ISC Stormcast For Thursday, April 9th, 2026 https://isc.sans.edu/podcastdetail/9886, (Thu, Apr 9th)

2026-04-09T19:23:46Z8ec38f5abd7a20d2c82553c681147a67e876094537f98075a85d85f8be617ac7
CISA-KEVCiscoGTIGSaaS-compromiseTeamPCPTrivyUNC6780credential-thefthoneypot-fingerprintingopen-redirectspasswordsphishingsecurity-intelsource-code-theftsupply-chainthreat-actorwebshells

What happened

SANS ISC diary feed (April 6–9, 2026) containing multiple intelligence posts. The most critical item is TeamPCP Supply Chain Campaign Update 007 reporting a Trivy-linked breach with Cisco source code exfiltration, Google GTIG tracking the actor as UNC6780, and commentary on CISA KEV deadlines and broad SaaS impact. Other entries cover password-number usage in leaked credentials, honeypot fingerprinting and scans, webshell naming/password issues, and the prevalence/misuse of redirects in phishing. No specific CVE identifiers are listed in the diary entries.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
8ec38f5abd7a20d2c82553c681147a67e876094537f98075a85d85f8be617ac7
Enrichment time
2026-04-09T19:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ISC Stormcast For Thursday, April 9th, 2026 https://isc.sans.edu/podcastdetail/9886, (Thu, Apr 9th) · Baitaphish