IntelPC

SANS ISC: Handler's Diary (Full text)

SANS Internet Storm Center, InfoCON: green

SANS Internet Storm Center - Cooperative Cyber Security Monitor SANS Internet Storm Center, InfoCON: green
  • AutoIT Payload Injector , (Tue, Jul 28th)

    For a long time, AutoIT[1] has been pretty common in the malware ecosystem. Threat actors still use it because it's easy to write and powerful. Indeed, it can perform all the required actions to inject a payload into a remote process as you'll see below.

  • ISC Stormcast For Tuesday, July 28th, 2026 https://isc.sans.edu/podcastdetail/10026, (Tue, Jul 28th)
    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
  • Java Spring Boot "heapdump" scans, (Mon, Jul 27th)

    Spring Boot exposes the endpoint "/actuator/heapdump" to collect debug information. By default, the endpoint will return a file heapdump.hprof, which includes a binary heapdump that can be used to analyze the current state of the application. Non-Java readers may be familiar with a similar concept, core dumps, which are produced by binaries to expose a memory image at the time the software crashes. "heapdumps" are the Java analog to "core-dumps". The heapdump often includes secrets used by the application to connect to backend systems. API keys, database passwords, and other sensitive data may be exposed in the heapdump.

  1. You are here:  
  2. Home

Home

Main Menu

  • Home