ISC Stormcast For Friday, April 3rd, 2026 https://isc.sans.edu/podcastdetail/9878, (Fri, Apr 3rd)

2026-04-03T07:23:48Z8df63a4f0a7b1c95d34dab94d0daf085632bd5c337585b44892dd0036ad750ad
AstraZenecaCVE-2025-30208CowrieDShieldDatabricksTeamPCPactive-exploitationapplication-control-bypasscloud-enumerationdata-exfiltrationexploitfileless-malwarehoneypotmalicious-scriptransomwareregistry-persistencesupply-chainvite

What happened

ISC SANS diary (late Mar–early Apr 2026) highlights active exploitation attempts against exposed Vite installs (CVE-2025-30208), ongoing TeamPCP supply-chain campaign with confirmed victim disclosure, cloud post‑compromise enumeration, dual ransomware operations and at least one public data release (AstraZeneca). Additional entries describe a malicious/scripted fileless technique that uses the registry for persistence, an application‑control bypass used for data exfiltration, and honeypot (DShield/Cowrie) telemetry analysis useful for detecting automated or fingerprinted sessions. Overall, the

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
8df63a4f0a7b1c95d34dab94d0daf085632bd5c337585b44892dd0036ad750ad
Enrichment time
2026-04-03T07:23:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.