Interesting Message Stored in Cowrie Logs, (Wed, Mar 18th)

This activity was found and reported by BACS student Adam Thorman&#xc2&#x3b;&#xa0&#x3b;as part of one of his assignments which I posted his final paper &#x5b&#x3b;1&#x5d&#x3b; last week. This activity appeared to only have occurred on the 19 Feb 2026 where at least 2 sensors detected on the same day by DShield sensor in the cowrie logs an echo command that included: “MAGIC_PAYLOAD_KILLER_HERE_OR_LEAVE_EMPTY_iranbot_was_here“. My DShield sensor captured activity from source IP 64.89.161.198 between 30 Jan – 22 Feb 2026 that included portscans, a successful login via Telnet (TCP/23) and web access that included all the activity listed below captured by the DShield sensor (cowrie, webhoneypot & iptables logs).

Continue reading Interesting Message Stored in Cowrie Logs, (Wed, Mar 18th)

Posted in Uncategorized

Smashing Security podcast #459: This clever scam nearly hijacked a tech CEO’s Apple ID

In episode 459 of Smashing Security, we dive into a chillingly clever account takeover attempt targeting WordPress co-founder Matt Mullenweg – involving MFA fatigue, real Apple alerts, a convincing support call, and a phishing page that oh-so-nearly wo… Continue reading Smashing Security podcast #459: This clever scam nearly hijacked a tech CEO’s Apple ID

Cisco’s latest vulnerability spree has a more troubling pattern underneath

Cisco’s response to the latest SD-WAN and firewall defects has been fast, but the harder question is how long sophisticated actors had a head start — and what’s already compromised.

The post Cisco’s latest vulnerability spree has a more troubling pattern underneath appeared first on CyberScoop.

Continue reading Cisco’s latest vulnerability spree has a more troubling pattern underneath