How often are redirects used in phishing in 2026?, (Mon, Apr 6th)

2026-04-06T19:23:50Z42b55391067c72e124e2f3c1beb62c20844f751aa6689c9211612af1244d5e3b
CERT-EUCVE-2025-30208European-CommissionMercor-AISaaSTeamPCPViteapplication-control-bypasscloud-breachdata-exfiltrationexploitationfilelessmalwareopen-redirectpersistencephishingregistrysupply-chain

What happened

The ISC SANS diary collection for early April 2026 highlights multiple active threats: researchers note widespread interest by threat actors in finding and abusing open redirects for phishing; a major supply‑chain/cloud campaign tracked as TeamPCP is escalating (CERT‑EU confirmed a European Commission cloud breach, Sportradar disclosures, Mandiant reporting ~1,000+ impacted SaaS environments and confirmed victim disclosures such as Mercor AI); exploitation activity against exposed Vite installs (tracked as CVE-2025-30208) has been observed; and malware techniques continue to favor fileless/pol

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
42b55391067c72e124e2f3c1beb62c20844f751aa6689c9211612af1244d5e3b
Enrichment time
2026-04-06T19:23:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.