ISC Stormcast For Thursday, April 16th, 2026 https://isc.sans.edu/podcastdetail/9894, (Thu, Apr 16th)

2026-04-16T13:23:48Ze418e39f548a74b9ea88f9b50e68bba2147b3f7a3969410942c17a58276c3977
AI-model-probesDShieldDVREncystPHPFreePBXIoTMicrosoft-Patch-TuesdayRARmalwareobfuscated-javascriptphishingscanningthreat-intelvulnerability-managementwebshell

What happened

ISC SANS diary roundup (Apr 9–16, 2026): multiple active threat trends observed — DShield sensors started seeing broad probes for AI-model endpoints (claude, huggingface, etc.) beginning 2026-03-10; scanning and exploitation activity targeting IoT/DVR devices and compromised DVRs are discussed; attackers are scanning for and deploying the EncystPHP webshell (noted targeting vulnerable FreePBX instances); a phishing campaign delivered an obfuscated JavaScript payload inside a RAR (JS file SHA256: a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788b74c5285) with low AV detection; and April

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
e418e39f548a74b9ea88f9b50e68bba2147b3f7a3969410942c17a58276c3977
Enrichment time
2026-04-16T13:23:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.