ISC Stormcast For Tuesday, April 14th, 2026 https://isc.sans.edu/podcastdetail/9890, (Tue, Apr 14th)
2026-04-14T07:23:48Z•6fcc9754c27df968bd2d98f01dea888fdb3bcb49e838110de2cb5104565c2066
CISA-KEVCisco-source-codeEncystPHPFreePBXGTIGTeamPCPTrivyUNC6780credential-reusehoneypot-fingerprintingmalware-sampleobfuscated-javascriptphishingsha256:a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788bsupply-chainwebshell
What happened
SANS ISC diary roundup (Apr 7–14, 2026) describing active scanning and abuse trends: widespread scans for the EncystPHP web shell (noted targeting vulnerable FreePBX installs), increased fingerprinting of honeypots, and ongoing use/misuse of web shells with weak or preset credentials. A phishing-delivered obfuscated JavaScript sample (SHA256:a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788b74c5285) was observed with low AV detection. Major supply-chain intelligence: TeamPCP campaign update reports Cisco source code stolen via a Trivy-linked breach; Google GTIG tracks TeamPCP as UNC6780
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 6fcc9754c27df968bd2d98f01dea888fdb3bcb49e838110de2cb5104565c2066
- Enrichment time
- 2026-04-14T07:23:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.