ISC Stormcast For Wednesday, May 20th, 2026 https://isc.sans.edu/podcastdetail/9938, (Wed, May 20th)
2026-05-20T07:23:48Z•1b6c70652c440b30887f261697319cea0bdb6d69c13d5b70bcdd3161e15dee12
checkmarxemail-securityexe-trafficjenkinslink-preview-bypassmalware-librariesmini-shai-huludnpmoutlookphishingproxyingpypisupply-chainteampcpthreat-actortrivywebsite-fraudworm
What happened
SANS ISC diary feed (mid-May 2026) covering multiple security topics. Key item: TeamPCP supply-chain campaign escalation — an officially confirmed compromise of a Checkmarx Jenkins plugin and the emergence of a self‑spreading “Mini Shai‑Hulud” worm propagating via npm and PyPI (noted alongside the March Trivy disclosure). Other entries discuss new malware libraries (requiring signature updates), a simple bypass of Outlook’s link‑preview in the Junk folder that can expose link destinations, an analysis of website fraud techniques, and techniques for proxying EXE traffic to otherwise “unproxy-y
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 1b6c70652c440b30887f261697319cea0bdb6d69c13d5b70bcdd3161e15dee12
- Enrichment time
- 2026-05-20T07:23:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.