ISC Stormcast For Thursday, April 2nd, 2026 https://isc.sans.edu/podcastdetail/9876, (Thu, Apr 2nd)

2026-04-02T07:23:45Z8eec50877131ae625ed1fde20dd09951e8f33070bfa42fb5993d86e75822b35b
AstraZenecaDShieldDatabricksPyPITeamPCPTelnyxVectapplication-control-bypassattributioncloud-enumerationdata-exfiltrationdata-leakdual-ransomwarefileless-malwarehoneypotpost-compromiseransomwareregistry-persistencesupply-chainsupply-chain-compromise

What happened

SANS ISC diary entries (late Mar–early Apr 2026) highlight an ongoing TeamPCP supply-chain campaign (report v3.0) with multiple updates: confirmed victim disclosure, post-compromise cloud enumeration, narrowed attribution, and monetization via dual ransomware operations. Specific developments include a Databricks investigation, AstraZeneca data release, a Telnyx PyPI compromise and a Vect ransomware partnership. Separate posts describe malicious “fileless” scripts abusing the Windows registry for persistence, application-control bypass techniques used for data exfiltration, and DShield/Cowrie‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
8eec50877131ae625ed1fde20dd09951e8f33070bfa42fb5993d86e75822b35b
Enrichment time
2026-04-02T07:23:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ISC Stormcast For Thursday, April 2nd, 2026 https://isc.sans.edu/podcastdetail/9876, (Thu, Apr 2nd) · Baitaphish