ISC Stormcast For Thursday, April 16th, 2026 https://isc.sans.edu/podcastdetail/9894, (Thu, Apr 16th)
2026-04-16T13:23:48Z•e418e39f548a74b9ea88f9b50e68bba2147b3f7a3969410942c17a58276c3977
AI-model-probesDShieldDVREncystPHPFreePBXIoTMicrosoft-Patch-TuesdayRARmalwareobfuscated-javascriptphishingscanningthreat-intelvulnerability-managementwebshell
What happened
ISC SANS diary roundup (Apr 9–16, 2026): multiple active threat trends observed — DShield sensors started seeing broad probes for AI-model endpoints (claude, huggingface, etc.) beginning 2026-03-10; scanning and exploitation activity targeting IoT/DVR devices and compromised DVRs are discussed; attackers are scanning for and deploying the EncystPHP webshell (noted targeting vulnerable FreePBX instances); a phishing campaign delivered an obfuscated JavaScript payload inside a RAR (JS file SHA256: a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788b74c5285) with low AV detection; and April
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- e418e39f548a74b9ea88f9b50e68bba2147b3f7a3969410942c17a58276c3977
- Enrichment time
- 2026-04-16T13:23:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.