ISC Stormcast For Thursday, June 11th, 2026 https://isc.sans.edu/podcastdetail/9968, (Thu, Jun 11th)

2026-06-12T01:23:47Z0b3ac270f4d19da9551e8962d1c6ab949ac340ca1d4140915c26550d93452ddc
chromiumcloudcriticalcspedgeframe-ancestorsjpeg payloadmalwaremicrosoftmini shai-huludmsipatch tuesdayphishingsans iscsteganographysupply chainsupply-chain compromiseteampcpthreat intelligencetrancovulnerabilitiesweb security headerswetransferx-frame-optionszero-day disclosure

What happened

SANS Internet Storm Center summaries (early June 2026) covering multiple topics: Microsoft June 2026 Patch Tuesday released fixes for 204 vulnerabilities (38 critical; three previously disclosed), including 360 Chromium vulnerabilities incorporated into Edge and six cloud-impact issues requiring no user action. Ongoing TeamPCP supply-chain campaign continues to evolve, with the Mini Shai-Hulud framework open-sourced and wider adversary adoption. Observations of a resurgence in a phishing/malware technique embedding MSI-branded payloads in JPEGs (delivered via WeTransfer links) were reported. A

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
0b3ac270f4d19da9551e8962d1c6ab949ac340ca1d4140915c26550d93452ddc
Enrichment time
2026-06-12T01:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.