ISC Stormcast For Friday, March 27th, 2026 https://isc.sans.edu/podcastdetail/9868, (Fri, Mar 27th)
2026-03-27T07:23:45Z•b65ab6129fe13d8ebc8fd44b3948a92a0d89b97da8bde115b830025419c97013
Apple-patchesArechClient2CISA-KEVCheckmarxEclypsiumIP-KVMLiteLLMNetSupportPyPI-compromiseRATRemcosSectopSmartApeSGStealCTeamPCPdetection-toolsiOSmacOSsans-iscsupply-chainthreat-inteltool-updatestvOSvisionOSwatchOS
What happened
SANS ISC diary entries (Mar 23–27, 2026) highlight multiple active and developing threats: an update on the TeamPCP supply‑chain campaign (report “When the Security Scanner Became the Weapon” v3.0) noting a wider Checkmarx scope than initially reported, a CISA KEV entry and available detection tools; the March Apple security updates that fix ~85 vulnerabilities across Apple platforms (no in‑the‑wild exploitation reported); the SmartApeSG campaign distributing multiple RATs (Remcos, NetSupport, StealC and Sectop/ArechClient2); researcher reporting on IP‑KVM vulnerabilities and risks from rogue/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- b65ab6129fe13d8ebc8fd44b3948a92a0d89b97da8bde115b830025419c97013
- Enrichment time
- 2026-03-27T07:23:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.