ZeroHour
Organization

SANS

2 mentions in 7 days · 4 in 30 days · 4 total · first seen · last

Timeline

ISC Stormcast For Thursday, September 10th, 2026 https://isc.sans.edu/podcastdetail/10088, (Thu, Sep 10th)

SANS Internet Storm Center published its daily ISC Stormcast podcast episode for Thursday, September 10, 2026, with no substantive content in the feed.

The item is the RSS feed entry for the daily ISC Stormcast audio podcast from the SANS Internet Storm Center, dated September 10, 2026. The feed text contains only a copyright and licensing notice for SANS and the Creative Commons Attribution-Noncommercial license. No incidents, vulnerabilities, or other news details are included in the available text.

SANS Internet Storm Centerupdated · 20h agofirst · 5d agoOther 5 sources

ISC Stormcast For Wednesday, September 9th, 2026 https://isc.sans.edu/podcastdetail/10086, (Wed, Sep 9th)

SANS Internet Storm Center publishes its daily Stormcast cybersecurity news podcast for Wednesday, September 9th, 2026.

The ISC Stormcast is the SANS Internet Storm Center's daily short-form cybersecurity news podcast. This item is the episode for Wednesday, September 9th, 2026, linking to the podcast detail page. No article content was included beyond the podcast link and Creative Commons license notice, so no specific incidents or topics are described.

SANS Internet Storm Centerupdated · 20h agofirst · 6d agoAdvisory 5 sources

AD Rights Management Service (Part 1): Architecture, Deprecation, and Reconnaissance

Huntress maps AD RMS architecture and recon paths, setting up an offline key-extraction attack against its unrotatable 255-year root key.

Huntress's multi-part research examines Active Directory Rights Management Services, Microsoft's enterprise DRM role that still ships in Windows Server 2025 despite migration guidance favoring Azure Information Protection. Part 1 covers the trust model and how an ordinary domain account can locate RMS clusters and read rights-policy templates. Part 2 will detail four independent paths for extracting the Server Licensor Certificate (SLC) private key via service-group membership and the configuration database, enabling fully offline decryption of protected documents. The SLC certificate is valid from 2002 to 2258 and has no key-rotation mechanism, so a stolen key decrypts protected content indefinitely.

Huntress · 7d agoResearch1

Honeypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)

A SANS ISC guest diary describes batch.py, a Python tool that consolidates honeypot logs and enriches IOCs with threat intelligence data.

Written by a SANS.edu BACS intern, the diary explains analysis of the DShield Honeypot-Omaha sensor, which uses Cowrie to emulate SSH and Telnet and log attacker activity. The author's batch.py script implements a four-phase pipeline with SHA-256-generated master and guest authentication to consolidate JSON and log files, correlate data via external APIs, and produce MITRE, CVE, geolocation, threat-score and fingerprint enrichment for investigated indicators.

SANS Internet Storm Center · 12d agoTools1