Skip to content

Project

SANS Internet Storm Center

Publisher of the Stormcast podcast and the ISC diaries summarized in the episode.

Known aliases

  • Internet Storm Center
  • SANS ISC

Current stories

securityOne report1 publisher

Phishing campaign plants Action1 remote-management agent through fake PDF invoices

Phishing emails carrying fake PDF invoices are installing Action1's remote-management agent, SANS ISC handler Xavier Mertens reported. It follows a ScreenConnect campaign he documented a few days earlier that used the same fake-invoice lure.

Publishers:isc.sans.edu

Reality

Evidence70
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence72
securityConfirmed6 publishers

Attackers hit Atlassian's CVE-2026-21589 two hours after watchTowr published the technique

Previdian recorded exploitation attempts against Atlassian's CVE-2026-21589 within two hours of watchTowr publishing the arbitrary file access technique. The CVSS 9.3 flaw lets an unauthenticated attacker read specific webroot files across eight Data Center products.

Perspective Coverage

6 publishers
Builder
Builder 27%
Operator
Operator 67%
Investor
Investor 6%

Reality

Evidence78
Adoption30
Hype gap+15
Incentives45
Confidence70
securityOne report1 publisher

Microsoft rates its only two exploited July bugs important and moderate

Microsoft's July update fixes 622 vulnerabilities, 62 of them rated critical. The two it says attackers are already using, in AD FS and SharePoint Server, sit below that line, so exploited status has to order the work.

Publishers:sans.org

Reality

Evidence68
Adoption45
Hype gap+12
Incentives35
Confidence66