<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="/css/rss.css" type="text/css"?>
<rss version="2.0" 
    xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
>
<channel>
<atom:link href="https://isc.sans.edu/rssfeed.xml" rel="self" type="application/rss+xml" />
<title>SANS Internet Storm Center, InfoCON: green</title>
<atom:link href="https://isc.sans.edu/rssfeed.xml" rel="self" type="application/rss+xml" /><link>https://isc.sans.edu</link><description><![CDATA[SANS Internet Storm Center - Cooperative Cyber Security Monitor]]></description><language>   en-us</language><lastBuildDate>   Mon, 07 Sep 2026 00:05:04 +0000</lastBuildDate><pubDate>Sun, 06 Sep 2026 21:43:17 GMT</pubDate><copyright>(C) SANS Institute 2026</copyright>
             <generator>isc rss feed maker</generator>
             <ttl>30</ttl>
             <webMaster>handlers@sans.org (ISC Handlers)</webMaster>
             <image>
               <title>SANS Internet Storm Center, InfoCON: green</title>
               <url>https://isc.sans.edu/images/status.gif</url>
               <link>https://isc.sans.edu</link>
             </image>
  <item>
    <title><![CDATA[Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)]]></title>
    <link>https://isc.sans.edu/diary/rss/33314</link>    <guid>https://isc.sans.edu/diary/rss/33314</guid><description><![CDATA[ Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected devices to maintain access after a patch is installed.&#xd;]]></description><content:encoded><![CDATA[Mikrotik&nbsp;released a patch late last week for an already-exploited vulnerability. The vulnerability allows&nbsp;an SSH authentication bypass&nbsp;and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected devices to maintain access after a patch is installed.]]></content:encoded>    <pubDate>Sun, 06 Sep 2026 21:43:17 GMT</pubDate>  </item>  <item>
    <title><![CDATA[numbat - AI agent observability, (Fri, Sep 4th)]]></title>
    <link>https://isc.sans.edu/diary/rss/33312</link>    <guid>https://isc.sans.edu/diary/rss/33312</guid><content:encoded><![CDATA[]]></content:encoded>    <pubDate>Sat, 05 Sep 2026 03:39:52 GMT</pubDate>  </item>  <item>
    <title><![CDATA[ISC Stormcast For Friday, September 4th, 2026 https://isc.sans.edu/podcastdetail/10082, (Fri, Sep 4th)]]></title>
    <link>https://isc.sans.edu/diary/rss/33310</link>    <guid>https://isc.sans.edu/diary/rss/33310</guid>    <pubDate>Fri, 04 Sep 2026 02:00:02 GMT</pubDate>  </item>  <item>
    <title><![CDATA[Honeypot-Omaha and batch.py &#x5b;Guest Diary&#x5d;, (Wed, Sep 2nd)]]></title>
    <link>https://isc.sans.edu/diary/rss/33306</link>    <guid>https://isc.sans.edu/diary/rss/33306</guid><description><![CDATA[ &#x5b;This is a Guest Diary by Frank Igbokwe, an ISC intern as part of the SANS.edu BACS program&#x5d;&#xd;]]></description><content:encoded><![CDATA[[This is a Guest Diary by Frank Igbokwe, an ISC intern as part of the SANS.edu BACS program]]]></content:encoded>    <pubDate>Thu, 03 Sep 2026 02:02:56 GMT</pubDate>  </item>  <item>
    <title><![CDATA[ISC Stormcast For Thursday, September 3rd, 2026 https://isc.sans.edu/podcastdetail/10080, (Thu, Sep 3rd)]]></title>
    <link>https://isc.sans.edu/diary/rss/33308</link>    <guid>https://isc.sans.edu/diary/rss/33308</guid>    <pubDate>Thu, 03 Sep 2026 02:00:03 GMT</pubDate>  </item>  <item>
    <title><![CDATA[ISC Stormcast For Wednesday, September 2nd, 2026 https://isc.sans.edu/podcastdetail/10078, (Wed, Sep 2nd)]]></title>
    <link>https://isc.sans.edu/diary/rss/33304</link>    <guid>https://isc.sans.edu/diary/rss/33304</guid>    <pubDate>Wed, 02 Sep 2026 02:00:02 GMT</pubDate>  </item>  <item>
    <title><![CDATA[Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)]]></title>
    <link>https://isc.sans.edu/diary/rss/33300</link>    <guid>https://isc.sans.edu/diary/rss/33300</guid><description><![CDATA[ Introduction&#xd;]]></description><content:encoded><![CDATA[Introduction]]></content:encoded>    <pubDate>Tue, 01 Sep 2026 21:30:18 GMT</pubDate>  </item>  <item>
    <title><![CDATA[ISC Stormcast For Tuesday, September 1st, 2026 https://isc.sans.edu/podcastdetail/10076, (Tue, Sep 1st)]]></title>
    <link>https://isc.sans.edu/diary/rss/33302</link>    <guid>https://isc.sans.edu/diary/rss/33302</guid>    <pubDate>Tue, 01 Sep 2026 02:00:03 GMT</pubDate>  </item>  <item>
    <title><![CDATA[The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary, (Mon, Aug 31st)]]></title>
    <link>https://isc.sans.edu/diary/rss/33298</link>    <guid>https://isc.sans.edu/diary/rss/33298</guid><description><![CDATA[ One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide "free" LLM backends. It then received a real coding-agent session &&#x23&#x3b;x26&#x3b;&#x23&#x3b;xe2&#x3b;&&#x23&#x3b;x26&#x3b;&#x23&#x3b;x80&#x3b;&&#x23&#x3b;x26&#x3b;&#x23&#x3b;x94&#x3b; history, filesystem output, working paths, and the agent&&#x23&#x3b;x26&#x3b;&#x23&#x3b;39&#x3b;s local tool manifest. The honeypot did not request or cause any tool execution&#x3b; what the request exposed is what a malicious operator in that position could do.&#xd;]]></description><content:encoded><![CDATA[One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide &quot;free&quot; LLM backends. It then received a real coding-agent session &mdash; history, filesystem output, working paths, and the agent&#39;s local tool manifest. The honeypot did not request or cause any tool execution; what the request exposed is what a malicious operator in that position could do.]]></content:encoded>    <pubDate>Mon, 31 Aug 2026 20:00:34 GMT</pubDate>  </item>  <item>
    <title><![CDATA[ISC Stormcast For Monday, August 31st, 2026 https://isc.sans.edu/podcastdetail/10074, (Mon, Aug 31st)]]></title>
    <link>https://isc.sans.edu/diary/rss/33296</link>    <guid>https://isc.sans.edu/diary/rss/33296</guid>    <pubDate>Mon, 31 Aug 2026 02:00:03 GMT</pubDate>  </item></channel>
</rss>
