[Guest Diary] Compromised DVRs and Finding Them in the Wild, (Thu, Apr 16th)
2026-04-16T01:23:46Z•3f994a7a3d817f080aa20b3fddf61a87c96f88aca4a69e7af774a898a20cb50d
AI-probingDVREncystPHPFreePBXIoTJavaScriptclaudecompromisehuggingfacemalwareobfuscated-jsopenclawphishingreconnaissancescanningsha256:a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788bwebshell
What happened
Collection of SANS ISC diary entries (April 2026) highlighting multiple active threats and telemetry: reports of compromised DVRs and how to find them in the wild; broad Internet probing for AI model endpoints (claude, openclaw, huggingface, etc.); scans targeting EncystPHP webshells (noted against FreePBX systems); an obfuscated JavaScript malware sample delivered via phishing (SHA256:a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788b74c5285) with low AV detection; analysis of a large Microsoft Patch Tuesday release; and password/number-usage patterns observed in honeypot data. The set
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 3f994a7a3d817f080aa20b3fddf61a87c96f88aca4a69e7af774a898a20cb50d
- Enrichment time
- 2026-04-16T01:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.