<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #SANS ISC</title><description>Cybersecurity articles tagged #SANS ISC on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>DShield SIEM Update: ELK Stack 8.19.15 and Enhanced Logging</title><link>https://runtimerebel.com/blog/dshield-siem-update-elk-stack-8-19-15-and-enhanced-logging</link><guid isPermaLink="true">https://runtimerebel.com/blog/dshield-siem-update-elk-stack-8-19-15-and-enhanced-logging</guid><description>SANS ISC updates the DShield SIEM to ELK stack 8.19.15, introducing enhanced logging capabilities and new dashboards for improved honeypot data analysis.</description><pubDate>Wed, 15 Jul 2026 10:11:13 GMT</pubDate><category>DShield</category><category>SIEM</category><category>ELK Stack</category><category>SANS ISC</category><category>Honeypot</category><category>Log Analysis</category></item><item><title>MSI Malware Detection: Statistical Analysis for Base64 Payloads</title><link>https://runtimerebel.com/blog/msi-malware-detection-statistical-analysis-for-base64-payloads</link><guid isPermaLink="true">https://runtimerebel.com/blog/msi-malware-detection-statistical-analysis-for-base64-payloads</guid><description>Learn how to use statistical analysis to identify obfuscated Base64 payloads within malicious MSI files and improve your incident response capabilities.</description><pubDate>Mon, 15 Jun 2026 10:19:14 GMT</pubDate><category>MSI Malware</category><category>Base64 Obfuscation</category><category>Threat Detection</category><category>Malware Analysis</category><category>SANS ISC</category></item><item><title>Detecting API Discovery Scans for swagger.json: Security Guide</title><link>https://runtimerebel.com/blog/detecting-api-discovery-scans-for-swagger-json-security-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/detecting-api-discovery-scans-for-swagger-json-security-guide</guid><description>Analysis of automated scans for swagger.json and OpenAPI files. Learn how to secure RESTful APIs against discovery-based attacks and reconnaissance.</description><pubDate>Wed, 03 Jun 2026 13:51:10 GMT</pubDate><category>API Security</category><category>Reconnaissance</category><category>Swagger</category><category>OpenAPI</category><category>SANS ISC</category></item><item><title>YARA-X 1.17.0 Release: Enhanced Performance for Malware Analysis</title><link>https://runtimerebel.com/blog/yara-x-1-17-0-release-enhanced-performance-for-malware-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/yara-x-1-17-0-release-enhanced-performance-for-malware-analysis</guid><description>YARA-X version 1.17.0 release introduces five performance improvements and a bugfix for the Rust-based malware detection engine. Enhance your scanning speed.</description><pubDate>Sun, 31 May 2026 16:31:57 GMT</pubDate><category>YARA X</category><category>Malware Detection</category><category>Rust</category><category>Threat Hunting</category><category>SANS ISC</category></item><item><title>DShield Honeypot Updates: Ensuring Timely Threat Data Collection</title><link>https://runtimerebel.com/blog/dshield-honeypot-updates-ensuring-timely-threat-data-collection</link><guid isPermaLink="true">https://runtimerebel.com/blog/dshield-honeypot-updates-ensuring-timely-threat-data-collection</guid><description>SANS ISC announces upcoming updates for DShield honeypots. Learn why these automatic updates are crucial for maintaining effective threat intelligence collection.</description><pubDate>Mon, 04 May 2026 16:47:53 GMT</pubDate><category>DShield</category><category>Honeypot</category><category>SANS ISC</category><category>Threat Intelligence</category><category>Security Updates</category></item><item><title>IPv6 Security: Mitigating Rogue Router Advertisements and NDP Risks</title><link>https://runtimerebel.com/blog/ipv6-security-mitigating-rogue-router-advertisements-and-ndp-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/ipv6-security-mitigating-rogue-router-advertisements-and-ndp-risks</guid><description>Analysis of IPv6 Neighbor Discovery Protocol vulnerabilities and why security teams must prioritize RA Guard and monitoring to prevent traffic interception.</description><pubDate>Tue, 14 Apr 2026 08:41:10 GMT</pubDate><category>IPv6</category><category>Ndp</category><category>Network Security</category><category>SANS ISC</category><category>Router Advertisement</category></item><item><title>Honeypot Data Analysis: Predictable Year and Season Password Patterns</title><link>https://runtimerebel.com/blog/honeypot-data-analysis-predictable-year-and-season-password-patterns</link><guid isPermaLink="true">https://runtimerebel.com/blog/honeypot-data-analysis-predictable-year-and-season-password-patterns</guid><description>SANS ISC research reveals how attackers exploit predictable password patterns, such as years and seasons, driven by outdated rotation policies.</description><pubDate>Thu, 09 Apr 2026 08:43:49 GMT</pubDate><category>Password Security</category><category>Honeypot Analysis</category><category>Credential Stuffing</category><category>SANS ISC</category><category>Authentication</category></item><item><title>AI-Assisted Code Review: Uncovering Common Python Flaws</title><link>https://runtimerebel.com/blog/ai-assisted-code-review-uncovering-common-python-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-assisted-code-review-uncovering-common-python-flaws</guid><description>A SANS ISC diary highlights how AI identifies long-standing, common security and logic errors in Python scripts, emphasizing the need for robust code review.</description><pubDate>Tue, 24 Mar 2026 00:33:52 GMT</pubDate><category>AI Code Review</category><category>Python Security</category><category>Secure Development</category><category>Code Quality</category><category>SANS ISC</category></item><item><title>Phishing Credential Exfiltration via EmailJS and React Frameworks</title><link>https://runtimerebel.com/blog/phishing-credential-exfiltration-via-emailjs-and-react-frameworks</link><guid isPermaLink="true">https://runtimerebel.com/blog/phishing-credential-exfiltration-via-emailjs-and-react-frameworks</guid><description>Security analysis of a sophisticated React-based phishing kit that leverages the EmailJS service for stealthy exfiltration of user credentials.</description><pubDate>Fri, 13 Mar 2026 08:18:34 GMT</pubDate><category>Phishing</category><category>EmailJS</category><category>React</category><category>Credential Theft</category><category>SANS ISC</category></item><item><title>Phishing Campaign Leverages Donut Loader via Spoofed FedEx Alerts</title><link>https://runtimerebel.com/blog/phishing-campaign-leverages-donut-loader-via-spoofed-fedex-alerts</link><guid isPermaLink="true">https://runtimerebel.com/blog/phishing-campaign-leverages-donut-loader-via-spoofed-fedex-alerts</guid><description>Analysis of a phishing campaign using fake FedEx delivery notifications to deliver the Donut loader framework for in-memory shellcode execution.</description><pubDate>Fri, 27 Feb 2026 16:17:45 GMT</pubDate><category>DonutLoader</category><category>FedEx Phishing</category><category>Shellcode Injection</category><category>SANS ISC</category><category>In Memory Malware</category></item><item><title>Hypervisor-Based Persistence: Abusing Virtual Machines for Stealth</title><link>https://runtimerebel.com/blog/hypervisor-based-persistence-abusing-virtual-machines-for-stealth</link><guid isPermaLink="true">https://runtimerebel.com/blog/hypervisor-based-persistence-abusing-virtual-machines-for-stealth</guid><description>Analysis of how threat actors leverage virtualization platforms to host malicious guest OSs, bypassing host-level EDR and maintaining persistent access.</description><pubDate>Thu, 26 Feb 2026 04:39:45 GMT</pubDate><category>Persistence Mechanisms</category><category>EDR Evasion</category><category>Virtualization Abuse</category><category>Threat Hunting</category><category>SANS ISC</category></item></channel></rss>