Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected devices to maintain access after a patch is…
SANS ISCVulnerability
Brief overview
This item was published by SANS ISC. Read the source report for its complete evidence, indicators, scope, and caveats.
Defender next steps
•Confirm whether the affected product is present and internet-facing.
•Review vendor guidance, patch status, and signs of exploitation before closing the item.
Enterprises face an unmanaged crisis of AI agent and MCP server sprawl, characterized by rapid, decentralized proliferation of autonomous agents, protocol connections operating with excessive privilege, opaque execution paths, and identity blind spots. Absent agent-aware governance, modern…
SANS ISCVulnerability
Brief overview
This item was published by SANS ISC. Read the source report for its complete evidence, indicators, scope, and caveats.
Defender next steps
•Confirm whether the affected product is present and internet-facing.
•Review vendor guidance, patch status, and signs of exploitation before closing the item.
Welcome to this week’s edition of the Threat Source newsletter. Our goal is to get accurate threat intelligence to our audience as quickly as possible, with all the context you need to ask the right questions of your own environment: How at risk are we from this threat? Are we prepared for it? And…
Cisco TalosVulnerability
Brief overview
This item was published by Cisco Talos. Read the source report for its complete evidence, indicators, scope, and caveats.
Defender next steps
•Confirm whether the affected product is present and internet-facing.
•Review vendor guidance, patch status, and signs of exploitation before closing the item.
Honeypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)
[This is a Guest Diary by Frank Igbokwe, an ISC intern as part of the SANS.edu BACS program] Honeypot-Omaha is a DShied Sensor located at the Internet Storm Center (ISC) that is set up as a decoy for the original target and deployed over the internet. It is a flawed and very vulnerable system that…
SANS ISCVulnerability
Brief overview
This item was published by SANS ISC. Read the source report for its complete evidence, indicators, scope, and caveats.
Defender next steps
•Confirm whether the affected product is present and internet-facing.
•Review vendor guidance, patch status, and signs of exploitation before closing the item.
An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation
Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks.
Unit 42Research
Brief overview
This item was published by Unit 42. Read the source report for its complete evidence, indicators, scope, and caveats.
Defender next steps
•Compare the reported behavior with your environment and current detection coverage.
•Validate important findings in the original research before taking disruptive action.
“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend
Welcome to this week’s edition of the Threat Source newsletter. Hello, everyone. Long time reader, first time writer here at the Threat Source newsletter! I wanted to start out by introducing myself. My colleague and friend Mick Baccio set the bar pretty high last week , so I was planning to tell…
Cisco TalosVulnerability
Brief overview
This item was published by Cisco Talos. Read the source report for its complete evidence, indicators, scope, and caveats.
Defender next steps
•Confirm whether the affected product is present and internet-facing.
•Review vendor guidance, patch status, and signs of exploitation before closing the item.
JavaScript obfuscation: From party trick to phishing kit
We open a JavaScript artifact hoping for code, and instead get string arrays, strangely named functions, encoded URLs, runtime decoders, and eval statements. That is the point where “reading the script” stops being enough. Obfuscated JavaScript is still code, but it is code with the useful context…
Cisco TalosVulnerability
Brief overview
This item was published by Cisco Talos. Read the source report for its complete evidence, indicators, scope, and caveats.
Defender next steps
•Confirm whether the affected product is present and internet-facing.
•Review vendor guidance, patch status, and signs of exploitation before closing the item.