ISC Stormcast For Monday, August 24th, 2026 https://isc.sans.edu/podcastdetail/10064, (Mon, Aug 24th)

A Massive Spam Campaign Targets Global Businesses with Malware-Laced Emails A recent surge in spam emails has been detected by cybersecurity experts at SANS ISC, potentially putting millions of businesses worldwide at risk. The campaign, which began on Monday, August 24th, is characterized by sophisticated phishing tactics and the use of malware to compromise corporate … Read more

ToxicPanda Android malware uses VPN permissions to block Google Play

The ToxicPanda Android Malware Evolution: A Growing Threat to Mobile Security A new version of the highly sophisticated Android malware, ToxicPanda, has emerged with alarming features that allow it to evade detection and wreak havoc on infected devices. The latest variant, dubbed ToxicPanda 2.0, has expanded its targeting scope to 349 applications and now includes … Read more

ToxicPanda Android malware uses VPN permissions to block Google Play

ToxicPanda Malware Evolves, Bypassing Security Measures on Android Devices A new version of the ToxicPanda malware has emerged, equipped with advanced features that allow it to evade security checks and install its payload undetected. The malware, which targets 349 applications across 16 countries, has been distributed through Amazon AWS-hosted buckets, according to mobile security company … Read more

Postal Service moves to finalize mail ballot regs before SCOTUS ruling

The US Postal Service has quietly finalized new regulations that grant the federal government sweeping powers over mail-in ballots for voters, sparking concerns about election integrity and voter suppression. The move comes despite multiple lower courts striking down similar rules as unconstitutional. At issue are changes to postal services’ handling of mail-in ballots, which would … Read more

Named Pipes Under Attack: Securing Windows Interprocess Communication

Windows Named Pipes Under Attack: A Growing Security Concern In recent months, cybersecurity experts have sounded the alarm over a growing threat to Windows systems: unsecured named pipes. These pipes, used for communication between applications on the same computer, are increasingly being exploited by attackers. With potentially devastating consequences, it’s essential for administrators and developers … Read more

Named Pipes Under Attack: Securing Windows Interprocess Communication

Windows Named Pipes Under Attack: A Wake-Up Call for Developers and Admins Named pipes are a common communication mechanism between applications on the same Windows computer. They’re fast, reliable, and supported directly by the operating system. However, recent attacks have highlighted a disturbing trend: named pipes are not as secure as they seem. When a … Read more

Hackers infect Android car head units with proxy botnet malware

A sophisticated supply-chain attack has compromised thousands of Android-based car head units, turning them into proxy botnets or using them for ad fraud. The malware, attributed to the notorious MoYu group, was spread through a legitimate device-update app and allows attackers to remotely control infected devices. The target of the attack is DoFun, a Chinese … Read more