Talk With an Expert

Internet Storm Center Tech Corner

SANS Internet Storm Center StormCast Friday, August 8, 2025

ASN43350 Mass Scans; HTTP1.1 Must Die; Hybrid Exchange Vuln; SonicWall Update; SANS.edu Research: OSS Security and Shifting Left

https://isc.sans.edu/podcastdetail/9562

Mass Internet Scanning from ASN 43350

Our undergraduate intern Duncan Woosley wrote up aggressive scans from ASN 43350

https://isc.sans.edu/diary/Mass+Internet+Scanning+from+ASN+43350+Guest+Diary/32180

HTTP/1.1 Desync Attacks

Portswigger released details about new types of HTTP/1.1 desync attacks it uncovered. These attacks are particularly critical for organizations using middleboxes to translate from HTTP/2 to HTTP/1.1

https://portswigger.net/research/http1-must-die

Microsoft Warns of Exchange Server Vulnerability

An attacker with admin access to an Exchange Server in a hybrid configuration can use this vulnerability to gain full domain access. The issue is mitigated by an April hotfix, but was not noted in the release of the April Hotfix.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53786

Sonicwall Update

Sonicwall no longer believes that a new vulnerability was used in recent compromises

https://www.sonicwall.com/support/notices/gen-7-and-newer-sonicwall-firewalls-sslvpn-recent-threat-activity/250804095336430

SANS.edu Research: Wellington Rampazo, Shift Left the Awareness and Detection of Developers Using Vulnerable Open-Source Software Components

https://www.sans.edu/cyber-research/shift-left-awareness-detection-developers-using-vulnerable-open-source-software-components/

SANS Internet Storm Center StormCast Thursday, August 7, 2025

Sextortion Update; Akira Ransomware Group’s use of Drivers; Adobe and Trend Micro release emergency patches

https://isc.sans.edu/podcastdetail/9560

Do Sextortion Scams Still Work in 2025?

Jan looked at recent sextortion emails to check if any of the crypto addresses in these emails received deposits. Sadly, some did, so these scams still work.

https://isc.sans.edu/diary/Do+sextortion+scams+still+work+in+2025/32178

Akira Ransomware Group’s use of Drivers

Guidepoint Security observed the Akira ransomware group using specific legitimate drivers for privilege escalation

https://www.guidepointsecurity.com/blog/gritrep-akira-sonicwall/

Adobe Patches Critical Experience Manager Vulnerability

Adobe released emergency patches for a vulnerability in Adobe Experience Manager after a PoC exploit was made public.

https://slcyber.io/assetnote-security-research-center/struts-devmode-in-2025-critical-pre-auth-vulnerabilities-in-adobe-experience-manager-forms/

https://helpx.adobe.com/security/products/aem-forms/apsb25-82.html

Trend Micro Apex One Vulnerability

Trend Micro released an emergency patch for an actively exploited pre-authentication remote code execution vulnerability in the Apex One management console.

https://success.trendmicro.com/en-US/solution/KA-0020652

SANS Internet Storm Center StormCast Wednesday, August 6, 2025

Machinekeys and VIEWSTATEs; Perplexity Unethical Learning; SonicWall Updates

https://isc.sans.edu/podcastdetail/9558

Stealing Machinekeys for fun and profit (or riding the SharePoint wave)

Bojan explains in detail how .NET uses Machine Keys to protect the VIEWSTATE, and how to abuse the VIEWSTATE for code execution if the Machine Keys are lost.

https://isc.sans.edu/diary/Stealing+Machine+Keys+for+fun+and+profit+or+riding+the+SharePoint+wave/32174

Perplexity is using stealth, undeclared crawlers to evade website no-crawl directives

Perplexity will change its User Agent, or use different originating IP addresses, if it detects being blocked from scanning websites

https://blog.cloudflare.com/perplexity-is-using-stealth-undeclared-crawlers-to-evade-website-no-crawl-directives/

Gen 7 SonicWall Firewalls – SSLVPN Recent Threat Activity

Over the past 72 hours, there has been a notable increase in both internally and externally reported cyber incidents involving Gen 7 SonicWall firewalls where SSLVPN is enabled.

https://www.sonicwall.com/support/notices/gen-7-sonicwall-firewalls-sslvpn-recent-threat-activity/250804095336430

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive