ISC Stormcast For Wednesday, April 15th, 2026 https://isc.sans.edu/podcastdetail/9892, (Wed, Apr 15th)
2026-04-15T19:23:53Z•346144ef04c7f56fb7f0cd401c726a8e864ef5f933bf78305ca0d54d85cef722
AI-model-probingCISA-KEVCisco-source-code-theftDShieldEncystPHPFreePBXGTIGMicrosoft-Patch-TuesdayTeamPCPTrivyUNC6780VirusTotalhoneypot-password-analysismalicious-JavaScriptobfuscated-JSpatchesphishingscanningsupply-chainwebshell
What happened
SANS ISC diary entries (Apr 8–15, 2026) highlight multiple active threats and notable security events: widespread DShield probe activity beginning 2026-03-10 scanning for AI model endpoints (e.g., claude, openclaw, huggingface); scans for the EncystPHP webshell (noted as used against vulnerable FreePBX systems); an April 2026 Microsoft Patch Tuesday described as unusually large; phishing-delivered obfuscated JavaScript (sample SHA256:a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788b74c5285) with low AV detection; analysis of numeric usage in passwords seen in honeypots; and a majorTeam
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 346144ef04c7f56fb7f0cd401c726a8e864ef5f933bf78305ca0d54d85cef722
- Enrichment time
- 2026-04-15T19:23:53Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.