A .WAV With A Payload, (Tue, Apr 21st)
2026-04-21T19:23:47Z•3eea09e438478aa46725fcd3216882c99718f45fee5cdaaf368f0e66067d59f6
.wavAI-model scanningArechClient2CVE floodDShieldDVR compromiseEPSSIoTLumma StealerSectop RATaudio payloadclaudehuggingfacemalwareopenclawvulnerability management
What happened
SANS ISC Diary (Apr 14–21, 2026) highlights multiple active threats and operational guidance: reports of threat actors using .wav audio files as a malware delivery vector; a Lumma Stealer campaign that also deployed Sectop RAT (ArechClient2); discovery and analysis of compromised DVRs in the wild; widespread scanning for AI-model endpoints (e.g., claude, openclaw, huggingface) observed from March 10, 2026; and guidance on coping with the daily CVE volume using EPSS for prioritization. No specific CVEs were listed in these entries.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 3eea09e438478aa46725fcd3216882c99718f45fee5cdaaf368f0e66067d59f6
- Enrichment time
- 2026-04-21T19:23:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.