A .WAV With A Payload, (Tue, Apr 21st)

2026-04-21T13:23:46Z4be02dbfa2200fde89cd8b0087e5fe9fabbf8fcc5e5dd88f15feb3aae9d55bfc
.wavAI model scanningArechClient2CVE‑floodDVR compromiseEPSSIoTLumma StealerSectop RATaudio‑vectorclaudehuggingfacemalwarereconnaissancevulnerability‑management

What happened

SANS ISC diary highlights multiple ongoing threats and trends: reports of threat actors weaponizing .wav audio files to deliver malware payloads; a Lumma Stealer campaign observed delivering Sectop RAT (ArechClient2); discovery and enumeration of compromised DVRs in the wild; increased scanning activity probing AI model endpoints (e.g., claude, openclaw, huggingface); and guidance/discussion on handling the large daily influx of CVE entries using EPSS for prioritization. No specific CVE identifiers were provided in the entries.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
4be02dbfa2200fde89cd8b0087e5fe9fabbf8fcc5e5dd88f15feb3aae9d55bfc
Enrichment time
2026-04-21T13:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.