ISC Stormcast For Friday, April 24th, 2026 https://isc.sans.edu/podcastdetail/9906, (Fri, Apr 24th)

2026-04-27T07:23:47Z61577aa8c40568f2289b9da716f249a3bd56f3027da01035f9ceab03244ca502
appleaudio-malwarecredential-harvestingcve-2026-28950epssexploithoneypotiosipadosmalware-deliverynotification-servicespatchrss-feedsans-iscsecurity-podcasttdatatelegramvulnerability-managementwav

What happened

An ISC SANS diary RSS feed (Apr 17–24, 2026) with multiple short items: Apple released iOS/iPadOS updates (26.4.2 and 18.7.8) fixing an actively exploited Notification Services vulnerability (CVE-2026-28950); a guest diary examining Telegram "tdata" files used for credential harvesting observed in a honeypot; reports of threat actors using .wav audio files as malware delivery vectors; an article on using EPSS to prioritize the daily influx of new CVEs; and multiple ISC StormCast podcast entries.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
61577aa8c40568f2289b9da716f249a3bd56f3027da01035f9ceab03244ca502
Enrichment time
2026-04-27T07:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.