Category: SANS Internet Storm Center, InfoCON: green

Rondo Meets Geoserver, (Wed, Jul 22nd)

This isn't a new attack, but something I saw “pop-up” in our logs this week: This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: Rondo Meets Geoserver, (Wed, Jul 22nd)

Captive Portal Detection, (Tue, Jul 21st)

Not everything our honeypots detect is an attack. Sometimes it is just “odd traffic”, and this is one example: Our “First Seen” list currently includes “http://detectportal.firefox.co This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the…

WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)

Last week, Searchlight Cyber released details about a vulnerability they are calling “wp2shell”. The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-63030. Many WordPress plugin vulnerabilities are never assigned CVE numbers. But wp2shell is…

Recent DShield SIEM Update, (Tue, Jul 14th)

The last update to the DShield SIEM [4] was in Sep 2025 which contained some minor tweaks. This update currently is using ELK stack version 8.19.15, contains some additional dashboards and new logs. This article has been indexed from SANS…