ISC Stormcast For Friday, April 17th, 2026 https://isc.sans.edu/podcastdetail/9896, (Fri, Apr 17th)
2026-04-20T01:23:45Z•4fc56e33d605a87767ef01e384916c76fa973f1123a276a491ec7edeeba95712
ai-model-scanningarechclient2dshield-probesdvr-compromiseencystphpfreepbxlumma-stealermicrosoft-patch-tuesdaysectop-ratthreat-actorsvulnerability-scanningwebshell-scans
What happened
SANS ISC diary roundup (Apr 13–17, 2026) covering multiple active threats and observations: a Lumma Stealer infection delivering Sectop RAT (ArechClient2); reports of compromised DVRs in the wild and methods to find them; attackers scanning the internet for AI-model endpoints (claude, openclaw, huggingface, etc.) observed in DShield starting 2026-03-10; scans targeting the EncystPHP webshell—noted in attacks against FreePBX systems; coverage of a large Microsoft Patch Tuesday for April 2026; and several ISC Stormcast podcast entries. The entries indicate active scanning, webshell deployment, &
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 4fc56e33d605a87767ef01e384916c76fa973f1123a276a491ec7edeeba95712
- Enrichment time
- 2026-04-20T01:23:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.