ISC Stormcast For Friday, April 17th, 2026 https://isc.sans.edu/podcastdetail/9896, (Fri, Apr 17th)
2026-04-18T07:23:45Z•abe585a9c3b4e787150e26c53e5736feeac66977828c39ea9066ca615d1fc97b
AI-model-probesArechClient2DVR compromiseEncystPHPFreePBXIoTLumma StealerMicrosoft Patch TuesdaySectop RATscanningthreat huntingvulnerability managementwebshell
What happened
SANS ISC diary entries (Apr 13–17, 2026) highlight multiple active threats and activity: a reported Lumma Stealer infection delivering Sectop RAT (ArechClient2); ongoing Internet-wide scanning for AI model endpoints (e.g., claude, huggingface) that began ~2026-03-10; scans probing for EncystPHP webshells (commonly used against FreePBX) with attackers adapting credentials; and findings on compromised DVRs. The feed also notes the large April 2026 Microsoft Patch Tuesday release (many fixes). These items indicate active malware distribution, IoT/telemetry compromise risk, webshell exploitation,+
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- abe585a9c3b4e787150e26c53e5736feeac66977828c39ea9066ca615d1fc97b
- Enrichment time
- 2026-04-18T07:23:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.