ISC Stormcast For Thursday, July 23rd, 2026
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
The Government Accountability Office looked at 117 rules across 37 agencies and found 70% had reporting requirements that were overlapping. The post Most federal cybersecurity reporting rules are dupl
This isn&#;x26;#;39;t a new attack, but something I saw "pop-up" in our logs this week: 
The worm blends in with thousands of other commands occurring daily in any given environment, yet its intent and origins remain unknown. The post Malware is targeting AI tools in software development
While distillation attacks by foreign governments and companies have real national security implications, questions around who ultimately owns the data in AI systems are fraught. The post White House
Our collaboration with AXA XL brings Microsoft Incident Response services directly to cyber insurance policyholders, helping organizations coordinate technical, business, and insurance decisions. The
If you have a Chick-fil-A One account, now is a good time to change your password—and make sure it's one you don't use anywhere else.
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 22, 2026 – Watch our Videos at Cybercrime.TV CISOs and security leaders have spoken up on our hottest conten
A reported breach at microtask platform Paidwork exposed personal and financial data of more than 23 million users. Here's how to check if you're affected.
Harrowing story of an identity theft victim. Yes, the person made a mistake—they gave the scammer a two-factor authentication code that allowed the scammer to take over their email address. But
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
At the time, Hugging Face said it wasn’t clear which LLM was used in the attack. OpenAI confirmed it was one of their models being tested for “maximal” cyber capabilities. The post OpenAI says model t
The messy approach to U.S. AI regulation reflects both the rapid speed of model cyber capabilities and the White House’s “education” over the past two years, experts said. The post Where’s the Trump a
AWS WAF classifies web traffic by attaching metadata to each request it evaluates. Managed rule groups such as AWS WAF Bot Control and AWS WAF Fraud Control account takeover prevention (ATP) attach la
The House Intelligence Committee advanced its fiscal 2027 authorization legislation Monday. The post House intel bill includes provisions on state and local threat intelligence, election security, AI
Attackers started exploiting the critical wp2shell vulnerability chain within hours of patches being released, putting sites and their visitors at risk.
AI Delivers Value Only When It’s Built Into the Security Workflow – Christophe Briguet, Sr. Director of Product Management – AI & Security Analytics, Stellar Cyber San Jose, Calif. – Jul. 21
Not everything our honeypots detect is an attack. Sometimes it is just "odd traffic", and this is one example: Our "First Seen" list currently includes "http://detectportal.firefox.co 
 m/success.
We cover two recent cases of BitLocker extortion using RDP, MSSQL, RMM tools, web shells, and printers. The story includes TTPs and recommendations.
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 21, 2026 – Read the full story in StationX Nathan House, founder and CEO at StationX, one of the UK’s