ISC Stormcast For Tuesday, April 14th, 2026 https://isc.sans.edu/podcastdetail/9890, (Tue, Apr 14th)

2026-04-14T07:23:48Z6fcc9754c27df968bd2d98f01dea888fdb3bcb49e838110de2cb5104565c2066
CISA-KEVCisco-source-codeEncystPHPFreePBXGTIGTeamPCPTrivyUNC6780credential-reusehoneypot-fingerprintingmalware-sampleobfuscated-javascriptphishingsha256:a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788bsupply-chainwebshell

What happened

SANS ISC diary roundup (Apr 7–14, 2026) describing active scanning and abuse trends: widespread scans for the EncystPHP web shell (noted targeting vulnerable FreePBX installs), increased fingerprinting of honeypots, and ongoing use/misuse of web shells with weak or preset credentials. A phishing-delivered obfuscated JavaScript sample (SHA256:a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788b74c5285) was observed with low AV detection. Major supply-chain intelligence: TeamPCP campaign update reports Cisco source code stolen via a Trivy-linked breach; Google GTIG tracks TeamPCP as UNC6780

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
6fcc9754c27df968bd2d98f01dea888fdb3bcb49e838110de2cb5104565c2066
Enrichment time
2026-04-14T07:23:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.