Two practitioner write-ups highlighted that security telemetry is both essential and frequently misleading when it is incomplete, poorly scoped, or misinterpreted. A SANS ISC guest diary describing hands-on operation of a DShield internet-exposed honeypot reported collecting ~8 million logs from ~14,000 unique IPs over several months, emphasizing that most activity is automated “noise” and that meaningful conclusions depend on collecting the right data and applying a disciplined methodology to correlate events and preserve investigative breadcrumbs.
A separate Detection Engineering Weekly issue reinforced the theme that “there is no detection without telemetry,” while cautioning that detection outcomes are constrained by what logs actually capture and how trustworthy/observable that telemetry is. The newsletter also contained unrelated promotional material (e.g., hiring links and a webinar pitch), but its substantive security content aligned with the same core message: detection engineering must account for telemetry coverage and quality, because missing or deceptive logs can cause false confidence, missed detections, or incorrect incident narratives.

See real exploitation activity before you spend the cycle.
10 events from the most recent confirmed update back to the earliest known activity.
Researchers operating eleven SSH honeypots found that 99.23% of 177,622 authenticated attacker sessions over fifteen days in late May and early June were single-command, non-interactive sessions rather than human-operated shells. They also validated the pattern against a CZ.NIC dataset from thousands of Cowrie sensors, concluding that internet-exposed SSH attacks are dominated by automated reconnaissance and triage.
A SANS ISC diary reported an attacker from IP 45.135.194.48 probing a Cowrie SSH/Telnet honeypot with deliberately implausible username and password combinations to determine whether the system would accept random credentials. The write-up highlighted this as a common way attackers identify medium-interaction honeypots that rely on incomplete service simulation.
After research and AI-assisted triage, the honeypot operator assessed the "libredtail-http" traffic as more consistent with an automated multi-stage scanning toolkit or botnet targeting Apache servers, Linux web interfaces, and IoT devices than with a single malware family. This represented the main analytical conclusion from the investigation.
Over several months of operating the DShield honeypot, the researcher collected roughly 8 million logs from about 14,000 unique source IPs. The data largely reflected repeated automated scanning and background internet noise rather than clearly attributable intrusions.
A detection-focused post described how to identify OpenClaw or Clawbot activity using SentinelOne while avoiding overly disruptive responses such as killing node processes. The newsletter cited this as practical follow-on guidance related to the OpenClaw activity.
In the same reporting, GitLab disclosed operational-security mistakes by the threat actors, including committed internal documents and EXIF metadata that helped geolocate activity to Central Moscow. GitLab also published indicators such as email addresses and source IPs to support defender hunting.
GitLab reported that North Korean-linked clusters dubbed Contagious Interview and WageMole were using GitLab infrastructure for malicious coding interview lures and malware delivery. The report described evolving tradecraft including Function.constructor abuse, malicious npm dependencies, and malicious VS Code tasks.
Research by Birkan Kess argued that some Windows process-creation telemetry can be altered after the kernel-to-user-mode transition via the Process Environment Block. The finding implies that detections relying on such user-mode-visible fields may be evaded unless defenders use kernel-level telemetry such as ETW.
An incident involving an "OpenClaw" bot targeting or interacting with the matplotlib project was highlighted in the newsletter as a notable security-related development. The reference does not provide a specific date for when the interaction occurred.
A DShield honeypot sensor first observed requests using the unusual User-Agent string "libredtail-http" in December 2025. The activity appeared in bursts from 34 IPs with identical request characteristics, suggesting coordinated automated behavior.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourceisc.sans.edu
Open sourceisc.sans.edu
Open sourcedetectionengineering.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.