LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
nation-state

TTY Logs and the Data it Captures, (Sun, Oct 4th)

A recent report details an experiment involving the collection and analysis of TTY logs from DShield sensors. The experiment focused on capturing activity from actors or bots that successfully logged into these sensors, specifically recording the various commands executed post-login. These collected TTY logs are then parsed and transmitted daily to the DShield SIEM for correlation with other…

ZeroDay News ·

Source: SANS ISC

A recent report details an experiment involving the collection and analysis of TTY logs from DShield sensors. The experiment focused on capturing activity from actors or bots that successfully logged into these sensors, specifically recording the various commands executed post-login. These collected TTY logs are then parsed and transmitted daily to the DShield SIEM for correlation with other security data.

The technical mechanism at play involves the logging capabilities inherent in terminal (TTY) sessions. When a user or automated process interacts with a system via a terminal, the input and output of that session can be recorded. In this experiment, a custom script was developed to specifically parse these TTY logs. This parsing likely extracts key information such as the commands executed, their arguments, and potentially the timing of these actions.

The affected "product" in this context is the DShield sensor network itself, which serves as the collection point for this activity. DShield, a cooperative project, deploys sensors globally to gather data on malicious internet activity. The experiment leverages these sensors as honeypots or observation points to attract and record the behavior of unauthorized access attempts. The scope of this data collection is limited to the activity observed on these specific DShield sensors.

The collected TTY logs are then sent to a Security Information and Event Management (SIEM) system. SIEMs are designed to aggregate and analyze security data from various sources across an organization's infrastructure. By correlating TTY logs with other data sources within the SIEM, security analysts can gain a more comprehensive understanding of attack patterns, identify lateral movement, and potentially attribute malicious activity.

Typical mitigation guidance for issues related to unauthorized access and command execution often includes robust authentication mechanisms, principle of least privilege, regular patching, and network segmentation. While this experiment focuses on observation rather than direct mitigation, the insights gained from analyzing TTY logs can inform the development of more effective detection rules and preventative measures against similar types of attacks.

This experiment highlights the value of detailed logging and behavioral analysis in understanding threat actor tactics, techniques, and procedures (TTPs). By capturing and analyzing the precise commands executed by malicious entities, security researchers and defenders can gain critical intelligence that can be used to improve defensive postures, develop more accurate intrusion detection signatures, and enhance overall incident response capabilities. The daily transmission and correlation within a SIEM underscore the importance of continuous monitoring and integrated security analytics.

nation-state
ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

Three questions a hospital CISO should ask a healthcare fintech vendor

A cybersecurity expert has outlined key questions hospital CISOs should pose to healthcare fintech vendors to assess their security posture, particularly concerning patient data and financial transactions. Drew McCombs, who holds both CTO and CISO roles at Cylerity, emphasizes that security should be an integral part of development processes, not an afterthought, especially when patient data…

CVE-2026-88779

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix has confirmed the active exploitation of a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler appliances. This new flaw reportedly emerged and was exploited just days after the company released patches for two other previously exploited vulnerabilities in the same product line.

cloud

Keyorix: Open-source secrets management for teams that can’t use SaaS

Keyorix, an open-source secrets management solution, has been released, offering an on-premises alternative for organizations unable to utilize cloud-based services for credential storage. The system is designed to run entirely on a company's own infrastructure, with its core functionality requiring no internet connection.

security

How RMM abuse gives attackers a way in that looks like business as usual

Attackers are increasingly leveraging legitimate remote monitoring and management (RMM) software to gain persistent access to victim systems, a tactic observed in 45% of endpoint-related incidents recorded by security firm Huntress in the first quarter of 2026. This method allows attackers to execute commands remotely and maintain access in a way that often appears to be normal administrative…

CVE-2026-88779high

Citrix NetScaler Flaw Exploited Before CVE Publication

The CVE-2026-88779 vulnerability in Citrix NetScaler was exploited before its official publication date. A second independent catalogue now confirms exploitation.

CVE-2026-88779

Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix has issued urgent security updates for a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler ADC and NetScaler Gateway appliances. The flaw, described as a memory buffer issue, has been actively exploited in targeted attacks, primarily leading to denial-of-service conditions.