ISC Stormcast For Wednesday, April 15th, 2026 https://isc.sans.edu/podcastdetail/9892, (Wed, Apr 15th)

2026-04-15T07:23:49Zc969d33e29c88336df89b8159273542f2de1cb19f4eb16d87c01aab6aadfe1ae
ai-model-scanningcvesdshieldencystphpfreepbxioc:sha256:a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942bmalwaremicrosoft-patch-tuesdayobfuscated-javascriptphishingprobingwebshell

What happened

Collection of SANS ISC diary entries from April 2026 summarizing multiple active security trends and incidents: DShield sensors observed widespread scanning/probing for AI model endpoints (examples: claude, huggingface, openclaw) beginning March 10, 2026; Microsoft Patch Tuesday (April 2026) contained an unusually large set of fixes; scans detected targeting the EncystPHP webshell (noted against vulnerable FreePBX systems); phishing-delivered obfuscated JavaScript (SHA256 a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788b74c5285) with low AV detection was observed; analysis of password/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
c969d33e29c88336df89b8159273542f2de1cb19f4eb16d87c01aab6aadfe1ae
Enrichment time
2026-04-15T07:23:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.