ISC Stormcast For Friday, April 17th, 2026 https://isc.sans.edu/podcastdetail/9896, (Fri, Apr 17th)

2026-04-17T19:23:50Z922116ced4d39685a1db2f0f1d1c216521b6e28829e11b4a4a3ebee0ce408d97
AI model probesArechClient2DVREncystPHPFreePBXIoTLumma StealerMicrosoft Patch TuesdaySectop RATmalwarepatchingprobesscanningthreat intelwebshell

What happened

SANS ISC diary entries (Apr 13–17, 2026) report several active threats: Lumma Stealer infections observed delivering the Sectop RAT (ArechClient2); widespread probing for AI-model endpoints (e.g., claude, openclaw, huggingface) beginning around 2026-03-10; scans for the EncystPHP webshell (noted targeting vulnerable FreePBX systems); reports of compromised DVRs found in the wild; and a notably large Microsoft Patch Tuesday in April 2026. Observers note attackers are adjusting tooling (harder-to-guess webshell credentials) and continued broad scanning activity.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
922116ced4d39685a1db2f0f1d1c216521b6e28829e11b4a4a3ebee0ce408d97
Enrichment time
2026-04-17T19:23:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ISC Stormcast For Friday, April 17th, 2026 https://isc.sans.edu/podcastdetail/9896, (Fri, Apr 17th) · Baitaphish