ISC Stormcast For Wednesday, April 15th, 2026 https://isc.sans.edu/podcastdetail/9892, (Wed, Apr 15th)

2026-04-15T13:23:48Zdd8cf09f194608a7425491f3f433d7af42f79526aef22f59668cb6d4b547aa5b
TeamPCPTrivyUNC6780ai-probingcisco-source-codedata-breachdshieldencystphpfreepbxhoneypotisc-sansjavascript-obfuscationmalwaremicrosoft-patch-tuesdaypassword-reusephishingreconnaissancesupply-chainthreat-actorvulnerability-managementwebshell

What happened

This ISC SANS diary bundle (Apr 8–15, 2026) highlights multiple active threats and notable events: widespread scanning for AI model endpoints (probes for Claude, OpenClaw, HuggingFace observed since Mar 10 via DShield); a record‑sized Microsoft April 2026 Patch Tuesday (many fixes reported); scans for the EncystPHP webshell (noted targeting FreePBX instances); discovery of obfuscated JavaScript delivered via phishing RAR archives (low AV detection on VT); analysis of numeric/year patterns in passwords seen in honeypot collections; and an update to the TeamPCP supply‑chain campaign reporting a盗

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
dd8cf09f194608a7425491f3f433d7af42f79526aef22f59668cb6d4b547aa5b
Enrichment time
2026-04-15T13:23:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ISC Stormcast For Wednesday, April 15th, 2026 https://isc.sans.edu/podcastdetail/9892, (Wed, Apr 15th) · Baitaphish