliant with European privacy laws. This resolver is currently operated by ENISA, but the intent is to have a commercial entity operate and support it by a commercial entity.

https://www.joindns4.eu/

WordPress FAIR Package Manager

Recent legal issues around different WordPress-related entities have made it more difficult to maintain diverse sources of WordPress plugins. With WordPress plugins usually being responsible for many of the security issues, the Linux Foundation has come forward to support the ‘FAIR Package Manager,’ a tool intended to simplify the management of WordPress packages.

https://github.com/fairpm

SANS Internet Storm Center StormCast Monday, June 9, 2025

Extracting PNG Data; GlueStack Packages Backdoor; macOS targeted by Clickfix; INETPUB restore script

https://isc.sans.edu/podcastdetail/9484

Extracting With pngdump.py

Didier extended his pngdump.py script to make it easier to extract additional data appended to the end of the image file.

https://isc.sans.edu/diary/Extracting+With+pngdumppy/32022

16 React Native Packages for GlueStack Backdoored Overnight

16 npm packages with over a million weekly downloads between them were compromised. The compromised packages include a remote admin tool that was seen before in similar attacks.

https://www.aikido.dev/blog/supply-chain-attack-on-react-native-aria-ecosystem

Atomic macOS Stealer Exploits Clickfix

macOS users are now also targeted by fake captchas, tricking users into running exploit code.

https://www.cloudsek.com/blog/amos-variant-distributed-via-clickfix-in-spectrum-themed-dynamic-delivery-campaign-by-russian-speaking-hackers

Microsoft INETPUB Script

Microsoft published a simple PowerShell script to restore the inetpub folder in case you removed it by mistake.

https://www.powershellgallery.com/packages/Set-InetpubFolderAcl/1.0

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive