ISC Stormcast For Friday, April 3rd, 2026 https://isc.sans.edu/podcastdetail/9878, (Fri, Apr 3rd)
2026-04-03T07:23:48Z•8df63a4f0a7b1c95d34dab94d0daf085632bd5c337585b44892dd0036ad750ad
AstraZenecaCVE-2025-30208CowrieDShieldDatabricksTeamPCPactive-exploitationapplication-control-bypasscloud-enumerationdata-exfiltrationexploitfileless-malwarehoneypotmalicious-scriptransomwareregistry-persistencesupply-chainvite
What happened
ISC SANS diary (late Mar–early Apr 2026) highlights active exploitation attempts against exposed Vite installs (CVE-2025-30208), ongoing TeamPCP supply-chain campaign with confirmed victim disclosure, cloud post‑compromise enumeration, dual ransomware operations and at least one public data release (AstraZeneca). Additional entries describe a malicious/scripted fileless technique that uses the registry for persistence, an application‑control bypass used for data exfiltration, and honeypot (DShield/Cowrie) telemetry analysis useful for detecting automated or fingerprinted sessions. Overall, the
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 8df63a4f0a7b1c95d34dab94d0daf085632bd5c337585b44892dd0036ad750ad
- Enrichment time
- 2026-04-03T07:23:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.