Obfuscated JavaScript or Nothing, (Thu, Apr 9th)
2026-04-12T07:23:56Z•bceb351d16e3759d9e83032eb03c09f6f67784a653898452022d6086b7e89498
CISA-KEVCiscoSaaS-compromiseTeamPCPTrivyUNC6780credential-exposuredata-thefthoneypot-fingerprintinglow-detectionmalwareobfuscated-javascriptopen-redirectspassword-analyticsphishingrar-attachmentsupply-chainvirus-totalwebshells
What happened
Collection of SANS ISC diary entries (early April 2026) covering multiple active threats and observations: a phishing-delivered obfuscated JavaScript (cbmjlzan.JS, SHA256:a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788b74c5285) distributed inside a RAR and detected by only ~15 AV engines on VirusTotal; an ongoing TeamPCP supply-chain campaign update reporting Cisco source-code theft via a Trivy-linked breach, Google GTIG tracking TeamPCP as UNC6780, and related widespread SaaS compromises (no separate CISA KEV advisory at deadline); and operational telemetry covering honeypot-fingerpr
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- bceb351d16e3759d9e83032eb03c09f6f67784a653898452022d6086b7e89498
- Enrichment time
- 2026-04-12T07:23:56Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.