ISC Stormcast For Friday, May 29th, 2026 https://isc.sans.edu/podcastdetail/9950, (Fri, May 29th)
2026-05-29T07:23:44Z•50d48f18ae54f1c7113ca92f0ba8cbc74f9753f736cb24c24a65f5411491ed82
ACR stealerAkira ransomwareClaude impersonationDShieldGitHub compromiseMicrosoft AccessPython packagesSANS ISCTeamPCPVBAWindows Event Logfirewall logsforensicslog analysisphishingransomwaresoftware supply chainstormcast podcastsupply chaintelemetrytrojanized SDK
What happened
SANS ISC diary entries (May 25–29, 2026) covering multiple topics: an analysis of a year of files uploaded to DShield sensors showing upload peaks in Dec 2025–Feb 2026; a forensic-focused reconstruction of an Akira ransomware kill chain emphasizing correlating perimeter firewall and Windows event logs to answer pre‑impact questions; reporting on the TeamPCP supply‑chain campaign that trojanized a Microsoft‑published Python SDK, expanded across three package ecosystems, reached GitHub internal codebases, and published its framework; a potential ACR stealer page impersonating “Claude”; a note on
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 50d48f18ae54f1c7113ca92f0ba8cbc74f9753f736cb24c24a65f5411491ed82
- Enrichment time
- 2026-05-29T07:23:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.