A .WAV With A Payload, (Tue, Apr 21st)
2026-04-21T13:23:46Z•4be02dbfa2200fde89cd8b0087e5fe9fabbf8fcc5e5dd88f15feb3aae9d55bfc
.wavAI model scanningArechClient2CVE‑floodDVR compromiseEPSSIoTLumma StealerSectop RATaudio‑vectorclaudehuggingfacemalwarereconnaissancevulnerability‑management
What happened
SANS ISC diary highlights multiple ongoing threats and trends: reports of threat actors weaponizing .wav audio files to deliver malware payloads; a Lumma Stealer campaign observed delivering Sectop RAT (ArechClient2); discovery and enumeration of compromised DVRs in the wild; increased scanning activity probing AI model endpoints (e.g., claude, openclaw, huggingface); and guidance/discussion on handling the large daily influx of CVE entries using EPSS for prioritization. No specific CVE identifiers were provided in the entries.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 4be02dbfa2200fde89cd8b0087e5fe9fabbf8fcc5e5dd88f15feb3aae9d55bfc
- Enrichment time
- 2026-04-21T13:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.