ISC Stormcast For Monday, April 13th, 2026 https://isc.sans.edu/podcastdetail/9888, (Mon, Apr 13th)

2026-04-13T07:23:48Zf58620821ddff1ed6e07e3431e1ff5aa8aad62a90538b520cb1cdb5d7ab3738b
malware-sampleobfuscated-javascriptphishingsha256:a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788b

What happened

SANS ISC diary roundup (Apr 6–13, 2026) covering multiple operational-threat topics: a phishing-delivered obfuscated JavaScript sample (cbmjlzan.JS, SHA256:a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788b74c5285) with low AV detection on VirusTotal; an updated TeamPCP supply-chain campaign report noting Cisco source code theft via a Trivy-linked breach and Google GTIG tracking TeamPCP as UNC6780 (consolidating developments through Apr 8, 2026); research on honeypot fingerprinting activity; analysis of web shells and common weak/default credentials used by attackers; a study of number/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
f58620821ddff1ed6e07e3431e1ff5aa8aad62a90538b520cb1cdb5d7ab3738b
Enrichment time
2026-04-13T07:23:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.