ISC Stormcast For Wednesday, April 22nd, 2026 https://isc.sans.edu/podcastdetail/9902, (Wed, Apr 22nd)
2026-04-23T01:23:46Z•058a2d553e696162a607a3d3a07cd4f41a2c3fa01f510613ce84d43e106ce5bc
ArechClient2CVE-floodEPSSaudio-malwarecompromised-dvrcredential-harvestinghoneypotiotisc-sanslumma-stealerpodcastsectop-rattdatatelegramthreat-intelvulnerability-managementwav-malware
What happened
This ISC SANS diary RSS batch (Apr 16–22, 2026) aggregates podcast Stormcast entries plus several technical diaries covering active threats and defensive topics: a guest diary on Telegram 'tdata' files being abused as a credential-harvesting vector (observed via a honeypot incident), reports of malicious .wav files used to deliver payloads, a Lumma Stealer infection deploying the Sectop RAT (ArechClient2), analysis of compromised DVR devices found in the wild, and guidance on handling the daily CVE influx using EPSS. Content is a mix of operational incident findings (credential theft, malware,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 058a2d553e696162a607a3d3a07cd4f41a2c3fa01f510613ce84d43e106ce5bc
- Enrichment time
- 2026-04-23T01:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.