[Guest Diary] Compromised DVRs and Finding Them in the Wild, (Thu, Apr 16th)

2026-04-16T01:23:46Z3f994a7a3d817f080aa20b3fddf61a87c96f88aca4a69e7af774a898a20cb50d
AI-probingDVREncystPHPFreePBXIoTJavaScriptclaudecompromisehuggingfacemalwareobfuscated-jsopenclawphishingreconnaissancescanningsha256:a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788bwebshell

What happened

Collection of SANS ISC diary entries (April 2026) highlighting multiple active threats and telemetry: reports of compromised DVRs and how to find them in the wild; broad Internet probing for AI model endpoints (claude, openclaw, huggingface, etc.); scans targeting EncystPHP webshells (noted against FreePBX systems); an obfuscated JavaScript malware sample delivered via phishing (SHA256:a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788b74c5285) with low AV detection; analysis of a large Microsoft Patch Tuesday release; and password/number-usage patterns observed in honeypot data. The set

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
3f994a7a3d817f080aa20b3fddf61a87c96f88aca4a69e7af774a898a20cb50d
Enrichment time
2026-04-16T01:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · [Guest Diary] Compromised DVRs and Finding Them in the Wild, (Thu, Apr 16th) · Baitaphish