ISC Stormcast For Friday, April 17th, 2026 https://isc.sans.edu/podcastdetail/9896, (Fri, Apr 17th)

2026-04-18T13:23:44Z6c279822b20d51901511d1003a1e693842ef265da704cd739c0d8429b2caadbd
AI model scanningApril 2026ArechClient2DShieldDVR compromiseEncystPHPFreePBXIoTLumma StealerMicrosoft Patch TuesdaySANS ISCSectop RATmalwarepatchingreconnaissancescanningthreat intelwebshell

What happened

SANS ISC diary entries (Apr 13–17, 2026) covering multiple operational security topics: a reported Lumma Stealer infection that drops the Sectop RAT (ArechClient2); scanning activity for the EncystPHP webshell (noted targeting FreePBX devices); widespread probing for AI model endpoints (claude, huggingface, etc.) observed via DShield since Mar 10; a guest diary on compromised DVRs; and Microsoft Patch Tuesday coverage for April 2026. These items highlight active malware deployment, scanning/reconnaissance of Internet-facing services and IoT, and the need for timely patching and intrusion-dete​

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
6c279822b20d51901511d1003a1e693842ef265da704cd739c0d8429b2caadbd
Enrichment time
2026-04-18T13:23:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.