Number Usage in Passwords: Take Two, (Thu, Apr 9th)

2026-04-09T01:23:48Za94e6b8e1dbf433fbda8b5363881b5c915fe0eeee46098c7e4db27ba3acb9491
CERT-EUCiscoEuropean CommissionLiteLLMMandiantMercor AIShinyHuntersSportradarTeamPCPTrivyUNC6780breachcloud compromisecredential leakagehoneypothoneypot fingerprintingpasswordsphishingredirectssupply chainthreat intelwebshell

What happened

Collection of SANS ISC diary entries (Apr 3–9, 2026) covering: an ongoing TeamPCP supply‑chain campaign with multiple updates reporting Trivy‑linked breach activity (including stolen Cisco source code), Google GTIG tracking the actor as UNC6780, CERT‑EU confirmation of a European Commission cloud breach, Sportradar and Mercor AI impacts, Mandiant’s estimate of 1,000+ compromised SaaS environments, and related supply‑chain fallout (LiteLLM, ShinyHunters). Other posts discuss operational tradecraft and detection topics: honeypot fingerprinting scans, webshell names and embedded backdoor creds, a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
a94e6b8e1dbf433fbda8b5363881b5c915fe0eeee46098c7e4db27ba3acb9491
Enrichment time
2026-04-09T01:23:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.