ISC Stormcast For Friday, April 17th, 2026 https://isc.sans.edu/podcastdetail/9896, (Fri, Apr 17th)

2026-04-20T01:23:45Z4fc56e33d605a87767ef01e384916c76fa973f1123a276a491ec7edeeba95712
ai-model-scanningarechclient2dshield-probesdvr-compromiseencystphpfreepbxlumma-stealermicrosoft-patch-tuesdaysectop-ratthreat-actorsvulnerability-scanningwebshell-scans

What happened

SANS ISC diary roundup (Apr 13–17, 2026) covering multiple active threats and observations: a Lumma Stealer infection delivering Sectop RAT (ArechClient2); reports of compromised DVRs in the wild and methods to find them; attackers scanning the internet for AI-model endpoints (claude, openclaw, huggingface, etc.) observed in DShield starting 2026-03-10; scans targeting the EncystPHP webshell—noted in attacks against FreePBX systems; coverage of a large Microsoft Patch Tuesday for April 2026; and several ISC Stormcast podcast entries. The entries indicate active scanning, webshell deployment, &

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
4fc56e33d605a87767ef01e384916c76fa973f1123a276a491ec7edeeba95712
Enrichment time
2026-04-20T01:23:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.