ISC Stormcast For Tuesday, April 28th, 2026 https://isc.sans.edu/podcastdetail/9908, (Tue, Apr 28th)
2026-04-28T13:23:55Z•d449a8ed1396df9e82a523e75da38eb73cb507626e6299d5562e39c734877e79
AppleBitwarden CLICanisterSprawlCheckmarx KICSCisco source code theftEPSSPyPISANDCLOCKTeamPCPTelegram tdataTrivyUNC6780credential-harvestingcredential-monetizationcredential-theftiOSiPadOSnotification-servicesnpm wormsupply-chainvulnerability-managementwav-malwarexinference
What happened
Collection of SANS ISC diary items (Apr 20–28, 2026) covering an active supply‑chain campaign (TeamPCP) that resumed after a 26‑day pause with three concurrent compromises — Checkmarx KICS, Bitwarden CLI cascade, and xinference PyPI — plus identification of an npm worm (CanisterSprawl), return of Tier‑1 coverage, and continued credential‑monetization activity tied to UNC6780/SANDCLOCK and prior Trivy-linked Cisco source code theft. Also reports Apple released iOS/iPadOS updates fixing a Notification Services vulnerability (CVE-2026-28950), a discussion on CVE management with EPSS, a guest post
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- d449a8ed1396df9e82a523e75da38eb73cb507626e6299d5562e39c734877e79
- Enrichment time
- 2026-04-28T13:23:55Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.