Talk With an Expert

Internet Storm Center Tech Corner

SANS Internet Storm Center StormCast Friday, September 12, 2025

DShield SIEM Update; Another SonicWall Warning; Website Keystroke Logging

https://isc.sans.edu/podcastdetail/9610

DShield SIEM Docker Updates

Guy updated the “DShield SIEM” which graphically summarizes what is happening inside your honeypot.

https://isc.sans.edu/diary/DShield+SIEM+Docker+Updates/32276

Again: SonicWall SSL VPN Compromises

The Australian Government’s Signals Directorate noted an increase in compromised SonicWall devices.

https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/ongoing-active-exploitation-of-sonicwall-ssl-vpns-in-australia

Website Keystroke Logging

Many websites log every keystroke, not just data submitted in forms.

https://arxiv.org/pdf/2508.19825

SANS Internet Storm Center StormCast Thursday, September 11, 2025

BASE64 in DNS; Google Chrome, Ivanti and Sophos Patches; Apple Memory Integrity Feature

https://isc.sans.edu/podcastdetail/9608

BASE64 Over DNS

The base64 character set exceeds what is allowable in DNS. However, some implementations will work even with these “invalid” characters.

https://isc.sans.edu/diary/BASE64+Over+DNS/32274

Google Chrome Update

Google released an update for Google Chrome, addressing two vulnerabilities. One of the vulnerabilities is rated critical and may allow code execution.

https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_9.html

Ivanti Updates

Ivanti patched a number of vulnerabilities, several of them critical, across its product portfolio.

https://forums.ivanti.com/s/article/September-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-and-Neurons-for-Secure-Access-Multiple-CVEs

Sophos Patches

Sophos resolved authentication bypass vulnerability in Sophos AP6 series wireless access point firmware (CVE-2025-10159)

https://www.sophos.com/en-us/security-advisories/sophos-sa-20250909-ap6

Apple Introduces Memory Integrity Enforcement

With the new hardware promoted in yesterday’s event, Apple also introduced new memory integrity features based on this new hardware.

https://security.apple.com/blog/memory-integrity-enforcement/

SANS Internet Storm Center StormCast Wednesday, September 10, 2025

Microsoft Patch Tuesday; Adobe Patches; SAP Patches

https://isc.sans.edu/podcastdetail/9606

Microsoft Patch Tuesday

As part of its September patch Tuesday, Microsoft addressed 177 different vulnerabilities, 86 of which affect Microsoft products. None of the vulnerabilities has been exploited before today. Two of the vulnerabilities were already made public. Microsoft rates 13 of the vulnerabilities are critical.

https://isc.sans.edu/diary/Microsoft+Patch+Tuesday+September+2025/32270

Adobe Patches

Adobe released patches for nine products, including Adobe Commerce, Coldfusion, and Acrobat.

https://helpx.adobe.com/security/security-bulletin.html

SAP Patches

SAP patched vulnerabilities across its product portfolio. Particularly interesting are a few critical vulnerabilities in Netweaver, one of which scored a perfect 10.0 CVSS score.

https://onapsis.com/blog/sap-security-notes-september-2025-patch-day/

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive