Talk With an Expert

Internet Storm Center Tech Corner

SANS Internet Storm Center StormCast Tuesday, August 5, 2025

Daily Trends Report; NVidia Triton RCE; Cursor AI Misconfiguration

https://isc.sans.edu/podcastdetail/9556

Daily Trends Report

A new trends report will bring you daily data highlights via e-mail.

https://isc.sans.edu/diary/New%20Feature%3A%20Daily%20Trends%20Report/32170

NVidia Triton RCE

Wiz found an interesting information leakage vulnerability in NVidia’s Triton servers that can be leveraged to remote code execution.

https://www.wiz.io/blog/nvidia-triton-cve-2025-23319-vuln-chain-to-ai-server

Cursor AI MCP Vulnerability

An attacker could abuse negligent Cursor MCP configurations to implement backdoors into developer machines.

https://www.aim.security/lp/aim-labs-curxecute-blogpost

SANS Internet Storm Center StormCast Monday, August 4, 2025

Legacy Protocols; SonicWall SSL VPN Possible 0-Day; PAM Based Linux Backdoor

https://isc.sans.edu/podcastdetail/9554

Scans for pop3user with guessable password

A particular IP assigned to a network that calls itself “Unmanaged” has been scanning telnet/ssh for a user called “pop3user” with passwords “pop3user” or “123456”. I assume they are looking for legacy systems that either currently run pop3 or ran pop3 in the past, and left the user enabled.

https://isc.sans.edu/diary/Legacy+May+Kill/32166

Possible SonicWall SSL VPN 0-Day

Arctic Wolf observed compromised SonicWall SSL VPN devices used by the Akira group to install ransomware. These devices were fully patched, and credentials were recently rotated.

https://arcticwolf.com/resources/blog/arctic-wolf-observes-july-2025-uptick-in-akira-ransomware-activity-targeting-sonicwall-ssl-vpn/

PAM Based Linux Backdoor

For over a year, attackers have used a PAM-based Linux backdoor that so far has gotten little attention from anti-malware vendors. PAM-based backdoors can be stealthy, and this one in particular includes various anti-forensics tricks.

https://www.nextron-systems.com/2025/08/01/plague-a-newly-discovered-pam-based-backdoor-for-linux/

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive