ISC Stormcast For Tuesday, May 19th, 2026 https://isc.sans.edu/podcastdetail/9936, (Tue, May 19th)
2026-05-19T13:23:45Z•72397bb46d3d04558e3f281314b8131c4daa74dda4f3dbe85dffed41c15b9e74
checkmarxchromiumedgejenkins plugin compromiselink preview bypassmalware librariesmicrosoft patch tuesdaymini shai-huludnpmoutlookphishingproxying exe trafficpypisignaturessupply chainteampcpvulnerabilitieswebsite fraudworm
What happened
Collection of ISC SANS diary items (mid-May 2026) highlighting a noisy TeamPCP supply‑chain campaign: an officially confirmed compromise of a Checkmarx Jenkins plugin and emergence of a self‑spreading “Mini Shai‑Hulud” worm propagating across npm and PyPI. Microsoft’s May 2026 Patch Tuesday addressed 137 vulnerabilities plus 137 Chromium‑related issues affecting Edge. Other entries cover an Outlook Junk‑folder link‑preview bypass useful to phishing, new malware libraries requiring signature updates, website fraud analysis, and techniques for proxying EXE traffic.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 72397bb46d3d04558e3f281314b8131c4daa74dda4f3dbe85dffed41c15b9e74
- Enrichment time
- 2026-05-19T13:23:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.