ISC Stormcast For Wednesday, April 15th, 2026 https://isc.sans.edu/podcastdetail/9892, (Wed, Apr 15th)
2026-04-15T07:23:49Z•c969d33e29c88336df89b8159273542f2de1cb19f4eb16d87c01aab6aadfe1ae
ai-model-scanningcvesdshieldencystphpfreepbxioc:sha256:a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942bmalwaremicrosoft-patch-tuesdayobfuscated-javascriptphishingprobingwebshell
What happened
Collection of SANS ISC diary entries from April 2026 summarizing multiple active security trends and incidents: DShield sensors observed widespread scanning/probing for AI model endpoints (examples: claude, huggingface, openclaw) beginning March 10, 2026; Microsoft Patch Tuesday (April 2026) contained an unusually large set of fixes; scans detected targeting the EncystPHP webshell (noted against vulnerable FreePBX systems); phishing-delivered obfuscated JavaScript (SHA256 a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788b74c5285) with low AV detection was observed; analysis of password/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- c969d33e29c88336df89b8159273542f2de1cb19f4eb16d87c01aab6aadfe1ae
- Enrichment time
- 2026-04-15T07:23:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.