ISC Stormcast For Tuesday, March 31st, 2026 https://isc.sans.edu/podcastdetail/9872, (Tue, Mar 31st)
2026-03-31T07:23:47Z•112d4af929bd555e8e94051ec38d88e5a507cd200f26c88d2b26b90f61c4f852
AstraZenecaCISA-KEVCheckmarxCowrieDShieldDatabricksLiteLLMPyPITeamPCPTelnyxVectapple-patchesdata-leakdetectionhoneypotiOSmacOSransomwaresshsupply-chaintelnetthreat-inteltvOSvisionOSwatchOS
What happened
SANS ISC diary entries (Mar 25–31, 2026) cover an active TeamPCP supply-chain campaign (report: “When the Security Scanner Became the Weapon” v3.0) with multiple updates describing PyPI compromises (LiteLLM, Telnyx), an expanding Vect ransomware affiliate program, dual ransomware operations, alleged Databricks compromise investigation, and release of AstraZeneca data. Updates note CISA KEV activity, wider-than-reported Checkmarx impact, and published detection tools. Additional items: Apple’s March 2026 security updates (≈85 fixes across macOS, iOS/iPadOS, tvOS, watchOS, visionOS; no in-the-wt
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 112d4af929bd555e8e94051ec38d88e5a507cd200f26c88d2b26b90f61c4f852
- Enrichment time
- 2026-03-31T07:23:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.