ISC Stormcast For Wednesday, April 22nd, 2026 https://isc.sans.edu/podcastdetail/9902, (Wed, Apr 22nd)

2026-04-23T01:23:46Z058a2d553e696162a607a3d3a07cd4f41a2c3fa01f510613ce84d43e106ce5bc
ArechClient2CVE-floodEPSSaudio-malwarecompromised-dvrcredential-harvestinghoneypotiotisc-sanslumma-stealerpodcastsectop-rattdatatelegramthreat-intelvulnerability-managementwav-malware

What happened

This ISC SANS diary RSS batch (Apr 16–22, 2026) aggregates podcast Stormcast entries plus several technical diaries covering active threats and defensive topics: a guest diary on Telegram 'tdata' files being abused as a credential-harvesting vector (observed via a honeypot incident), reports of malicious .wav files used to deliver payloads, a Lumma Stealer infection deploying the Sectop RAT (ArechClient2), analysis of compromised DVR devices found in the wild, and guidance on handling the daily CVE influx using EPSS. Content is a mix of operational incident findings (credential theft, malware,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
058a2d553e696162a607a3d3a07cd4f41a2c3fa01f510613ce84d43e106ce5bc
Enrichment time
2026-04-23T01:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.