ISC Stormcast For Thursday, April 9th, 2026 https://isc.sans.edu/podcastdetail/9886, (Thu, Apr 9th)
2026-04-10T01:23:46Z•ddf62d1a8131472f1c89512906618ca38ef5dd30b152634170069b3dcc7e1b71
arbitrary-file-writecert-eucisaciscocredential-thefteuropean-commissiongoogle-gtighoneypothoneypot-fingerprintingkevlitellmmandiantmercor-aiopen-redirectspassword-analyticsphishingremote-code-executionsource-code-theftsportradarsupply-chain-compromiseteampcptrivyunc6780webshellswiz
What happened
The ISC SANS diary batch (Apr 6–9, 2026) highlights an ongoing, high-impact supply-chain campaign (TeamPCP) with Update 007 reporting Cisco source-code theft via a Trivy-linked breach and Google GTIG tracking the actor as UNC6780; prior updates describe CERT-EU confirmation of a European Commission cloud breach, Sportradar disclosures, Mandiant’s estimate of 1,000+ compromised SaaS environments, and other victim disclosures (e.g., Mercor AI, Wiz). Other entries cover operational tradecraft and defensive topics: measurements of number/year usage in leaked/honeypot-captured passwords, honeypot-f
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- ddf62d1a8131472f1c89512906618ca38ef5dd30b152634170069b3dcc7e1b71
- Enrichment time
- 2026-04-10T01:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.