A .WAV With A Payload, (Tue, Apr 21st)
2026-04-21T07:23:45Z•1fbfd71bcaa1ea53a1f74e491db62040fd8314dd54cd5b088198fadab9003def
AI-model-probingArechClient2CVE-floodEPSSIoT DVR compromiseLumma StealerSectop RATaudio-vectormalwarereconnaissancesteganography (possible)wav
What happened
SANS ISC diary entries (Apr 14–21, 2026) describe several active threats and observations: threat actors abusing .wav audio files as a vector for malware payloads; Lumma Stealer infections coupled with the Sectop RAT (ArechClient2); widespread scanning/probing for AI model endpoints (Claude, OpenClaw, HuggingFace, etc.); and research on compromised DVRs in the wild. The feed also includes commentary on managing large CVE volumes with EPSS. No specific CVE identifiers are referenced in the aggregated items.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 1fbfd71bcaa1ea53a1f74e491db62040fd8314dd54cd5b088198fadab9003def
- Enrichment time
- 2026-04-21T07:23:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.