ISC Stormcast For Wednesday, May 20th, 2026 https://isc.sans.edu/podcastdetail/9938, (Wed, May 20th)

2026-05-20T07:23:48Z1b6c70652c440b30887f261697319cea0bdb6d69c13d5b70bcdd3161e15dee12
checkmarxemail-securityexe-trafficjenkinslink-preview-bypassmalware-librariesmini-shai-huludnpmoutlookphishingproxyingpypisupply-chainteampcpthreat-actortrivywebsite-fraudworm

What happened

SANS ISC diary feed (mid-May 2026) covering multiple security topics. Key item: TeamPCP supply-chain campaign escalation — an officially confirmed compromise of a Checkmarx Jenkins plugin and the emergence of a self‑spreading “Mini Shai‑Hulud” worm propagating via npm and PyPI (noted alongside the March Trivy disclosure). Other entries discuss new malware libraries (requiring signature updates), a simple bypass of Outlook’s link‑preview in the Junk folder that can expose link destinations, an analysis of website fraud techniques, and techniques for proxying EXE traffic to otherwise “unproxy­-y

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
1b6c70652c440b30887f261697319cea0bdb6d69c13d5b70bcdd3161e15dee12
Enrichment time
2026-05-20T07:23:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.