Talk With an Expert

Internet Storm Center Tech Corner

SANS Internet Storm Center StormCast Tuesday, August 26, 2025

Decoding Word Reading Location; Image Downscaling AI Vulnerability; IBM Jazz Team Server Vuln

https://isc.sans.edu/podcastdetail/9586

Reading Location Position Value in Microsoft Word Documents

Jessy investigated how Word documents store the last visited document location in the registry.

https://isc.sans.edu/diary/Reading+Location+Position+Value+in+Microsoft+Word+Documents/32224

Weaponizing image scaling against production AI systems

AI systems often downscale images before processing them. An attacker can create a harmless looking image that would reveal text after downscaling leading to prompt injection

https://blog.trailofbits.com/2025/08/21/weaponizing-image-scaling-against-production-ai-systems/

IBM Jazz Team Server Vulnerability CVE-2025-36157

IBM patched a critical vulnerability in its Jazz Team Server

https://www.ibm.com/support/pages/node/7242925

SANS Internet Storm Center StormCast Monday, August 25, 2025

IP Cleanup; Linux Desktop Attacks; Malicious Go SSH Brute Forcer; Onmicrosoft Domain Restrictions

https://isc.sans.edu/podcastdetail/9584

The end of an era: Properly formatted IP addresses in all of our data.

When initially designing DShield, addresses were “zero padded”, an unfortunate choice. As of this week, datafeeds should no longer be “zero padded”.

https://isc.sans.edu/diary/The+end+of+an+era+Properly+formated+IP+addresses+in+all+of+our+data/32228

.desktop files used in an attack against Linux Desktops

Pakistani attackers are using .desktop files to target Indian Linux desktops.

https://www.cyfirma.com/research/apt36-targets-indian-boss-linux-systems-with-weaponized-autostart-files/

Malicious Go Module Disguised as SSH Brute Forcer Exfiltrates Credentials via Telegram

A go module advertising its ability to quickly brute force passwords against random IP addresses, has been used to exfiltrate credentials from the person running the module.

https://socket.dev/blog/malicious-go-module-disguised-as-ssh-brute-forcer-exfiltrates-credentials

Limiting Onmicrosoft Domain Usage for Sending Emails

Microsoft is limiting how many emails can be sent by Microsoft 365 users using the “onmicrosoft.com” domain.

https://techcommunity.microsoft.com/blog/exchange/limiting-onmicrosoft-domain-usage-for-sending-emails/4446167

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive