ISC Stormcast For Friday, April 17th, 2026 https://isc.sans.edu/podcastdetail/9896, (Fri, Apr 17th)
2026-04-17T19:23:50Z•922116ced4d39685a1db2f0f1d1c216521b6e28829e11b4a4a3ebee0ce408d97
AI model probesArechClient2DVREncystPHPFreePBXIoTLumma StealerMicrosoft Patch TuesdaySectop RATmalwarepatchingprobesscanningthreat intelwebshell
What happened
SANS ISC diary entries (Apr 13–17, 2026) report several active threats: Lumma Stealer infections observed delivering the Sectop RAT (ArechClient2); widespread probing for AI-model endpoints (e.g., claude, openclaw, huggingface) beginning around 2026-03-10; scans for the EncystPHP webshell (noted targeting vulnerable FreePBX systems); reports of compromised DVRs found in the wild; and a notably large Microsoft Patch Tuesday in April 2026. Observers note attackers are adjusting tooling (harder-to-guess webshell credentials) and continued broad scanning activity.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 922116ced4d39685a1db2f0f1d1c216521b6e28829e11b4a4a3ebee0ce408d97
- Enrichment time
- 2026-04-17T19:23:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.