ISC Stormcast For Wednesday, May 20th, 2026 https://isc.sans.edu/podcastdetail/9938, (Wed, May 20th)

2026-05-21T01:23:47Z10cb95251580fb282043471f9e92e2d8761bef11c00412444a31c8e8be26cac6
CheckmarxJenkinsMini Shai-HuludPyPITeamPCPexe-trafficlink-preview-bypassmalwarenpmoutlookpackage-manager-compromisephishingproxyingsupply-chainwebsite-fraudworm

What happened

SANS ISC diary (mid-May 2026) highlights a noisy resurgence of the TeamPCP supply-chain campaign through 2026-05-17, including an officially confirmed compromise of a Checkmarx Jenkins plugin and a new self‑spreading “Mini Shai‑Hulud” worm propagating via npm and PyPI packages. Other entries cover new malware libraries requiring updated signatures, a simple bypass of Outlook link-preview protections in the Junk folder (phishing/triage implication), analysis of website fraud, and techniques for proxying EXE traffic to a proxy.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
10cb95251580fb282043471f9e92e2d8761bef11c00412444a31c8e8be26cac6
Enrichment time
2026-05-21T01:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ISC Stormcast For Wednesday, May 20th, 2026 https://isc.sans.edu/podcastdetail/9938, (Wed, May 20th) · Baitaphish