ISC Stormcast For Friday, April 17th, 2026 https://isc.sans.edu/podcastdetail/9896, (Fri, Apr 17th)
2026-04-17T07:23:46Z•3b798e9af4bf36e005900f466779565dca4c30b0b45dc9f7907705f0fcb00be3
AI model probesArechClient2DShieldDVR compromiseEncystPHPFreePBXIoTLumma StealerMicrosoft Patch TuesdaySectop RATmalwarepatchingscanningthreat intelligencewebshell
What happened
ISC SANS diary highlights active threats and widespread scanning activity in mid-April 2026: a Lumma Stealer infection paired with the Sectop RAT (ArechClient2) was observed, attackers are scanning for the EncystPHP webshell (noted targeting vulnerable FreePBX instances), and many compromised DVRs continue to be found in the wild. DShield sensors reported probes for AI model endpoints (e.g., claude, openclaw, huggingface) beginning 2026-03-10 and persisting. The feed also calls out a large Microsoft Patch Tuesday (April 2026) with numerous updates. No specific CVE identifiers were provided in‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 3b798e9af4bf36e005900f466779565dca4c30b0b45dc9f7907705f0fcb00be3
- Enrichment time
- 2026-04-17T07:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.