Talk With an Expert

Internet Storm Center Tech Corner

SANS Internet Storm Center StormCast Friday, August 29, 2025

Scans for ZIP Files; FreePBX 0-Day; Passwordstate Patch

https://isc.sans.edu/podcastdetail/9592

Increasing Searches for ZIP Files

Attackers are scanning our honeypots more and more for .zip files. They are looking for backups of credential files and the like left behind by careless administrators and developers.

https://isc.sans.edu/diary/Increasing+Searches+for+ZIP+Files/32242

FreePBX Vulnerability

An upatched vulnerability in FreePBX is currently being exploited. FreePBX offers mitigation advice and has also just released a “beta” patch.

https://community.freepbx.org/t/security-advisory-please-lock-down-your-administrator-access/107203

Passwordstate Vulnerability

Clickstudios patched an authentication bypass vulnerability in its password manager, Passwordstate. The vulnerability can be used to access the emergency password page.

https://www.clickstudios.com.au/passwordstate-changelog.aspx

SANS Internet Storm Center StormCast Thursday, August 28, 2025

Launching Shellcode; NX Compromise; Volt Typhoon Report

https://isc.sans.edu/podcastdetail/9590

Interesting Technique to Launch a Shellcode

Xavier came across malware that PowerShell and the CallWindowProcA() API to launch code.

https://isc.sans.edu/diary/Interesting+Technique+to+Launch+a+Shellcode/32238

NX Compromised to Steal Wallets and Credentials

The popular open source NX build package was compromised. Code was added that uses the help of AI tools like Claude and Gemini to steal credentials from affected systems

https://semgrep.dev/blog/2025/security-alert-nx-compromised-to-steal-wallets-and-credentials/

Countering Chinese State-Sponsored Actors’ Compromise of Networks Worldwide to Feed the Global Espionage System

Several law enforcement and cybersecurity agencies worldwide collaborated to release a detailed report on the recent Volt Typhoon incident.

https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a

SANS Internet Storm Center StormCast Wednesday, August 27, 2025

Analyzing IDNs; NetScaler 0-Day Vuln; Git Vuln Exploited

https://isc.sans.edu/podcastdetail/9588

Getting a Better Handle on International Domain Names and Punycode

International Domain names can be used for phishing and other attacks. One way to identify suspect names is to look for mixed script use.

https://isc.sans.edu/diary/Getting+a+Better+Handle+on+International+Domain+Names+and+Punycode/32234

Citrix NetScaler Vulnerabilities CVE-2025-7775, CVE-2025-7776 and CVE-2025-8424

Citrix patched three vulnerabilities in NetScaler. One is already being exploited

https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938&articleTitle=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2025_7775_CVE_2025_7776_and_CVE_2025_8424

git vulnerability exploited (CVE-2025-48384)

A git vulnerability patched in early July is now being exploited

https://github.com/git/git/security/advisories/GHSA-vwqx-4fm8-6qc9

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive