ISC Stormcast For Friday, April 17th, 2026 https://isc.sans.edu/podcastdetail/9896, (Fri, Apr 17th)

2026-04-17T13:23:46Z6d4fb9177c5ee6aa63588930e0d4f56dbb3d85f37b7acb8597c679b775d894bb
AI model scanningArechClient2DVR compromiseEncystPHPFreePBXLumma StealerMicrosoft Patch TuesdaySANS ISCSectop RATclaudehuggingfacemalwareopenclawscanningwebshell

What happened

SANS ISC diary (mid-April 2026) highlights multiple active threats and observations: a reported Lumma Stealer infection that delivers the Sectop RAT (ArechClient2); ongoing scans for the EncystPHP webshell—noted targeting vulnerable FreePBX systems; increased Internet scanning probing AI model endpoints (claude, openclaw, huggingface, etc.) since 2026-03-10; a guest diary on compromised DVRs and how to find them in the wild; and commentary on a large April 2026 Microsoft Patch Tuesday. No specific CVE identifiers were referenced in the entries.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
6d4fb9177c5ee6aa63588930e0d4f56dbb3d85f37b7acb8597c679b775d894bb
Enrichment time
2026-04-17T13:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ISC Stormcast For Friday, April 17th, 2026 https://isc.sans.edu/podcastdetail/9896, (Fri, Apr 17th) · Baitaphish