ISC Stormcast For Friday, April 17th, 2026 https://isc.sans.edu/podcastdetail/9896, (Fri, Apr 17th)
2026-04-19T19:23:43Z•bbb6e13d08e28826d798e6aa272084b48599a9dbd514061902e73b6c107d5f5d
AI model probesArechClient2DVR compromiseEncystPHPFortinetFreePBXIoTLumma StealerMicrosoft Patch TuesdaySectop RATclaudehuggingfacemalwarenetwork probesopenclawpatchesscanningthreat intelligencewebshell
What happened
ISC SANS diary RSS entries (Apr 13–17, 2026) covering multiple active threats and observations: a reported Lumma Stealer infection delivering the Sectop RAT (ArechClient2); discussion of compromised DVRs and how to find them in the wild; widespread scanning activity probing AI model endpoints (e.g., claude, openclaw, huggingface) beginning ~2026-03-10; a large Microsoft Patch Tuesday (April 2026) with many fixes; and scans looking for the EncystPHP webshell (noted by Fortinet) commonly used against vulnerable FreePBX systems. Several daily “ISC Stormcast” podcast entries are also included.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- bbb6e13d08e28826d798e6aa272084b48599a9dbd514061902e73b6c107d5f5d
- Enrichment time
- 2026-04-19T19:23:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.