Talk With an Expert

Internet Storm Center Tech Corner

SANS Internet Storm Center StormCast Friday, August 22, 2025

The -n switch; Commvault Exploit; Docker Desktop Escape Vuln

https://isc.sans.edu/podcastdetail/9582

Don't Forget The "-n" Command Line Switch

Disabling reverse DNS lookups for IP addresses is important not just for performance, but also for opsec. Xavier is explaining some of the risks.

https://isc.sans.edu/diary/Dont+Forget+The+n+Command+Line+Switch/32220

watchTowr releases details about recent Commvault flaws

Users of the Commvault enterprise backup solution must patch now after watchTowr released details about recent vulnerabilities

https://labs.watchtowr.com/guess-who-would-be-stupid-enough-to-rob-the-same-vault-twice-pre-auth-rce-chains-in-commvault/?123

Docker Desktop Vulnerability CVE-2025-9074

A vulnerability in Docker Desktop allows attackers to escape from containers to attack the host.

https://docs.docker.com/desktop/release-notes/#4443

SANS Internet Storm Center StormCast Thursday, August 21, 2025

Airtel Scans; Apple Patch; Microsoft Copilot Audit Log Issue; Password Manager Clickjacking

https://isc.sans.edu/podcastdetail/9580

Airtel Router Scans and Mislabeled Usernames

A quick summary of some odd usernames that show up in our honeypot logs

https://isc.sans.edu/diary/Airtell+Router+Scans+and+Mislabeled+usernames/32216

Apple Patches 0-Day CVE-2025-43300

Apple released an update for iOS, iPadOS and MacOS today patching a single, already exploited, vulnerability in ImageIO.

https://support.apple.com/en-us/124925

Microsoft Copilot Audit Logs

A user retrieving data via copilot obscures the fact that the user may have had access to data in a specific file

https://pistachioapp.com/blog/copilot-broke-your-audit-log

Password Managers Susceptible to Clickjacking

Many password managers are susceptible to clickjacking, and only few have fixed the problem so far

https://marektoth.com/blog/dom-based-extension-clickjacking/

SANS Internet Storm Center StormCast Wednesday, August 20, 2025

Increased Elasticsearch Scans; MSFT Patch Issues; SAP Vulnerabilities Exploited

https://isc.sans.edu/podcastdetail/9578

Increased Elasticsearch Recognizance Scans

Our honeypots noted an increase in reconnaissance scans for Elasticsearch. In particular, the endpoint /_cluster/settings is hit hard.

https://isc.sans.edu/diary/Increased+Elasticsearch+Recognizance+Scans/32212

Microsoft Patch Tuesday Issues

Microsoft noted some issues deploying the most recent patches with WSUS. There are also issues with certain SSDs if larger files are transferred.

https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-24h2#3635msgdesc

https://www.tomshardware.com/pc-components/ssds/latest-windows-11-security-patch-might-be-breaking-ssds-under-heavy-workloads-users-report-disappearing-drives-following-file-transfers-including-some-that-cannot-be-recovered-after-a-reboot

SAP Vulnerabilities Exploited CVE-2025-31324, CVE-2025-42999

Details explaining how to take advantage of two SAP vulnerabilities were made public

https://onapsis.com/blog/new-exploit-for-cve-2025-31324/

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive