ISC Stormcast For Friday, April 17th, 2026 https://isc.sans.edu/podcastdetail/9896, (Fri, Apr 17th)
2026-04-18T13:23:44Z•6c279822b20d51901511d1003a1e693842ef265da704cd739c0d8429b2caadbd
AI model scanningApril 2026ArechClient2DShieldDVR compromiseEncystPHPFreePBXIoTLumma StealerMicrosoft Patch TuesdaySANS ISCSectop RATmalwarepatchingreconnaissancescanningthreat intelwebshell
What happened
SANS ISC diary entries (Apr 13–17, 2026) covering multiple operational security topics: a reported Lumma Stealer infection that drops the Sectop RAT (ArechClient2); scanning activity for the EncystPHP webshell (noted targeting FreePBX devices); widespread probing for AI model endpoints (claude, huggingface, etc.) observed via DShield since Mar 10; a guest diary on compromised DVRs; and Microsoft Patch Tuesday coverage for April 2026. These items highlight active malware deployment, scanning/reconnaissance of Internet-facing services and IoT, and the need for timely patching and intrusion-dete
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 6c279822b20d51901511d1003a1e693842ef265da704cd739c0d8429b2caadbd
- Enrichment time
- 2026-04-18T13:23:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.