ISC Stormcast For Friday, April 17th, 2026 https://isc.sans.edu/podcastdetail/9896, (Fri, Apr 17th)

2026-04-18T19:23:48Z4c1f5161aa23a67fcaf2a590f242b03768174391df892deda9123a6471e24215
AI model probesArechClient2DShieldDVR compromiseEncystPHPFortinetFreePBXIoTLumma StealerMicrosoft Patch TuesdayRATSectop RATinformation-stealermalwarepatchingscanningwebshell

What happened

SANS ISC diary feed (mid-April 2026) summarizing active threat and telemetry observations: a reported Lumma Stealer infection delivering the Sectop RAT (ArechClient2); research on compromised DVRs observed in the wild; widespread scanning for AI model endpoints (claude, openclaw, huggingface) observed by DShield starting 2026-03-10; scans for the EncystPHP webshell (noted by Fortinet) targeting FreePBX systems; and commentary on Microsoft Patch Tuesday April 2026 (large set of fixes). Multiple daily 'ISC Stormcast' podcast entries also included.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
4c1f5161aa23a67fcaf2a590f242b03768174391df892deda9123a6471e24215
Enrichment time
2026-04-18T19:23:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ISC Stormcast For Friday, April 17th, 2026 https://isc.sans.edu/podcastdetail/9896, (Fri, Apr 17th) · Baitaphish