Category: SANS Internet Storm Center, InfoCON: green

Updates to Domainname API, (Wed, Nov 5th)

For several years, we have offered a “new domain” list of recently registered (or, more accurately, recently discovered) domains. This list is offered via our API (https://isc.sans.edu/api). However, the size of the list has been causing issues, resulting in a…

Apple Patches Everything, Again, (Tue, Nov 4th)

Apple released its expected set of operating system upgrades. This is a minor feature upgrade that also includes fixes for 110 different vulnerabilities. As usual for Apple, many of the vulnerabilities affect multiple operating systems. None of the vulnerabilities is…

Bytes over DNS, (Mon, Oct 27th)

I was intrigued when Johannes talked about malware that uses BASE64 over DNS to communicate. Take a DNS request like this: label1.label2.tld. Labels in a request like this can only be composed with letters (not case-sensitive), digits and a hyphen…

Kaitai Struct WebIDE, (Sun, Oct 26th)

When I have a binary file to analyze, I often use tools like 010 Editor or format-bytes.py (a tool I develop). Sometimes I also use Kaitai Struct. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read…

Infostealer Targeting Android Devices, (Thu, Oct 23rd)

Infostealers landscape exploded in 2024 and they remain a top threat today. If Windows remains a nice target (read: Attackers' favorite), I spotted an Infostealer targeting Android devices. This sounds logical that attackers pay attention to our beloved mobile devices…