1. Scans for Atlassian vulnerablity (CVE-2026-21589), (Wed, Oct 7th)

    SANS Internet Storm Center On October 5th, Atlassian published patches for multiple products to fix an "Arbitrary File Access" vulnerability [CVE-2026-21589]. An attacker can read arbitrary files in the web application's directory, potentially exposing sensitive information such as configuration files.

  2. Image: SANS Internet Storm Center

    More RMM Tools In the Wild, (Tue, Oct 6th)

    SANS Internet Storm Center It seems that a trend started… I continue my journey discovering more RMM ("Remote Management & Monitoring") tools abused by threat actors! A few days ago, I wrote a diary[1] about ScreenConnect used in the wild. Today, I found another one.

  3. Image: SANS Internet Storm Center

    TTY Logs and the Data it Captures, (Sun, Oct 4th)

    SANS Internet Storm Center For an experiment, I created a script [1] that parses and send the TTY logs collected from actors or bots activity that run various commands after they successfully login the DShield sensor. Those TTY logs are sent daily at the end of each day to the DShield SIEM [2] to be…