ISC Stormcast For Thursday, April 30th, 2026 https://isc.sans.edu/podcastdetail/9912, (Thu, Apr 30th)
2026-04-30T13:23:53Z•bd3a151dffc4423d025e4d77791155cca5bcff80af9c4ededf6fb224231bd52d
AppleBitwardenBitwarden-CLICVE-2026-28950CVE-2026-33634CanisterSprawlCheckmarxCiscoKEVKICSLibredtailPyPISANDCLOCKTeamPCPTrivyUNC6780credential-thefthoneypotiOSnotification-servicenpm-wormpatchreconnaissance','X-Vercel-Set-Bypass-Cookiesupply-chainxinference
What happened
SANS ISC diary posts (late April 2026) highlight a significant TeamPCP supply-chain campaign update describing a 26-day pause ending with three concurrent compromises (Checkmarx KICS, Bitwarden CLI cascade, xinference PyPI), identification of a CanisterSprawl npm worm, and continued credential-theft activity tied to Trivy-linked credentials and Cisco source code exfiltration. Google GTIG designated the operators UNC6780 and the credential stealer as SANDCLOCK. The update references a lapsed KEV remediation window for CVE-2026-33634. Separately, Apple released iOS/iPadOS updates (26.4.2 / 18.7.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- bd3a151dffc4423d025e4d77791155cca5bcff80af9c4ededf6fb224231bd52d
- Enrichment time
- 2026-04-30T13:23:53Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.