How often are redirects used in phishing in 2026?, (Mon, Apr 6th)

2026-04-07T01:23:50Zdc3eb105462d92b688b1c14b5c5da791f2a453b19c8ae67a6c1f5b81ed597ac4
ADSCERT-EUCVE-2025-30208MandiantSaaSSportradarTeamPCPViteapplication-control-bypasscloud-breachdata-exfiltrationexploitationmalwareopen-redirectsphishingregistry-persistencesupply-chain-compromise

What happened

Collection of ISC SANS diary items (late Mar–early Apr 2026) covering multiple active threats: ongoing TeamPCP supply‑chain campaign (Updates 005/006) with CERT‑EU confirmation of a European Commission cloud breach and Mandiant reporting impact across 1,000+ SaaS environments; observations of attackers actively hunting and abusing open redirects in phishing; active attempts to exploit Vite (CVE-2025-30208); discussion of malware using registry/ADS for persistence; and research on application‑control bypasses used for data exfiltration. Overall this feed highlights active, broad-impact supply‑s

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
dc3eb105462d92b688b1c14b5c5da791f2a453b19c8ae67a6c1f5b81ed597ac4
Enrichment time
2026-04-07T01:23:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.