ISC Stormcast For Wednesday, June 17th, 2026 https://isc.sans.edu/podcastdetail/9976, (Wed, Jun 17th)

2026-06-17T07:23:44Z413485d64084ffc09850d30cad8ef7c8b67aa6c743f34999cdc52143b09e30ce
CSPChromiumEdgeJavaScriptMicrosoftRATRemcosVHDXX-Frame-OptionsZIPdiaryevil-msiframing-protectioniscmalwarepatch-tuesdaysanssecurity-headersthreat-intelvulnerabilities

What happened

Collection of ISC SANS diary entries (June 9–17, 2026). Highlights: a reader-submitted malicious ZIP (SHA256: a0104921a2d37ab87482ac9a9f5c3713479c118846c3e999178e75b81620c094) contains a VHDX that, when mounted by modern Windows, exposes a malicious JavaScript that leads to a Remcos RAT. Other entries cover statistical analysis of malicious MSI background images, a study of framing protection headers (X-Frame-Options/CSP frame-ancestors) across popular sites, and the Microsoft June 2026 Patch Tuesday (204 vulnerabilities, 38 critical, 3 previously disclosed; six affect cloud services withoutユー

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
413485d64084ffc09850d30cad8ef7c8b67aa6c743f34999cdc52143b09e30ce
Enrichment time
2026-06-17T07:23:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.