ISC Stormcast For Wednesday, April 15th, 2026 https://isc.sans.edu/podcastdetail/9892, (Wed, Apr 15th)

2026-04-15T19:23:53Z346144ef04c7f56fb7f0cd401c726a8e864ef5f933bf78305ca0d54d85cef722
AI-model-probingCISA-KEVCisco-source-code-theftDShieldEncystPHPFreePBXGTIGMicrosoft-Patch-TuesdayTeamPCPTrivyUNC6780VirusTotalhoneypot-password-analysismalicious-JavaScriptobfuscated-JSpatchesphishingscanningsupply-chainwebshell

What happened

SANS ISC diary entries (Apr 8–15, 2026) highlight multiple active threats and notable security events: widespread DShield probe activity beginning 2026-03-10 scanning for AI model endpoints (e.g., claude, openclaw, huggingface); scans for the EncystPHP webshell (noted as used against vulnerable FreePBX systems); an April 2026 Microsoft Patch Tuesday described as unusually large; phishing-delivered obfuscated JavaScript (sample SHA256:a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788b74c5285) with low AV detection; analysis of numeric usage in passwords seen in honeypots; and a majorTeam

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
346144ef04c7f56fb7f0cd401c726a8e864ef5f933bf78305ca0d54d85cef722
Enrichment time
2026-04-15T19:23:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.