ISC Stormcast For Wednesday, April 8th, 2026 https://isc.sans.edu/podcastdetail/9884, (Wed, Apr 8th)
2026-04-08T13:23:45Z•7c1c12145fb169206885e5a82dcc38ae018f24fcb4d93c043e8d792902d97eb7
CVE-2025-30208European-CommissionISCMandiantSANSSaaSTeamPCPVitecloud-breachdefault-credentialsexploitationfileless-malwaremalicious-scriptopen-redirectpersistencephishingregistry-persistencesupply-chainthreat-intelligenceweb-shell
What happened
ISC SANS diary entries (Apr 1–8, 2026) covering multiple active threats and research: web shells and weak/default credentials used for persistence on compromised web servers; the misuse of open redirects in phishing campaigns; a major TeamPCP supply‑chain/cloud campaign update (CERT‑EU confirms a European Commission cloud breach, Sportradar disclosures, Mandiant quantifies >1,000 impacted SaaS environments); active attempts to exploit exposed Vite installs (CVE‑2025‑30208); and analysis of a fileless/malicious script leveraging registry persistence to remove ADS. The feed also includes daily "
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 7c1c12145fb169206885e5a82dcc38ae018f24fcb4d93c043e8d792902d97eb7
- Enrichment time
- 2026-04-08T13:23:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.