ISC Stormcast For Friday, April 17th, 2026 https://isc.sans.edu/podcastdetail/9896, (Fri, Apr 17th)

2026-04-19T01:23:46Z572da27f2a987d8916cbc497b99493ede98e1530cda57f69264cf1fe4058fcb3
AI model scanningArechClient2DShieldDVR compromiseEncystPHPFreePBXLumma StealerMicrosoft Patch TuesdaySectop RATmalwarereconnaissancethreat-intelwebshell

What happened

SANS ISC diary entries (mid-April 2026) report multiple active threats and reconnaissance trends: observed Lumma Stealer infections combined with Sectop RAT (ArechClient2); scanning for the EncystPHP webshell targeting FreePBX systems; compromised DVR devices discovered in the wild; and sustained probes for AI model endpoints (claude, openclaw, huggingface, etc.) beginning 2026-03-10 as seen by DShield sensors. Microsoft’s April 2026 Patch Tuesday was unusually large and is highlighted for review and remediation. No specific CVEs were identified in the feed.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
572da27f2a987d8916cbc497b99493ede98e1530cda57f69264cf1fe4058fcb3
Enrichment time
2026-04-19T01:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.