ISC Stormcast For Thursday, April 30th, 2026 https://isc.sans.edu/podcastdetail/9912, (Thu, Apr 30th)

2026-05-01T01:23:47Zeffe0bd51a22f61646f8c868b5276d945afeae2b0e1c9554bc4955ed027b6ac7
applebitwardencanistersprawlcheckmarxcredential-thefthoneypotioskicslibredtailnotification-service-vulnnpm-wormpypireconnaissancesandclocksupply-chainteampcptrivyunc6780x-vercel-set-bypass-cookiexinference

What happened

SANS ISC diary roundup (Apr 23–30, 2026): Key item is a TeamPCP supply‑chain campaign update reporting a renewed activity window with three concurrent compromises (Checkmarx KICS, Bitwarden CLI cascade, xinference PyPI), identification of a CanisterSprawl npm worm, and ongoing credential theft linked to Trivy-related credentials (previously associated with CVE-2026-33634). Also noted: honeypot/recon activity including odd web requests and HTTP traffic containing an X-Vercel-Set-Bypass-Cookie header, a guest diary on the danger of Libredtail, and Apple releasing iOS/iPadOS patches addressing CV

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
effe0bd51a22f61646f8c868b5276d945afeae2b0e1c9554bc4955ed027b6ac7
Enrichment time
2026-05-01T01:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.