ISC Stormcast For Friday, April 17th, 2026 https://isc.sans.edu/podcastdetail/9896, (Fri, Apr 17th)

2026-04-18T07:23:45Zabe585a9c3b4e787150e26c53e5736feeac66977828c39ea9066ca615d1fc97b
AI-model-probesArechClient2DVR compromiseEncystPHPFreePBXIoTLumma StealerMicrosoft Patch TuesdaySectop RATscanningthreat huntingvulnerability managementwebshell

What happened

SANS ISC diary entries (Apr 13–17, 2026) highlight multiple active threats and activity: a reported Lumma Stealer infection delivering Sectop RAT (ArechClient2); ongoing Internet-wide scanning for AI model endpoints (e.g., claude, huggingface) that began ~2026-03-10; scans probing for EncystPHP webshells (commonly used against FreePBX) with attackers adapting credentials; and findings on compromised DVRs. The feed also notes the large April 2026 Microsoft Patch Tuesday release (many fixes). These items indicate active malware distribution, IoT/telemetry compromise risk, webshell exploitation,+

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
abe585a9c3b4e787150e26c53e5736feeac66977828c39ea9066ca615d1fc97b
Enrichment time
2026-04-18T07:23:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.