ISC Stormcast For Thursday, April 2nd, 2026 https://isc.sans.edu/podcastdetail/9876, (Thu, Apr 2nd)
2026-04-02T07:23:45Z•8eec50877131ae625ed1fde20dd09951e8f33070bfa42fb5993d86e75822b35b
AstraZenecaDShieldDatabricksPyPITeamPCPTelnyxVectapplication-control-bypassattributioncloud-enumerationdata-exfiltrationdata-leakdual-ransomwarefileless-malwarehoneypotpost-compromiseransomwareregistry-persistencesupply-chainsupply-chain-compromise
What happened
SANS ISC diary entries (late Mar–early Apr 2026) highlight an ongoing TeamPCP supply-chain campaign (report v3.0) with multiple updates: confirmed victim disclosure, post-compromise cloud enumeration, narrowed attribution, and monetization via dual ransomware operations. Specific developments include a Databricks investigation, AstraZeneca data release, a Telnyx PyPI compromise and a Vect ransomware partnership. Separate posts describe malicious “fileless” scripts abusing the Windows registry for persistence, application-control bypass techniques used for data exfiltration, and DShield/Cowrie‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 8eec50877131ae625ed1fde20dd09951e8f33070bfa42fb5993d86e75822b35b
- Enrichment time
- 2026-04-02T07:23:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.