Who’s Tracking You? Use This New Service to Find Out

The Dark World of Adtech: A New Service Sheds Light on Who’s Tracking You A new, free online service called DecryptAds is changing the game for individuals and organizations seeking to uncover who’s behind the ads they see on their favorite websites and mobile apps. This powerful tool scrapes and correlates publicly available data from … Read more

ISC Stormcast For Friday, August 14th, 2026 https://isc.sans.edu/podcastdetail/10052, (Fri, Aug 14th)

A Devastating DNS Amplification Attack Hits Global Networks, Causing Widespread Disruptions A massive DNS amplification attack has rocked global networks, leaving a trail of destruction in its wake. The assault, which began on Thursday evening, has already affected numerous organizations and individuals worldwide, causing widespread disruptions to online services. The attack, attributed to a sophisticated … Read more

AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

Cybersecurity researchers have discovered a sophisticated macOS malware that not only steals sensitive data but also takes control of the victim’s browser sessions. The malware, dubbed AmnesiaStealer, has been spreading through a series of complex attacks, leaving many users unaware of their compromised systems. AmnesiaStealer is a multi-stage Rust-based information stealer that has been distributed … Read more

Hackers Exploiting Unpatched GeoServer Zero-Day

Hackers Quickly Exploit Unpatched GeoServer Zero-Day Vulnerability, Exposing Organizations to Remote Code Execution Attacks A critical zero-day vulnerability in the popular open source platform for geospatial data processing and sharing, GeoServer, has been publicly disclosed by a security researcher just hours ago. Unfortunately, threat actors have already started exploiting this flaw, putting organizations that rely … Read more

14,000 Trezor Customers Impacted by Data Breach at ShipMonk

A data breach at ShipMonk has compromised the personal information of nearly 14,000 customers who use hardware crypto wallets from Trezor. While Trezor’s own systems were not affected, hackers gained access to sensitive customer data through a vulnerability in ShipMonk’s Metabase tool. The incident is believed to have been carried out by the notorious extortion … Read more

Data analyst sent to prison for stealing data, extorting employer

A Data Analyst’s Descent into Extortion: Former Brightly Employee Sentenced to Prison for $2.5 Million Scheme In a shocking case of betrayal, a former data analyst has been sentenced to two years in prison for orchestrating a massive extortion scheme against his employer, Brightly Software. Cameron Curry, also known as “Loot,” targeted the company’s sensitive … Read more

Using Gemma4 with Ollama – Testing File Hash Analysis and Recommendations with AI, (Wed, Aug 12th)

Cybersecurity analysts are increasingly turning to artificial intelligence (AI) to aid in their work, and one recent experiment with a Large Language Model (LLM) has yielded some surprising insights. A cybersecurity professional used Gemma4, an LLM, to analyze file hashes uploaded to the DShield sensor over the past 30 days. The model was tasked with … Read more

ISC Stormcast For Thursday, August 13th, 2026 https://isc.sans.edu/podcastdetail/10050, (Thu, Aug 13th)

A Devastating DNS Water Torture Attack Hits Global Networks, Leaving Widespread Disruption in Its Wake In a shocking display of cyber cunning, a sophisticated attack on internet infrastructure has left millions of users struggling to access online services worldwide. The assault, which targets the Domain Name System (DNS) – the internet’s address book – has … Read more

ISC Stormcast For Friday, August 14th, 2026 https://isc.sans.edu/podcastdetail/10052, (Fri, Aug 14th)

A Critical Vulnerability in WebSockets Protocol Exposed by Recent Exploit Researchers have discovered a severe vulnerability in the WebSockets protocol, which is used for real-time communication between web servers and clients. The exploit, detected by the SANS Internet Storm Center (ISC), allows an attacker to execute arbitrary code on a server-side application, compromising system security. … Read more

AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

A New macOS Malware Threat: AmnesiaStealer Steals Data and Takes Control of Browser Sessions A sophisticated piece of malware has been discovered targeting macOS users, with alarming capabilities that allow attackers to steal sensitive data and even control browser sessions. Dubbed AmnesiaStealer, this multi-stage threat is being spread through fake GitHub download pages in recent … Read more