ISC Stormcast For Wednesday, April 22nd, 2026 https://isc.sans.edu/podcastdetail/9902, (Wed, Apr 22nd)

2026-04-22T13:23:48Z3fbe1986d639c0808c0ea0ae12a1abc3cbeb8dcf04ad42e96347aa12119aacd8
arechclient2audio-steganographycredential-harvestingcve-flooddvrepsshoneypotincident-responseiot-compromiselumma-stealermalwaresectop-rattdatatelegramthreat-intelvulnerability-managementwav-malware

What happened

This ISC SANS diary digest (April 16–22, 2026) highlights multiple active threats and defensive topics: a guest diary describing Telegram "tdata" folders being abused as a credential-harvesting vector (based on a honeypot incident); reports of threat actors embedding malware payloads in .wav audio files; a Lumma Stealer infection observed delivering the Sectop RAT (ArechClient2); widespread compromised DVRs and techniques to find them in the wild; and guidance on handling the daily CVE influx using EPSS for prioritization. Combined, these entries show active credential-theft operations, audio‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
3fbe1986d639c0808c0ea0ae12a1abc3cbeb8dcf04ad42e96347aa12119aacd8
Enrichment time
2026-04-22T13:23:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.