Talk With an Expert

Internet Storm Center Tech Corner

SANS Internet Storm Center StormCast Friday, August 1, 2025

Scattered Spider Domains; Excel Blocking Dangerous Links; CISA Releasing Thorium Platform

https://isc.sans.edu/podcastdetail/9552

Scattered Spider Related Domain Names

A quick demo of our domain feeds and how they can be used to find Scattered Spider related domains

https://isc.sans.edu/diary/Scattered+Spider+Related+Domain+Names/32162

Excel External Workbook Links to Blocked File Types Will Be Disabled by Default

Excel will discontinue allowing links to dangerous file types starting as early as October.

https://support.microsoft.com/en-us/topic/external-workbook-links-to-blocked-file-types-will-be-disabled-by-default-6dd12903-0592-463d-9e68-0741cf62ee58

CISA Releases Thorium

CISA announced that it released its malware analysis platform, Thorium, as open-source software.

https://www.cisa.gov/news-events/alerts/2025/07/31/thorium-platform-public-availability

SANS Internet Storm Center StormCast Thursday, July 31, 2025

Firebase Security; WebKit Vuln Exploited; Scattered Spider Update

https://isc.sans.edu/podcastdetail/9550

Securing Firebase: Lessons Re-Learned from the Tea Breach

Inspired by the breach of the Tea app, Brendon Evans recorded a video to inform of Firebase security issues

https://isc.sans.edu/diary/Securing+Firebase+Lessons+ReLearned+from+the+Tea+Breach/32158

WebKit Vulnerability Exploited before Apple Patch

A WebKit vulnerability patched by Apple yesterday has already been exploited in Google Chrome. Google noted the exploit with its patch for the same vulnerability in Chrome.

https://nvd.nist.gov/vuln/detail/CVE-2025-6558

Scattered Spider Update

CISA released an update for its report on Scattered Spider, noting that the group also calls helpdesks impersonating users, not just the other way around.

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a

SANS Internet Storm Center StormCast Wednesday, July 30, 2025

Apple Updates; Python Triage; PaperCut Vuln Exploited

https://isc.sans.edu/podcastdetail/9548

Apple Updates Everything: July 2025 Edition

Apple released updates for all of its operating systems patching 89 different vulnerabilities. Many vulnerabilities apply to multiple operating systems.

https://isc.sans.edu/diary/Apple+Updates+Everything+July+2025/32154

Python Triage

A quick python script by Xavier to efficiently search through files, even compressed once, for indicators of compromise.

https://isc.sans.edu/diary/Triage+is+Key+Python+to+the+Rescue/32152/

PaperCut Attacks

CISA added a 2024 PaperCut vulnerability to the known exploited vulnerability list.

https://www.cisa.gov/news-events/alerts/2025/07/28/cisa-adds-three-known-exploited-vulnerabilities-catalog

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive