<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><description>http://isc.sans.edu - Global Network Security Information Sharing Community - Daily blogs and cyber security news podcast.</description><link>https://bsky.app/profile/sansisc.bsky.social</link><title>@sansisc.bsky.social - SANS.edu Internet Storm Center</title><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3mk4w4f5rza24</link><description>SANS Stormcast Thursday, April 23rd, 2026: Stealing Telegram Sessions; Oracle CPU; Firefox Patches&#xA; https://isc.sans.edu/podcastdetail/9904</description><pubDate>23 Apr 2026 02:00 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3mk4w4f5rza24</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3mk2foluvxv2e</link><description>SANS Stormcast Wednesday, April 22nd, 2026: WAV Malware; GitHub OAUTH Phishing; Perforce Settings&#xA; https://isc.sans.edu/podcastdetail/9902</description><pubDate>22 Apr 2026 02:01 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3mk2foluvxv2e</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3mk277iyoy42c</link><description>Beyond Cryptojacking: Telegram tdata as a Credential Harvesting Vector – Lessons from a Honeypot I https://isc.sans.edu/diary/32888</description><pubDate>22 Apr 2026 00:05 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3mk277iyoy42c</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3mjygraf5522f</link><description>A .WAV With A Payload https://isc.sans.edu/diary/32910</description><pubDate>21 Apr 2026 07:15 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3mjygraf5522f</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3mjxv6tgl5723</link><description>SANS Stormcast Tuesday, April 21st, 2026: CVE and EPSS; Windows Server 2025 OOB;  QEMU Abuse;&#xA; https://isc.sans.edu/podcastdetail/9900</description><pubDate>21 Apr 2026 02:01 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3mjxv6tgl5723</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3mjvumnvd642q</link><description>Handling the CVE Flood With EPSS https://isc.sans.edu/diary/32914</description><pubDate>20 Apr 2026 06:45 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3mjvumnvd642q</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3mjvepwvqlu2h</link><description>SANS Stormcast Monday, April 20th, 2026: Lumma Stealer and Sectop RAT; Windows 0-Day Exploited; NIST NVD Update; FortiSandbox PoC&#xA; https://isc.sans.edu/podcastdetail/9898</description><pubDate>20 Apr 2026 02:01 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3mjvepwvqlu2h</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3mjntd5s2n32p</link><description>SANS Stormcast Friday, April 17th, 2026: DVRs Again; Cisco Again; Windows Defender Again; Sonatype&#xA; https://isc.sans.edu/podcastdetail/9896</description><pubDate>17 Apr 2026 02:01 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3mjntd5s2n32p</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3mjnobf2znp2p</link><description>ISC Diary: #LummaStealer infection with #SectopRAT (#ArechClient2) https://isc.sans.edu/diary/32904</description><pubDate>17 Apr 2026 00:30 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3mjnobf2znp2p</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3mjlcudutr22w</link><description>SANS Stormcast Thursday, April 16th, 2026: AI Credential Scans; Microsoft Update Issues; RDP Warnings; GitHub Action Vulns;&#xA; https://isc.sans.edu/podcastdetail/9894</description><pubDate>16 Apr 2026 02:01 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3mjlcudutr22w</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3mjl46i6wy32o</link><description>Compromised DVRs and Finding Them in the Wild https://isc.sans.edu/diary/32886</description><pubDate>16 Apr 2026 00:01 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3mjl46i6wy32o</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3mjisfizbuw2o</link><description>SANS Stormcast Wednesday, April 15th, 2026: Microsoft, Adobe, Fortinet and others Patches&#xA; https://isc.sans.edu/podcastdetail/9892</description><pubDate>15 Apr 2026 02:01 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3mjisfizbuw2o</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3mjimro5hov22</link><description>Scanning for AI Models https://isc.sans.edu/diary/32896</description><pubDate>15 Apr 2026 00:20 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3mjimro5hov22</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3mjhwzzawb725</link><description>Microsoft Patch Tuesday April 2026. https://isc.sans.edu/diary/32898</description><pubDate>14 Apr 2026 17:51 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3mjhwzzawb725</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3mjgbwbdafp26</link><description>SANS Stormcast Tuesday, April 14th, 2026: EncystPHP Webshell; CPUID Compromise; OpenAI Mac Cert Issue; Axios Vulnerability&#xA; https://isc.sans.edu/podcastdetail/9890</description><pubDate>14 Apr 2026 02:00 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3mjgbwbdafp26</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3mjewlzo2t62h</link><description>Scans for EncystPHP Webshell https://isc.sans.edu/diary/32892</description><pubDate>13 Apr 2026 13:05 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3mjewlzo2t62h</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3mjdrhctmm62o</link><description>SANS Stormcast Monday, April 13th, 2026: Obfuscated JavaScript; Numbers in Passwords; Adobe Patches 0-Day; ClickFix Fix Bypass&#xA; https://isc.sans.edu/podcastdetail/9888</description><pubDate>13 Apr 2026 02:00 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3mjdrhctmm62o</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3mj5war2och22</link><description>Application Control Bypass for Data Exfiltration https://isc.sans.edu/diary/32850</description><pubDate>10 Apr 2026 18:10 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3mj5war2och22</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3mj5wapljj52w</link><description>ISC Diary: ClickFix Attacks Still Using the Finger https://isc.sans.edu/diary/32566</description><pubDate>10 Apr 2026 18:10 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3mj5wapljj52w</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3mj5walp5242v</link><description>XWorm Cocktail:  A Mix of PE data with PowerShell Code https://isc.sans.edu/diary/31700</description><pubDate>10 Apr 2026 18:10 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3mj5walp5242v</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3mj5vxq4xyk2n</link><description>Obfuscated JavaScript or Nothing https://isc.sans.edu/diary/32884</description><pubDate>10 Apr 2026 18:05 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3mj5vxq4xyk2n</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3mj2byw6ii22k</link><description>SANS Stormcast Thursday, April 9th, 2026: Honeypot Fingerprinting; Microsoft Locks Developer Accounts; ActiveMQ Vuln;&#xA; https://isc.sans.edu/podcastdetail/9886</description><pubDate>09 Apr 2026 07:30 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3mj2byw6ii22k</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3mj2byuxv7u23</link><description>Number Usage in Passwords: Take Two https://isc.sans.edu/diary/32866</description><pubDate>09 Apr 2026 07:30 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3mj2byuxv7u23</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3miysc2foje2l</link><description>TeamPCP Supply Chain Campaign: Update 007 - Cisco Source Code Stolen via Trivy-Linked Breach, Google https://isc.sans.edu/diary/32880</description><pubDate>08 Apr 2026 17:16 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3miysc2foje2l</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3miyirwhclk2t</link><description>More Honeypot Fingerprinting Scans https://isc.sans.edu/diary/32878</description><pubDate>08 Apr 2026 14:26 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3miyirwhclk2t</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3mixrk5l2tr2l</link><description>SANS Stormcast Wednesday, April 8th, 2026: Pivoting for Webshells; WatchGuard Firebox Patch; Project Glasswing; Kubernetes Misconfigurations&#xA; https://isc.sans.edu/podcastdetail/9884</description><pubDate>08 Apr 2026 07:30 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3mixrk5l2tr2l</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3miwfz2fcpx2j</link><description>A Little Bit Pivoting: What Web Shells are Attackers Looking for? https://isc.sans.edu/diary/32874</description><pubDate>07 Apr 2026 18:31 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3miwfz2fcpx2j</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3mivb3633gk2r</link><description>SANS Stormcast Tuesday, April 7th, 2026: Redirects in Phishing; Internet Bug Bounty Suspended; Bluehammer; Keycloak MFA Bypass&#xA; https://isc.sans.edu/podcastdetail/9882</description><pubDate>07 Apr 2026 07:30 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3mivb3633gk2r</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3misv5erqpy2l</link><description>How often are redirects used in phishing in 2026? https://isc.sans.edu/diary/32870</description><pubDate>06 Apr 2026 08:51 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3misv5erqpy2l</guid></item><item><link>https://bsky.app/profile/sansisc.bsky.social/post/3misqdh5igc2t</link><description>SANS Stormcast Monday, April 6th, 2026: TeamPCP Update and Axio Post Mortem; Fortinet 0-Day&#xA; https://isc.sans.edu/podcastdetail/9880</description><pubDate>06 Apr 2026 07:25 +0000</pubDate><guid isPermaLink="false">at://did:plc:dfq4cbyws7syiwdxes73krjs/app.bsky.feed.post/3misqdh5igc2t</guid></item></channel></rss>