ISC Stormcast For Tuesday, May 19th, 2026 https://isc.sans.edu/podcastdetail/9936, (Tue, May 19th)

2026-05-19T07:23:42Z5af54b7f2151f556e65e0ed2c18eff0593bbf096eaf7c97b25ccddf06f81efa0
checkmarxchromium-edgeemail-securityexe-trafficjenkins-plugin-compromiselink-preview-bypassmalware-librariesmicrosoft-patch-tuesdaymini-shai-huludnpmoutlookproxyingpypisignaturessupply-chainteampcpweb-fraudworm

What happened

Collection of ISC SANS diary items (May 2026) covering multiple active threats and advisories: a TeamPCP supply-chain campaign that includes an officially confirmed compromise of a Checkmarx Jenkins plugin and a new self‑spreading “Mini Shai‑Hulud” worm targeting npm and PyPI; Microsoft May 2026 Patch Tuesday fixing 137 vulnerabilities (including 137 Chromium/Edge issues); a simple bypass of Outlook Junk-folder link preview that exposes true link destinations; notes on new malware libraries requiring updated signatures; analyses of website fraud mechanics; and discussion of techniques for prox

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
5af54b7f2151f556e65e0ed2c18eff0593bbf096eaf7c97b25ccddf06f81efa0
Enrichment time
2026-05-19T07:23:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.