ISC Stormcast For Friday, April 17th, 2026 https://isc.sans.edu/podcastdetail/9896, (Fri, Apr 17th)
2026-04-18T19:23:48Z•4c1f5161aa23a67fcaf2a590f242b03768174391df892deda9123a6471e24215
AI model probesArechClient2DShieldDVR compromiseEncystPHPFortinetFreePBXIoTLumma StealerMicrosoft Patch TuesdayRATSectop RATinformation-stealermalwarepatchingscanningwebshell
What happened
SANS ISC diary feed (mid-April 2026) summarizing active threat and telemetry observations: a reported Lumma Stealer infection delivering the Sectop RAT (ArechClient2); research on compromised DVRs observed in the wild; widespread scanning for AI model endpoints (claude, openclaw, huggingface) observed by DShield starting 2026-03-10; scans for the EncystPHP webshell (noted by Fortinet) targeting FreePBX systems; and commentary on Microsoft Patch Tuesday April 2026 (large set of fixes). Multiple daily 'ISC Stormcast' podcast entries also included.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 4c1f5161aa23a67fcaf2a590f242b03768174391df892deda9123a6471e24215
- Enrichment time
- 2026-04-18T19:23:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.