How often are redirects used in phishing in 2026?, (Mon, Apr 6th)
2026-04-07T01:23:50Z•dc3eb105462d92b688b1c14b5c5da791f2a453b19c8ae67a6c1f5b81ed597ac4
ADSCERT-EUCVE-2025-30208MandiantSaaSSportradarTeamPCPViteapplication-control-bypasscloud-breachdata-exfiltrationexploitationmalwareopen-redirectsphishingregistry-persistencesupply-chain-compromise
What happened
Collection of ISC SANS diary items (late Mar–early Apr 2026) covering multiple active threats: ongoing TeamPCP supply‑chain campaign (Updates 005/006) with CERT‑EU confirmation of a European Commission cloud breach and Mandiant reporting impact across 1,000+ SaaS environments; observations of attackers actively hunting and abusing open redirects in phishing; active attempts to exploit Vite (CVE-2025-30208); discussion of malware using registry/ADS for persistence; and research on application‑control bypasses used for data exfiltration. Overall this feed highlights active, broad-impact supply‑s
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- dc3eb105462d92b688b1c14b5c5da791f2a453b19c8ae67a6c1f5b81ed597ac4
- Enrichment time
- 2026-04-07T01:23:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.