ISC Stormcast For Tuesday, April 28th, 2026 https://isc.sans.edu/podcastdetail/9908, (Tue, Apr 28th)

2026-04-28T13:23:55Zd449a8ed1396df9e82a523e75da38eb73cb507626e6299d5562e39c734877e79
AppleBitwarden CLICanisterSprawlCheckmarx KICSCisco source code theftEPSSPyPISANDCLOCKTeamPCPTelegram tdataTrivyUNC6780credential-harvestingcredential-monetizationcredential-theftiOSiPadOSnotification-servicesnpm wormsupply-chainvulnerability-managementwav-malwarexinference

What happened

Collection of SANS ISC diary items (Apr 20–28, 2026) covering an active supply‑chain campaign (TeamPCP) that resumed after a 26‑day pause with three concurrent compromises — Checkmarx KICS, Bitwarden CLI cascade, and xinference PyPI — plus identification of an npm worm (CanisterSprawl), return of Tier‑1 coverage, and continued credential‑monetization activity tied to UNC6780/SANDCLOCK and prior Trivy-linked Cisco source code theft. Also reports Apple released iOS/iPadOS updates fixing a Notification Services vulnerability (CVE-2026-28950), a discussion on CVE management with EPSS, a guest post

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
d449a8ed1396df9e82a523e75da38eb73cb507626e6299d5562e39c734877e79
Enrichment time
2026-04-28T13:23:55Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ISC Stormcast For Tuesday, April 28th, 2026 https://isc.sans.edu/podcastdetail/9908, (Tue, Apr 28th) · Baitaphish