Talk With an Expert

Internet Storm Center Tech Corner

SANS Internet Storm Center StormCast Tuesday, June 24, 2025

Ichano ATHome IP Camera Scans; NetScaler Vulnerability; WinRar Vulnerability

https://isc.sans.edu/podcastdetail/9502

Scans for Ichano AtHome IP Cameras

A couple days ago, a few sources started scanning for the username super_yg and the password 123. This is associated with Ichano IP Camera software.

https://isc.sans.edu/diary/Scans+for+Ichano+AtHome+IP+Cameras/32062

Critical NetScaler Security Update CVE-2025-5777

CVE 2025-5777 is a critical severity vulnerability impacting NetScaler Gateway, i.e. if NetScaler has been configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.

https://www.netscaler.com/blog/news/critical-security-updates-for-netscaler-netscaler-gateway-and-netscaler-console/

WinRar Vulnerability CVE-2025-6218

WinRar may be tricked into extracting files into attacker-determined locations, possibly leading to remote code execution

https://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=276&cHash=b5165454d983fc9717bc8748901a64f9

SANS Internet Storm Center StormCast Monday, June 23, 2025

ADS and Python; More Secure Cloud PCs; Zend.to Path Traversal; Parser Differentials

https://isc.sans.edu/podcastdetail/9500

ADS & Python Tools

Didier explains how to use his tools cut-bytes.py and filescanner to extract information from alternate data streams.

https://isc.sans.edu/diary/ADS+Python+Tools/32058

Enhanced security defaults for Windows 365 Cloud PCs

Microsoft announced more secure default configurations for its Windows 365 Cloud PC offerings.

https://techcommunity.microsoft.com/blog/windows-itpro-blog/enhanced-security-defaults-for-windows-365-cloud-pcs/4424914

CVE-2025-34508: Another File Sharing Application, Another Path Traversal

Horizon3 reveals details of a recently patched directory traversal vulnerability in zend.to.

https://horizon3.ai/attack-research/attack-blogs/cve-2025-34508-another-file-sharing-application-another-path-traversal/

Unexpected security footguns in Go's parsers

Go parsers for JSON and XML are not always compatible and can parse data in unexpected ways. This blog by Trails of Bits goes over the various security implications of this behaviour.

https://blog.trailofbits.com/2025/06/17/unexpected-security-footguns-in-gos-parsers/

SANS Internet Storm Center StormCast Friday, June 20, 2025

New Employee Phishing; Malicious Tech Support Links; Social Engineering App Specific Passwords

https://isc.sans.edu/podcastdetail/9498

How Long Until the Phishing Starts? About Two Weeks

After setting up a Google Workspace and adding a new user, it took only two weeks for the new employee to receive somewhat targeted phishing emails.

https://isc.sans.edu/diary/How+Long+Until+the+Phishing+Starts+About+Two+Weeks/32052

Scammers hijack websites of Bank of America, Netflix, Microsoft, and more to insert fake phone numbers

Scammers are placing Google ads that point to legitimate companiesÕ sites, but are injecting malicious text into the page advertising fake tech support numbers

https://www.malwarebytes.com/blog/news/2025/06/scammers-hijack-websites-of-bank-of-america-netflix-microsoft-and-more-to-insert-fake-phone-number

What’s in an ASP? Creative Phishing Attack on Prominent Academics and Critics of Russia

Targeted attacks are tricking victims into creating app-specific passwords to Google resources.

https://cloud.google.com/blog/topics/threat-intelligence/creative-phishing-academics-critics-of-russia

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive