SANS Stormcast Monday, June 29th, 2026: Automated Cybercrime; Linux Process Names; Amazon Q VS Code
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 755 Ratings
🗓️ 29 June 2026
⏱️ 6 minutes
🔗️ Recording | Apple Podcasts | RSS
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Monday, June 29, 2006 edition of the Sands Internet Storm Center's Stormcast. |
| 0:12.7 | My name is Johannes Ulrich, recording day from Riyadh, Saudi Arabia. |
| 0:18.0 | And this episode is brought you by the sands.edu bachelor's degree program |
| 0:22.4 | in Applied Cybersecurity. Well, in diaries today, we actually have yet another diary by one of |
| 0:29.1 | our bachelor's degree students. I just mentioned the bachelor's degree we offer as part of our |
| 0:34.1 | sans.edu college. As partnership here, we have Nicole Phillips looking at some |
| 0:41.9 | of the background noise that you are seeing in honeypots. And of course, that background noise can |
| 0:46.9 | quickly be overwhelming. In particular, since much of that background noise really doesn't |
| 0:53.3 | appear to be relevant as far as current exploits go. |
| 0:57.2 | The vulnerabilities being exploited are often decades old and, well, in many cases, actually, |
| 1:02.8 | the exploits being used are not even functional. |
| 1:05.6 | But what Nicole here is pointing out that even though there is a lot of garbage essentially being sent at the honeypot, |
| 1:13.2 | there are also some newer threats that are very relevant and are easily drowned by all the noise that the honeypot receives. |
| 1:22.9 | And, well, just like in a real system you're protecting, so not a honeypot, it can be quite difficult sometimes to isolate this relevant activity from all the background noise, because overall the requests and patterns often look very similar. |
| 1:40.5 | So what you're seeing here is a little bit a breakdown in this diary of the different attacks being seen, what the exploits are that are being exploited, and well, some of the newer threats and the one here being Rondo, but that's something that I've mentioned a few times in the past, that very aggressively, as Nicole points out, picks out newer vulnerabilities and |
| 2:03.3 | adds them to the repertoire of scans against vulnerable systems that are covering the internet |
| 2:09.7 | very quickly and sometimes several times a day. |
| 2:13.9 | And then you have a second diary from late last week, and that's by Xavier, about how to |
| 2:19.4 | manipulate the process name that's being reported in Linux. |
| 2:24.5 | Now, there are really two locations. |
| 2:26.4 | The process name is kept in the proc directory for the respective process. |
| 2:32.2 | One is com, COMM. Well, that's just the process name. That's easy to |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

