A .WAV With A Payload, (Tue, Apr 21st)

2026-04-21T19:23:47Z3eea09e438478aa46725fcd3216882c99718f45fee5cdaaf368f0e66067d59f6
.wavAI-model scanningArechClient2CVE floodDShieldDVR compromiseEPSSIoTLumma StealerSectop RATaudio payloadclaudehuggingfacemalwareopenclawvulnerability management

What happened

SANS ISC Diary (Apr 14–21, 2026) highlights multiple active threats and operational guidance: reports of threat actors using .wav audio files as a malware delivery vector; a Lumma Stealer campaign that also deployed Sectop RAT (ArechClient2); discovery and analysis of compromised DVRs in the wild; widespread scanning for AI-model endpoints (e.g., claude, openclaw, huggingface) observed from March 10, 2026; and guidance on coping with the daily CVE volume using EPSS for prioritization. No specific CVEs were listed in these entries.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
3eea09e438478aa46725fcd3216882c99718f45fee5cdaaf368f0e66067d59f6
Enrichment time
2026-04-21T19:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.