ISC Stormcast For Tuesday, June 9th, 2026 https://isc.sans.edu/podcastdetail/9964, (Tue, Jun 9th)
2026-06-09T07:23:44Z•8197ec26cadf2f7c421ab06a99594720b8fdcffedb11f7af85ff2b394e58d81c
api-exposurejpegmalwaremini-shai-huludmsi-themed-luresopen-source-frameworkphishingsans-iscscanningsteganographysupply-chainsupply-chain-compromisesvgswagger.jsonteampcpthreat-actors
What happened
SANS ISC feed (early June 2026) highlights active and evolving threats: an ongoing TeamPCP supply-chain campaign that has been publicly tracked and whose Mini Shai-Hulud framework was open-sourced and adopted by other attackers (now drawing formal US government attention); renewed use of steganographic payloads embedded in images (MSI-branded JPEGs) delivered via email/WeTransfer; a spike in phishing emails delivering malicious SVG files as inline images; and continued scanning for exposed swagger.json endpoints that can reveal or enable API abuse. These items indicate increased tooling/techni
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 8197ec26cadf2f7c421ab06a99594720b8fdcffedb11f7af85ff2b394e58d81c
- Enrichment time
- 2026-06-09T07:23:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.