ISC Stormcast For Tuesday, March 31st, 2026 https://isc.sans.edu/podcastdetail/9872, (Tue, Mar 31st)

2026-03-31T07:23:47Z112d4af929bd555e8e94051ec38d88e5a507cd200f26c88d2b26b90f61c4f852
AstraZenecaCISA-KEVCheckmarxCowrieDShieldDatabricksLiteLLMPyPITeamPCPTelnyxVectapple-patchesdata-leakdetectionhoneypotiOSmacOSransomwaresshsupply-chaintelnetthreat-inteltvOSvisionOSwatchOS

What happened

SANS ISC diary entries (Mar 25–31, 2026) cover an active TeamPCP supply-chain campaign (report: “When the Security Scanner Became the Weapon” v3.0) with multiple updates describing PyPI compromises (LiteLLM, Telnyx), an expanding Vect ransomware affiliate program, dual ransomware operations, alleged Databricks compromise investigation, and release of AstraZeneca data. Updates note CISA KEV activity, wider-than-reported Checkmarx impact, and published detection tools. Additional items: Apple’s March 2026 security updates (≈85 fixes across macOS, iOS/iPadOS, tvOS, watchOS, visionOS; no in-the-wt

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
112d4af929bd555e8e94051ec38d88e5a507cd200f26c88d2b26b90f61c4f852
Enrichment time
2026-03-31T07:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ISC Stormcast For Tuesday, March 31st, 2026 https://isc.sans.edu/podcastdetail/9872, (Tue, Mar 31st) · Baitaphish