ISC Stormcast For Wednesday, April 15th, 2026 https://isc.sans.edu/podcastdetail/9892, (Wed, Apr 15th)
2026-04-15T13:23:48Z•dd8cf09f194608a7425491f3f433d7af42f79526aef22f59668cb6d4b547aa5b
TeamPCPTrivyUNC6780ai-probingcisco-source-codedata-breachdshieldencystphpfreepbxhoneypotisc-sansjavascript-obfuscationmalwaremicrosoft-patch-tuesdaypassword-reusephishingreconnaissancesupply-chainthreat-actorvulnerability-managementwebshell
What happened
This ISC SANS diary bundle (Apr 8–15, 2026) highlights multiple active threats and notable events: widespread scanning for AI model endpoints (probes for Claude, OpenClaw, HuggingFace observed since Mar 10 via DShield); a record‑sized Microsoft April 2026 Patch Tuesday (many fixes reported); scans for the EncystPHP webshell (noted targeting FreePBX instances); discovery of obfuscated JavaScript delivered via phishing RAR archives (low AV detection on VT); analysis of numeric/year patterns in passwords seen in honeypot collections; and an update to the TeamPCP supply‑chain campaign reporting a盗
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- dd8cf09f194608a7425491f3f433d7af42f79526aef22f59668cb6d4b547aa5b
- Enrichment time
- 2026-04-15T13:23:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.