ISC Stormcast For Friday, May 29th, 2026 https://isc.sans.edu/podcastdetail/9950, (Fri, May 29th)

2026-05-30T19:23:47Z49184f768f08536e2e05c142fc3e5261543c33a44b2168d2cd9cdbcbc8f589cb
ai-impersonationakira-ransomwarecredential-stealerdshieldfirewall-logsforensicsgithub-compromisekill-chainmicrosoft-accesspackage-ecosystemsphishingpython-sdkransomwaresans-iscsoftware-supply-chainsupply-chainteamPCPthreat-telemetrytrojanized-packagevba-macroswindows-event-logs

What happened

SANS ISC diary entries (May 25–29, 2026) covering multiple operational-security topics: a forensic reconstruction of an Akira ransomware kill chain that emphasizes correlating perimeter firewall logs with Windows event logs to determine initial access and lateral movement; telemetry analysis of one year of files uploaded to DShield sensors showing a peak in malicious uploads during Dec 2025–Feb 2026; reporting on TeamPCP supply-chain activity through 2026-05-24, including operation across three package ecosystems, trojanization of an officially Microsoft-published Python SDK, reaching GitHub’s

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
49184f768f08536e2e05c142fc3e5261543c33a44b2168d2cd9cdbcbc8f589cb
Enrichment time
2026-05-30T19:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.