Read more of this story at Slashdot.
Intelligence View
⚡ tsecurity.de Intelligence
Interns At Tech Companies Are Better Paid Than Most American Workers
According to a survey conducted by Jesse Collins, a senior at Purdue University and former Yelp intern, interns at tech companies make much more money on an annualized basis than workers in the vast majority of other occupations. From a…
Reagiere als Erste:r — dein Feedback zählt!
According to a survey conducted by Jesse Collins, a senior at Purdue University and former Yelp intern, interns at tech companies make much more money on an annualized basis than workers in the vast majority of other occupations. From a report on Quartz: About 300 of the nearly 600 people who responded to the survey said they had received internship offers from big companies like Facebook, Twitter, Yelp, and Goldman Sachs for 2017. On average, the internship recipients said they would be paid $6,500 per month, the equivalent of $78,000 per year (the survey is still open, so results may change). Many also said they would receive more than $1,000 worth of stipends per month for housing and travel or signing bonuses. Internships typically run for a summer, but we've annualized the numbers. If the average intern who responded to Collins' survey were to work for a year, he would make $30,000 more than the average annual income for all occupations in the U.S., which is $48,000. Of the 1,088 occupation categories within which the Bureau of Labor Statistics tracks average income, workers in only about 200 of them on average make more money in a year than the intern would.
1. Sofort-Triage & Abwehrmaßnahmen
SOC Incident Playbook: Vulnerability Remediation & Verification
Syntax validiert (0 Fehler)
title: Detect Exploitation - Interns At Tech Companies Are Better Paid Than Most American Workers
id: 691e4c5a-720b-4a90-8ee4-9af2ad83a857
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
- https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-27
logsource:
category: network_connection
product: any
detection:
selection:
CommandLine|contains:
- 'exploit'
condition: selection
falsepositives:
- Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
- attack.initial_accessSyntax validiert (0 Fehler)
rule CTI_Threat_Indicator {
meta:
author = "iShareStuff CTI Automated Detection Engine"
date = "2026-09-27"
description = "YARA Signature for "
strings:
$str = "Interns At Tech Companies Are " ascii wide
condition:
any of them
}Syntax validiert (0 Fehler)
index=security sourcetype IN ("cisco:asa", "pan:traffic", "zeek_conn", "suricata", "WinEventLog:Security")
("Interns At Tech Companies Are Better Pai")
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip, dest_ip, dest_host, signature
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort - countSyntax validiert (0 Fehler)
message: "*Interns At Tech Companies Are Better Pai*"Syntax validiert (0 Fehler)
CommonSecurityLog
| where Message has "Interns At Tech Companies Are Better Pai"
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by SourceIP, DestinationIP, DestinationPort, Activity
| extend DetectionRule = "iShareStuff-CTI-Compiled"
| sort by EventCount desc2. Cyber Threat Intelligence & Forensik
CTI Threat Relationship Graph2 Knoten / 1 Relationen
🎯
MITRE ATT&CK Matrix Navigator 14 Taktiken
Reconnaissance
-
Resource Development
-
Initial Access
Execution
Persistence
-
Privilege Escalation
Defense Evasion
Credential Access
-
Discovery
-
Lateral Movement
-
Collection
-
Command and Control
Exfiltration
-
Impact
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:
Analyse für identifizierte Bedrohung auf Basis von Live-CTI (ENISA EUVD): CVSS 0.0 · EPSS 0.0% · CISA KEV: nein. Handlungsableitung aus den verlinkten Hersteller-Quellen.
🛡️ Angriffsfläche & Exposure
Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.
⚡ Empfohlene Sofortmaßnahmen
- 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
- 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
- 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
Synthetische RAG-Antwort